# WA OIC Technical Assistance Advisory 2017-01a: Two-day Notification Requirement for Security Breaches

> Washington · Agency guidance · In force

URL: https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2017_01a

## Section

- **Citation:** WA OIC Technical Assistance Advisory 2017-01a
- **Heading:** Two-day Notification Requirement for Security Breaches
- **Jurisdiction:** Washington
- **Kind:** Agency guidance
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** Washington OIC Technical Assistance Advisories and Emergency Orders / Two-day Notification Requirement for Security Breaches

## Text

STATE OF WASHINGTON
MIKE KREIDLER

Phone: (360) 725-7000
STATE INSURANCE COMMISSIONER

www.insurance.wa.gov

OFFICE OF
INSURANCE COMMISSIONER

Technical Assistance Advisory 2017-01A1 2

TO: All Licensees with Consumers residing in the State of Washington
FROM: Insurance Commissioner, Mike Kreidler

DATE: November 13, 2017

SUBJECT: Two Day Notification Requirement for Security Breaches

A security breach is the unauthorized acquisition of data that compromises the security,
confidentiality, or integrity of personal information maintained by a person or business.3

Two types of information are included within the security breach notification requirements:
 personal information that seems reasonably likely to subject consumers to a risk of
criminal activity, 4 and
 unsecured protected health information which compromises the security or privacy of the
consumer’s protected information.5

If a security breach of either of these types occurs, all licensees must notify the Insurance
Commissioner. The notification must be made in writing and must include the number of
consumers potentially affected and the actions being taken by the licensee.

For breaches of personal information, the notification must be made within two (2) business days
after determining that notification must be sent to consumers or customers, and that the breach
seems reasonably likely to subject consumers to a risk of criminal activity.6

1 This advisory is an interpretive policy statement released to advise the public of the OIC’s current opinions,
approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).
2 This TAA replaces and supercedes TAA 2017-01, issued on April 30, 2017.
3 RCW 19.255.010(4).
4 RCW 19.255.010(5); WAC 284-04-625(2)(a)
.6

1 This advisory is an interpretive policy statement released to advise the public of the OIC’s current opinions,
approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).
2 This TAA replaces and supercedes TAA 2017-01, issued on April 30, 2017.
3 RCW 19.255.010(4).
4 RCW 19.255.010(5); WAC 284-04-625(2)(a). Categories include social security number, driver’s license number
or Washington identification card number, and account number or credit or debit card number in combination with
any required security code, access code, or password that would permit access to an individual’s financial account.
5 WAC 284-04-625(2)(b).
6 WAC 284-04-625(2).

For breaches of unsecured protected health information, the notification must be made within two
(2) business days after the breach occurs. A security breach of unsecured protected health
information occurs the first day on which the breach is known to the licensee or the date when the
breach should have been known to the licensee if reasonable diligence had been used.7 A licensee
is considered to have knowledge of a breach if the event is known, or, by exercising reasonable
diligence, would have been known to any person who works for or is an agent of the licensee.8

Failure to notify the Insurance Commissioner is considered an unfair practice.9 It may result in
the levying of fines or an order to cease and desist the selling of insurance in the state of
Washington under RCW 48.30.010.

For a single breach of personal information that involves more than five hundred (500) Washington
residents, the person or business must notify the Washington State Attorney General’s Office.10
The breach of unprotected health information must also be reported and notification provided
pursuant to 45 C.F.R. 164.400 through 164.410
f insurance in the state of
Washington under RCW 48.30.010.

For a single breach of personal information that involves more than five hundred (500) Washington
residents, the person or business must notify the Washington State Attorney General’s Office.10
The breach of unprotected health information must also be reported and notification provided
pursuant to 45 C.F.R. 164.400 through 164.410.

For any questions related to security breach notifications, please contact Dan Halpin, Compliance
Analyst, at DanH@oic.wa.gov, or (360) 725-7089.

7 See 45 C.F.R. 164.404(a)(2).
8 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.
9 WAC 284-04-625(1)
10 Please refer to: http://www.atg.wa.gov/data-breach-notifications

## Nearby sections

- [WA OIC Advisory Notice (2020) Advisory notice regarding COVID-19 claims](https://www.frixlaw.com/law-library/statutes/WA_OIC_ADV_PROPERTY_CASUALTY_ADVISORY_NOTICE_COVID_19.md)
- [WA OIC Emergency Order (2026) Providing relief to Washington consumers from 2026 wildfires by addressing grace periods for nonpayment of premium and temporarily prohibiting cancellation and nonrenewal of property and automobile policies](https://www.frixlaw.com/law-library/statutes/WA_OIC_EO_WSR_26_16_059.md)
- [WA OIC Emergency Order No. 25-01 Providing relief to Washington consumers from December 2025 atmospheric river and winter weather event](https://www.frixlaw.com/law-library/statutes/WA_OIC_EO_25_01.md)
- [WA OIC Emergency Order No. 26-02 Ordering one-time refill of prescription medications prior to waiting periods, providing a minimum 60-day grace period for payment of premiums, prohibiting cancellations](https://www.frixlaw.com/law-library/statutes/WA_OIC_EO_26_02.md)
- [WA OIC Memorandum (2024-08-30) Aug. 30, 2024, memorandum regarding Aetna and Providence contract negotiations](https://www.frixlaw.com/law-library/statutes/WA_OIC_MEMO_AETNA_PROVIDENCE_BRIEFING_MEMO_AUG_2024.md)
- [WA OIC Technical Assistance Advisory 2015-01 Price Optimization, July 9, 2015](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2015_01.md)
- [WA OIC Technical Assistance Advisory 2016-01 Student Health Plans, March 28, 2016](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2016_01.md)
- [WA OIC Technical Assistance Advisory 2017-01 Two-day Notification Requirement for Security Breaches](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2017_01.md)
- [WA OIC Technical Assistance Advisory 2017-01a Two-day Notification Requirement for Security Breaches](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2017_01a.md)
- [WA OIC Technical Assistance Advisory 2018-01 Implementation credits as illegal inducement or rebate](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2018_01.md)
- [WA OIC Technical Assistance Advisory 2021-01 Unlicensed Producer Activity](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2021_01.md)
- [WA OIC Technical Assistance Advisory 2021-02 Commissioner's Universal Life Reserve Valuation Method](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2021_02.md)
- [WA OIC Technical Assistance Advisory 2021-03 Submission of Higher Education Student Health Insurance Plans](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2021_03.md)
- [WA OIC Technical Assistance Advisory 2021-04 Access to Inpatient Substance Use Disorder Treatment Under RCW 48.43.761](https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2021_04.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/WA_OIC_TAA_2017_01a. Check the current official text before relying on it. Not legal advice.
