Florida’s New Data Breach Notice Law

Florida has a new law to combat the recent surge of data security breaches involving sensitive personal information. On July 1, 2014, Florida’s current data breach notification statute will be replaced by the Florida Information Protection Act of 2014 (Act). Though similar to Florida’s current statute, the Act makes some significant changes that businesses must incorporate into their data security practices and procedures.

Under the Act, sole proprietors, partnerships, corporations, trusts, estates, cooperatives, associations and other commercial entities that acquire, maintain, store or use personal information (Covered Entities) are required to take reasonable measures to protect and secure such personal information. The Act broadens the definition of Personal Information to include:

  • An individual’s first name or first initial and last name in combination with that individual’s social security number, driver license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity. (Broader)
  • Financial account, credit and debit card numbers, in combination with any security code, access code or password.
  • Information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional. (New)
  • An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual. (New)
  • A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account. (New)

Like the current statute, Personal Information does not include information that is encrypted, secured or modified by any other method or technology that removes personally identifying elements or that otherwise renders the information unusable.

In the event of a breach, Covered Entities must follow one or more of the Act’s various notice requirements. The Act generally defines a breach as unauthorized access of electronic data containing personal information. Covered Entities must notify each individual in Florida whose Personal Information was, or is reasonably believed to have been, breached no later than 30 days after the Covered Entity determines that a breach occurred or has reason to believe a breach occurred. Under the current statute, Covered Entities had 45 days to provide notice.

This notice, which may be sent by mail or e-mail, must include:

  • The date, estimated date or estimated date range of the breach
  • A description of the Personal Information that was or may have been accessed during the breach
  • Contact information that individuals can use to inquire about the breach

If a Covered Entity is required to notify more than 1,000 individuals at a single time, the Covered Entity must also provide notice to all national consumer reporting agencies. If a breach affects 500 or more individuals in Florida, the Department of Legal Affairs must be notified no later than 30 days after the Covered Entity determines that a breach occurred or had reason to believe a breach occurred. This is a new notice requirement.

If a Covered Entity uses a third-party vendor to maintain, store or process Personal Information, then that third-party agent must notify the Covered Entity no later than 10 days after the third-party agent determines that a breach occurred or had reason to believe a breach occurred. Though a third-party agent may provide the required notices, the Covered Entity is ultimately responsible for compliance with the Act.

The Act also requires Covered Entities and their third-party agents to take all reasonable measures to dispose, or arrange for the disposal, of customer records containing Personal Information within its custody or control when they are no longer retained. Disposal shall involve shredding, erasing, or otherwise modifying the records to make Personal Information unreadable or undecipherable through any means.

Unlike the general descriptions provided in this article, the Act is highly technical and very specific. Though the Act does not create a private cause of action, civil penalties of up to $500,000 should be enough motivation for Covered Entities to learn more about Florida’s new law and ways to limit the new risks with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Developing a Cybersecurity Framework

In February 2013, President Obama issued Executive Order 13636 on Improving Critical Infrastructure Cybersecurity. This Order calls for the development of a framework of industry standards and best practices to help organizations manage increasing cybersecurity risks. On February 12, 2014, the National Institute of Standards and Technology (NIST) responded to the President’s order with its Cybersecurity Framework.

The Cybersecurity Framework, which was created in collaboration with the private sector, focuses on using business drivers to guide cybersecurity activities. It is a risk-based approach that uses common language to address and manage cybersecurity risks in a business-specific, cost effective way. This voluntary framework is made up of three parts, each of which reinforces the connection between business drivers and cybersecurity activities.

The Framework Core provides a set of activities designed to achieve specific cybersecurity outcomes. The core is made up of five broad functions that help organizations express their management of cybersecurity risks.

  • Identify: Develop organizational understanding to manage cybersecurity risks to systems, assets, data and capabilities.
  • Protect: Develop and implement appropriate safeguards to ensure delivery of critical infrastructure services.
  • Detect: Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.
  • Respond: Develop and implement appropriate activities to respond to a cybersecurity event.
  • Recover: Develop and implement appropriate activities to maintain operations and restore capabilities or services impaired by a cybersecurity event.

Framework Implementation Tiers provide context on how organizations view cybersecurity risks and the processes in place to manage that risk. Tiers are used to describe an organization’s commitment and sophistication in managing cybersecurity risks. They also describe the extent to which cybersecurity risk management is informed by business needs and integrated into an organization’s overall risk management practices.

The four tiers reflect a progression from informal, reactive responses to cybersecurity risks to approaches that are agile and risk-informed.

  • Tier 1 (Partial)
  • Tier 2 (Risk Informed)
  • Tier 3 (Repeatable)
  • Tier 4 (Adaptive)

Determining which tier applies to an organization depends on current risk management practices, threat environment, regulatory requirements, business objectives and organizational constraints. However, the NIST notes that tiers do not represent maturity levels, so progression to higher tiers is encouraged when it would reduce cybersecurity risks in a cost effective manner.

The Framework Profile is the alignment of an organization’s cybersecurity framework with its business requirements, risk tolerance and resources. Profiles enable organizations to establish a roadmap for reducing cybersecurity risk that meets organizational goals, implements best practices, considers regulatory requirements and reflects priorities.

Profiles can be used to describe an organization’s current state or target state of cybersecurity activities. Comparing current and target profiles can be used to identify gaps in an organization’s cybersecurity risk management practices. Given the need for flexibility, the NIST did not impose or require a specific form or format that must be followed when creating and implementing a profile.

It is important to remember that the Cybersecurity Framework is voluntary and that, according to the NIST, it will not place additional regulatory requirements on businesses. Nevertheless, it should serve as a reminder that data security breaches can happen to any organization.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches

If you would like to subscribe to our newsletters please click here.

Preventing Data Security Breaches

Every business must be able to identify the likeliest source of a data security breach so that they can also identify how to prevent it. Is it an executive’s laptop computer, the copy machine or the office’s wireless network? Could it be something else? Since the first step to preventing a data security breach is understanding the risk, it’s time to learn more about your business’s sensitive data.

Effective data security starts by assessing the kind of information a business has and identifying who has access to it. Evaluating data security vulnerabilities requires an understanding of how sensitive data moves into, through, and out of a business, and who has or could have access to it. Here are some tips from the Federal Trade Commission.

Take Inventory

Take an inventory of all devices and equipment capable of storing sensitive data, such as laptop computers, mobile devices, flash drives, off-site servers, disks and digital copiers. Do employees work from home? If so, add their home computers to the list.

The type and location of sensitive data should also be inventoried. Don’t stop with the office’s filing cabinets and computer systems. Sensitive data may also be received from other sources, such as websites, contractors or call centers. Every possible source and destination for sensitive data must be considered.

Track Sensitive Data

It is important to know how the business obtains, stores, shares and disposes of sensitive data. Every department should be consulted, including sales, information technology, human resources and accounting. Don’t forget about contractors and other third-party service providers.

This process should provide a business with a thorough understanding of:

  • Who provides sen­sitive data? Does it come from customers, credit card companies, banks or other financial institutions, credit bureaus, job applicants, contractors, third-party service providers?
  • How is sensitive data received? Does it come via phone, fax, mail or email? Is there a website designed to request and receive sensitive data? Are there any other possible entry points?
  • What kind of sensitive data is collected? Do business operations require or permit collecting financial information (credit cards, bank accounts, credit reports), personally identifying information (drivers’ licenses, social security numbers) or medical information?
  • Where is sensitive data stored? Is it kept on disks, tapes, laptops, smartphones, tablets or other mobile devices? Employees’ personal computers or mobile devices? Where are data backups and copies stored?
  • Who can access sensitive data? Is access to sensitive data limited to only those who need it? Are there security measures in place? Is sensitive data protected against unauthorized access by contractors or other third-party service providers?

Throughout this process, pay particular attention to certain kinds of sensitive data. Identity thieves typically look for social security numbers, credit card and other financial information.

Organizations should also consider protecting against data security breaches with insurance.Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to subscribe to our newsletters please click here.