Massachusetts 2023-2024 Regular Session

Massachusetts House Bill H76 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 1 of 1
22 HOUSE DOCKET, NO. 1851 FILED ON: 1/18/2023
33 HOUSE . . . . . . . . . . . . . . . No. 76
44 The Commonwealth of Massachusetts
55 _________________
66 PRESENTED BY:
77 Tram T. Nguyen
88 _________________
99 To the Honorable Senate and House of Representatives of the Commonwealth of Massachusetts in General
1010 Court assembled:
1111 The undersigned legislators and/or citizens respectfully petition for the adoption of the accompanying bill:
1212 An Act relative to protecting sensitive information from security breaches.
1313 _______________
1414 PETITION OF:
1515 NAME:DISTRICT/ADDRESS :DATE ADDED:Tram T. Nguyen18th Essex1/18/2023 1 of 7
1616 HOUSE DOCKET, NO. 1851 FILED ON: 1/18/2023
1717 HOUSE . . . . . . . . . . . . . . . No. 76
1818 By Representative Nguyen of Andover, a petition (accompanied by bill, House, No. 76) of Tram
1919 T. Nguyen relative to protecting sensitive information from security breaches. Advanced
2020 Information Technology, the Internet and Cybersecurity.
2121 The Commonwealth of Massachusetts
2222 _______________
2323 In the One Hundred and Ninety-Third General Court
2424 (2023-2024)
2525 _______________
2626 An Act relative to protecting sensitive information from security breaches.
2727 Be it enacted by the Senate and House of Representatives in General Court assembled, and by the authority
2828 of the same, as follows:
2929 1 SECTION 1. Section 1 of chapter 93H of the General Laws is hereby amended by
3030 2inserting after the definition of “Agency” the following definition:-
3131 3 “Biometric information”, a retina or iris scan, fingerprint, voiceprint, map or scan of hand
3232 4or face geometry, vein pattern, gait pattern, or other data generated from the specific technical
3333 5processing of an individual’s unique biological or physiological patterns or characteristics used
3434 6to authenticate or identify a specific individual; provided, however, that “biometric information”
3535 7shall not include:
3636 8 (i) a digital or physical photograph;
3737 9 (ii) an audio or video recording; or
3838 10 (iii) data generated from a digital or physical photograph, or an audio or video recording,
3939 11unless such data is generated to identify a specific individual. 2 of 7
4040 12 SECTION 2. Said section 1 of said chapter 93H is hereby further amended by striking out
4141 13the definition of “Breach of security” and inserting in place thereof the following definition:-
4242 14 “Breach of security”, the unauthorized acquisition or use of unencrypted electronic data,
4343 15or encrypted electronic data when the encryption key or security credential has been acquired;
4444 16provided, however, that such unauthorized acquisition or use compromises the security,
4545 17confidentiality, or integrity of personal information maintained by a person or agency; and
4646 18provided further, that a good faith but unauthorized acquisition of personal information by an
4747 19employee or agent of a person or agency for the lawful purposes of such person or agency is not
4848 20a breach of security unless the personal information is used in an unauthorized manner or subject
4949 21to further unauthorized disclosure.
5050 22 SECTION 3. Said section 1 of said chapter 93H is hereby further amended by inserting
5151 23after the definition of “Encrypted” the following definitions:-
5252 24 “Genetic information”, information, regardless of format, that:
5353 25 (i) results from the analysis of a biological sample of an individual, or from another
5454 26source enabling equivalent information to be obtained; and
5555 27 (ii) concerns an individual’s genetic material, including, but not limited to,
5656 28deoxyribonucleic acids (DNA), ribonucleic acids (RNA), genes, chromosomes, alleles, genomes,
5757 29alterations or modifications to DNA or RNA, single nucleotide polymorphisms (SNPs),
5858 30uninterpreted data that results from analysis of the biological sample or other source, and any
5959 31information extrapolated, derived, or inferred therefrom. 3 of 7
6060 32 "Health insurance information”, an individual’s health insurance policy number,
6161 33subscriber identification number, or any identifier used by a health insurer to identify the
6262 34individual.
6363 35 “Medical information”, information regarding an individual’s medical history, mental or
6464 36physical condition, or medical treatment or diagnosis by a healthcare professional.
6565 37 SECTION 4. Said section 1 of said chapter 93H is hereby further amended by striking out
6666 38the definition of “Personal information” and inserting in place thereof the following definition:-
6767 39 “Personal information” shall mean either of the following:
6868 40 (i) a resident’s first name and last name or first initial and last name in combination with
6969 41any 1 or more of the following data elements that relate to such resident:
7070 42 (A) social security number;
7171 43 (B) taxpayer identification number or identity protection personal identification number
7272 44issued by the Internal Revenue Service;
7373 45 (C) driver’s license number, passport number, military identification number, state-issued
7474 46identification card number, or other unique identification number issued by the government that
7575 47is commonly used to verify the identity of a specific individual;
7676 48 (D) financial account number, or credit or debit card number, with or without any
7777 49required security code, access code, personal identification number or password, that would
7878 50permit access to a resident's financial account;
7979 51 (E) biometric information; 4 of 7
8080 52 (F) date of birth;
8181 53 (G) genetic information;
8282 54 (H) health insurance information;
8383 55 (I) medical information; or
8484 56 (J) specific geolocation information; or
8585 57 (ii) a username or electronic mail address, in combination with a password or security
8686 58question and answer that would permit access to an online account.
8787 59 SECTION 5. Said section 1 of said chapter 93H is hereby further amended by inserting
8888 60after the definition of “Personal information” the following definition:-
8989 61 “Specific geolocation information”, information derived from technology including, but
9090 62not limited to, global positioning system level latitude and longitude coordinates or other
9191 63mechanisms that directly identify the specific location of an individual within a geographic area
9292 64that is equal to or less than the area of a circle with a radius of 1,850 feet; provided, however,
9393 65that “geolocation information” shall exclude the content of communications or any information
9494 66generated by or connected to advanced utility metering infrastructure systems or equipment for
9595 67use by a utility.
9696 68 SECTION 6. Section 2 of said chapter 93H is hereby amended by inserting the following
9797 69subsection:- 5 of 7
9898 70 (d) The rules and regulations adopted pursuant to this section shall be updated from time
9999 71to time to reflect any changes to the definitions of “breach of security” or “personal information”
100100 72in section 1.
101101 73 SECTION 7. Section 3 of said chapter 93H is hereby amended by inserting after the
102102 74words “unauthorized purpose” in subsection (b) the following words:- and such use or
103103 75acquisition presents a reasonably foreseeable risk of financial, physical, reputational or other
104104 76cognizable harm to the resident.
105105 77 SECTION 8. Said section 3 of said chapter 93H is hereby further amended by striking out
106106 78clause (vii) of subsection (b) and inserting in place thereof the following clause:- (vii) the type of
107107 79personal information compromised, including, but not limited to, any of the categories of
108108 80personal information set forth in subclauses (A) through (J) of clause (i) or in clause (ii) of the
109109 81definition of “personal information” in section 1.
110110 82 SECTION 9. Said section 3 of said chapter 93H is hereby further amended by striking out
111111 83the last sentence of the first paragraph of subsection (b) and inserting in place thereof the
112112 84following sentence:- A person who experienced a breach of security shall file a report with the
113113 85attorney general and the director of consumer affairs and business regulation certifying their
114114 86credit monitoring services comply with section 3A; provided, however, that such a report shall
115115 87not be required if the personal information compromised by the breach of security is medical
116116 88information or specific geolocation information.
117117 89 SECTION 10. Said section 3 of said chapter 93H is hereby further amended by striking
118118 90out the third paragraph of subsection (b) and inserting in place thereof the following paragraphs:- 6 of 7
119119 91 The notice to be provided to the resident shall include, but shall not be limited to: (i) the
120120 92date, estimated date, or estimated date range of the breach of security; (ii) the type of personal
121121 93information compromised, including, but not limited to, any of the categories of personal
122122 94information set forth in subclauses (A) through (J) of clause (i) or in clause (ii) of the definition
123123 95of “personal information” in section 1; (iii) a general description of the breach of security; (iv)
124124 96information that the resident can use to contact the person or agency reporting the breach of
125125 97security; (v) the resident’s right to obtain a police report; (vi) how a resident may request a
126126 98security freeze and the necessary information to be provided when requesting the security freeze;
127127 99(vii) a statement that there shall be no charge for a security freeze; (viii) mitigation services to be
128128 100provided pursuant to this chapter; and (ix) the toll-free numbers, address, and website for the
129129 101federal trade commission. The notice shall not need to include information pursuant to clauses
130130 102(vi) and (vii) if the personal information compromised by the breach of security is medical
131131 103information or specific geolocation information.
132132 104 The person or agency that experienced the breach of security shall provide a sample copy
133133 105of the notice it sent to consumers to the attorney general and the office of consumer affairs and
134134 106business regulation. A notice provided pursuant to this section shall not be delayed on grounds
135135 107that the total number of residents affected is not yet ascertained. In such case, and where
136136 108otherwise necessary to update or correct the information required, a person or agency shall
137137 109provide additional notice as soon as practicable and without unreasonable delay upon learning
138138 110such additional information.
139139 111 If the breach of security involves log-in credentials, pursuant to clause (ii) of the
140140 112definition of “personal information” in section 1, for an online account and no other personal
141141 113information, the person or agency may comply with this chapter by providing notice in electronic 7 of 7
142142 114or other form; provided, however, that such notice shall direct the resident whose personal
143143 115information has been breached to: (i) promptly change the resident’s password and security
144144 116question or answer, as applicable; or (ii) take other steps appropriate to protect the affected
145145 117online account with the person or agency and all other online accounts for which the resident
146146 118whose personal information has been breached uses the same username or electronic mail
147147 119address and password or security question or answer.
148148 120 If the breach of security involves the log-in credentials, pursuant to clause (ii) of the
149149 121definition of “personal information” in section 1, of an electronic mail account furnished by a
150150 122person or agency, the person or agency shall not comply with this chapter by providing notice of
151151 123the breach of security to such electronic mail address but shall instead provide notice by another
152152 124acceptable method of notice pursuant to this chapter or by clear and conspicuous notice delivered
153153 125to the resident online when the resident is connected to the online account from an internet
154154 126protocol address or online location from which the person or agency knows the resident
155155 127customarily accesses the account.