Massachusetts 2025-2026 Regular Session

Massachusetts House Bill H93 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 1 of 1
22 HOUSE DOCKET, NO. 707 FILED ON: 1/11/2025
33 HOUSE . . . . . . . . . . . . . . . No. 93
44 The Commonwealth of Massachusetts
55 _________________
66 PRESENTED BY:
77 Tram T. Nguyen
88 _________________
99 To the Honorable Senate and House of Representatives of the Commonwealth of Massachusetts in General
1010 Court assembled:
1111 The undersigned legislators and/or citizens respectfully petition for the adoption of the accompanying bill:
1212 An Act relative to protecting sensitive information from security breaches.
1313 _______________
1414 PETITION OF:
1515 NAME:DISTRICT/ADDRESS :DATE ADDED:Tram T. Nguyen18th Essex1/11/2025 1 of 7
1616 HOUSE DOCKET, NO. 707 FILED ON: 1/11/2025
1717 HOUSE . . . . . . . . . . . . . . . No. 93
1818 By Representative Nguyen of Andover, a petition (accompanied by bill, House, No. 93) of Tram
1919 T. Nguyen relative to protecting sensitive information from security breaches. Advanced
2020 Information Technology, the Internet and Cybersecurity.
2121 [SIMILAR MATTER FILED IN PREVIOUS SESSION
2222 SEE HOUSE, NO. 76 OF 2023-2024.]
2323 The Commonwealth of Massachusetts
2424 _______________
2525 In the One Hundred and Ninety-Fourth General Court
2626 (2025-2026)
2727 _______________
2828 An Act relative to protecting sensitive information from security breaches.
2929 Be it enacted by the Senate and House of Representatives in General Court assembled, and by the authority
3030 of the same, as follows:
3131 1 SECTION 1. Section 1 of chapter 93H of the General Laws is hereby amended by
3232 2inserting after the definition of “Agency” the following definition:-
3333 3 “Biometric information”, a retina or iris scan, fingerprint, voiceprint, map or scan of hand
3434 4or face geometry, vein pattern, gait pattern, or other data generated from the specific technical
3535 5processing of an individual’s unique biological or physiological patterns or characteristics used
3636 6to authenticate or identify a specific individual; provided, however, that “biometric information”
3737 7shall not include:
3838 8 (i) a digital or physical photograph;
3939 9 (ii) an audio or video recording; or 2 of 7
4040 10 (iii) data generated from a digital or physical photograph, or an audio or video recording,
4141 11unless such data is generated to authenticate or identify a specific individual.
4242 12 SECTION 2. Said section 1 of said chapter 93H is hereby further amended by striking out
4343 13the definition of “Breach of security” and inserting in place thereof the following definition:-
4444 14 “Breach of security”, the unauthorized acquisition or use of unencrypted electronic data,
4545 15or encrypted electronic data when the encryption key or security credential has been acquired;
4646 16provided, however, that such unauthorized acquisition or use compromises the security,
4747 17confidentiality, or integrity of personal information maintained by a person or agency; and
4848 18provided further, that a good faith but unauthorized acquisition of personal information by an
4949 19employee or agent of a person or agency for the lawful purposes of such person or agency is not
5050 20a breach of security unless the personal information is used in an unauthorized manner or subject
5151 21to further unauthorized disclosure.
5252 22 SECTION 3. Said section 1 of said chapter 93H is hereby further amended by inserting
5353 23after the definition of “Encrypted” the following definitions:-
5454 24 “Genetic information”, information, regardless of format, that:
5555 25 (i) results from the analysis of a biological sample of an individual, or from another
5656 26source enabling equivalent information to be obtained; and
5757 27 (ii) concerns an individual’s genetic material, including, but not limited to,
5858 28deoxyribonucleic acids (DNA), ribonucleic acids (RNA), genes, chromosomes, alleles, genomes,
5959 29alterations or modifications to DNA or RNA, single nucleotide polymorphisms (SNPs), 3 of 7
6060 30uninterpreted data that results from analysis of the biological sample or other source, and any
6161 31information extrapolated, derived, or inferred therefrom.
6262 32 "Health insurance information”, an individual’s health insurance policy number,
6363 33subscriber identification number, or any identifier used by a health insurer to identify the
6464 34individual.
6565 35 “Medical information”, information regarding an individual’s medical history, mental or
6666 36physical condition, or medical treatment or diagnosis by a healthcare professional.
6767 37 SECTION 4. Said section 1 of said chapter 93H is hereby further amended by striking out
6868 38the definition of “Personal information” and inserting in place thereof the following definition:-
6969 39 “Personal information” shall mean either of the following:
7070 40 (i) a resident’s first name and last name or first initial and last name in combination with
7171 41any 1 or more of the following data elements that relate to such resident:
7272 42 (A) social security number;
7373 43 (B) taxpayer identification number or identity protection personal identification number
7474 44issued by the Internal Revenue Service;
7575 45 (C) driver’s license number, passport number, military identification number, state-issued
7676 46identification card number, or other unique identification number issued by the government that
7777 47is commonly used to verify the identity of a specific individual; 4 of 7
7878 48 (D) financial account number, or credit or debit card number, with or without any
7979 49required security code, access code, personal identification number or password, that would
8080 50permit access to a resident's financial account;
8181 51 (E) biometric information;
8282 52 (F) date of birth;
8383 53 (G) genetic information;
8484 54 (H) health insurance information;
8585 55 (I) medical information; or
8686 56 (J) specific geolocation information; or
8787 57 (ii) a username or electronic mail address, in combination with a password or security
8888 58question and answer that would permit access to an online account.
8989 59 SECTION 5. Said section 1 of said chapter 93H is hereby further amended by inserting
9090 60after the definition of “Personal information” the following definition:-
9191 61 “Specific geolocation information”, information derived from technology including, but
9292 62not limited to, global positioning system level latitude and longitude coordinates or other
9393 63mechanisms that directly identify the specific location of an individual within a geographic area
9494 64that is equal to or less than the area of a circle with a radius of 1,850 feet; provided, however,
9595 65that “geolocation information” shall exclude the content of communications or any information
9696 66generated by or connected to advanced utility metering infrastructure systems or equipment for
9797 67use by a utility. 5 of 7
9898 68 SECTION 6. Section 2 of said chapter 93H is hereby amended by inserting the following
9999 69subsection:-
100100 70 (d) The rules and regulations adopted pursuant to this section shall be updated from time
101101 71to time to reflect any changes to the definitions of “breach of security” or “personal information”
102102 72in section 1.
103103 73 SECTION 7. Section 3 of said chapter 93H is hereby amended by inserting after the
104104 74words “unauthorized purpose” in subsection (b) the following words:- and such use or
105105 75acquisition presents a reasonably foreseeable risk of financial, physical, reputational or other
106106 76cognizable harm to the resident.
107107 77 SECTION 8. Said section 3 of said chapter 93H is hereby further amended by striking out
108108 78clause (vii) of subsection (b) and inserting in place thereof the following clause:- (vii) the type of
109109 79personal information compromised, including, but not limited to, any of the categories of
110110 80personal information set forth in subclauses (A) through (J) of clause (i) or in clause (ii) of the
111111 81definition of “personal information” in section 1.
112112 82 SECTION 9. Said section 3 of said chapter 93H is hereby further amended by inserting
113113 83after the words “attorney general” in subsection (b), the first two times they appear, the
114114 84following words each time so appearing:- , Federal Bureau of Investigation.
115115 85 SECTION 10. Said section 3 of said chapter 93H is hereby further amended by striking
116116 86out the last sentence of the first paragraph of subsection (b) and inserting in place thereof the
117117 87following sentence:- A person who experienced a breach of security shall file a report with the
118118 88attorney general and the director of consumer affairs and business regulation certifying their
119119 89credit monitoring services comply with section 3A; provided, however, that such a report shall 6 of 7
120120 90not be required if the personal information compromised by the breach of security is medical
121121 91information or specific geolocation information.
122122 92 SECTION 11. Said section 3 of said chapter 93H is hereby further amended by striking
123123 93out the third paragraph of subsection (b) and inserting in place thereof the following paragraphs:-
124124 94 The notice to be provided to the resident shall include, but shall not be limited to: (i) the
125125 95date, estimated date, or estimated date range of the breach of security; (ii) the type of personal
126126 96information compromised, including, but not limited to, any of the categories of personal
127127 97information set forth in subclauses (A) through (J) of clause (i) or in clause (ii) of the definition
128128 98of “personal information” in section 1; (iii) a general description of the breach of security; (iv)
129129 99information that the resident can use to contact the person or agency reporting the breach of
130130 100security; (v) the resident’s right to obtain a police report; (vi) how a resident may request a
131131 101security freeze and the necessary information to be provided when requesting the security freeze;
132132 102(vii) a statement that there shall be no charge for a security freeze; (viii) mitigation services to be
133133 103provided pursuant to this chapter; and (ix) the toll-free number, address, and website for the
134134 104federal trade commission. The notice shall not be required to include information pursuant to
135135 105clauses (vi) and (vii) if the personal information compromised by the breach of security is
136136 106medical information or specific geolocation information.
137137 107 The person or agency that experienced the breach of security shall provide a sample copy
138138 108of the notice it sent to consumers to the attorney general and the office of consumer affairs and
139139 109business regulation. A notice provided pursuant to this section shall not be delayed on grounds
140140 110that the total number of residents affected is not yet ascertained. In such case, and where
141141 111otherwise necessary to update or correct the information required, a person or agency shall 7 of 7
142142 112provide additional notice as soon as practicable and without unreasonable delay upon learning
143143 113such additional information.
144144 114 If the breach of security involves log-in credentials, pursuant to clause (ii) of the
145145 115definition of “personal information” in section 1, for an online account and no other personal
146146 116information, the person or agency may comply with this chapter by providing notice in electronic
147147 117or other form; provided, however, that such notice shall direct the resident whose personal
148148 118information has been breached to: (i) promptly change the resident’s password and security
149149 119question or answer, as applicable; or (ii) take other steps appropriate to protect the affected
150150 120online account with the person or agency and all other online accounts for which the resident
151151 121whose personal information has been breached uses the same username or electronic mail
152152 122address and password or security question or answer.
153153 123 If the breach of security involves the log-in credentials, pursuant to clause (ii) of the
154154 124definition of “personal information” in section 1, of an electronic mail account furnished by a
155155 125person or agency, the person or agency shall not comply with this chapter by providing notice of
156156 126the breach of security to such electronic mail address but shall instead provide notice by another
157157 127acceptable method of notice pursuant to this chapter or by clear and conspicuous notice delivered
158158 128to the resident online when the resident is connected to the online account from an internet
159159 129protocol address or online location from which the person or agency knows the resident
160160 130customarily accesses the account.