Rhode Island 2025 Regular Session

Rhode Island House Bill H6346

Introduced
5/16/25  

Caption

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

Impact

One significant aspect of H6346 is its requirement for municipal and state agencies to establish and maintain a risk-based information security program. This program must align with current best practices of an approved cybersecurity framework and define reasonable security procedures to protect personal data. Moreover, the bill mandates timely notification to affected individuals in the event of a data breach, reinforcing the accountability of agencies responsible for handling personal information.

Summary

House Bill H6346 aims to amend the Identity Theft Protection Act of 2015 by redefining key terms and increasing penalties for violations. Notably, the bill eliminates outdated definitions such as 'classified data' and 'personal information', replacing them with a clarified term 'personally identifiable information'. This amendment seeks to strengthen protection measures regarding personal data in light of evolving cybersecurity threats, thereby enhancing the overall framework of identity theft protections in Rhode Island.

Contention

While the overall intent of the bill appears beneficial in improving data security, there may be contention surrounding the effectiveness and feasibility of the notification requirements. Critics could argue that the strict timelines for notifications could impose additional burdens on entities that could already be struggling to manage cybersecurity incidents. The bill also increases penalties for violations, which some may view as excessively punitive, especially for smaller agencies or businesses.

Companion Bills

No companion bills found.

Previously Filed As

RI H5639

Establishes the crime of attempted kidnapping of a minor.

RI S0950

Establishes the crime of attempted kidnapping of a minor.

RI S0552

RELATED TO CRIMINAL OFFENSES -- DISARMING A PEACE OFFICER

RI H6042

Exempts certain U.S. employees from having to obtain state licenses to carry a visible or concealed pistol or revolver.

RI H5890

Specifies that it is unlawful for any person under the age of eighteen (18) to possess a firearm.

RI S0294

Makes it unnecessary to prove that a person’s transmission of electronic communications be for the sole purpose of harassment before being found guilty of cyberstalking or cyberharassment.

RI H5924

Increases minimum sentence for first degree sexual assault and provides first 10 years of a sentence for first degree sexual assault not be subject to a suspension or deferment of sentence.

RI S0558

Adds a rebuttable defense if any person shall die or sustain a personal injury while committing robbery of the owner, lessor, or occupant of a motor vehicle and that the owner or occupant of the vehicle acted in self-defense.

Similar Bills

RI S1037

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

CA AB2777

Office of Information Security: Baseline Information Security Score.

NJ S3100

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A1981

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

NJ A2200

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

AL HB68

State government, Office of Information Technology, cybersecurity requirements, provided

CA AB2135

Information security.

KS HB2019

Implementing additional reporting requirements for information technology projects and state agencies, requiring additional information technology security training and status reports, requiring reporting of significant cybersecurity audits and changing the membership requirements, terms of members and the quorum requirements for the information technology executive council.