Texas 2009 - 81st Regular

Texas House Bill HB2004 Compare Versions

The same version is selected twice. Please select two different versions to compare.
OldNewDifferences
11 H.B. No. 2004
22
33
44 AN ACT
55 relating to a breach of computer security involving sensitive
66 personal information and to the protection of sensitive personal
77 information and certain protected health information.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. Section 521.002(a)(2), Business & Commerce Code,
1010 as effective April 1, 2009, is amended to read as follows:
1111 (2) "Sensitive personal information" means, subject
1212 to Subsection (b):
1313 (A) [,] an individual's first name or first
1414 initial and last name in combination with any one or more of the
1515 following items, if the name and the items are not encrypted:
1616 (i) [(A)] social security number;
1717 (ii) [(B)] driver's license number or
1818 government-issued identification number; or
1919 (iii) [(C)] account number or credit or
2020 debit card number in combination with any required security code,
2121 access code, or password that would permit access to an
2222 individual's financial account; or
2323 (B) information that identifies an individual
2424 and relates to:
2525 (i) the physical or mental health or
2626 condition of the individual;
2727 (ii) the provision of health care to the
2828 individual; or
2929 (iii) payment for the provision of health
3030 care to the individual.
3131 SECTION 2. Section 521.052, Business & Commerce Code, is
3232 amended by adding Subsection (d) to read as follows:
3333 (d) As used in this section, "business" includes a nonprofit
3434 athletic or sports association.
3535 SECTION 3. Section 521.053(a), Business & Commerce Code, as
3636 effective April 1, 2009, is amended to read as follows:
3737 (a) In this section, "breach of system security" means
3838 unauthorized acquisition of computerized data that compromises the
3939 security, confidentiality, or integrity of sensitive personal
4040 information maintained by a person, including data that is
4141 encrypted if the person accessing the data has the key required to
4242 decrypt the data. Good faith acquisition of sensitive personal
4343 information by an employee or agent of the person for the purposes
4444 of the person is not a breach of system security unless the person
4545 uses or discloses the sensitive personal information in an
4646 unauthorized manner.
4747 SECTION 4. Subchapter F, Chapter 2054, Government Code, is
4848 amended by adding Section 2054.1125 to read as follows:
4949 Sec. 2054.1125. SECURITY BREACH NOTIFICATION BY STATE
5050 AGENCY. (a) In this section:
5151 (1) "Breach of system security" has the meaning
5252 assigned by Section 521.053, Business & Commerce Code.
5353 (2) "Sensitive personal information" has the meaning
5454 assigned by Section 521.002, Business & Commerce Code.
5555 (b) A state agency that owns, licenses, or maintains
5656 computerized data that includes sensitive personal information
5757 shall comply, in the event of a breach of system security, with the
5858 notification requirements of Section 521.053, Business & Commerce
5959 Code, to the same extent as a person who conducts business in this
6060 state.
6161 SECTION 5. Subchapter A, Chapter 181, Health and Safety
6262 Code, is amended by adding Section 181.006 to read as follows:
6363 Sec. 181.006. PROTECTED HEALTH INFORMATION NOT PUBLIC. For
6464 a covered entity that is a governmental unit, an individual's
6565 protected health information:
6666 (1) includes any information that reflects that an
6767 individual received health care from the covered entity; and
6868 (2) is not public information and is not subject to
6969 disclosure under Chapter 552, Government Code.
7070 SECTION 6. Chapter 205, Local Government Code, is amended
7171 by adding Section 205.010 to read as follows:
7272 Sec. 205.010. SECURITY BREACH NOTIFICATION BY LOCAL
7373 GOVERNMENT. (a) In this section:
7474 (1) "Breach of system security" has the meaning
7575 assigned by Section 521.053, Business & Commerce Code.
7676 (2) "Sensitive personal information" has the meaning
7777 assigned by Section 521.002, Business & Commerce Code.
7878 (b) A local government that owns, licenses, or maintains
7979 computerized data that includes sensitive personal information
8080 shall comply, in the event of a breach of system security, with the
8181 notification requirements of Section 521.053, Business & Commerce
8282 Code, to the same extent as a person who conducts business in this
8383 state.
8484 SECTION 7. The changes in law made by this Act apply only to
8585 a breach of system security that occurs on or after the effective
8686 date of this Act. A breach of system security that occurs before the
8787 effective date of this Act is governed by the law in effect on the
8888 date the breach occurred, and the former law is continued in effect
8989 for that purpose.
9090 SECTION 8. This Act takes effect September 1, 2009.
9191 ______________________________ ______________________________
9292 President of the Senate Speaker of the House
9393 I certify that H.B. No. 2004 was passed by the House on April
9494 28, 2009, by the following vote: Yeas 148, Nays 0, 1 present, not
9595 voting.
9696 ______________________________
9797 Chief Clerk of the House
9898 I certify that H.B. No. 2004 was passed by the Senate on May
9999 21, 2009, by the following vote: Yeas 31, Nays 0.
100100 ______________________________
101101 Secretary of the Senate
102102 APPROVED: _____________________
103103 Date
104104 _____________________
105105 Governor