CIPP-US - State Privacy Laws (23% of the exam) - Section 5.5

Compare state data breach notification requirements across timing, covered information types, notification recipients, and safe-harbour provisions for encrypted data.

Compare how state data breach notification laws define the covered information that triggers notice, typically a name combined with a financial, health, or government identifier, and vary in their notification timelines. Recognise that most states offer a safe harbour for encrypted data, and that entities must often notify the attorney general or regulator alongside affected consumers.

Data breach notificationReasonable securitySafe harbour encryptionNotification timeline

Practice question for this objective

Free sampleState Privacy Lawsmedium

A clinic-adjacent wellness business that is not a HIPAA covered entity suffers a breach exposing, for residents of a state whose breach statute defines personal information to include medical and health-insurance information, each affected person's full name together with their diagnosis and health-insurance policy number. No Social Security numbers or financial account numbers were exposed. Counsel asks whether this combination triggers that state's breach-notification duty. Which assessment is correct?

  • ANotice is triggered, because in a state whose breach definition covers medical or health-insurance information, a resident's name combined with a diagnosis or policy number is protected personal information even without a financial identifier. Correct
  • BNotice is not triggered, because no HIPAA covered entity is involved, so health data exposed by a non-covered wellness business falls outside every state breach-notification statute and is governed only by the HIPAA Breach Notification Rule.
  • CNotice is not triggered, because state breach statutes universally require a first name or initial and surname combined with an SSN, driver's licence number, or financial account number, and none of those were exposed.
  • DNotice is triggered only after the state insurance regulator confirms in writing that the exposed diagnosis and policy numbers create a likelihood of harm to the affected residents before any notice may be sent.
Some state breach statutes define personal information to include medical and health-insurance information, so exposing it triggers notice without any financial identifier. Several states broadened their breach-notification definitions of personal information beyond name-plus-financial-identifier to add categories such as medical information and health-insurance information. In such a state, exposure of a resident's name together with a diagnosis or a health-insurance policy number is a reportable breach for any business holding that data, regardless of HIPAA covered-entity status and without any SSN or financial account number being involved.

Why A is correct: Correct because a number of states expanded their breach definitions of personal information to add medical information and health-insurance information, so name plus diagnosis or health-insurance policy number is covered and triggers notice independent of any SSN or financial account number.

Why B is wrong: Tempting because HIPAA governs covered entities, but state breach statutes apply to businesses regardless of HIPAA status, so the absence of a covered entity does not remove the data from a state breach law that defines medical information as personal information.

Why C is wrong: Tempting because that is the traditional core definition in many statutes, but it is wrong to call it universal; states that added medical and health-insurance information cover this exposure even though the core financial identifiers were not involved.

Why D is wrong: Tempting because some breach analyses involve a harm assessment, but the statute does not condition the duty on a prior written confirmation from the insurance regulator; the business itself assesses the breach and notifies affected residents directly.

See more CIPP-US practice questions, answers explained.

Exam traps in State Privacy Laws

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-US bank for this domain.

  • Notice is required regardless of the encryption, because once names and financial account numbers are exfiltrated together the safe harbour can no longer apply to that combination of data.

    Why it is wrong: Tempting because name plus financial account number is core covered personal information, but the encryption safe harbour exists precisely to excuse notice when that covered data was rendered unreadable and the key was not compromised, so an automatic duty here misreads the safe harbour.

  • Any single data element about a resident, such as a surname, a postal address, or a date of birth, standing alone, because the statutes treat all identifying fields as equally sensitive for notice purposes.

    Why it is wrong: Tempting because each of those fields does identify a person, but the typical statute does not treat a lone name or address as triggering personal information; it requires an identifier paired with a separately listed sensitive element, so a standalone field usually falls outside the definition.

  • The retailer follows the single most lenient state timeline, because notifying under any one applicable state law satisfies the others by reciprocity.

    Why it is wrong: Tempting because one notification effort feels efficient, but state breach laws do not give reciprocity, so meeting the most lenient deadline leaves the retailer non-compliant in states with stricter timing or regulator-notice duties.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.