CIPP-US - State Privacy Laws - Section 5.5

Compare state data breach notification requirements across timing, covered information types, notification recipients, and safe-harbour provisions for encrypted data.

Compare how state data breach notification laws define the covered information that triggers notice, typically a name combined with a financial, health, or government identifier, and vary in their notification timelines. Recognise that most states offer a safe harbour for encrypted data, and that entities must often notify the attorney general or regulator alongside affected consumers.

Data breach notificationReasonable securitySafe harbour encryptionNotification timeline

Practice question for this objective

Free sampleState Privacy Lawsmedium

A clinic-adjacent wellness business that is not a HIPAA covered entity suffers a breach exposing, for residents of a state whose breach statute defines personal information to include medical and health-insurance information, each affected person's full name together with their diagnosis and health-insurance policy number. No Social Security numbers or financial account numbers were exposed. Counsel asks whether this combination triggers that state's breach-notification duty. Which assessment is correct?

  • ANotice is triggered, because in a state whose breach definition covers medical or health-insurance information, a resident's name combined with a diagnosis or policy number is protected personal information even without a financial identifier. Correct
  • BNotice is not triggered, because no HIPAA covered entity is involved, so health data exposed by a non-covered wellness business falls outside every state breach-notification statute and is governed only by the HIPAA Breach Notification Rule.
  • CNotice is not triggered, because state breach statutes universally require a first name or initial and surname combined with an SSN, driver's licence number, or financial account number, and none of those were exposed.
  • DNotice is triggered only after the state insurance regulator confirms in writing that the exposed diagnosis and policy numbers create a likelihood of harm to the affected residents before any notice may be sent.
Some state breach statutes define personal information to include medical and health-insurance information, so exposing it triggers notice without any financial identifier. Several states broadened their breach-notification definitions of personal information beyond name-plus-financial-identifier to add categories such as medical information and health-insurance information. In such a state, exposure of a resident's name together with a diagnosis or a health-insurance policy number is a reportable breach for any business holding that data, regardless of HIPAA covered-entity status and without any SSN or financial account number being involved.

Why A is correct: Correct because a number of states expanded their breach definitions of personal information to add medical information and health-insurance information, so name plus diagnosis or health-insurance policy number is covered and triggers notice independent of any SSN or financial account number.

Why B is wrong: Tempting because HIPAA governs covered entities, but state breach statutes apply to businesses regardless of HIPAA status, so the absence of a covered entity does not remove the data from a state breach law that defines medical information as personal information.

Why C is wrong: Tempting because that is the traditional core definition in many statutes, but it is wrong to call it universal; states that added medical and health-insurance information cover this exposure even though the core financial identifiers were not involved.

Why D is wrong: Tempting because some breach analyses involve a harm assessment, but the statute does not condition the duty on a prior written confirmation from the insurance regulator; the business itself assesses the breach and notifies affected residents directly.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all State Privacy Laws objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.