2015 -- S 0134 SUBSTITUTE B ======== LC000486/SUB B/2 ======== S T A T E O F R H O D E I S L A N D



Similar documents
H 6191 SUBSTITUTE A AS AMENDED ======= LC02663/SUB A/2 ======= STATE OF RHODE ISLAND IN GENERAL ASSEMBLY JANUARY SESSION, A.D.

January An Overview of U.S. Security Breach Statutes

Security Breaches Under the NC Identity Theft Protection Act: Basic Information for Local Health Departments

SENATE FILE NO. SF0065. Sponsored by: Senator(s) Johnson and Case A BILL. for. AN ACT relating to consumer protection; providing for

DATA BREACH CHARTS (Current as of December 31, 2015)

Michie's Legal Resources. This part shall be known and may be cited as the Tennessee Identity Theft Deterrence Act of [Acts 1999, ch. 201, 2.

51ST LEGISLATURE - STATE OF NEW MEXICO - SECOND SESSION, 2014

KRS Chapter 61. Personal Information Security and Breach Investigations

Client Advisory October Data Security Law MGL Chapter 93H and 201 CMR 17.00

Comparison of US State and Federal Security Breach Notification Laws. Current through August 26, 2015

HIPAA BUSINESS ASSOCIATE AGREEMENT

CHAPTER 226. C.56:11-44 Short title. 1. This act shall be known and may be cited as the "Identity Theft Prevention Act."

PLEASE READ. The official text of New Jersey Statutes can be found through the home page of the New Jersey Legislature

GENERAL ASSEMBLY OF NORTH CAROLINA SESSION 2005 H 2 HOUSE BILL 629 Committee Substitute Favorable 5/18/05

NC General Statutes - Chapter 75 Article 2A 1

Model Business Associate Agreement

IDENTITY THEFT IN SOUTH CAROLINA: 2014 UPDATE. Marti Phillips, Esq. Director, Identity Theft Unit South Carolina Department of Consumer Affairs

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT

FEDERAL AND STATE BREACH NOTIFICATION LAWS FOR CALIFORNIA

CYBERSECURITY: THREATS, SOLUTIONS AND PROTECTION. Robert N. Young, Director Carruthers & Roth, P.A. rny@crlaw.com Phone: (336)

FirstCarolinaCare Insurance Company Business Associate Agreement

BUSINESS ASSOCIATE AGREEMENT

Terms and Conditions Relating to Protected Health Information ( City PHI Terms ) Revised and Effective as of September 23, 2013

BREVIUM HIPAA BUSINESS ASSOCIATE TERMS AND CONDITIONS

North Carolina General Statutes Chapter 75 Monopolies, Trusts, and Consumer Protection Article 2A Identity Theft Protection Act

BUSINESS ASSOCIATE AGREEMENT

Disclaimer: Template Business Associate Agreement (45 C.F.R )

Business Associate Agreement

BENCHMARK MEDICAL LLC, BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT

a. Credit to be used primarily for personal, family, or household purposes. c. Any other purpose authorized under 15 U.S.C. 168l(b).

BUSINESS ASSOCIATE AGREEMENT ( BAA )

Tulane University. Tulane University Business Associates Agreement SCOPE OF POLICY STATEMENT OF POLICY IMPLEMENTATION OF POLICY

BUSINESS AND COMMERCE CODE PERSONAL IDENTITY INFORMATION UNAUTHORIZED USE OF IDENTIFYING INFORMATION

Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:

HIPAA BUSINESS ASSOCIATE AGREEMENT

Articles. Three Large States Revise Their Security Breach Notification Laws and Texas Applies Its Law to Residents of Some Other States to Boot

GENERAL ASSEMBLY OF NORTH CAROLINA SESSION 2005 SESSION LAW SENATE BILL 1048

(1) regulate the storage, retention, transmission, and security measures for credit card, debit card, and other payment-related data;

BUSINESS ASSOCIATE AGREEMENT

STANDARD ADMINISTRATIVE PROCEDURE

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT BUSINESS ASSOCIATE TERMS AND CONDITIONS

BUSINESS ASSOCIATE AGREEMENT

Business Associate Agreement Involving the Access to Protected Health Information

BUSINESS ASSOCIATE AGREEMENT

The ReHabilitation Center Buffalo Street. Olean. NY

PENNSYLVANIA IDENTITY THEFT RANKING BY STATE: Rank 14, 72.5 Complaints Per 100,000 Population, 9016 Complaints (2007) Updated January 29, 2009

UNIVERSITY PHYSICIANS OF BROOKLYN HIPAA BUSINESS ASSOCIATE AGREEMENT CONTRACT NO(S):

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA Business Associate Addendum

SAMPLE BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Commercial Law - Consumer Credit Report Security Freezes

OFFICE OF CONTRACT ADMINISTRATION PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA)

BUSINESS ASSOCIATE AGREEMENT

University Healthcare Physicians Compliance and Privacy Policy

Identity Theft Prevention and Security Breach Notification Policy. Purpose:

SAMPLE BUSINESS ASSOCIATE AGREEMENT

CATHOLIC SOCIAL SERVICES BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT TERMS

Regular Session, ACT No To amend and reenact R.S. 9:3573.1, (A), (1), (8), (9) and (10), ,

BUSINESS ASSOCIATE AGREEMENT

The Rosenthal Fair Debt Collection Practices Act California Civil Code 1788 et seq.

HIPAA BUSINESS ASSOCIATE AGREEMENT

SAMPLE TEMPLATE. Massachusetts Written Information Security Plan

HIPAA BUSINESS ASSOCIATE AGREEMENT

SaaS. Business Associate Agreement

BUSINESS ASSOCIATE AGREEMENT

Business Associate Contract

BUSINESS ASSOCIATE AGREEMENT

ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016

COMPLIANCE ALERT 10-12

Five Rivers Medical Center, Inc Medical Center Drive Pocahontas, AR Notification of Security Breach Policy

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

COLORADO IDENTITY THEFT RANKING BY STATE: Rank 8, 89.0 Complaints Per 100,000 Population, 4328 Complaints (2007) Updated November 28, 2008

Business Associate Agreement

CONNECTICUT IDENTITY THEFT RANKING BY STATE: Rank 19, 68.8 Complaints Per 100,000 Population, 2409 Complaints (2007) Updated November 28, 2008

Business Associate Agreement

HIPAA Breach Notification Policy

FORM OF HIPAA BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT

NACHC Issue Brief Changes to the Health Insurance Portability and Accountability Act Included in ARRA. March 2010

HIPAA Business Associate Agreement

HSHS BUSINESS ASSOCIATE AGREEMENT BACKGROUND AND RECITALS

BUSINESS ASSOCIATE AGREEMENT

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

BUSINESS ASSOCIATE ADDENDUM

BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT

SECTION-BY-SECTION ANALYSIS

BUSINESS ASSOCIATE AGREEMENT. Emory University and/or Emory Healthcare, Inc. ( Emory ) ( Covered Entity ) and

Chapter No. 911] PUBLIC ACTS, CHAPTER NO. 911 HOUSE BILL NO. 3403

ACCG Identity Theft Prevention Program. ACCG 50 Hurt Plaza, Suite 1000 Atlanta, Georgia (404) (404)

The Institute of Professional Practice, Inc. Business Associate Agreement

Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT

New York Consolidated Law Service General Business Law Article 25 - Fair Credit Reporting Act

Transcription:

0 -- S 01 SUBSTITUTE B LC000/SUB B/ S T A T E O F R H O D E I S L A N D IN GENERAL ASSEMBLY JANUARY SESSION, A.D. 0 A N A C T RELATING TO CRIMINAL OFFENSES - IDENTITY THEFT PROTECTION Introduced By: Senators DiPalma, McCaffrey, Algiere, Coyne, and Lombardi Date Introduced: January, 0 Referred To: Senate Judiciary It is enacted by the General Assembly as follows: 1 1 1 1 1 1 1 SECTION 1. Chapter -. of the General Laws entitled "Identity Theft Protection" is hereby repealed in its entirety. CHAPTER -. Identity Theft Protection -.-1. Short title. -- This chapter shall be known and may be cited as the "Rhode Island Identity Theft Protection Act of 00." -.-. Legislative findings. -- It is hereby found and declared as follows: (1) There is a growing concern regarding the possible theft of an individual's identity and a resulting need for measures to protect the privacy of personal information. It is the intent of the general assembly to ensure that personal information about Rhode Island residents is protected. To that end, the purpose of this chapter is to require businesses that own or license personal information about Rhode Islanders to provide reasonable security for that information. For the purpose of this chapter, the phrase "owns or licenses" is intended to include, but is not limited to, personal information that a business retains as part of the business' internal customer account or for the purpose of using that information in transactions with the person to whom the information relates. () A business that owns or licenses computerized unencripted personal information about a Rhode Island resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from

1 1 1 1 1 1 0 1 0 1 unauthorized access, destruction, use, modification, or disclosure. () A business that discloses computerized unencripted personal information about a Rhode Island resident pursuant to a contract with a nonaffiliated third-party shall require by contract that the third-party implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. -.-. Notification of breach. -- (a) Any state agency or person that owns, maintains or licenses computerized data that includes personal information, shall disclose any breach of the security of the system which poses a significant risk of identity theft following discovery or notification of the breach in the security of the data to any resident of Rhode Island whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person or a person without authority, to acquire said information. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. (b) Any state agency or person that maintains computerized unencripted data that includes personal information that the state agency or person does not own shall notify the owner or licensee of the information of any breach of the security of the data which poses a significant risk of identity theft immediately, following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. (c) The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made after the law enforcement agency determines that it will not compromise the investigation. (d) The notification must be prompt and reasonable following the determination of the breach unless otherwise provided in this section. Any state agency or person required to make notification under this section and who fails to do so promptly following the determination of a breach or receipt of notice from law enforcement as provided for is subsection (c) is liable for a fine as set forth in -.-. -.-. Notification of breach -- Consultation with law enforcement. -- Notification of a breach is not required if, after an appropriate investigation or after consultation with relevant federal, state, or local law enforcement agencies, a determination is made that the breach has not and will not likely result in a significant risk of identity theft to the individuals LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 whose personal information has been acquired. -.-. Definitions. -- The following definitions apply to this section: (a) "Person" shall include any individual, partnership association, corporation or joint venture. (b) For purposes for this section, "breach of the security of the system" means unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the state agency or person. Good faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. (c) For purposes of this section, "personal information" means an individual's first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted: (1) Social security number; () Driver's license number or Rhode Island Identification Card number; () Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account. (d) For purposes of this section, "notice" may be provided by one of the following methods: (1) Written notice; () Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set for the in Section 001 of Title of the United States Code; () Substitute notice, if the state agency or person demonstrates that the cost of providing notice would exceed twenty-five thousand dollars ($,000), or that the affected class of subject persons to be notified exceeds fifty thousand (0,000), or the state agency or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) E-mail notice when the state agency or person has an e-mail address for the subject persons; (B) Conspicuous posting of the notice on the state agency's or person's website page, if the state agency or person maintains one; (C) Notification to major statewide media. -.-. Penalties for violation. -- (a) Each violation of this chapter is a civil violation for which a penalty of not more than a hundred dollars ($0) per occurrence and not more than LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 twenty-five thousand dollars ($,000) may be adjudged against a defendant. (b) No Waiver of Notification. - Any waiver of a provision of this section is contrary to public policy and is void and unenforceable. -.-. Agencies with security breach procedures. -- Any state agency or person that maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of -.-, shall be deemed to be in compliance with the security breach notification requirements of -.-, provided such person notifies subject persons in accordance with such person's policies in the event of a breach of security. Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelines established by the primary or functional regulator, as defined in USC 0(), shall be deemed to be in compliance with the security breach notification requirements of this section, provided such person notifies subject persons in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of security of the system. A financial institution, trust company, credit union or its affiliates that is subject to and examined for, and found in compliance with the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the federal Department of Health and Human Services, Parts 0 and of Title of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of (HIPAA) shall be deemed in compliance with this chapter. SECTION. Title of the General Laws entitled "CRIMINAL OFFENSES" is hereby amended by adding thereto the following chapter: CHAPTER. IDENTITY THEFT PROTECTION ACT OF 0 -.-1. Short title. -- This chapter shall be known and may be cited as the "Rhode Island Identity Theft Protection Act of 0." -.-. Risk-based information security program. -- (a) A municipal agency, state agency or person that stores, collects, processes, maintains, acquires, uses, owns or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program which contains reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information and the purpose for which the information was collected in order to protect the personal information from LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 unauthorized access, use, modification, destruction or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency or person shall not retain personal information for a period longer than is reasonably required to provide the services requested, to meet the purpose for which it was collected, or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. (b) A municipal agency, state agency or person that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. -.-. Definitions. -- (a) The following definitions apply to this section: (1) "Breach of the security of the system" means unauthorized access or acquisition of unencrypted computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency or person. Good faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. () "Encrypted" means the transformation of data through the use of a one hundred twenty-eight (1) bit or higher algorithmic process into a form in which there is a low probability of assigning meaning without use of a confidential process or key. Data shall not be considered to be encrypted if it is acquired in combination with any key, security code, or password that would permit access to the encrypted data. () "Health Insurance Information" means an individual's health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual. () "Medical Information" means any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. () "Municipal agency" means any department, division, agency, commission, board, LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 office, bureau, authority, quasi-public authority, or school, fire or water district within Rhode Island other than a state agency and any other agency that is in any branch of municipal government and exercises governmental functions other than in an advisory nature. () "Owner" means the original collector of the information. () "Person" shall include any individual, sole proprietorship, partnership, association, corporation, or joint venture, business or legal entity, trust, estate, cooperative or other commercial entity. () "Personal information" means an individual's first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy paper format: (i) Social security number; (ii) Driver's license number, or Rhode Island identification card number or tribal identification number; (iii) Account number, credit or debit card number, in combination with any required security code, access code, password or personal identification number that would permit access to an individual's financial account; (iv) Medical or health insurance information; or (v) E-mail address with any required security code, access code, or password that would permit access to an individual's personal, medical, insurance or financial account. () "Remediation service provider" means any person which in its usual course of business provides services pertaining to a consumer credit report including, but not limited to, credit report monitoring and alerts, that are intended to mitigate the potential for identity theft. () "State agency" means any department, division, agency, commission, board, office, bureau, authority, or quasi-public authority within Rhode Island, either branch of the Rhode Island general assembly, or an agency or committee thereof, the judiciary, or any other agency that is in any branch of Rhode Island state government and which exercises governmental functions other than in an advisory nature. (b) For purposes of this section, personal information does not include publicly available information that is lawfully made available to the general public from federal, state or local government records. (c) For purposes of this section, "notice" may be provided by one of the following methods: (i) Written notice; (ii) Electronic notice, if the notice provided is consistent with the provisions regarding LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 electronic records and signatures set forth in U.S.C. 001; (iii) Substitute notice, if the municipal agency, state agency or person demonstrates that the cost of providing notice would exceed twenty-five thousand dollars ($,000), or that the affected class of subject persons to be notified exceeds fifty thousand (0,000), or the municipal agency, state agency or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) E-mail notice when the municipal agency, state agency or person has an e-mail address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency's, state agency's or person's website page, if the municipal agency, state agency or person maintains one; and (C) Notification to major statewide media. -.-. Notification of breach. -- (a)(1) Any municipal agency, state agency or person that stores, owns, collects, processes, maintains, acquires, uses or licenses data that includes personal information, shall provide notification as set forth in this section of any disclosure of personal information, or any breach of the security of the system, which poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. () The notification shall be made in the most expedient time possible but no later than forty-five () calendar days after confirmation of the breach and the ability to ascertain the information required to fulfill the notice requirements contained in subsection (d) of this section and shall be consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section. In the event that more than five hundred (00) Rhode Island residents are to be notified, the municipal agency, state agency or person shall notify the attorney general and the major credit reporting agencies as to the timing, content and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. (b) The notification required by this section may be delayed if a federal, state or local law enforcement agency determines that the notification will impede a criminal investigation. The federal, state or local law enforcement agency must notify the municipal agency, state agency or person of the request to delay notification without unreasonable delay. If notice is delayed due to such determination then as soon as the federal, state or municipal law enforcement agency determines and informs the municipal agency, state agency or person that notification no longer poses a risk of impeding an investigation, notice shall be provided, as soon as practicable LC000/SUB B/ - Page of

1 1 1 1 1 1 0 1 0 1 pursuant to -.-(a)(). The municipal agency, state agency or person shall cooperate with federal, state or municipal law enforcement in its investigation of any breach of security or unauthorized acquisition or use, which shall include the sharing of information relevant to the incident; provided however, that such disclosure shall not require the disclosure of confidential business information or trade secrets. (c) Any municipal agency, state agency or person required to make notification under this section and who fails to do so is liable for a violation as set forth in -.-. (d) The notification to individuals must include the following information to the extent known: (1) A general and brief description of the incident, including how the security breach occurred and the number of affected individuals; () The type of information that was subject to the breach; () Date of breach, estimated date of breach or the date range within which the breach occurred; () Date that the breach was discovered; () A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and () A clear and concise description of: the consumer's ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. -.-. Penalties for violation. -- (a) Each reckless violation of this chapter is a civil violation for which a penalty of not more than one hundred dollars ($0) per record may be adjudged against a defendant. (b) Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than two hundred dollars ($00) per record may be adjudged against a defendant. (c) Whenever the attorney general has reason to believe that a violation of this chapter has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. -.-. Agencies or persons with security breach procedures. -- (a) Any municipal agency, state agency or person shall be deemed to be in compliance with the security breach notification requirements of -.-, if: LC000/SUB B/ - Page of

1 1 1 1 1 1 0 (1) The municipal agency, state agency or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of -.-, and notifies subject persons in accordance with such municipal agency's, state agency's, or person's notification policies in the event of a breach of security; or () The person maintains a security breach procedure pursuant to the rules, regulations, procedures or guidelines established by the primary or functional regulator, as defined in U.S.C. 0(), and notifies subject persons in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of security of the system. (b) A financial institution, trust company, credit union or its affiliates that is subject to and examined for, and found in compliance with the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter. (c) A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 0 and of Title of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of (HIPAA) shall be deemed in compliance with this chapter. SECTION. This act shall take effect one year following the date of passage. LC000/SUB B/ LC000/SUB B/ - Page of

EXPLANATION BY THE LEGISLATIVE COUNCIL OF A N A C T RELATING TO CRIMINAL OFFENSES - IDENTITY THEFT PROTECTION *** 1 This act would create the Identity Theft Protection Act of 0, to protect personal information from unauthorized access, use, modification, destruction or disclosure, and to preserve the confidentiality and integrity of such information. This act would take effect one year following the date of passage. LC000/SUB B/ LC000/SUB B/ - Page of