Data Breach Requirements: Fla. Stat. § 501.171.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
(g)1. The term “personal information” means either of the following:
a. An individual’s first name or first initial and last name in combination with any one or more of the following data elements for that individual:
(I) A Social Security number;
(II) A driver’s license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity;
(III) A financial account number or credit or debit card number, in combination with any required security code, access code, or password that is necessary to permit access to an individual’s financial account;
(IV) Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
(V) An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual;
(VI) An individual's biometric data as defined in s. 501.702; or Any information regarding an individual’s geolocation.
Security Breach Definition
The term a “breach of security” or “breach” means unauthorized access of data in electronic form containing personal information.
Good Faith Exception
Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use.
Risk of Harm Analysis
A breach notice to the affected individuals is not required if, after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies, the covered entity reasonably determines that the breach has not and will not likely result in identity theft or any other financial harm to the individuals whose personal information has been accessed. Such a determination must be documented in writing and maintained for at least five years. The covered entity shall provide the written determination to the department within 30 days after the determination.
Notification Timeline
A breach notice shall be made as expeditiously as practicable and without unreasonable delay, taking into account the time necessary to allow the covered entity to determine the scope of the breach of security, to identify individuals affected by the breach, and to restore the reasonable integrity of the data system that was breached. A breach notice shall be made no later than 30 days after the determination of a breach or reason to believe a breach occurred unless subject to a delay authorized under paragraph (b) (security and investigation exceptions) or waiver under paragraph (c) (risk of harm analysis).
Security and Investigation Exceptions
If a federal, state, or local law enforcement agency determines that notice to individuals required under this subsection would interfere with a criminal investigation, the notice shall be delayed upon the written request of the law enforcement agency for a specified period that the law enforcement agency determines is reasonably necessary. A law enforcement agency may, by a subsequent written request, revoke such delay as of a specified date or extend the period set forth in the original request made under this paragraph to a specified date if further delay is necessary.
Notification Content Requirements
The notice to an individual with respect to a breach of security shall include, at a minimum:
- The date, estimated date, or estimated date range of the breach of security.
- A description of the personal information that was accessed or reasonably believed to have been accessed as a part of the breach of security.
- Information that the individual can use to contact the covered entity to inquire about the breach of security and the personal information that the covered entity maintained about the individual.
Delivery Methods
A breach notice may be provided by one of the following methods:
- Written notice sent to the mailing address of the individual in the records of the covered entity; or
- Email notice sent to the email address of the individual in the records of the covered entity.
- A covered entity required to provide notice to an individual may provide substitute notice in lieu of direct notice if such direct notice is not feasible because the cost of providing notice would exceed $250,000, because the affected individuals exceed 500,000 persons, or because the covered entity does not have an email address or mailing address for the affected individuals.
Substitute Notice
The substitute notice shall include the following:
- A conspicuous notice on the internet website of the covered entity if the covered entity maintains a website; and
- Notice in print and to broadcast media, including major media in urban and rural areas where the affected individuals reside.
Notice to Government Agencies
(a) A covered entity shall provide notice to the department of any breach of security affecting 500 or more individuals in this state. Such notice must be provided to the department as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred. A covered entity may receive 15 additional days to provide notice as required in subsection (4) if good cause for delay is provided in writing to the department within 30 days after determination of the breach or reason to believe a breach occurred.
(b) The written notice to the department must include:
- A synopsis of the events surrounding the breach at the time notice is provided.
- The number of individuals in this state who were or potentially have been affected by the breach.
- Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions as to how to use such services.
- A copy of the notice required under subsection (4), or an explanation of the other actions taken pursuant to subsection (4).
- The name, address, telephone number, and email address of the employee or agent of the covered entity from whom additional information may be obtained about the breach.
(c) The covered entity must provide the following information to the department upon its request:
- A police report, incident report, or computer forensics report.
- A copy of the policies in place regarding breaches.
- Steps that have been taken to rectify the breach.
(d) A covered entity may provide the department with supplemental information regarding a breach at any time.
Consumer Reporting Agencies
If a covered entity discovers circumstances requiring a breach notice to more than 1,000 individuals at a single time, the covered entity shall also notify, without unreasonable delay, all consumer reporting agencies of the timing, distribution, and content of the notices.
Preemption and Compliance
Notice provided pursuant to rules, regulations, procedures, or guidelines established by the covered entity’s primary or functional federal regulator is deemed to be in compliance with the notice requirement in this subsection if the covered entity notifies affected individuals in accordance with the rules, regulations, procedures, or guidelines established by the primary or functional federal regulator in the event of a breach of security. Under this paragraph, a covered entity that provides a copy of such notice to the department in a timely manner is deemed to be in compliance with the notice requirement herein.
Data Processor Obligations
In the event of a breach of security of a system maintained by a third-party agent, such third-party agent shall notify the covered entity of the breach of security as expeditiously as practicable, but no later than 10 days following the determination of the breach of security or reason to believe the breach occurred. A third-party agent shall provide a covered entity with all information that the covered entity needs to comply with its notice requirements.
Other Information
The “Department” means the Department of Legal Affairs.
Data Disposal and Security: Fla. Stat. § 501.171.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal information” means either of the following:
a. An individual’s first name or first initial and last name in combination with any one or more of the following data elements for that individual:
(I) A Social Security number;
(II) A driver’s license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity;
(III) A financial account number or credit or debit card number, in combination with any required security code, access code, or password that is necessary to permit access to an individual’s financial account;
(IV) Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; or
(V) An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual. b. A username or email address, in combination with a password or security question and answer that would permit access to an online account.
Security Requirements
Each covered entity, governmental entity, or third-party agent shall take reasonable measures to protect and secure data in electronic form containing personal information.
Data Disposal
Each covered entity or third-party agent shall take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within its custody or control when the records are no longer to be retained. Such disposal shall involve shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means.