TENNESSEE LEGISLATORS MUDDY WATERS AROUND PRIVACY BREACH NOTIFICATION REQUIREMENTS

The Tennessee legislature recently passed a modification to the state privacy breach notification requirements, § 47-18-2107.  The modification has been sent to the governor for signature.  Unfortunately, the modification just confuses the law’s requirements.

The existing code says that a breach notification is required if “unauthorized acquisition of unencrypted computerized data” takes place.  The breach also has to materially compromise the security, confidentiality, or integrity of personal information. This seems clear to me.

The new code says that notification is required when acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information takes place.  The data does not have to be unencrypted.

However, subsections add an exception for encrypted data.  If the data breached is encrypted, breach notification is not triggered.  One encryption exception is for data encrypted in accordance with FIPS 140-2, a Federal Information Processing Standard.  I have never seen this used in private business.  The second exception is for information that has been made “unusable”.  On the face of it, this would seem to include any type of “encryption” processes, good or bad.

So, in the old (current) law, if you lost unencrypted data, you had to carry out notification.  The new law seems to say that that’s still true, but if you have any reasonable encryption process, you have no duty to notify.

Frederick Scholl

Frederick Scholl is an accomplished Global Senior Information Security Risk Manager. Dr. Scholl earned a BS and Ph.D. in Electrical Engineering from Cornell University. In 1991, Fred founded Monarch Information Networks, LLC to enable forward-thinking organizations to protect their information. Previously, he co-founded Codenoll Technology Corporation (NASDAQ: CODN). He chaired the IEEE committee that wrote the first standard for Ethernet communication over fiber optic links, now used world-wide.

Book an Appointment for Cybersecurity Issues

Request an appointment with Dr. Fred Scholl. We will discuss any cybersecurity issues you have.

More Good Reading

Healthcare: Time to Review Your Cybersecurity Plan

Cybersecurity Thrives in An Organizational Context

The First National Cybersecurity Summit

New Privacy Laws Require Security Professionals Up Their Game

Cybersecurity Workforce Development: Real or Imagined Problem?