PENNSYLVANIA
FINES & PENALTIES
Violations
Constitutes an unfair trade practice
BREACH NOTIFICATION
Mandated Timeframe
Without unreasonable delay
BREACH REPORTING
When notification is made to more than 1,000 persons at one time, the breached Organization must report to all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. Heightened disclosure requirements may apply to entities dealing with Social Security Numbers.
CONSUMER NOTIFICATION
If any state residents are affected by a breach, the breached Organization must give notice without delay to each affected individual. If a breach affects residents of otehr jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
FINES & PENALTIES
A violation of the Breach of Personal Information Notification Act shall be deemed to be an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law, of which the Offices of Attorney General shall have exclusive authority to bring an action for violation.
INDUSTRY SPECIFIC LAWS
There are specific additional requirements for licensees under the “Insurance Company Law of 1921” that addresses how a licensed insurer should handle and protect nonpublic personal financial information as defined under the law.
VENDOR/3RD PARTIES
Vendors must notify Organizations without delay after the discovery of a breach or suspected breach. The Organization will be responsible to complete any required regulatory reporting and consumer notification.