Pennsylvania Amends Breach Notification Law
Time 2 Minute Read

On November 3, 2022, Pennsylvania Governor Tom Wolf signed Senate Bill 696 into law (the “Act”), amending Pennsylvania’s breach notification law. 

The Act expands the definition of “personal information” to include the following data elements when compromised in combination with a resident’s name:

  • Medical information: any individually identifiable information contained in the individual’s current or historical record of medical history or medical treatment or diagnosis created by a healthcare professional.
  • Health insurance information: an individual’s health insurance policy number or subscriber number in combination with access code or other medical information that permits misuse of an individual’s health insurance benefits.
  • Username or e-mail address, in combination with a password or security question that would permit access to an online account

The Act also provides a new permissible method of providing notice of a breach if the affected personal information consists of a username or email address in combination with a password, allowing for electronic notice “if the notice directs the person whose personal information has been materially compromised by a breach of the security of the system to promptly change the person’s password and security question or answer, as applicable, or to take other steps appropriate to protect the person’s online account….” Additionally, the Act includes an exemption for covered entities and business associates subject to HIPAA.  The amendments take effect May 2, 2023.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page