More Posts

BakerHostetler’s inaugural Data Security Incident Response Report offers a wealth of information regarding the causes of data security breaches, the manner in which those incidents are handled, and the legal and regulatory aftermath for affected companies. Among the Report’s interesting takeaways is a rebuttal of the popular assumption that data security incidents are all about electronic information: in approximately 20% of the incidents we handled in 2014, paper records were the vector of compromise.

Although most state security breach notification laws focus on incidents affecting electronic records, a number of states across the country impose notification requirements when a breach concerns hard-copy records that contain personal information. State breach notification laws that are triggered by incidents involving paper records include those of Alaska, Hawaii, Indiana, Massachusetts, North Carolina, and Wisconsin—and South Carolina’s law arguably may apply to both paper and electronic data. Most recently, in April 2015, Washington State enacted several amendments to its breach notification law, one of which expands the law’s coverage to encompass other media by removing the explicit reference to “computerized” data in its definition of “breach of the security of the system.” Other industry-specific state laws that govern certain types of entities, such as health facilities or insurers, impose breach notification obligations regardless of whether the personal information at issue was in paper or electronic form.