Full text
Official document · full textBulletinWA OIC TAA 2017-01
2017-01 Two-day Notification Requirement for Security Breaches
Version history
v1fetched Jul 20, 2026b3e48ce0b587
¶1
STATE OF WASHINGTON
MIKE KREIDLER Phone: (360) 725-7000
¶2
STATE INSURANCE COMMISSIONER www.lnsurance.wa.gov
¶3
OFFICE OF
¶4
INSURANCE COMMISSIONER
¶5
Technical Assistance Advisory 2017-01 1
TO: All Licensees with Consumers residing in the State of Washington
¶6
FROM: Insnrance Commissioner Mike Kreidler 'YY1 B t\
DATE: April 30, 2017
¶7
SUBJECT: Two-day Notification Requirement for Security Breaches
¶8
A security breach is the unauthorized acquisition of data that compromises the security,
confidentiality, or integrity of personal inforrnation maintained by a person or business. 2
¶9
If a security breach occurs, all licensees must notify the Insurance Commissioner. The notification
must be made in writing and must include the number of consumers potentially affected and the
actions being taken by the licensee. The notification must be made within two (2) business days
after determining that a security breach occurred. 3
¶10
A security breach occurs the first day on which the breach is known to the licensee or the date
when the breach should have been known to the licensee if reasonable diligence had been used. 4
A licensee is considered to have knowledge of a breach if the event is known or, by exercising
reasonable diligence, would have been known to any person who works for or is an agent of the
licensee. 5
¶11
Two types of information are included within the security breach notification requirements:
• Personal information that seems reasonably likely to subject consumers to a risk of criminal
activity, 6 and
¶12
1
This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions,
approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).
2
RCW 19.255.010(4).
3
WAC 284-04-625(2).
4 See 45 C.F.R. 164.404(a)(2).
5
See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.
6
RCW 19.255.010(5); WAC 284-04-625(2)(a). Categories include social security number, driver's license munber
or Washington identification card nun1ber, and account nu1nber or credit or debit card nu1nber in cotnbination with
any required security code, access code, or password that would per1nit access to an individual's financial account.
• Unsecured protected health information that compromises the security or privacy of the
consumer's protected information. 7
¶13
Failure to notify the Insurance Commissioner of a security breach is considered an unfair method
of competition or a deceptive practice. 8 It may result in the levying of fines or an order to cease
and desist the selling of insurance in the state ofWashington under RCW 48.30.010.
¶14
For a single breach of personal information that involves more than five hundred ( 500) Washington
residents, the person or business must notify the Washington State Attorney General's Office. 9
The breach of unprotected health infonnation must also be reported and notification provided
pursuant to 45 C.F.R. 164.400 through 164.410.
¶15
For any questions related to security breach notifications, please contact Dan Halpin, Compliance
Analyst, at DanH@oic.wa.gov or (360) 725-7089.
¶16
7 WAC 284-04-625(2)(b);
8
WAC 284-04-625(1)
9 Please refer to: http://www.atg.wa.gov/data-breach-notifications