Another State Passes Data Security Protections

Alabama is the 48th state to enact data security laws, and one of a few that have revamped data security statutes post major retail data breaches. The Alabama legislation will triger notification within 30 days when any of the following information is hacked:

  •  medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
  • health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual;
  • User name or e-mail address, in combination with a password or security question and answer that would permit access to an online account.

It also addresses record retention of data breaches.

National Law Review