Back in November of 2022, Governor Tom Wolf signed Senate Bill 696 into law which amended the Pennsylvania’s existing breach notification law.
Senate Bill 696 expands the definition of personal information to now include medical, health information, and usernames or email addresses.
The amendments make it clear that an individual's medical information, health insurance information and email addresses can also be deemed as “personal information” when compromised along with the resident's name.
Medical information incudes any personally identifiable information contained in a residents’s current or historical records created by a healthcare professional.
Health insurance information includes an individual’s health insurance policy number or subscriber number in combination with access code or other medical information that permits misuse of an individual’s health insurance benefits.
There are also provisions on how and when individuals should be notified when their data is compromised as well as what should be included in the notification.
The law also grants an exemption to businesses who are already covered under HIPAA.
The amendments, which go into effect on May, 2 2023, address an important issue that has gained traction ever since the Insight Global Data cyberbreach exposed data for approxmimately tens of thousands of Pennsylvanians.
View SB 696
Track History of SB 696
|