Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Electronic Health Records | Policy and Legislation | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

California law will better inform consumers of privacy breaches

September 08, 2011 | Molly Merrill, Associate Editor

Suggested Content

  • California bans forced RFID implants
  • Gateway EDI acquires NHXS
  • States scramble to handle 'tsunami-like wave' of HIT demands
  • HP, Blue Shield of California sign 5-year infrastructure deal
  • Blue Shield of California gives $20M in ACO help
  • Telehealth services to reach more rural Californians
  • IHA names top P4P physician organizations

Related Resources

  • The Anatomy of a VNA Done Right: The Case for Silo Busting
  • Role of Analytics Post Healthcare Reform
  • May 29th @ 1PM ET--St. Joseph’s Security and Compliance Success Story: Implementing Identity Management in Healthcare
  • Integrating Faxes into Today's World of Healthcare e-Records
  • Protect your Patient Data: Learn How to Avoid Costly Privacy & Security Breaches within your Organization

SACRAMENTO, CA – A bill in California aimed at strengthening the state’s existing data breach notification requirements will become law on January 1, 2012.

Senate Bill 24, championed by Sen. Joe Simitian (D-Palo Alto), was approved last week by Gov. Jerry Brown.

[See also: Privacy breach worries still dog electronic health records]

As a result of legislation Simitian passed in 2002 (AB 700), California law requires data holders, such as businesses or state agencies, to notify individuals when there has been a breach of personal information. However, the law does not indicate what information should be contained in this notification.

“Senate Bill 24 is the logical next step to ensure consumers have the specific information they need to protect themselves after a data breach,” said Simitian. 

Specifically, SB 24 establishes standard, core content for data breach notifications including a general description of the incident, the type of information breached, the time of the breach and toll-free telephone numbers and addresses of the major credit reporting agencies in California.

[See also: Data breaches top of mind for IT decision makers]

“No one likes to get the news that personal information about them has been stolen,” said Simitian. “But when it happens, people deserve to get the information they need to decide what to do next.”

SB 24 also requires data holders to send an electronic copy of the notification to the Attorney General, if a single breach affects more than 500 Californians. This requirement will “give law enforcement the ability to see the big picture and better understand the patterns and practices of identity theft statewide,” Simitian explained.

A survey by the Samuelson Law, Technology & Public Policy Clinic at UC Berkeley found that 28 percent of data breach victims receiving a security breach notification letter “do not understand the potential consequences of the breach after reading the letter.”

The California Office of Privacy Protection referred to the bill signing as, “a great day for California” and indicated that the senator’s bill, “helps protect and empower Californians.”

Privacy Rights Clearinghouse, a non-profit consumer education and advocacy group, reports that at least 500 million sensitive records have been compromised nationwide since 2005.

Since Simitian’s original privacy legislation (AB 700) was signed into law in 2002, more than 45 states have adopted legislation modeled on California’s statute. At least 14 other states, and Puerto Rico, also require security breach notifications to include specified information, just as SB 24 does.

For more information on SB 24, click here.

Related Topics:
  • California
  • Jerry Brown
  • Joe Simitian
  • Palo Alto
  • Sacramento
  • Electronic Health Records
  • Policy and Legislation
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • AMA calls for 2-year extension of ICD-10 deadline
  • Twitter recap: Lee Aase talks social media in healthcare
  • FCC to vote on broadband space for patient monitoring
  • Allscripts in skid mode as shares plunge, chairman ousted
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
more news

WEBINARS AND WHITE PAPERS

  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
  • ON DEMAND WEBINARS
    Redefining Value and Success in Healthcare: Charting the Path to the Future
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
  • Chief Information Officer - West Virginia - InfoPartners, Inc. - West Virginia
  • IT Technical Services Director - Genesis HealthCare System - Zanesville, OH
  • VP, CLINICAL INFORMATICS - The Methodist Hospital System - Houston, TX
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy