Attorney General Launches Online Portal to Report Data Breaches
On June 28, 2024, Governor Josh Shapiro approved amendments to the Breach of Personal Information Notification Act (BPINA). In response, the Attorney General’s Office recently announced the launch of an online portal to streamline the process for companies and other entities reporting data breaches.
BPINA was initially signed into law on December 22, 2005 by Governor Ed Rendell in order to ensure that personal information of Pennsylvanians was protected in the event it is stolen. Now, credit reporting companies, or other entities that hold onto personal data such as dealerships, must report data breaches to the Office of Attorney General, when a data breach affects more than 500 Pennsylvanians. The most recent amendments to BPINA include:
In addition to the requirement to report data breaches, companies must also provide impacted individuals with 12 months of credit monitoring and access to a credit report, if the breach involves the person’s name and Social Security Number, bank account number, or driver’s license or state ID number.
BPINA defines a breach as the unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by an entity as part of a database of personal information and that causes or the entity reasonably believes has caused or will cause loss or injury to a Pennsylvania resident.
Personal information consists of two components:
1. An individual’s first name or first initial and last name; and
2. Any one or more of the following, not made publicly available:
The Attorney General notice must include:
To report a data breach to the Office of the Attorney General or to learn more about BPINA, visit https://www.attorneygeneral.gov/report-breach/