What Utah Companies Need to Know About Utah Cybersecurity Law

From: Utah Business

By David M. Stauss, Gregory P. Szewczyk, and Zaven Sargsian

***

Perhaps the most notable requirement is that Utah law requires entities (with the exception of certain financial institutions) to implement and maintain “reasonable procedures” to prevent the unlawful use or disclosure of PI. The law defines “personal information” an individual’s first name or first initial and last name combined with a social security number, driver’s license number, state identification card number, or financial account number, credit card or debit card number in combination with any required security code, access code or password that would permit access to a person’s account. In essence, any entity with employee or customer records containing these data elements is subject to this “reasonable procedures” requirement.

Unfortunately, the law does not define what constitutes reasonable procedures. This is not uncommon—many states that have enacted similar legislation have failed to provide such guidance. Therefore, Utah entities should look to analogous laws and regulations such as HIPAA’s Security Rule, the Gramm-Leach Bliley Act’s Safeguards Rule, Massachusetts’ data security regulations, and the New York Department of Financial Services Cybersecurity Regulations. For example, entities may consider preparing written information security and cyber-incident response plans, creating a data map, performing a risk assessment and implementing appropriate employee policies and administrative safeguards, among other things.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *