Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Data Security Has to Be A Priority For Your Organization

Data Security Has to Be A Priority For Your Organization

Considering that since January 1st of this year, there has been upwards of 10 million personal information records lost or stolen each day, odds are that you, or someone you know, has had their records compromised by a data breach. With such a high incident rate, individuals and businesses that have never received any kind of notification that their records were included in a breach, generally consider themselves lucky and assume that they are not at risk of identity theft or unauthorized account usage. Unfortunately for them, that is not always the case.

The fact is that there is a significant chance that your personal or non-public business information has been compromised in some way but, legally, the company that lost your information was not obligated to make you aware of the event. For your own benefit, understanding what your rights are when it comes to data breach laws is the first step in protecting your data. For example, do you know what information is considered ‘personal’? Are there ways that your data could have been lost or stolen but the offending entity was not compelled by law to notify you for some reason? The answer is yes.

Legal Definitions of Personal Information
Even though each state has their own laws and policies regarding data breaches and notification requirements, there is pretty much a consensus on the basics of what elements or combination of elements constitutes as ‘personal information’ in the eyes of the law. At a minimum, personal information includes:

  1. First name or first initial and last name
                        AND
  2. One or more of the following elements: social security number, driver’s license or state ID number, finance account numbers.

As mentioned, this does make up the foundation of most secular legislation on data breaches. Many states go a step further, and only consider account information requiring a pin or password as having been compromised if the required pin or password was included with the record that was stolen. That is, if the use of a debit card requires a pin for a transaction, you will not be notified of the data loss unless both your debit card number and the pin are accessed.

A few of the more progressive states, like North Carolina and Nebraska, include biometrics and fingerprint information as part of their definition of personal information. Similarly, some states, like Missouri have more specific, detailed laws, limiting the legal maneuverability that comes with ambiguity in statutes.

Even though laws regarding the majority of health and medical information and data policies are covered under the United States’ federally mandated Health Insurance Portability and Accountability Act (HIPAA), a few states do include health-related information in their definition of personal information.

One more thing that the some of the state laws regarding data breaches of personal information address is that once a relatively high number of records have been stolen, the information holders must also notify consumer reporting agencies in addition to the Attorney Generals of all states that have affected residents. The number of records lost that trigger reporting to a consumer reporting agency tend to number between 1,000 and 5,000.

When it comes to sectoral legislation, the current statutes are, in general, skewed in favor of protecting the corporate information holder, as opposed to the individuals that have their information compromised.

  • Encryption: In many states, there is specific language that says that if the personal information was redacted or encrypted at the time of the unauthorized access, then no breach or loss of data has occurred. The laws do not address the policy and notification standards for encryption that is broke post-theft.
  • Questionable Non-Personal Information: Depending on the state, some questionable information might be included as non-personal information. For example, the last four digits of your social security number may not be counted as personal information, despite the amount of accounts that only require you to confirm these four digits before making changes to your account.
  • Good-faith Acquisitions: Nearly every state lists ‘good faith acquisitions’ as exemptions to the data breach laws. A ‘good faith acquisition’ is defined a data loss event where the recipient of the personal information in question is employed internally or with a trusted vendor or partner - and is therefore not likely to be misused or further exposed. It’s important to note that businesses are not required to notify anyone in the event that the data breach meets ‘good faith’ requirements.
  • Risk of Harm Analysis: About half of the United States has laws that allow the information-holding entity to run a ‘Risk of Harm’ analysis that is used to determine the likelihood that the personal information compromised is likely to be abused or used in unauthorized transactions by the parties that have obtained it - or may obtain it in the future. In the event that the risk of harm is found to be minimal, they do not have to notify the attorney general of the state for which the analysis was run, nor do they need to notify the parties whose personal information was lost.

For most small and medium-sized businesses, a data breach, regardless of whether their information was stolen or their network had been penetrated losing client records, has the potential be catastrophic. Working with Voyage Technology, we can help you take proactive data and network security measures and significantly reduce the chance that your network will fall victim to cybercriminals. Contact us at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 04 June 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips IT Services Internet Malware Workplace Tips Phishing Privacy IT Support Google Email Computer Workplace Strategy Small Business Collaboration Hosted Solutions Managed Service Backup Ransomware Users AI Mobile Device Productivity Microsoft Saving Money Quick Tips Passwords Communication Cybersecurity Data Backup Smartphone Disaster Recovery Data Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Browser Social Media Microsoft Office Managed IT Services Current Events Network Tech Term Internet of Things Remote Miscellaneous Information Training Facebook Holiday Automation Artificial Intelligence Outsourced IT Compliance Gadgets Cloud Computing Covid-19 Remote Work Server Managed Service Provider IT Support Encryption Spam Employee/Employer Relationship Office Windows 10 Government Data Management Business Continuity Virtualization Blockchain Wi-Fi Vendor Business Technology Windows 10 Bandwidth Data Security Apps Two-factor Authentication Mobile Office Tip of the week Managed Services WiFi Networking Apple App Employer-Employee Relationship BYOD Mobile Device Management Chrome Gmail Budget Voice over Internet Protocol Managed IT Services How To BDR HIPAA Computing Physical Security Hacker Applications Information Technology Avoiding Downtime Marketing Access Control Office 365 Conferencing Password Bring Your Own Device Big Data Operating System Router Computers Virtual Private Network Risk Management Website Health 2FA Help Desk Analytics Office Tips Augmented Reality Retail Storage Healthcare Scam The Internet of Things Data loss Cooperation Free Resource Social Project Management Windows 7 Patch Management Going Green Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Customer Service Cybercrime Display Printer Paperless Office Windows 11 Infrastructure Monitoring Excel Firewall Document Management Remote Workers Managed IT Service Telephone Mouse iPhone Licensing Administration Entertainment Vulnerabilities Data Privacy Images 101 Telephone System Multi-Factor Authentication Robot Mobility Cost Management Customer Relationship Management Settings Wireless Printing Content Filtering IT Management Hacking VPN Employees Meetings Presentation YouTube Integration Cryptocurrency User Tip Modem Wireless Technology Computer Repair Mobile Security Processor Virtual Desktop Holidays Data storage LiFi Data Storage Word Smart Technology Supply Chain Outlook Video Conferencing Machine Learning Managed Services Provider Saving Time Virtual Machines Money Professional Services Humor Safety Maintenance Antivirus Downloads Sports Education Browsers Smartwatch Connectivity IT Social Engineering Break Fix Scams Remote Computing Azure Hybrid Work Upload Procurement Social Network Telework Cyber security Mobile Computing Multi-Factor Security Tech Human Resources Search CES Tablet IoT Communitications Dark Web Cables Trends Supply Chain Management Alert Application Best Practice Managed IT Customer Resource management FinTech File Sharing Regulations Dark Data Google Calendar Term Google Apps Buisness How To Microsoft Excel IT Maintenance IT solutions Data Analysis Star Wars IT Assessment IBM Legal Gamification Flexibility Notifications Staff Value Business Intelligence Business Growth Organization Travel Social Networking Legislation Shortcuts Ransmoware Cortana Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Content Remote Working Wearable Technology Memory Vendors Alt Codes Health IT Unified Threat Management Motherboard Data Breach Competition Comparison Google Play Be Proactive Downtime Permissions Workforce Hosted Solution Unified Threat Management Directions Videos Assessment Electronic Health Records Wasting Time Threats Typing Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Fraud Meta User Knowledge User Error Microchip Internet Exlporer Software as a Service Google Drive Username Managing Costs Amazon 5G Point of Sale eCommerce Black Friday SSID IP Address Google Docs Virtual Assistant Outsource IT Unified Communications Experience Database Surveillance Network Management Tech Support IT Technicians Virtual Machine Environment Bitcoin Media Running Cable Proxy Server Reviews Cookies Google Wallet Monitors Cyber Monday Medical IT Hotspot Transportation Small Businesses Recovery Tactics Development Websites Mirgation Hypervisor Displays Hard Drives Windows 8 Laptop Shopping Nanotechnology Optimization Domains Drones PowerPoint Electronic Medical Records Language Employer/Employee Relationships Outsourcing SharePoint Addiction Management PCI DSS Chatbots Refrigeration Navigation Halloween Lenovo Gig Economy Screen Reader Public Speaking Writing Distributed Denial of Service Workplace Lithium-ion battery Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Service Level Agreement Internet Service Provider Server Management Regulations Compliance Private Cloud Identity Hacks Evernote Paperless Entrepreneur Scary Stories Fun Superfish Bookmark Identity Theft Smart Tech Memes Co-managed IT Twitter Alerts SQL Server Technology Care Deep Learning Download Net Neutrality Financial Data Error History Undo Business Communications

Blog Archive