Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region

      Select your region below to see curated info.

    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    back
    Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    back
    Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
  • Select Region

      Select your region below to see curated info.

    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Employment Law & Compliance
  3. Pennsylvania Data Breach Law's Amendments Will Take Effect Soon
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Pennsylvania Data Breach Law's Amendments Will Take Effect Soon

March 20, 2023 | Lauren Godfrey © Constangy, Brooks, Smith & Prophete

A man using a laptop with a security symbol on it.


​Recent amendments to Pennsylvania's data breach law, the Breach of Personal Information Notification Act, will take effect May 3.

Originally enacted in 2006, the law provides for the security of computerized data and requires notification to Pennsylvania residents whose personal information data was, or may have been, disclosed due to a breach of the security of an entity's system. In amending the law, the state legislature took steps similar to other states' data breach notification statutes and expanded the definition of personal information.

Forthcoming Changes

The expanded definition that will take effect May 3 includes medical and health information, and a user name or email address in combination with a password or security questions and answers that would permit access to an online account. These are in addition to the categories of personal information that all states regulate – for example, name in combination with a Social Security Number, driver license number or state identification card number, or financial account or debit/credit card number in combination with an access code, password, or security code that would allow access to the account.

The law currently requires notification when a discovery has been made that there was a security breach. As amended, the law will require notification when a determination of a breach has been made. The new standard will be more entity-friendly than the prior standard because it takes into account an entity's need to investigate whether a breach has occurred before it is obligated to provide notice. A discovery occurs when the entity has "the knowledge of or reasonable suspicion" that a breach has occurred. A determination occurs when the entity has "a verification or reasonable certainty" that a breach has occurred.

A breach of the security of the system is defined as "unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals."

The law currently applies to state agencies, but the amendments will expand the law to cover state agency contractors, as well. The amended law includes specific timelines and requirements for notification by state agencies, state agency contractors, public schools, counties, and municipalities when a determination of breach has been made.

For example, state agencies and their contractors will have seven business days to notify individuals after the breach determination, and they must also notify the Office of the Attorney General by the same deadline. Counties, public schools, and municipalities will have seven days to notify individuals and three days to notify the district attorney's office in the county in which the breach occurred. Other governmental entities are not required to notify the attorney general's office.

The amendments include provisions that require state agencies and state agency contractors to protect the personal information of the commonwealth that they maintain, store, or manage. These protective measures include encryption or other appropriate security measures to protect the information from unauthorized access or acquisition, either when being transmitted or when at rest. 

The amendments also require the development of policies and procedures to protect such data. With regard to storing personal information on behalf of the commonwealth, the amended law requires state agencies and their contractors to "develop a policy to govern reasonably proper storage of the personal information" with the goal of reducing the risk of future breaches of the security of the systems. The amendments even dictate the considerations that state agencies and their contractors must take into account when developing those policies and procedures, including best practices considered by the federal government and the commonwealth.

Entities will be allowed to provide email notice to the affected individuals when the breach involves a user name or email address in combination with a password, or a security question and answer that would permit access to an online account. Email notice will be permitted under these circumstances if the email directs the individual to promptly change his or her password and security question or answer, or to take other appropriate steps to protect the online account with the entity or other online accounts involving the same personal information.

In Compliance

Entities will be deemed to comply with Pennsylvania law if they are in compliance with the privacy rule of the federal Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act.

State agencies and their contractors will be deemed to comply with the Pennsylvania law if they are in compliance with the notification requirements established by their primary state or functional federal regulators.

In sum, the amendments will bring Pennsylvania's data breach notification scheme into line with other states that are seeking to hold entities responsible for the protection of consumer personal information and personal health information. It will hold state agencies and their contractors to stricter notification requirements and a higher degree of responsibility when maintaining, storing, and managing personal information.

Lauren Godfrey is an attorney with Constangy, Brooks, Smith & Prophete in Philadelphia. © 2023. All rights reserved. Reprinted with permission.

ESG, Ethics & Compliance
Privacy & Security Compliance
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

Workplace Compliance Newsletter

Keep abreast of employment law and compliance developments and their wide-reaching impacts.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • SHRM India Advisory Council
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Ask an Advisor
  • SHRM Newsletter
  • Post a Job
  • Find an HR Job
  • Advertise with us
  • Copyright & Permission
Contact Us


Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

SHRM India Corporate Information

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now