HB 6607 — AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
Last action — SIGNED BY GOVERNOR
-
✓Introduced
-
✓In Committee
-
✓Passed House
-
✓Passed Senate
-
✓To Executive
-
6Enacted
This bill has been enacted into law. Introduced March 10, 2021. Enacted.
Odds of enactment
High chanceBased on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.
Upgrade to see the exact probability and what's driving it.
A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.
Prognosis
-
Enacted
Current position in the legislative process.
-
7 sponsors
7 primary, 0 co-sponsors signed on.
-
Bipartisan support
Sponsored across 2 parties (3 R · 1 D) — cross-party backing.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
Bill Text
What changed in the latest version
155 added · 365 removed155 line(s) added, 365 removed.
Substitute House ofBill Representatives File No.
7146607 GeneralPublic AssemblyAct January Session, 2021(Reprint of File No.
598)21-119 SubstituteAN HouseACT BillINCENTIVIZING No.THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
6607 As Amended by House Amendment Schedule "A" Approved by the Legislative Commissioner May 24, 2021 AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
(3) "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of sHB6607personal /information Fileor No.restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.
714"Data sHB6607breach" Filedoes not include (A) good faith acquisition of personal information or restricted information Substitute House Bill No.
7146607 personalby informationthe orcovered restrictedentity's informationemployee ownedor byagent orfor licensedthe topurposes aof the covered entityentity, andprovided thatthe causes,personal reasonablyinformation or restricted information is believednot toused havefor causedan unlawful purpose or reasonablysubject isto believedfurther willunauthorized causedisclosure, aor material(B) riskacquisition of identitypersonal theftinformation or restricted information pursuant to a search warrant, subpoena or other fraudcourt order, or pursuant to a personsubpoena, order or property.duty of a regulatory state agency;
"Data breach" does not include (A) good faith acquisition of personal information or restricted information by the covered entity's employee or agent for the purposes of the covered entity, provided the personal information or restricted information is not used for an unlawful purpose or subject to further unauthorized disclosure, or (B) acquisition of personal information or restricted information pursuant to a search warrant, subpoena or other court order, or pursuant to a subpoena, order or duty of a regulatory state agency;
"Personal information" does not include publicly available information that is lawfully made sHB6607available /to Filethe No.general public from federal, state or local government records or widely distributed media;
714and sHB6607Public FileAct No.
71421-119 available2 toof the6 generalSubstitute publicHouse fromBill federal,No. state or local government records or widely distributed media;
and6607 (5) "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered by any method or technology in such a manner that the information is unreadable, and the breach of which is likely to result in a material risk of identity theft or other fraud to a person or property.
(i) The "Framework for Improving Critical Infrastructure sHB6607Public /Act File No.
71421-119 sHB66073 Fileof 6 Substitute House Bill No.
7146607 Cybersecurity" published by the National Institute of Standards and Technology;
106-102, as amendedPublic fromAct timeNo. to time;
sHB660721-119 /4 Fileof 6 Substitute House Bill No.
7146607 sHB6607amended Filefrom No.time to time;
714 (iii) The Federal Information Security Modernization Act of 2014,P.L.
and (C) protect against unauthorized access to and acquisition of the information that would result in a material risk of identity theft or other fraudPublic toAct theNo. individual to whom the information relates.
21-119 5 of 6 Substitute House Bill No.
6607 fraud to the individual to whom the information relates.
(A) The size and complexity of sHB6607the /covered Fileentity; No.
714 sHB6607 File No.
714 the covered entity;
ThisApproved actJuly shall6, take2021 effectPublic asAct followsNo. and shall amend the following sections:
Section21-119 16 Octoberof 1,6 2021 New section sHB6607 / File No.
714 6 sHB6607 File No.
714 The following Fiscal Impact Statement and Bill Analysis are prepared for the benefit of the members of the General Assembly, solely for purposes of information, summarization and explanation and do not represent the intent of the General Assembly or either chamber thereof for any purpose.
In general, fiscal impacts are based upon a variety of informational sources, including the analyst’s professional knowledge.
Whenever applicable, agency data is consulted as part of the analysis, however final products do not necessarily reflect an assessment from any specific department.
OFA Fiscal Note State Impact:
None Municipal Impact:
None Explanation The bill establishes an affirmative defense for covered entities in civil actions and does not result in a fiscal impact to the state or municipalities.
House "A" makes technical and clarifying changes that do not result in a fiscal impact.
The Out Years State Impact:
None Municipal Impact:
None sHB6607 / File No.
714 sHB6607 File No.
714 OLR Bill Analysis sHB 6607 (as amended by House "A")* AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
Show all 116 changed lines (76 more)
SUMMARY This bill prohibits the Superior Court from assessing punitive damages against a covered entity (see below) for a data breach of personal or restricted information if the covered entity meets specified cybersecurity requirements.
Specifically, when a civil action alleges that a data breach resulted from a covered entity’s failure to implement reasonable cybersecurity controls, thecourtmaynot assesspunitive damagesif thecoveredentity created, maintained, and complied with a written cybersecurity program containing administrative, technical, and physical safeguards for protecting personal or restricted information.
To qualify for this protection, these cybersecurity programs must (1) meet specified design requirements and (2) conform to an industry-recognized cybersecurity framework.
However, the protection does not apply if the covered entity’s failure to implement reasonable cybersecurity controls resulted from gross negligence or willful or wanton conduct.
Under the bill, “covered entities” are businesses accessing, maintaining, communicating, or processing personal or restricted information in or through systems, networks, or services located inside or outside the state.
The bill’s provisions do not:
1.
affect or limit the process of granting certification in class actions;
sHB6607 / File No.
714 8 sHB6607 File No.
714 2.
affect or limit existing statutory requirements for (a) state contractors who receive confidential information and (b) Connecticut businesses that maintain computerized personal information and suffer security breaches;
or 3.
limit the authority of the attorney general or the Department of Consumer Protection commissioner to seek administrative, legal, or equitable relief allowed by law.
*House Amendment “A” (1) changes the bill’s protection for qualifying covered entities from an affirmative defense to a prohibition on punitive damages and disqualifies covered entities from this protection for certain conduct;
(2) changes, to six months, the time period by which a covered entity’s cybersecurity program must conform with revisions or amendments to certain cybersecurity frameworks, laws, and regulations;
(3) explicitly exempts certain statutes, executive powers, and legal processes from the bill’s provisions;
(4) makes changes to the definitions of personal and restricted information;
and (5) makes minor and technical changes.
EFFECTIVE DATE:
October 1, 2021 CYBERSECURITY PROGRAM DESIGN REQUIREMENTS To qualify for the bill’s protection against punitive damages, a covered entity’s cybersecurity program must be designed to protect the security and confidentiality of personal and restricted information.
The program must specifically protect this information against (1) threats or hazards to its security or integrity and (2) unauthorized access and acquisition that would cause material risk of identity theft or other fraud.
The bill requires the scale and scope of a covered entity’s cybersecurity program to be based on the:
1.
entity’s size and complexity, and the nature and scope of its activities;
sHB6607 / File No.
714 9 sHB6607 File No.
714 2.
sensitivity of the information to be protected;
and 3.
cost and availability of tools to improve information security and reduce vulnerabilities.
INDUSTRY-RECOGNIZED CYBERSECURITY FRAMEWORKS Under the bill, an industry-recognized cybersecurity framework includes the most current version of:
1.
one or any combination of six specifically recognized frameworks (see Table 1), 2.
one of four specified federal laws and regulations (for entities regulated by any ofthese lawsor thestate or federalgovernment;
see Table 2), or 3.
the “Payment Card Industry Data Security Standard” in combination with one of the acceptable frameworks mentioned in Table 1 below.
Table 1:
Industry-Recognized Cybersecurity Frameworks Publisher Framework National Institute of Standards and "Framework for Improving Critical Technology Infrastructure Cybersecurity" Special Publication (SP) 800-171 SP 800-53 and 800-53a Federal Risk and Management "FedRAMP Security Assessment Program Framework" Center for Internet Security "Center for Internet Security Critical Security Controls for Effective Cyber Defense" International Organization for "ISO/IEC 27000-series" Standardization and the International Electrotechnical Commission sHB6607 / File No.
714 10 sHB6607 File No.
714 Table 2:
Federal Cybersecurity Laws and Regulations Citation Law or Regulation P.L.
104-191;
Security requirements of the Health Insurance Portability and C.F.R.
164 Accountability Act of 1996 (Subpart C) P.L.
106-102 Title V of the Gramm-Leach-Bliley Act of 1999 P.L.
113-283 Federal Information Security Modernization Act of 2014 C.F.R.
162 Security requirements of the Health Information Technology for Economic and Clinical Health Act The bill requires a covered entity to conform with revisions or amendments to these frameworks, laws, and regulations within six months after the revised document is published or the laws or regulations are amended, as applicable.
DEFINITIONS Businesses Under the bill, a covered entity’s business type may include an individualor a sole proprietorship,partnership,firm, corporation,trust, limited liability company or partnership, joint stock company, joint ventures, associations, or other legal entities through which for-profit or non-profit business is conducted.
Data Breach The bill defines a “data breach” as unauthorized access to and acquisition of computerized data that (1) compromises the security or confidentiality of personal or restricted information owned by or licensedtoacoveredentityand(2)causesamaterialriskofidentitytheft or other fraud to a person or property (or reasonably is believed to have caused or will cause such risk).
The definition specifically excludes:
1.
employees or agents of a covered entity acquiring personal or restricted information in good faith for the purposes of the entity, so long as the entity does not unlawfully use this information or subject it to further unauthorized disclosure, or sHB6607 / File No.
714 11 sHB6607 File No.
714 2.
the acquisition of this information pursuant to a (a) search warrant, (b) subpoena or other court order, or (c) regulatory state agency’s order or duty.
Personal and Restricted Information Under the bill, “personal information” means an individual’s first name or initial and last name in combination with one or more of the following:
1.
social security, taxpayer identification, Internal Revenue Service- issued identity protection personal identification, driver’s license, state identification card, passport, or military identification numbers, or other commonly used government- issued identification numbers;
2.
credit or debit card numbers;
financial account numbers in combination with required security codes, access codes, or passwords that would permit access to these accounts;
3.
medical information on an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
4.
health insurance policy or subscriber identification numbers, or unique identifiers health insurers use to identify individuals;
or 5.
biometric information that can identify an individual using their unique physical characteristics, including a fingerprint, voice print, or retina or iris image.
Personal information also includes user names or e-mail addresses in combination with passwords or security questions and answers that would permit access to online accounts.
However, the definition excludespublicly availableinformationlawfully availabletothegeneral public from federal, state, or local government records or widely distributed media.
sHB6607 / File No.
714 12 sHB6607 File No.
714 “Restricted information” means any unencrypted, unredacted, or unaltered information about an individual that, alone or in combination with other information (including personal information as described above), (1) can be used to distinguish or trace the individual’s identity or is reasonably linked or linkable to an individual and (2) is likely to result in a material risk of identity theft or other fraud to a person or property if breached.
The definition excludes personal or publicly available information.
COMMITTEE ACTION Commerce Committee Joint Favorable Change of Reference - JUD Yea 22 Nay 1 (03/22/2021) Judiciary Committee Joint Favorable Substitute Yea 32 Nay 3 (04/09/2021) sHB6607 / File No.
714 13
Show all 116 changed rows (76 more)
View plain text versions (6)
- Chaptered Public Act No. 21-119 Current pdf
- File No. 714 View text pdf
- File No. 598 View text pdf
- CE Joint Favorable Change of Reference View text pdf
- Raised Bill View text pdf
- Substitute JUD Joint Favorable Substitute pdf
AI-generated reading aid from the bill's amendatory text — verify against the official bill.
The bill establishes definitions and legal protections for businesses adopting cybersecurity standards, specifically shielding them from punitive damages in certain data breach lawsuits if they comply with specified cybersecurity guidelines.
-
(b)
none→ the Superior Court shall not assess punitive damages against a covered entity if such entity created, maintained and complied with a written cybersecurity program that contains administrative, technical and physical safeguards for the protection of personal or restricted information and that conforms to an industry recognized cybersecurity framework, as described in subsection (c) of this section and that such covered entity designed its cybersecurity program in accordance with the provisions of subsection (d) of this section.Introduces a legal protection for businesses that implement a compliant cybersecurity program against punitive damages in data breach related lawsuits.
-
(g)
none→ but shall not be construed to affect or limit any requirement of section 4e-70 or 36a-701b of the general statutes.Clarifies that the new cybersecurity regulations do not alter existing requirements under specific sections of the general statutes.
-
Section 1 (a) (1)
none→ "Business" means any individual or sole proprietorship, partnership, firm, corporation, trust, limited liability company, limited liability partnership, joint stock company, joint venture, association or other legal entity through which business for profit or not-for-profit is conducted;Defines what constitutes a 'business' for the purposes of cybersecurity regulation.
-
Section 1 (a) (2)
none→ "Covered entity" means a business that accesses, maintains, communicates or processes personal information or restricted information in or through one or more systems, networks or services located in or outside this state;Defines 'covered entity' to clarify which businesses are subject to the cybersecurity protections.
-
Section 1 (a) (3)
none→ "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information or restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.Establishes a legal definition of 'data breach' that delineates the specific conditions constituting a breach.
-
Section 1 (a) (4)
none→ "Personal information" means an individual's (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; ... (B) user name or electronic mail address, in combination with a password or security question and answer that would permit access to an online account.Defines 'personal information' to establish the types of data that are subject to protections against breaches.
-
Section 1 (a) (5)
none→ "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered.Defines 'restricted information' to set parameters for what additional data may require protection under cybersecurity standards.
-
(c) (1) (A) (vi)
none→ the "ISO/IEC 27000-series" information security standards published by the International Organization for Standardization and the International Electrotechnical Commission.Specifies that compliance with ISO/IEC 27000-series standards is a valid framework for cybersecurity programs.
-
(c) (2) (A) (iv)
none→ or the security requirements of the Health Information Technology for Economic and Clinical Health Act, as amended from time to time, as set forth in 45 CFR 162, as amended from time to time.Includes the security requirements of additional federal legislation as a possible standard for compliance.
-
(c) (3) (A)
none→ The cybersecurity program complies with the current version of the "Payment Card Industry Data Security Standard" and the current version of another applicable industry recognized cybersecurity framework described in subparagraph (A) of subdivision (1) of this subsection.Mandates compliance with the Payment Card Industry Data Security Standards as part of cybersecurity requirements.
Action History
-
SIGNED BY GOVERNOR
-
TRANSMITTED BY SECRETARY OF THE STATE TO GOVERNOR
-
TRANSMITTED TO SECRETARY OF THE STATE
-
PUBLIC ACT 21-119
-
ON CONSENT CALENDAR /IN CONCURRENCE
-
SEN. PASSED, HO. AMEND. SCH. A
-
SEN. ADOPTED HO. AMEND. SCH. A
-
FILE NO. 714
-
SENATE CALENDAR NUMBER 476
-
FAV. RPT., TAB. FOR CAL., SEN.
-
HOUSE PASSED, HOUSE AMEND. SCH. A
-
HOUSE ADOPTED HOUSE AMEND. SCH. A
-
FILE NO. 598
-
HOUSE CALENDAR NUMBER 421
-
FAV. RPT., TABLED FOR HOUSE CALENDAR
-
RPTD. OUT OF LCO
-
REFERRED TO Office of Legislative Research AND Office of Fiscal Analysis 04/26/21
-
FILED WITH LCO
-
Joint Favorable Substitute
-
FAV. CHG. OF REF., SEN. TO COMM. ON Judiciary
-
FAV. CHG. OF REF. HOUSE TO COMM. ON Judiciary
-
RPTD. OUT OF LCO
-
FILED WITH LCO
-
Joint Favorable Change of Reference JUD
-
PUBLIC HEARING 0318
-
REF. TO JOINT COMM. ON Commerce
Sponsors
- David Rutigliano · Primary
- Robyn A. Porter · Primary
- Kathy Kennedy · Primary
- Charles J. Ferraro · Primary
- Craig C. Fishbein · Primary
- Kevin D. Witkos · Primary
- Larry B. Butler · Primary
Sponsorship breakdown
Export CSV (upgrade) →7 sponsors · 0 co-sponsors · 180 not signed on
Sponsors (7)
- David Rutigliano Republican
- Porter, Robyn A.
- Kathy Kennedy Republican
- Ferraro, Charles J.
- Craig C. Fishbein Republican
- Witkos, Kevin D.
- Larry B. Butler Democratic
Co-sponsors (0)
None.
Not signed on (180)
180 members have not signed on to this bill.
Show all 180 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Subjects
Frequently asked questions
- Who sponsors HB 6607?
- HB 6607 is sponsored by David Rutigliano (Republican), Porter, Robyn A., Kathy Kennedy (Republican), Ferraro, Charles J., Craig C. Fishbein (Republican), Witkos, Kevin D., and Larry B. Butler (Democratic).
- What is the current status of HB 6607?
- This bill has been enacted into law. Introduced March 10, 2021. Enacted.
- Where can I track HB 6607?
- Track HB 6607 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 6607
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 6607
Last checked for changes 2 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →