Connecticut 2021 Regular Session Status: Enacted Bipartisan · 3 R · 1 D cosponsors

HB 6607 — AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.

Last action — SIGNED BY GOVERNOR

  1. ✓
    Introduced
  2. ✓
    In Committee
  3. ✓
    Passed House
  4. ✓
    Passed Senate
  5. ✓
    To Executive
  6. 6
    Enacted

This bill has been enacted into law. Introduced March 10, 2021. Enacted.

Odds of enactment

High chance

Based on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Likely to advance 78% · moderate confidence
  • Enacted

    Current position in the legislative process.

  • 7 sponsors

    7 primary, 0 co-sponsors signed on.

  • Bipartisan support

    Sponsored across 2 parties (3 R · 1 D) — cross-party backing.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

Bill Text

What changed in the latest version

155 added · 365 removed

155 line(s) added, 365 removed.

→
Previous
Latest
House of Representatives File No.
Substitute House Bill No.
714 General Assembly January Session, 2021(Reprint of File No.
6607 Public Act No.
598) Substitute House Bill No.
21-119 AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
6607 As Amended by House Amendment Schedule "A" Approved by the Legislative Commissioner May 24, 2021 AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
(3) "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of sHB6607 / File No.
(3) "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information or restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.
714 sHB6607 File No.
"Data breach" does not include (A) good faith acquisition of personal information or restricted information Substitute House Bill No.
714 personal information or restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.
6607 by the covered entity's employee or agent for the purposes of the covered entity, provided the personal information or restricted information is not used for an unlawful purpose or subject to further unauthorized disclosure, or (B) acquisition of personal information or restricted information pursuant to a search warrant, subpoena or other court order, or pursuant to a subpoena, order or duty of a regulatory state agency;
"Data breach" does not include (A) good faith acquisition of personal information or restricted information by the covered entity's employee or agent for the purposes of the covered entity, provided the personal information or restricted information is not used for an unlawful purpose or subject to further unauthorized disclosure, or (B) acquisition of personal information or restricted information pursuant to a search warrant, subpoena or other court order, or pursuant to a subpoena, order or duty of a regulatory state agency;
"Personal information" does not include publicly available information that is lawfully made sHB6607 / File No.
"Personal information" does not include publicly available information that is lawfully made available to the general public from federal, state or local government records or widely distributed media;
714 sHB6607 File No.
and Public Act No.
714 available to the general public from federal, state or local government records or widely distributed media;
21-119 2 of 6 Substitute House Bill No.
and (5) "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered by any method or technology in such a manner that the information is unreadable, and the breach of which is likely to result in a material risk of identity theft or other fraud to a person or property.
6607 (5) "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered by any method or technology in such a manner that the information is unreadable, and the breach of which is likely to result in a material risk of identity theft or other fraud to a person or property.
(i) The "Framework for Improving Critical Infrastructure sHB6607 / File No.
(i) The "Framework for Improving Critical Infrastructure Public Act No.
714 sHB6607 File No.
21-119 3 of 6 Substitute House Bill No.
714 Cybersecurity" published by the National Institute of Standards and Technology;
6607 Cybersecurity" published by the National Institute of Standards and Technology;
106-102, as amended from time to time;
106-102, as Public Act No.
sHB6607 / File No.
21-119 4 of 6 Substitute House Bill No.
714 sHB6607 File No.
6607 amended from time to time;
714 (iii) The Federal Information Security Modernization Act of 2014,P.L.
(iii) The Federal Information Security Modernization Act of 2014,P.L.
and (C) protect against unauthorized access to and acquisition of the information that would result in a material risk of identity theft or other fraud to the individual to whom the information relates.
and (C) protect against unauthorized access to and acquisition of the information that would result in a material risk of identity theft or other Public Act No.
21-119 5 of 6 Substitute House Bill No.
6607 fraud to the individual to whom the information relates.
(A) The size and complexity of sHB6607 / File No.
(A) The size and complexity of the covered entity;
714 sHB6607 File No.
714 the covered entity;
This act shall take effect as follows and shall amend the following sections:
Approved July 6, 2021 Public Act No.
Section 1 October 1, 2021 New section sHB6607 / File No.
21-119 6 of 6
714 6 sHB6607 File No.
714 The following Fiscal Impact Statement and Bill Analysis are prepared for the benefit of the members of the General Assembly, solely for purposes of information, summarization and explanation and do not represent the intent of the General Assembly or either chamber thereof for any purpose.
In general, fiscal impacts are based upon a variety of informational sources, including the analyst’s professional knowledge.
Whenever applicable, agency data is consulted as part of the analysis, however final products do not necessarily reflect an assessment from any specific department.
OFA Fiscal Note State Impact:
None Municipal Impact:
None Explanation The bill establishes an affirmative defense for covered entities in civil actions and does not result in a fiscal impact to the state or municipalities.
House "A" makes technical and clarifying changes that do not result in a fiscal impact.
The Out Years State Impact:
None Municipal Impact:
None sHB6607 / File No.
714 sHB6607 File No.
714 OLR Bill Analysis sHB 6607 (as amended by House "A")* AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES.
Show all 116 changed rows (76 more)
Previous
Latest
SUMMARY This bill prohibits the Superior Court from assessing punitive damages against a covered entity (see below) for a data breach of personal or restricted information if the covered entity meets specified cybersecurity requirements.
Specifically, when a civil action alleges that a data breach resulted from a covered entity’s failure to implement reasonable cybersecurity controls, thecourtmaynot assesspunitive damagesif thecoveredentity created, maintained, and complied with a written cybersecurity program containing administrative, technical, and physical safeguards for protecting personal or restricted information.
To qualify for this protection, these cybersecurity programs must (1) meet specified design requirements and (2) conform to an industry-recognized cybersecurity framework.
However, the protection does not apply if the covered entity’s failure to implement reasonable cybersecurity controls resulted from gross negligence or willful or wanton conduct.
Under the bill, “covered entities” are businesses accessing, maintaining, communicating, or processing personal or restricted information in or through systems, networks, or services located inside or outside the state.
The bill’s provisions do not:
1.
affect or limit the process of granting certification in class actions;
sHB6607 / File No.
714 8 sHB6607 File No.
714 2.
affect or limit existing statutory requirements for (a) state contractors who receive confidential information and (b) Connecticut businesses that maintain computerized personal information and suffer security breaches;
or 3.
limit the authority of the attorney general or the Department of Consumer Protection commissioner to seek administrative, legal, or equitable relief allowed by law.
*House Amendment “A” (1) changes the bill’s protection for qualifying covered entities from an affirmative defense to a prohibition on punitive damages and disqualifies covered entities from this protection for certain conduct;
(2) changes, to six months, the time period by which a covered entity’s cybersecurity program must conform with revisions or amendments to certain cybersecurity frameworks, laws, and regulations;
(3) explicitly exempts certain statutes, executive powers, and legal processes from the bill’s provisions;
(4) makes changes to the definitions of personal and restricted information;
and (5) makes minor and technical changes.
EFFECTIVE DATE:
October 1, 2021 CYBERSECURITY PROGRAM DESIGN REQUIREMENTS To qualify for the bill’s protection against punitive damages, a covered entity’s cybersecurity program must be designed to protect the security and confidentiality of personal and restricted information.
The program must specifically protect this information against (1) threats or hazards to its security or integrity and (2) unauthorized access and acquisition that would cause material risk of identity theft or other fraud.
The bill requires the scale and scope of a covered entity’s cybersecurity program to be based on the:
1.
entity’s size and complexity, and the nature and scope of its activities;
sHB6607 / File No.
714 9 sHB6607 File No.
714 2.
sensitivity of the information to be protected;
and 3.
cost and availability of tools to improve information security and reduce vulnerabilities.
INDUSTRY-RECOGNIZED CYBERSECURITY FRAMEWORKS Under the bill, an industry-recognized cybersecurity framework includes the most current version of:
1.
one or any combination of six specifically recognized frameworks (see Table 1), 2.
one of four specified federal laws and regulations (for entities regulated by any ofthese lawsor thestate or federalgovernment;
see Table 2), or 3.
the “Payment Card Industry Data Security Standard” in combination with one of the acceptable frameworks mentioned in Table 1 below.
Table 1:
Industry-Recognized Cybersecurity Frameworks Publisher Framework National Institute of Standards and "Framework for Improving Critical Technology Infrastructure Cybersecurity" Special Publication (SP) 800-171 SP 800-53 and 800-53a Federal Risk and Management "FedRAMP Security Assessment Program Framework" Center for Internet Security "Center for Internet Security Critical Security Controls for Effective Cyber Defense" International Organization for "ISO/IEC 27000-series" Standardization and the International Electrotechnical Commission sHB6607 / File No.
714 10 sHB6607 File No.
714 Table 2:
Federal Cybersecurity Laws and Regulations Citation Law or Regulation P.L.
104-191;
Security requirements of the Health Insurance Portability and C.F.R.
164 Accountability Act of 1996 (Subpart C) P.L.
106-102 Title V of the Gramm-Leach-Bliley Act of 1999 P.L.
113-283 Federal Information Security Modernization Act of 2014 C.F.R.
162 Security requirements of the Health Information Technology for Economic and Clinical Health Act The bill requires a covered entity to conform with revisions or amendments to these frameworks, laws, and regulations within six months after the revised document is published or the laws or regulations are amended, as applicable.
DEFINITIONS Businesses Under the bill, a covered entity’s business type may include an individualor a sole proprietorship,partnership,firm, corporation,trust, limited liability company or partnership, joint stock company, joint ventures, associations, or other legal entities through which for-profit or non-profit business is conducted.
Data Breach The bill defines a “data breach” as unauthorized access to and acquisition of computerized data that (1) compromises the security or confidentiality of personal or restricted information owned by or licensedtoacoveredentityand(2)causesamaterialriskofidentitytheft or other fraud to a person or property (or reasonably is believed to have caused or will cause such risk).
The definition specifically excludes:
1.
employees or agents of a covered entity acquiring personal or restricted information in good faith for the purposes of the entity, so long as the entity does not unlawfully use this information or subject it to further unauthorized disclosure, or sHB6607 / File No.
714 11 sHB6607 File No.
714 2.
the acquisition of this information pursuant to a (a) search warrant, (b) subpoena or other court order, or (c) regulatory state agency’s order or duty.
Personal and Restricted Information Under the bill, “personal information” means an individual’s first name or initial and last name in combination with one or more of the following:
1.
social security, taxpayer identification, Internal Revenue Service- issued identity protection personal identification, driver’s license, state identification card, passport, or military identification numbers, or other commonly used government- issued identification numbers;
2.
credit or debit card numbers;
financial account numbers in combination with required security codes, access codes, or passwords that would permit access to these accounts;
3.
medical information on an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
4.
health insurance policy or subscriber identification numbers, or unique identifiers health insurers use to identify individuals;
or 5.
biometric information that can identify an individual using their unique physical characteristics, including a fingerprint, voice print, or retina or iris image.
Personal information also includes user names or e-mail addresses in combination with passwords or security questions and answers that would permit access to online accounts.
However, the definition excludespublicly availableinformationlawfully availabletothegeneral public from federal, state, or local government records or widely distributed media.
sHB6607 / File No.
714 12 sHB6607 File No.
714 “Restricted information” means any unencrypted, unredacted, or unaltered information about an individual that, alone or in combination with other information (including personal information as described above), (1) can be used to distinguish or trace the individual’s identity or is reasonably linked or linkable to an individual and (2) is likely to result in a material risk of identity theft or other fraud to a person or property if breached.
The definition excludes personal or publicly available information.
COMMITTEE ACTION Commerce Committee Joint Favorable Change of Reference - JUD Yea 22 Nay 1 (03/22/2021) Judiciary Committee Joint Favorable Substitute Yea 32 Nay 3 (04/09/2021) sHB6607 / File No.
714 13
View plain text versions (6)

How this bill changes current law

10 changes Share ↗

AI-generated reading aid from the bill's amendatory text — verify against the official bill.

The bill establishes definitions and legal protections for businesses adopting cybersecurity standards, specifically shielding them from punitive damages in certain data breach lawsuits if they comply with specified cybersecurity guidelines.

  • (b)

    none → the Superior Court shall not assess punitive damages against a covered entity if such entity created, maintained and complied with a written cybersecurity program that contains administrative, technical and physical safeguards for the protection of personal or restricted information and that conforms to an industry recognized cybersecurity framework, as described in subsection (c) of this section and that such covered entity designed its cybersecurity program in accordance with the provisions of subsection (d) of this section.

    Introduces a legal protection for businesses that implement a compliant cybersecurity program against punitive damages in data breach related lawsuits.

  • (g)

    none → but shall not be construed to affect or limit any requirement of section 4e-70 or 36a-701b of the general statutes.

    Clarifies that the new cybersecurity regulations do not alter existing requirements under specific sections of the general statutes.

  • Section 1 (a) (1)

    none → "Business" means any individual or sole proprietorship, partnership, firm, corporation, trust, limited liability company, limited liability partnership, joint stock company, joint venture, association or other legal entity through which business for profit or not-for-profit is conducted;

    Defines what constitutes a 'business' for the purposes of cybersecurity regulation.

  • Section 1 (a) (2)

    none → "Covered entity" means a business that accesses, maintains, communicates or processes personal information or restricted information in or through one or more systems, networks or services located in or outside this state;

    Defines 'covered entity' to clarify which businesses are subject to the cybersecurity protections.

  • Section 1 (a) (3)

    none → "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information or restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.

    Establishes a legal definition of 'data breach' that delineates the specific conditions constituting a breach.

  • Section 1 (a) (4)

    none → "Personal information" means an individual's (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; ... (B) user name or electronic mail address, in combination with a password or security question and answer that would permit access to an online account.

    Defines 'personal information' to establish the types of data that are subject to protections against breaches.

  • Section 1 (a) (5)

    none → "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered.

    Defines 'restricted information' to set parameters for what additional data may require protection under cybersecurity standards.

  • (c) (1) (A) (vi)

    none → the "ISO/IEC 27000-series" information security standards published by the International Organization for Standardization and the International Electrotechnical Commission.

    Specifies that compliance with ISO/IEC 27000-series standards is a valid framework for cybersecurity programs.

  • (c) (2) (A) (iv)

    none → or the security requirements of the Health Information Technology for Economic and Clinical Health Act, as amended from time to time, as set forth in 45 CFR 162, as amended from time to time.

    Includes the security requirements of additional federal legislation as a possible standard for compliance.

  • (c) (3) (A)

    none → The cybersecurity program complies with the current version of the "Payment Card Industry Data Security Standard" and the current version of another applicable industry recognized cybersecurity framework described in subparagraph (A) of subdivision (1) of this subsection.

    Mandates compliance with the Payment Card Industry Data Security Standards as part of cybersecurity requirements.

Action History

  1. SIGNED BY GOVERNOR

  2. TRANSMITTED BY SECRETARY OF THE STATE TO GOVERNOR

  3. TRANSMITTED TO SECRETARY OF THE STATE

  4. PUBLIC ACT 21-119

  5. ON CONSENT CALENDAR /IN CONCURRENCE

  6. SEN. PASSED, HO. AMEND. SCH. A

  7. SEN. ADOPTED HO. AMEND. SCH. A

  8. FILE NO. 714

  9. SENATE CALENDAR NUMBER 476

  10. FAV. RPT., TAB. FOR CAL., SEN.

  11. HOUSE PASSED, HOUSE AMEND. SCH. A

  12. HOUSE ADOPTED HOUSE AMEND. SCH. A

  13. FILE NO. 598

  14. HOUSE CALENDAR NUMBER 421

  15. FAV. RPT., TABLED FOR HOUSE CALENDAR

  16. RPTD. OUT OF LCO

  17. REFERRED TO Office of Legislative Research AND Office of Fiscal Analysis 04/26/21

  18. FILED WITH LCO

  19. Joint Favorable Substitute

  20. FAV. CHG. OF REF., SEN. TO COMM. ON Judiciary

  21. FAV. CHG. OF REF. HOUSE TO COMM. ON Judiciary

  22. RPTD. OUT OF LCO

  23. FILED WITH LCO

  24. Joint Favorable Change of Reference JUD

  25. PUBLIC HEARING 0318

  26. REF. TO JOINT COMM. ON Commerce

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

7 sponsors · 0 co-sponsors · 180 not signed on

Sponsors (7)

Co-sponsors (0)

None.

Not signed on (180)

180 members have not signed on to this bill.

Show all 180 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

Who sponsors HB 6607?
HB 6607 is sponsored by David Rutigliano (Republican), Porter, Robyn A., Kathy Kennedy (Republican), Ferraro, Charles J., Craig C. Fishbein (Republican), Witkos, Kevin D., and Larry B. Butler (Democratic).
What is the current status of HB 6607?
This bill has been enacted into law. Introduced March 10, 2021. Enacted.
Where can I track HB 6607?
Track HB 6607 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 6607

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 6607

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →