How HB 6607 changes current law
AN ACT INCENTIVIZING THE ADOPTION OF CYBERSECURITY STANDARDS FOR BUSINESSES. · Connecticut
How this bill changes current law
10 changesAI-generated reading aid from the bill's amendatory text — verify against the official bill.
The bill establishes definitions and legal protections for businesses adopting cybersecurity standards, specifically shielding them from punitive damages in certain data breach lawsuits if they comply with specified cybersecurity guidelines.
-
(b)
none→ the Superior Court shall not assess punitive damages against a covered entity if such entity created, maintained and complied with a written cybersecurity program that contains administrative, technical and physical safeguards for the protection of personal or restricted information and that conforms to an industry recognized cybersecurity framework, as described in subsection (c) of this section and that such covered entity designed its cybersecurity program in accordance with the provisions of subsection (d) of this section.Introduces a legal protection for businesses that implement a compliant cybersecurity program against punitive damages in data breach related lawsuits.
-
(g)
none→ but shall not be construed to affect or limit any requirement of section 4e-70 or 36a-701b of the general statutes.Clarifies that the new cybersecurity regulations do not alter existing requirements under specific sections of the general statutes.
-
Section 1 (a) (1)
none→ "Business" means any individual or sole proprietorship, partnership, firm, corporation, trust, limited liability company, limited liability partnership, joint stock company, joint venture, association or other legal entity through which business for profit or not-for-profit is conducted;Defines what constitutes a 'business' for the purposes of cybersecurity regulation.
-
Section 1 (a) (2)
none→ "Covered entity" means a business that accesses, maintains, communicates or processes personal information or restricted information in or through one or more systems, networks or services located in or outside this state;Defines 'covered entity' to clarify which businesses are subject to the cybersecurity protections.
-
Section 1 (a) (3)
none→ "Data breach" means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information or restricted information owned by or licensed to a covered entity and that causes, reasonably is believed to have caused or reasonably is believed will cause a material risk of identity theft or other fraud to a person or property.Establishes a legal definition of 'data breach' that delineates the specific conditions constituting a breach.
-
Section 1 (a) (4)
none→ "Personal information" means an individual's (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; ... (B) user name or electronic mail address, in combination with a password or security question and answer that would permit access to an online account.Defines 'personal information' to establish the types of data that are subject to protections against breaches.
-
Section 1 (a) (5)
none→ "Restricted information" means any information about an individual, other than personal information or publicly available information, that, alone or in combination with other information, including personal information, can be used to distinguish or trace the individual's identity or that is reasonably linked or linkable to an individual, if the information is not encrypted, redacted or altered.Defines 'restricted information' to set parameters for what additional data may require protection under cybersecurity standards.
-
(c) (1) (A) (vi)
none→ the "ISO/IEC 27000-series" information security standards published by the International Organization for Standardization and the International Electrotechnical Commission.Specifies that compliance with ISO/IEC 27000-series standards is a valid framework for cybersecurity programs.
-
(c) (2) (A) (iv)
none→ or the security requirements of the Health Information Technology for Economic and Clinical Health Act, as amended from time to time, as set forth in 45 CFR 162, as amended from time to time.Includes the security requirements of additional federal legislation as a possible standard for compliance.
-
(c) (3) (A)
none→ The cybersecurity program complies with the current version of the "Payment Card Industry Data Security Standard" and the current version of another applicable industry recognized cybersecurity framework described in subparagraph (A) of subdivision (1) of this subsection.Mandates compliance with the Payment Card Industry Data Security Standards as part of cybersecurity requirements.
Download the branded redline PDF
A print-ready, House Comparative-Print–style redline to forward to your team or leadership.
One email, no spam — used to send updates on bills like this.
https://www.oneclickpolitics.com/bills/735148-hb-6607/current-law