Timing of Consumer Notification
“As expeditiously as practicable and without unreasonable delay but no later than 30 days after determination of breach”
Method of Notice
Mail or email.
Breach Definition
Unauthorized access of data in electronic form containing personal information.
PII Definition
Individual’s first name or first initial and last name in combination with any of these:
  1. Social Security number;
  2. Driver’s license or identification card number, passport number, military identification number, or other similar number issued on government id;
  3. Financial account number or credit or debit card number, in combination with any required security code, access code, or password necessary to permit access to financial account;
  4. Information regarding individual’s medical history, mental or physical condition, or medical treatment or diagnosis by health care professional; or
  5. Individual’s health insurance policy number or subscriber identification number and any unique identifier used by health insurer.
OR
  1. User name or e-mail address, in combination with password or security question and answer that would permit access to online account.
Third Party Notice
If data collector maintains covered information for someone else, it must notify them following discovery of breach as expeditiously as practicable, but no later than 10 days following determination of breach.
How to Notify
Notice must include date of breach, description of covered info that was or reasonably believed to have been accessed, and covered entity’s contact info.
Substitute Notice
maintains one; and (b) notice in print and to broadcast media, including major media in urban and rural areas where affected individuals reside.
Credit Monitoring
Not required.
When to Notify Credit Agencies
If more than 1,000 Florida residents notified.
This State's Law
Upon request of Florida Attorney General, covered entity may be required to provide police report, incident report, or computer forensics report, and entity’s policies in place regarding breaches.
State Government Agency Notification Required
Yes, Florida Department of Legal Affairs, if 500 or more Florida residents affected. Must be made no later than 30 days after determination of breach.