(1) Except to the extent prohibited by law other than this chapter, the administrator or administrator’s agent shall notify a holder as soon as practicable of:
(a) A suspected loss, misuse or unauthorized access, disclosure, modification, or destruction of confidential information obtained from the holder in the possession of the administrator or an administrator’s agent; and

Terms Used In Kentucky Statutes 393A.830

  • Action: includes all proceedings in any court of this state. See Kentucky Statutes 446.010
  • Administrator: means the Kentucky State Treasurer. See Kentucky Statutes 393A.010
  • Attorney: means attorney-at-law. See Kentucky Statutes 446.010
  • Confidential information: means records, reports, and information that are confidential under KRS §. See Kentucky Statutes 393A.010
  • Fraud: Intentional deception resulting in injury to another.
  • Holder: means a person obligated to hold for the account of, or to deliver or pay to, the owner, property subject to this chapter. See Kentucky Statutes 393A.010
  • Litigation: A case, controversy, or lawsuit. Participants (plaintiffs and defendants) in lawsuits are called litigants.
  • Person: means an individual, estate, business association, public corporation, government or governmental subdivision, agency, or instrumentality or other legal entity. See Kentucky Statutes 393A.010
  • Record: means information that is inscribed on a tangible medium or that is stored in an electronic or other medium and is retrievable in perceivable form. See Kentucky Statutes 393A.010
  • Security: means :
    (a) A security as defined in KRS §. See Kentucky Statutes 393A.010

(b) Any interference with operations in any system hosting or housing confidential information which:
1. Compromises the security, confidentiality, or integrity of the information; or
2. Creates a substantial risk of identity fraud or theft.
(2) Except as necessary to inform an insurer, attorney, investigator, or others as required by law, the administrator and an administrator’s agent shall not disclose, without the express consent in a record of the holder, an event described in subsection (1) of this section to a person whose confidential information was supplied by the holder.
(3) If an event described in subsection (1) of this section occurs, the administrator and the administrator’s agent shall:
(a) Take action necessary for the holder to understand and minimize the effect of the event and determine its scope; and
(b) Cooperate with the holder with respect to:
1. Any notification required by law concerning a data or other security breach; and
2. A regulatory inquiry, litigation, or similar action.
Effective: July 14, 2018
History: Created 2018 Ky. Acts ch. 163, sec. 83, effective July 14, 2018.