U.S. Senators Mark Kirk (R-Ill.) and Kirsten Gillibrand (D-N.Y.) today introduced the Data Breach Notification and Punishing Cyber Criminals Act (S.1027), which sets a national consumer-friendly data breach notification standard to protect and inform individuals when their personal information is compromised or made public. Last year, 780 data breach incidents occurred in the United States at stores like Target, Michael's, Dairy Queen, and Neiman Marcus, exposing millions of credit card numbers and personal information.
"In 2013 the state of Illinois saw a 1,600 percent increase in data breach complaints. By creating a low-cost, easy to implement standard for companies to notify consumers when personal information is stolen and increasing penalties on cyber criminals, we can stay ahead of the hackers and better protect Americans from cyber crimes," said Senator Kirk.
"Hackers have put consumers and businesses in their crosshairs, and have shown they can easily access confidential information we trust can and should remain private. It's time to improve our security and establish standards that better protect consumers in New York and across the country," said Senator Gillibrand. "This legislation is an important first step toward a national solution and opportunity to address our vulnerabilities, strengthening defenses against emerging data breaches, taking necessary safeguards to help victims and prosecuting perpetrators of these attacks."
As we have seen with recent high-profile data breaches at Sony Pictures and Anthem, information that is unlawfully acquired far surpasses normal financial data such as credit cards and PIN numbers. This bill would require a notification not only when personal financial information is breached, but also when personal medical information (including medical history and mental/physical conditions or diagnoses) and health insurance information is breached.
This bipartisan legislation increases the maximum allowable fines and imprisonment for many of the most common cyber-crimes, including identity theft and theft of personal information. Current law does not sufficiently punish cyber criminals, and incidences like these recent devastating breaches of confidential information must be punished more aggressively. By modernizing these punishments, as many prosecutors have requested, we will better align punishments to the degree of harm that these crimes may inflict on victims.