109th CONGRESS
1st Session

S. 1789

To prevent and mitigate identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information.

IN THE SENATE OF THE UNITED STATES

September 29, 2005

Mr. SPECTER (for himself, Mr. LEAHY, Mrs. FEINSTEIN, and Mr. FEINGOLD) introduced the following bill; which was read twice and referred to the Committee on the Judiciary


A BILL

To prevent and mitigate identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information.

SECTION 1. SHORT TITLE; TABLE OF CONTENTS.

TITLE I--ENHANCING PUNISHMENT FOR IDENTITY THEFT AND OTHER VIOLATIONS OF DATA PRIVACY AND SECURITY

TITLE II--ASSISTANCE FOR STATE AND LOCAL LAW ENFORCEMENT COMBATING CRIMES RELATED TO FRAUDULENT, UNAUTHORIZED, OR OTHER CRIMINAL USE OF PERSONALLY IDENTIFIABLE INFORMATION

TITLE III--DATA BROKERS

TITLE IV--PRIVACY AND SECURITY OF PERSONALLY IDENTIFIABLE INFORMATION

Subtitle A--Data Privacy and Security Program

Subtitle B--Security Breach Notification

TITLE V--GOVERNMENT ACCESS TO AND USE OF COMMERCIAL DATA

SEC. 2. FINDINGS.

SEC. 3. DEFINITIONS.

(aa) the past, present, or future physical or mental health or condition of an individual;

(bb) the provision of health care to an individual; or

(cc) the past, present, or future payment for the provision of health care to an individual.

TITLE I--ENHANCING PUNISHMENT FOR IDENTITY THEFT AND OTHER VIOLATIONS OF DATA PRIVACY AND SECURITY

SEC. 101. FRAUD AND RELATED CRIMINAL ACTIVITY IN CONNECTION WITH UNAUTHORIZED ACCESS TO PERSONALLY IDENTIFIABLE INFORMATION.

SEC. 102. ORGANIZED CRIMINAL ACTIVITY IN CONNECTION WITH UNAUTHORIZED ACCESS TO PERSONALLY IDENTIFIABLE INFORMATION.

SEC. 103. CONCEALMENT OF SECURITY BREACHES INVOLVING SENSITIVE PERSONALLY IDENTIFIABLE INFORMATION.

`Sec. 1039. Concealment of security breaches involving sensitive personally identifiable information

SEC. 104. AGGRAVATED FRAUD IN CONNECTION WITH COMPUTERS.

`Sec. 1030A. Aggravated fraud in connection with computers

SEC. 105. REVIEW AND AMENDMENT OF FEDERAL SENTENCING GUIDELINES RELATED TO FRAUDULENT ACCESS TO OR MISUSE OF DIGITIZED OR ELECTRONIC PERSONALLY IDENTIFIABLE INFORMATION.

TITLE II--ASSISTANCE FOR STATE AND LOCAL LAW ENFORCEMENT COMBATING CRIMES RELATED TO FRAUDULENT, UNAUTHORIZED, OR OTHER CRIMINAL USE OF PERSONALLY IDENTIFIABLE INFORMATION

SEC. 201. GRANTS FOR STATE AND LOCAL ENFORCEMENT.

SEC. 202. AUTHORIZATION OF APPROPRIATIONS.

TITLE III--DATA BROKERS

SEC. 301. TRANSPARENCY AND ACCURACY OF DATA COLLECTION.

SEC. 302. ENFORCEMENT.

SEC. 303. RELATION TO STATE LAWS.

SEC. 304. EFFECTIVE DATE.

TITLE IV--PRIVACY AND SECURITY OF PERSONALLY IDENTIFIABLE INFORMATION

Subtitle A--Data Privacy and Security Program

SEC. 401. PURPOSE AND APPLICABILITY OF DATA PRIVACY AND SECURITY PROGRAM.

SEC. 402. REQUIREMENTS FOR A PERSONAL DATA PRIVACY AND SECURITY PROGRAM.

SEC. 403. ENFORCEMENT.

SEC. 404. RELATION TO STATE LAWS.

Subtitle B--Security Breach Notification

SEC. 421. NOTICE TO INDIVIDUALS.

SEC. 422. EXEMPTIONS.

SEC. 423. METHODS OF NOTICE.

SEC. 424. CONTENT OF NOTIFICATION.

SEC. 425. COORDINATION OF NOTIFICATION WITH CREDIT REPORTING AGENCIES.

SEC. 426. NOTICE TO LAW ENFORCEMENT.

SEC. 427. CIVIL REMEDIES.

SEC. 428. ENFORCEMENT BY STATE ATTORNEYS GENERAL.

SEC. 429. EFFECT ON FEDERAL AND STATE LAW.

SEC. 430. AUTHORIZATION OF APPROPRIATIONS.

SEC. 431. REPORTING ON RISK ASSESSMENT EXEMPTION.

SEC. 432. EFFECTIVE DATE.

TITLE V--GOVERNMENT ACCESS TO AND USE OF COMMERCIAL DATA

SEC. 501. GENERAL SERVICES ADMINISTRATION REVIEW OF CONTRACTS.

SEC. 502. REQUIREMENT TO AUDIT INFORMATION SECURITY PRACTICES OF CONTRACTORS AND THIRD PARTY BUSINESS ENTITIES.

SEC. 503. PRIVACY IMPACT ASSESSMENT OF GOVERNMENT USE OF COMMERCIAL INFORMATION SERVICES CONTAINING PERSONALLY IDENTIFIABLE INFORMATION.

SEC. 504. IMPLEMENTATION OF CHIEF PRIVACY OFFICER REQUIREMENTS.

END