To Ease Pain Of Breach Notification Laws, Protect Passwords

By Jason Wool (July 31, 2018, 12:59 PM EDT) -- Arizona recently amended its data breach notification law to include user credentials to an online account as one of the types of data that can trigger mandatory notification obligations. In doing so, it became just the latest in a string of states to require notification for breaches of online credentials, indicating that more jurisdictions are likely to follow. As a result, organizations may want to take this opportunity to review their practices for securing user credentials to minimize the likelihood of password-related incidents that could give rise to breach notification obligations, along with the negative publicity that can affect a business' bottom line. Read on for details about these laws, and technical considerations for evaluating your organization's password creation and storage practices....

Law360 is on it, so you are, too.

A Law360 subscription puts you at the center of fast-moving legal issues, trends and developments so you can act with speed and confidence. Over 200 articles are published daily across more than 60 topics, industries, practice areas and jurisdictions.


A Law360 subscription includes features such as

  • Daily newsletters
  • Expert analysis
  • Mobile app
  • Advanced search
  • Judge information
  • Real-time alerts
  • 450K+ searchable archived articles

And more!

Experience Law360 today with a free 7-day trial.

Start Free Trial

Already a subscriber? Click here to login

Hello! I'm Law360's automated support bot.

How can I help you today?

For example, you can type:
  • I forgot my password
  • I took a free trial but didn't get a verification email
  • How do I sign up for a newsletter?
Ask a question!