Pennsylvania Privacy Law
Pennsylvania’s breach statute was a bare-bones 2005 law until two rounds of amendment turned it into one of the more demanding in the country. Act 151 of 2022 added definitions of determination and discovery, brought medical and health insurance information and online account credentials into the definition of personal information, and put state agencies on a seven-business-day clock with counties, public schools and municipalities reporting to the district attorney within three. Act 33 of 2024 then added the Attorney General notification at 500 residents and, in section 5.4, a requirement that the notifying entity pay for a credit report and twelve months of credit monitoring where a Social Security number, bank account number or driver’s licence number was accessed — an obligation few states impose on private businesses. Separately from the statute, the Supreme Court of Pennsylvania held in Dittman v. UPMC that an employer owes a common-law duty of reasonable care in storing employees’ sensitive personal information, and that the economic loss doctrine does not bar the resulting negligence claim.
Sector-Specific Privacy Laws in Pennsylvania
Breach of Personal Information Notification Act (73 P.S. §§ 2301-2329)
The Act of December 22, 2005, P.L. 474, No. 94 now carries two substantial layers of amendment. Act 151 of November 3, 2022 added the definitions of “determination” (a verification or reasonable certainty that a breach has occurred) and “discovery” (knowledge of or reasonable suspicion that one has), which matter because the general notice duty in section 3(a) now runs from determination rather than discovery. It brought medical information and health insurance information into the definition of personal information and added a user name or email address in combination with a password or security question and answer. It added section 5.1 requiring encryption or other appropriate security measures for personal information transmitted over the internet on the Commonwealth’s behalf and an annually reviewed transmission policy, section 5.2 requiring a storage policy with the stated goal of reducing the risk of future breaches, and section 5.3 deeming HIPAA and HITECH compliance to satisfy the Act. Act 33 of June 28, 2024 added the Attorney General notification in section 3(c.1), exempted entities subject to 40 Pa.C.S. ch. 45 from it in section (c.2), moved the consumer reporting agency threshold in section 5, and added the credit monitoring obligation in section 5.4. Section 6 preempts local rules and ordinances on the matters the Act expressly addresses. The Office of Attorney General describes the 2024 amendments as approved on July 28, 2024 and effective September 26, 2024.
Insurance Data Security (40 Pa.C.S. ch. 45)
Act 2 of 2023 created chapter 45 of Title 40. Section 4518(a) requires a licensee to notify the Insurance Commissioner as promptly as possible and no later than five business days from a determination that a cybersecurity event involving nonpublic information in its possession has occurred, on either of two triggers: the event has a reasonable likelihood of materially harming a Pennsylvania consumer or a material part of the licensee’s normal operations and Pennsylvania is the insurer’s state of domicile or the producer’s home state; or the licensee reasonably believes 250 or more Pennsylvania consumers are involved and the event either requires notice to a governmental body, self-regulatory agency or other supervisory body, or carries that same likelihood of material harm. The chapter’s substantive requirements run through section 4512 risk assessment, section 4513 information security program, section 4514 corporate oversight, section 4515 oversight of third-party service provider arrangements and section 4516 certification. Section 4532 exempts a licensee from those five sections where it has fewer than ten employees, less than $5,000,000 in gross revenue, or less than $10,000,000 in year-end total assets. Section 4536 gave licensees one year from the effective date to implement sections 4512, 4513, 4514 and 4516 and two years for section 4515. Section 4522 sets a graduated penalty after notice and hearing: suspension, revocation or refusal to renew a licence, a cease and desist order, up to $5,000 per violation the licensee knew or reasonably should have known was a violation with an aggregate cap of $100,000 in a calendar year, and up to $1,000 per violation it did not and reasonably should not have known of, capped at $20,000 a year.
Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.)
The Act of December 17, 1968, P.L. 1224, No. 387 is the statute a breach violation is channelled into. Section 4 supplies the injunction action; section 4.1 lets a court issuing a permanent injunction direct restitution of money or property acquired by means of a violation; section 5 lets the Attorney General accept a written assurance of voluntary compliance, which may include a stipulation for voluntary payment and must be filed with the court. Section 8(a) makes a person who violates an injunction or the terms of a filed assurance liable for a civil penalty of not more than $5,000 for each violation, with the issuing court retaining jurisdiction. Section 8(b) provides that where the court finds a wilful use of an unlawful practice, the Attorney General or the appropriate District Attorney may recover a civil penalty not exceeding $1,000 per violation, rising to a ceiling of $3,000 per violation where the victim of the wilful conduct is sixty years of age or older. Section 9 allows the court, on the Attorney General’s petition, to order dissolution, suspension or forfeiture of the franchise or right to do business of a person who violates an injunction. Section 9.2 gives a private claim to a person who purchases or leases goods or services primarily for personal, family or household purposes and suffers an ascertainable loss, for actual damages or $100 whichever is greater, with treble damages available in the court’s discretion and costs and reasonable attorney fees; a permanent injunction or judgment obtained by the Commonwealth is prima facie evidence in such an action.
Data Breach Notification in Pennsylvania
Section 3(a) requires an entity that maintains, stores or manages computerized data including personal information to notify any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person, without unreasonable delay following determination of the breach. The definition of a breach in section 2 carries a materiality and injury element: unauthorized access and acquisition that materially compromises the security or confidentiality of personal information maintained as part of a database regarding multiple individuals, and that causes or the entity reasonably believes has caused or will cause loss or injury to a Pennsylvania resident. Personal information now covers six categories, added at different times: a Social Security number; a driver’s licence or State identification card number; a financial account, credit or debit card number with the code permitting access; medical information in the possession of a State agency or State agency contractor; health insurance information; and a user name or email address with a password or security question and answer that would permit access to an online account. Section 3(c.1), added by Act 33 of 2024, requires concurrent notice to the Office of Attorney General above 500 affected Pennsylvanians, carrying the organisation’s name and location, the date of the breach, a summary of the incident, an estimated total number of individuals affected and an estimated total number affected in the Commonwealth. Section 5 requires notice to the nationwide consumer reporting agencies above the same 500 threshold. Substitute notice under the definition in section 2 becomes available where the cost of notice would exceed $100,000, the affected class exceeds 175,000, or contact information is insufficient. Section 8 makes a violation an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law and gives the Office of Attorney General exclusive authority to bring that action.
Residents must be notified without unreasonable delay following determination of the breach; seven business days for a State agency, and three business days for a county, public school or municipality to notify the district attorney. Notify the Office of Attorney General concurrently when notice must be given to more than 500 affected individuals in the Commonwealth. Complaints are taken by the Pennsylvania Office of Attorney General, which enforces the statute.
How Pennsylvania Enforces Its Privacy Laws
Exclusive authority, routed through the consumer protection law. Section 8 of the Breach of Personal Information Notification Act deems a violation an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law and gives the Office of Attorney General exclusive authority to bring the resulting action. The office’s own description of the consequence is that it may seek injunctive relief, restitution and penalties against any business entity for violating the law. That routes a notification failure into section 4 for the injunction, section 4.1 for restitution, section 5 for an assurance of voluntary compliance and section 8 for civil penalties.
The insurance chapter is enforced by the Commissioner, not the Attorney General. Section 4522 of Title 40 places the penalty decision with the Insurance Commissioner after notice and hearing, and the available sanctions are licence-based as well as monetary: suspension or revocation of the licence, authorisation to operate or registration; refusal to issue or renew one; a cease and desist order; and the two-tier per-violation penalty with annual aggregate caps. Section 4521 gives the Commissioner the power to examine licensees. That is a separate track from the breach statute, which is why section 3(c.2) exempts chapter 45 entities from the Attorney General notification.
A common-law duty sits alongside the statute. Dittman v. UPMC establishes that the absence of a private claim under the notification statute does not end the analysis. The Supreme Court held that an employer collecting and storing employees’ sensitive personal information on an internet-accessible system owes a duty of reasonable care in doing so, and that Pennsylvania’s economic loss doctrine permits recovery of purely pecuniary damages in negligence where the duty breached arises under common law independent of contract. The opinion was authored by Justice Baer and joined by Justices Dougherty, Wecht and Mundy, with Chief Justice Saylor concurring and dissenting joined by Justice Todd.
Recent Enforcement in Pennsylvania
23andMe — multistate settlement covering 192,093 Pennsylvanians. Attorney General Dave Sunday joined a coalition of forty-two states in an $18 million bankruptcy claim settlement with 23andMe, resolving allegations arising from the October 2023 breach that compromised genetic data on 6.9 million consumers worldwide. Pennsylvania received $491,902, and the office states that 192,093 Pennsylvanians were among those affected. The attackers used credential stuffing, attempting to force access to accounts using passwords stolen from other websites; the office’s statement singles out the company’s partnership with MyHeritage, itself compromised years earlier and exposing credentials shared between the two sites, as making the failure to guard against that technique particularly serious. The identified security failures include not comparing passwords against blocklists of known breached passwords and not requiring multifactor authentication. Pennsylvanians were also covered by a separate $46.75 million class settlement in the bankruptcy for consumers who submitted claims by February 17, 2026.
DNA Diagnostics Center — joint investigation with Ohio, February 16, 2023. The Office of Attorney General investigated the 2021 breach at DNA Diagnostics Center jointly with the Ohio Attorney General’s office, and each state negotiated its own agreement with the company. The breach exposed the Social Security numbers and other personal data of roughly 12,500 Pennsylvanians, alongside about 33,000 Ohioans, and the data taken was material the company had purchased from another business rather than its own customer records. The joint investigation concluded that the company had made unfair and deceptive statements about its cybersecurity and had failed to employ reasonable measures to detect and prevent a breach. As part of the negotiations with both states the company was required to have its new cybersecurity program assessed by a certified third party. Then Acting Attorney General Michelle Henry described the action as taken with the assistance of the Ohio Attorney General.
Pending Privacy Legislation
House Bill 78 of the 2025-2026 regular session is the Commonwealth’s comprehensive privacy bill and is further along than any predecessor. Prime-sponsored by Representative Ed Neilson with more than twenty-five co-sponsors from both caucuses, it is described in the General Assembly’s own summary as an act providing for consumer data privacy, for duties of controllers and for duties of processors, and imposing penalties. Its recorded history: referred to the House Commerce Committee on January 14, 2025; reported as amended on March 18, 2025 as printer’s number 1024; second consideration with amendments and re-committal to House Appropriations on April 23, 2025 as printer’s number 1476; re-reported as committed and given third consideration and final passage in the House on October 1, 2025 by a vote of 127 to 76; referred to the Senate Consumer Protection and Professional Licensure Committee on October 3, 2025; reported from that committee and re-referred to Senate Communications and Technology on February 4, 2026; re-reported as amended from that committee on June 24, 2026 as printer’s number 3688; and second consideration in the Senate on June 25, 2026. Third consideration and executive action are both recorded as milestones the bill has not yet reached.
Federal Privacy Laws That Apply in Pennsylvania
Federal privacy law applies in Pennsylvania by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.), which the Pennsylvania Office of Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Pennsylvania Businesses
With no comprehensive state statute, most privacy obligations on a Pennsylvania business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Pennsylvania businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Pennsylvania itself has none, and any business holding personal information about Pennsylvania residents is subject to the state’s breach-notification statute described above.
Pennsylvania Privacy Law FAQ
When must a Pennsylvania breach be reported to the Attorney General?
Does Pennsylvania require an entity to pay for credit monitoring after a breach?
Is there a private right of action for a Pennsylvania breach-notification failure?
What did Dittman v. UPMC decide?
Do Pennsylvania public schools and counties have their own breach deadlines?
How quickly must a Pennsylvania insurance licensee report a cybersecurity event?
What is the status of Pennsylvania’s comprehensive privacy bill?
Which small insurers are exempt from Pennsylvania’s insurance data security requirements?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Breach of Personal Information Notification Act — Act of Dec. 22, 2005, P.L. 474, No. 94, as amended statute
- Act 33 of June 28, 2024 — amendments to the Breach of Personal Information Notification Act statute
- Act 2 of 2023 — Insurance Data Security, 40 Pa.C.S. ch. 45 statute
- Unfair Trade Practices and Consumer Protection Law — Act of Dec. 17, 1968, P.L. 1224, No. 387 statute
- House Bill 78 (2025-2026) — bill status and history legislation
- Pennsylvania Office of Attorney General — Breach of Personal Information Notification Act guidance agency
- Pennsylvania Office of Attorney General — $18 million national settlement with 23andMe agency
- Ohio Attorney General — joint Ohio and Pennsylvania agreements with DNA Diagnostics Center agency
- Dittman v. UPMC — Supreme Court of Pennsylvania majority opinion, J-20-2018 (Nov. 21, 2018) decision
- Pennsylvania Insurance Department — data security requirements for licensees agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.