Pennsylvania

Pennsylvania Privacy Law

Pennsylvania’s breach statute was a bare-bones 2005 law until two rounds of amendment turned it into one of the more demanding in the country. Act 151 of 2022 added definitions of determination and discovery, brought medical and health insurance information and online account credentials into the definition of personal information, and put state agencies on a seven-business-day clock with counties, public schools and municipalities reporting to the district attorney within three. Act 33 of 2024 then added the Attorney General notification at 500 residents and, in section 5.4, a requirement that the notifying entity pay for a credit report and twelve months of credit monitoring where a Social Security number, bank account number or driver’s licence number was accessed — an obligation few states impose on private businesses. Separately from the statute, the Supreme Court of Pennsylvania held in Dittman v. UPMC that an employer owes a common-law duty of reasonable care in storing employees’ sensitive personal information, and that the economic loss doctrine does not bar the resulting negligence claim.

Sector-Specific Privacy Laws in Pennsylvania

Breach of Personal Information Notification Act (73 P.S. §§ 2301-2329)

The Act of December 22, 2005, P.L. 474, No. 94 now carries two substantial layers of amendment. Act 151 of November 3, 2022 added the definitions of “determination” (a verification or reasonable certainty that a breach has occurred) and “discovery” (knowledge of or reasonable suspicion that one has), which matter because the general notice duty in section 3(a) now runs from determination rather than discovery. It brought medical information and health insurance information into the definition of personal information and added a user name or email address in combination with a password or security question and answer. It added section 5.1 requiring encryption or other appropriate security measures for personal information transmitted over the internet on the Commonwealth’s behalf and an annually reviewed transmission policy, section 5.2 requiring a storage policy with the stated goal of reducing the risk of future breaches, and section 5.3 deeming HIPAA and HITECH compliance to satisfy the Act. Act 33 of June 28, 2024 added the Attorney General notification in section 3(c.1), exempted entities subject to 40 Pa.C.S. ch. 45 from it in section (c.2), moved the consumer reporting agency threshold in section 5, and added the credit monitoring obligation in section 5.4. Section 6 preempts local rules and ordinances on the matters the Act expressly addresses. The Office of Attorney General describes the 2024 amendments as approved on July 28, 2024 and effective September 26, 2024.

Insurance Data Security (40 Pa.C.S. ch. 45)

Act 2 of 2023 created chapter 45 of Title 40. Section 4518(a) requires a licensee to notify the Insurance Commissioner as promptly as possible and no later than five business days from a determination that a cybersecurity event involving nonpublic information in its possession has occurred, on either of two triggers: the event has a reasonable likelihood of materially harming a Pennsylvania consumer or a material part of the licensee’s normal operations and Pennsylvania is the insurer’s state of domicile or the producer’s home state; or the licensee reasonably believes 250 or more Pennsylvania consumers are involved and the event either requires notice to a governmental body, self-regulatory agency or other supervisory body, or carries that same likelihood of material harm. The chapter’s substantive requirements run through section 4512 risk assessment, section 4513 information security program, section 4514 corporate oversight, section 4515 oversight of third-party service provider arrangements and section 4516 certification. Section 4532 exempts a licensee from those five sections where it has fewer than ten employees, less than $5,000,000 in gross revenue, or less than $10,000,000 in year-end total assets. Section 4536 gave licensees one year from the effective date to implement sections 4512, 4513, 4514 and 4516 and two years for section 4515. Section 4522 sets a graduated penalty after notice and hearing: suspension, revocation or refusal to renew a licence, a cease and desist order, up to $5,000 per violation the licensee knew or reasonably should have known was a violation with an aggregate cap of $100,000 in a calendar year, and up to $1,000 per violation it did not and reasonably should not have known of, capped at $20,000 a year.

Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.)

The Act of December 17, 1968, P.L. 1224, No. 387 is the statute a breach violation is channelled into. Section 4 supplies the injunction action; section 4.1 lets a court issuing a permanent injunction direct restitution of money or property acquired by means of a violation; section 5 lets the Attorney General accept a written assurance of voluntary compliance, which may include a stipulation for voluntary payment and must be filed with the court. Section 8(a) makes a person who violates an injunction or the terms of a filed assurance liable for a civil penalty of not more than $5,000 for each violation, with the issuing court retaining jurisdiction. Section 8(b) provides that where the court finds a wilful use of an unlawful practice, the Attorney General or the appropriate District Attorney may recover a civil penalty not exceeding $1,000 per violation, rising to a ceiling of $3,000 per violation where the victim of the wilful conduct is sixty years of age or older. Section 9 allows the court, on the Attorney General’s petition, to order dissolution, suspension or forfeiture of the franchise or right to do business of a person who violates an injunction. Section 9.2 gives a private claim to a person who purchases or leases goods or services primarily for personal, family or household purposes and suffers an ascertainable loss, for actual damages or $100 whichever is greater, with treble damages available in the court’s discretion and costs and reasonable attorney fees; a permanent injunction or judgment obtained by the Commonwealth is prima facie evidence in such an action.

Data Breach Notification in Pennsylvania

Section 3(a) requires an entity that maintains, stores or manages computerized data including personal information to notify any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person, without unreasonable delay following determination of the breach. The definition of a breach in section 2 carries a materiality and injury element: unauthorized access and acquisition that materially compromises the security or confidentiality of personal information maintained as part of a database regarding multiple individuals, and that causes or the entity reasonably believes has caused or will cause loss or injury to a Pennsylvania resident. Personal information now covers six categories, added at different times: a Social Security number; a driver’s licence or State identification card number; a financial account, credit or debit card number with the code permitting access; medical information in the possession of a State agency or State agency contractor; health insurance information; and a user name or email address with a password or security question and answer that would permit access to an online account. Section 3(c.1), added by Act 33 of 2024, requires concurrent notice to the Office of Attorney General above 500 affected Pennsylvanians, carrying the organisation’s name and location, the date of the breach, a summary of the incident, an estimated total number of individuals affected and an estimated total number affected in the Commonwealth. Section 5 requires notice to the nationwide consumer reporting agencies above the same 500 threshold. Substitute notice under the definition in section 2 becomes available where the cost of notice would exceed $100,000, the affected class exceeds 175,000, or contact information is insufficient. Section 8 makes a violation an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law and gives the Office of Attorney General exclusive authority to bring that action.

Residents must be notified without unreasonable delay following determination of the breach; seven business days for a State agency, and three business days for a county, public school or municipality to notify the district attorney. Notify the Office of Attorney General concurrently when notice must be given to more than 500 affected individuals in the Commonwealth. Complaints are taken by the Pennsylvania Office of Attorney General, which enforces the statute.

How Pennsylvania Enforces Its Privacy Laws

Exclusive authority, routed through the consumer protection law. Section 8 of the Breach of Personal Information Notification Act deems a violation an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law and gives the Office of Attorney General exclusive authority to bring the resulting action. The office’s own description of the consequence is that it may seek injunctive relief, restitution and penalties against any business entity for violating the law. That routes a notification failure into section 4 for the injunction, section 4.1 for restitution, section 5 for an assurance of voluntary compliance and section 8 for civil penalties.

The insurance chapter is enforced by the Commissioner, not the Attorney General. Section 4522 of Title 40 places the penalty decision with the Insurance Commissioner after notice and hearing, and the available sanctions are licence-based as well as monetary: suspension or revocation of the licence, authorisation to operate or registration; refusal to issue or renew one; a cease and desist order; and the two-tier per-violation penalty with annual aggregate caps. Section 4521 gives the Commissioner the power to examine licensees. That is a separate track from the breach statute, which is why section 3(c.2) exempts chapter 45 entities from the Attorney General notification.

A common-law duty sits alongside the statute. Dittman v. UPMC establishes that the absence of a private claim under the notification statute does not end the analysis. The Supreme Court held that an employer collecting and storing employees’ sensitive personal information on an internet-accessible system owes a duty of reasonable care in doing so, and that Pennsylvania’s economic loss doctrine permits recovery of purely pecuniary damages in negligence where the duty breached arises under common law independent of contract. The opinion was authored by Justice Baer and joined by Justices Dougherty, Wecht and Mundy, with Chief Justice Saylor concurring and dissenting joined by Justice Todd.

Recent Enforcement in Pennsylvania

23andMe — multistate settlement covering 192,093 Pennsylvanians. Attorney General Dave Sunday joined a coalition of forty-two states in an $18 million bankruptcy claim settlement with 23andMe, resolving allegations arising from the October 2023 breach that compromised genetic data on 6.9 million consumers worldwide. Pennsylvania received $491,902, and the office states that 192,093 Pennsylvanians were among those affected. The attackers used credential stuffing, attempting to force access to accounts using passwords stolen from other websites; the office’s statement singles out the company’s partnership with MyHeritage, itself compromised years earlier and exposing credentials shared between the two sites, as making the failure to guard against that technique particularly serious. The identified security failures include not comparing passwords against blocklists of known breached passwords and not requiring multifactor authentication. Pennsylvanians were also covered by a separate $46.75 million class settlement in the bankruptcy for consumers who submitted claims by February 17, 2026.

DNA Diagnostics Center — joint investigation with Ohio, February 16, 2023. The Office of Attorney General investigated the 2021 breach at DNA Diagnostics Center jointly with the Ohio Attorney General’s office, and each state negotiated its own agreement with the company. The breach exposed the Social Security numbers and other personal data of roughly 12,500 Pennsylvanians, alongside about 33,000 Ohioans, and the data taken was material the company had purchased from another business rather than its own customer records. The joint investigation concluded that the company had made unfair and deceptive statements about its cybersecurity and had failed to employ reasonable measures to detect and prevent a breach. As part of the negotiations with both states the company was required to have its new cybersecurity program assessed by a certified third party. Then Acting Attorney General Michelle Henry described the action as taken with the assistance of the Ohio Attorney General.

Pending Privacy Legislation

House Bill 78 of the 2025-2026 regular session is the Commonwealth’s comprehensive privacy bill and is further along than any predecessor. Prime-sponsored by Representative Ed Neilson with more than twenty-five co-sponsors from both caucuses, it is described in the General Assembly’s own summary as an act providing for consumer data privacy, for duties of controllers and for duties of processors, and imposing penalties. Its recorded history: referred to the House Commerce Committee on January 14, 2025; reported as amended on March 18, 2025 as printer’s number 1024; second consideration with amendments and re-committal to House Appropriations on April 23, 2025 as printer’s number 1476; re-reported as committed and given third consideration and final passage in the House on October 1, 2025 by a vote of 127 to 76; referred to the Senate Consumer Protection and Professional Licensure Committee on October 3, 2025; reported from that committee and re-referred to Senate Communications and Technology on February 4, 2026; re-reported as amended from that committee on June 24, 2026 as printer’s number 3688; and second consideration in the Senate on June 25, 2026. Third consideration and executive action are both recorded as milestones the bill has not yet reached.

Federal Privacy Laws That Apply in Pennsylvania

Federal privacy law applies in Pennsylvania by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.), which the Pennsylvania Office of Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Pennsylvania Businesses

With no comprehensive state statute, most privacy obligations on a Pennsylvania business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Pennsylvania businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Pennsylvania itself has none, and any business holding personal information about Pennsylvania residents is subject to the state’s breach-notification statute described above.

Pennsylvania Privacy Law FAQ

When must a Pennsylvania breach be reported to the Attorney General?
Section 3(c.1), added by Act 33 of 2024, requires notice concurrently with individual notice when notice must be given to more than 500 affected individuals in the Commonwealth. The report must include, to the extent known, the organisation’s name and location, the date of the breach, a summary of the incident, an estimated total number of individuals affected, and an estimated total number of individuals in Pennsylvania affected. Section 3(c.2) exempts an entity subject to the insurance data security chapter at 40 Pa.C.S. ch. 45 from that requirement.
Does Pennsylvania require an entity to pay for credit monitoring after a breach?
Section 5.4, added by Act 33 of 2024, requires it in defined circumstances. Where an entity providing notification under section 5 determines a breach has occurred and reasonably believes an individual’s name was accessed in combination with a Social Security number, a bank account number, or a driver’s licence or State ID number, the entity assumes all costs and fees of providing that individual with access to one independent credit report, if the individual is not eligible for a free one under federal law, and access to credit monitoring services for twelve months following notification. Subsection (c) requires the entity to inform the individual of the availability of those no-cost services when it gives notice.
Is there a private right of action for a Pennsylvania breach-notification failure?
Not under the Act itself. Section 8 provides that a violation is deemed an unfair or deceptive act or practice in violation of the Unfair Trade Practices and Consumer Protection Law, and states that the Office of Attorney General “shall have exclusive authority to bring an action under the Unfair Trade Practices and Consumer Protection Law for a violation of this act”. A separate private claim under section 9.2 of that Law remains available on its own terms to a purchaser of goods or services who suffers an ascertainable loss.
What did Dittman v. UPMC decide?
Decided November 21, 2018, it answered two questions. The Supreme Court of Pennsylvania held that an employer has a legal duty to exercise reasonable care to safeguard its employees’ sensitive personal information stored on an internet-accessible computer system; and it held that under Pennsylvania’s economic loss doctrine, recovery for purely pecuniary damages is permissible in negligence provided the plaintiff establishes breach of a legal duty arising under common law independent of any duty assumed by contract. The case arose from a breach exposing the names, birth dates, Social Security numbers, addresses, tax forms and bank account information of all 62,000 UPMC employees and former employees, used to file fraudulent tax returns. The Court vacated the Superior Court’s judgment, reversed the trial court and remanded.
Do Pennsylvania public schools and counties have their own breach deadlines?
Section 3(a.2), added by Act 151 of 2022, gives a county, public school or municipality seven business days following determination to provide the notice required by subsection (a), and three business days following determination to notify the district attorney in the county where the breach occurred. “Public school” is defined in subsection (d) as any school district, intermediate unit, charter school, cyber charter school or area career and technical school. Section 3(a.1) gives State agencies the same seven-business-day period, with concurrent notice to the Office of Attorney General.
How quickly must a Pennsylvania insurance licensee report a cybersecurity event?
Section 4518(a) of Title 40 sets five business days from a determination that a cybersecurity event involving nonpublic information in the licensee’s possession has occurred. That is longer than the three business days Ohio and North Dakota allow and the seventy-two hours South Carolina allows, and the triggering criteria are the same NAIC pattern: state of domicile or home state combined with a reasonable likelihood of material harm, or a reasonable belief that 250 or more Pennsylvania consumers are involved together with either a reporting obligation elsewhere or that same likelihood of harm.
What is the status of Pennsylvania’s comprehensive privacy bill?
House Bill 78 of the 2025-2026 regular session, prime-sponsored by Representative Ed Neilson, is an act providing for consumer data privacy, for duties of controllers and for duties of processors, and imposing penalties. It was referred to House Commerce on January 14, 2025, reported as amended on March 18, re-committed to Appropriations on April 23, re-reported on October 1 and passed the House the same day by 127 to 76. In the Senate it was referred to Consumer Protection and Professional Licensure on October 3, 2025, reported from that committee and re-referred to Communications and Technology on February 4, 2026, re-reported as amended on June 24, 2026, and given second consideration on June 25, 2026. It has not yet reached third consideration.
Which small insurers are exempt from Pennsylvania’s insurance data security requirements?
Section 4532(a) exempts a licensee from the risk assessment, information security program, corporate oversight, third-party service provider oversight and certification sections where it meets any one of three criteria: fewer than ten employees, less than $5,000,000 in gross revenue, or less than $10,000,000 in year-end total assets. The exemption reaches those five sections only, so the cybersecurity-event notification duty in section 4518 continues to apply.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.