{"data":{"id":"us-ky/krs-393a.830","jurisdiction":"us-ky","citation":"KRS 393A.830","heading":"Security breach.","body":"(1) Except to the extent prohibited by law other than this chapter, the administrator or\nadministrator's agent shall notify a holder as soon as practicable of:\n(a) A suspected loss, misuse or unauthorized access, disclosure, modification, or\ndestruction of con fidential information obtained from the holder in the\npossession of the administrator or an administrator's agent; and\n(b) Any interference with operations in any system hosting or housing\nconfidential information which:\n1. Compromises the security, confid entiality, or integrity of the\ninformation; or\n2. Creates a substantial risk of identity fraud or theft.\n(2) Except as necessary to inform an insurer, attorney, investigator, or others as\nrequired by law, the administrator and an administrator's agent sha ll not disclose,\nwithout the express consent in a record of the holder, an event described in\nsubsection (1) of this section to a person whose confidential information was\nsupplied by the holder.\n(3) If an event described in subsection (1) of this section occurs, the administrator and\nthe administrator's agent shall:\n(a) Take action necessary for the holder to understand and minimize the effect of\nthe event and determine its scope; and\n(b) Cooperate with the holder with respect to:\n1. Any notification requi red by law concerning a data or other security\nbreach; and\n2. A regulatory inquiry, litigation, or similar action.","path":["KRS Chapter 393A"],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=48180","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:59:25Z","sha256":"52ea96dca50192f2999dc34aa0e3994a73ac3521ea755f831ee2b9a266693bf8","source_id":"us-ky","stale":false,"prev":"us-ky/krs-393a.820","next":"us-ky/krs-393a.840"},"notice":"GroundRules: Original legal text. Not legal advice."}
