{"data":{"id":"us-nv/nrs-603a.525","jurisdiction":"us-nv","citation":"NRS 603A.525","heading":"Regulated entity to limit authority of employees and processors to access consumer health data; regulated entity to establish, implement and maintain policies and practices for security of consumer health data.","body":"1. A regulated entity shall only authorize the employees and processors of the regulated entity to access consumer health data where reasonably necessary to:\n(a) Further the purpose for which the consumer consented to the collection or sharing of the consumer data pursuant to NRS 603A.500; or\n(b) Provide a product or service that the consumer to whom the consumer health data relates has requested from the regulated entity.\n2. A regulated entity shall establish, implement and maintain policies and practices for the administrative, technical and physical security of consumer health data. The policies must:\n(a) Satisfy the standard of care in the industry in which the regulated entity operates to protect the confidentiality, integrity and accessibility of consumer health data;\n(b) Comply with the provisions of NRS 603A.010 to 603A.290, inclusive, where applicable; and\n(c) Be reasonable, taking into account the volume and nature of the consumer health data at issue.","path":["TITLE 52 — TRADE REGULATIONS AND PRACTICES","CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION","SECURITY AND PRIVACY OF CONSUMER HEALTH DATA","Regulation of Business Practices"],"source_url":"https://www.leg.state.nv.us/NRS/NRS-603A.html#NRS603ASec525","current_through":"2025 session (NRS as revised 2026-08-25)","vintage":"","retrieved_at":"2026-09-03T05:51:43Z","sha256":"0fe72c44bc54cb34a3871639cc01b51f914e0c5ac1c7f4b4c45f06e6b288a7ea","source_id":"us-nv","stale":true,"prev":"us-nv/nrs-603a.520","next":"us-nv/nrs-603a.530"},"notice":"GroundRules: Original legal text. Not legal advice."}
