At a hearing on Thursday, the subcommittee heard testimonies from a number of private-sector witnesses about the importance of a uniform federal standard for dealing with data breaches. Currently, there is no federal, cross-industry standard for informing the population after a data breach.
The subcommittee heard testimonies from representatives of the National Retail Federation, Providence, R.I.-based Brown University, the Information Technology Industry Council, the American Bankers Association, Symantec Corp. and the State of Illinois. Several witnesses cited the Anthem data breach, which had been announced the night before the hearing, as a major impetus for drafting a federal data breach bill.
More than 550 million identities were exposed in 2013, with eight breaches exposing more than 10 million identities each, said Cheri F. McGuire, the vice president of global government affairs and cybersecurity policy for Symantec Corp. in her testimony. Currently, 48 states have specific data breach notification policies, but a federal standard would be easier for companies, she said.
“Legislation cannot stop breaches from happening, but smart data breach legislation can help businesses and governments respond effectively and efficiently and empower consumers with accurate and timely information,” McGuire said.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.