Written Information Security Program (Wisp) For Protection Of Personal Information Template Page 9

ADVERTISEMENT

2. To the extent required by M.G.L. c. 93H,§3 for Personal Information
other than personally identifiable health information, notice shall be
provided to the Massachusetts Attorney General and to the
Massachusetts Director of Consumer Affairs and Business regulation.
Such notice shall include the nature of the breach of security or
unauthorized acquisition or use, the number of residents of
Massachusetts affected by such incident at the time of notification, and
any steps the Corporation has taken or plans to take relating to the
incident.
C.
Whenever there is a Personal Information security breach or unauthorized
use of Personal Information, there shall be an immediate mandatory post-
incident review of events and actions taken, if any, with a view to
determining whether any changes in the Corporation’s security practices are
required to improve the security of Personal Information for which the
Corporation is responsible.
9

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Life