17.3 State Differences, PA SB 696, and Utah S.B. 127

Key Takeaways

  • States diverge on the personal-information list (medical, health insurance, biometrics, login credentials, tax ID), on harm-threshold versus acquisition-is-enough, on attorney-general and cyber-center triggers, on whether a vendor notifies the owner rather than residents, and on substitute-notice dollar and headcount math
  • Pennsylvania Act 151 of 2022 (SB 696), signed 3 November 2022 and effective 180 days later, expanded “personal information” to medical information, health-insurance information, and username-or-email plus password or security question; shifted private-entity notice from discovery to determination; and added credential-specific electronic notice
  • Act 151 also put 7-business-day resident clocks on Commonwealth agencies and on counties, public schools, and municipalities, required concurrent Attorney General notice from a State agency, and deemed HIPAA-compliant covered entities and business associates compliant with the Pennsylvania act
  • Utah S.B. 127 Cybersecurity Amendments, signed 23 March 2023 and effective 3 May 2023, created the Utah Cyber Center and requires notice to both the Attorney General and the Cyber Center when an investigation shows misuse of personal information of 500 or more Utah residents for identity theft or fraud has occurred or is reasonably likely; 1,000 or more also requires consumer-reporting-agency notice
  • Utah kept its harm/misuse threshold; California and post-SB 696 Pennsylvania remain acquisition-based. A later 2024 Utah S.B. 98 specified the contents of the Attorney General / Cyber Center report — it did not repeal S.B. 127
Last updated: August 2026

How States Diverge — The Comparison Grid

Once you know the common skeleton, Body of Knowledge V.C PI2 tests the forks. Do not invent a uniform 30-day, 500-person, acquisition-only United States. Run five questions against the statute that actually applies.

1. What is in “personal information”? The original triad — Social Security number, driver’s license, financial account plus access code — is the floor. Many states have added medical information, health-insurance information, unique biometrics, tax identification or other government IDs, and login credentials (username or email plus password or security question). California’s current list, taught in 17.2, is the long form. Pennsylvania’s 2022 amendment, below, is the BoK’s worked example of a mid-size expansion. A stolen email-and-password file can trigger notice in California and Pennsylvania and still miss a state that never added credentials.

2. Harm threshold or acquisition-is-enough? California § 1798.82 and post-amendment Pennsylvania fire when unencrypted, unredacted personal information was accessed and acquired (or reasonably believed acquired). Utah still asks whether misuse of that information for identity theft or fraud has occurred or is reasonably likely. A ransomware incident that locked files but produced no evidence of identity-theft misuse can be a California letter and a Utah “investigate, then decide.”

3. Attorney-general and other regulator triggers. California now wants a sample letter when more than 500 residents are notified, due 15 calendar days after the consumer mailing. Some states want the attorney general notified at 250, 500, or 1,000, sometimes before or at the same time as residents. Utah S.B. 127, below, adds a Cyber Center and keys the 500-resident report to the misuse finding, not to the mere fact of acquisition.

4. Third-party / vendor notice. Almost every statute says a person that maintains data it does not own notifies the owner or licensee, and the owner writes the resident letters. Pennsylvania Act 151 restates that vendor rule and then adds a special State agency contractor path: the contractor tells the agency’s chief information security officer, and the agency tells residents. The exam answer is almost never “the processor mails 50,000 consumer letters on day one.”

5. Substitute-notice math. The tests are not interchangeable. California: cost over $250,000, class over 500,000, or insufficient contact information; website posting at least 30 days. Pennsylvania Act 151: cost over $100,000, class over 175,000, or insufficient contact information. Using California’s numbers on a Pennsylvania-only incident is an exam miss.

ForkCalifornia § 1798.82 (2026)Pennsylvania after Act 151Utah after S.B. 127
PI extrasMedical, health insurance, biometrics, genetic, tax/passport/military ID, ALPR, credentialsMedical, health insurance, credentialsStill a tighter identity-theft-oriented list; misuse analysis sits on top
TriggerUnauthorized acquisition (encrypted data in if the key is taken)Determination that unencrypted, unredacted PI was accessed and acquiredInvestigation shows misuse for identity theft or fraud has occurred or is reasonably likely
Resident timing30 calendar days from discovery or notificationWithout unreasonable delay after determination (7 business days for State agencies and local governments)Without unreasonable delay after the misuse finding
AG / otherSample to AG if >500 residents, 15 days after consumer noticeState agency notifies AG concurrently; counties notify the district attorney in 3 business days; no general private-entity AG mailingAG and Utah Cyber Center if 500+ residents; CRAs if 1,000+
Substitute math$250,000 / 500,000 / no contact$100,000 / 175,000 / no contactStatute-specific; do not import California’s figures

Pennsylvania SB 696 — Act 151 of 2022

The Body of Knowledge names Pennsylvania SB 696. The enacted law is Act 151 of 2022, signed by Governor Tom Wolf on 3 November 2022, amending the Breach of Personal Information Notification Act (2005 P.L. 474, No. 94). It took effect in 180 days (early May 2023). Official act page: https://www.palegis.us/statutes/unconsolidated/law-information?sessYr=2022&sessInd=0&actNum=151.

What actually changed — from the enacted text, not a paraphrase.

The definition of personal information grew. It is still a Pennsylvania resident’s first name or first initial and last name, linked to an unencrypted, unredacted data element, but the element list now includes medical information (individually identifiable information in a current or historical record of medical history, treatment, or diagnosis created by a health-care professional), health-insurance information (policy or subscriber number in combination with an access code or other medical information that permits misuse of health-insurance benefits), and a username or e-mail address plus a password or security question and answer that would permit access to an online account. Publicly available government-record information, and information in widely distributed media, stay out.

Act 151 split discovery from determination. Discovery is knowledge of, or reasonable suspicion of, a breach. Determination is verification or reasonable certainty that a breach occurred. A private entity’s resident-notice duty now runs from determination, not from the first suspicious log line. That is more than semantics: Pennsylvania does not require a consumer letter on a mere suspicion.

Credential-only incidents gained an electronic path. If the personal information is a username or email plus a password or security question, the entity — to the extent it has contact information — may comply by sending electronic or other notice that tells the person to change the password and protect other accounts that reuse it. A State agency contractor in that situation may instead give the affected-resident list and known email addresses to the State agency.

Government clocks are tighter. If a State agency determines it is the subject of a breach affecting personal information it or its contractor maintains, it must give the subsection (a) resident notice within seven business days after determination and must notify the Office of Attorney General concurrently. A State agency contractor notifies the agency’s chief information security officer (or designee) upon discovery, no later than the contract’s stated period. An agency under the Governor’s jurisdiction also tells the Governor’s Office of Administration within three business days after determination. A county, public school, or municipality has the same seven-business-day resident clock and must notify the district attorney in the county where the breach occurred within three business days after determination. “Public school” includes a school district, intermediate unit, charter school, cyber charter school, or area career and technical school.

Vendors that maintain data on behalf of another entity still notify that entity after discovery; the entity makes the remaining determinations. Covered entities and business associates that are subject to and in compliance with HIPAA and HITECH privacy and security standards are deemed in compliance with the Pennsylvania act. An entity that follows its primary or functional federal regulator’s notification rules is also in compliance. Act 151 added encryption-in-transit and data-storage policy duties for entities that maintain Commonwealth personal information; those are government-side security duties, not a new private-sector comprehensive privacy law.

Scenario. A Pennsylvania hospital’s cloud billing vendor finds unusual downloads on Monday (discovery) and confirms Tuesday that an attacker took names plus health-insurance subscriber numbers and access codes (determination). The vendor notifies the hospital immediately. Because the hospital is a HIPAA covered entity and follows the HITECH individual-notice rule, Act 151 deems it compliant with the Pennsylvania act if that federal compliance is real. A non-HIPAA Pennsylvania retailer with the same credential-and-insurance file would send resident notice after Tuesday’s determination, could use the electronic “change your password” form for credential-only accounts, and would use Pennsylvania’s $100,000 / 175,000 substitute tests — not California’s.

Utah S.B. 127 Cybersecurity Amendments

The Body of Knowledge names Utah S.B. 127 Cybersecurity Amendments. Governor Spencer Cox signed the bill on 23 March 2023. It took effect 3 May 2023. It amended the Protection of Personal Information Act (Utah Code tit. 13, ch. 44) and created the Utah Cyber Center in the state’s technology-governance code.

What S.B. 127 actually added.

Utah already required a person who owns or licenses computerized personal information of a Utah resident to investigate a suspected breach and to notify the resident when the investigation showed that misuse of that information for identity theft or fraud had occurred or was reasonably likely. S.B. 127 kept that harm threshold. It did not convert Utah into an acquisition-is-enough state.

What it added is a second addressee and a headcount. If the investigation reveals that misuse of personal information relating to 500 or more Utah residents for identity theft or fraud has occurred or is reasonably likely, the person must notify both the Office of the Attorney General and the newly created Utah Cyber Center. If 1,000 or more Utah residents are affected, the person must also notify consumer-reporting agencies. Before S.B. 127, Utah’s private-sector statute had no attorney-general or CRA mailing duty.

The Cyber Center is not a privacy commission. It is a statewide cybersecurity coordination shop: receive breach reports, share threat intelligence, help develop incident-response measures, and build a statewide strategic cybersecurity plan. Governmental entities must notify the Cyber Center as soon as practicable when they become aware of a system-security breach. The Center may then assist, including by conducting all or part of the investigation. Do not confuse that government-to-Center duty with the private-sector 500-resident dual notice.

A later, verified follow-on — Utah S.B. 98 (Online Data Security and Privacy Amendments, signed 19 March 2024, effective 1 May 2024) — specified what a required Attorney General / Cyber Center report must contain: date of the breach, date discovered, total people affected and total Utah residents affected, type of personal information involved, and a short description. S.B. 98 also treated those submissions as confidential protected records in defined circumstances. Teach S.B. 98 as a contents amendment. It is not the BoK-named bill, and it did not repeal the 500 / 1,000 triggers or the misuse threshold.

Scenario. A Utah retailer confirms that an attacker acquired 700 residents’ names and Social Security numbers and that fraudulent tax filings have already appeared for some of them. Utah resident notice is due because misuse for identity theft has occurred. Because 700 is above 500 and below 1,000, the retailer also notifies the Attorney General and the Cyber Center, using the S.B. 98 content list. CRA notice is not yet required. The same incident in California would have been an acquisition letter even if no tax fraud had appeared, with a sample to the California Attorney General only if more than 500 California residents were notified.

Other 2025–2026 breach amendments exist — California SB 446’s 30-day / 15-day clocks, taught in 17.2, are the ones with an official 1 January 2026 effective date and a current code section. Do not invent a 2026 Pennsylvania or Utah rewrite that the legislature has not enacted.

Exam traps

  • Pennsylvania SB 696 is a breach-statute amendment, not a comprehensive consumer-privacy law and not Utah’s Cyber Center bill.
  • “Determination” versus “discovery” is a Pennsylvania exam word. Suspicion is discovery; reasonable certainty is determination.
  • Utah S.B. 127 added AG + Cyber Center at 500 and CRAs at 1,000. It did not drop the misuse threshold.
  • Substitute-notice figures are state-specific. Pennsylvania’s $100,000 / 175,000 pair is not California’s $250,000 / 500,000 pair.
  • A vendor’s first call is the owner (or the State agency CISO), not a 50-state resident mailing.
Loading diagram...
State Breach-Notification Difference Engine
Test Your Knowledge

A Pennsylvania retailer has reasonable suspicion on Monday that a laptop with names and health-insurance subscriber numbers plus access codes was stolen, and on Wednesday it verifies the theft. Counsel wants to wait because “Pennsylvania never covers medical or insurance data.” Which statement matches Act 151 of 2022 (SB 696)?

A
B
C
D
Test Your Knowledge

A Utah retailer’s investigation shows that names and Social Security numbers of 700 Utah residents were taken and that fraudulent accounts have already been opened for some of them. Which S.B. 127 result is correct?

A
B
C
D
Test Your Knowledge

The same attacker took a file covering California, Pennsylvania, and Utah residents. The file is unencrypted names plus driver’s-license numbers. There is not yet evidence of identity theft. Substitute notice is being considered because contact data are thin. Which comparison is accurate?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams