25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

New Washington D.C. Data Breach Notification Law Takes Effect

On May 19, 2020, legislative changes to the Washington D.C. data breach notification law took effect. The changes were introduced in March and significantly updated existing breach notification requirements. There has been a major expansion of data classified as personal information that warrants breach notifications if subjected to unauthorized access and new data security requirements have been introduced.

Prior to the change, notifications were required if personal information such as names, phone numbers, and addresses were exposed in combination with a Social Security number, driver’s license number, DC ID card, or credit/debit  card number or if numbers and codes were breached that allowed credit or finance accounts to be accessed.

The change has seen several other data elements added to the list. Breach notifications are now required if any of the following data is breached, even in the absence of a name if the data could be used for identity theft:

  • Medical information
  • Health insurance information
  • Genetic data and DNA profiles
  • Biometric information
  • Passport numbers
  • Usernames or email addresses in combination with a password or security questions and answers that would allow the account to be accessed
  • Taxpayer ID numbers
  • Military ID numbers
  • Other unique government-issued ID numbers

The D.C. Attorney General’s office must be notified in the event of a breach involving the data of more than 50 D.C. residents, and notifications must be issued without unreasonable delay in the most expedient manner possible. As is the case in states such as California, there are now content requirements for breach notifications.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

It is also now mandatory for the breached entity to offer a minimum of 18 months of complementary identity theft protection services to breach victims if a Social Security number or taxpayer ID number has been breached.

The update also calls for all businesses that collect, maintain, or process the personal information of D.C. residents to implement and maintain reasonable safeguards to secure personal information. The policies, procedures, and practices should reflect the nature and size of the entity. In cases where the entity works with third-party service providers, they must enter into a service agreement with the covered entity confirming they too will implement reasonable safeguards to ensure the confidentiality, integrity, and availability of personal information provided to them.

Breach notifications are not required if encrypted data is breached unless it can be decrypted, and neither if the breached entity determines, in conjunction with the D.C. Attorney General, that there is a low risk of harm.

HIPAA-covered entities in compliance with the HIPAA Breach Notification Rule are deemed to be compliant with the breach notification requirements of the updated law but are still required to notify the D.C. Attorney General about a data breach. The same applies to entities that are subject to and compliant with GLBA.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist