Mandated Timeframe
Without unreasonable delay
Violations
Up to $150,000 per breach
Breach Reporting |
Consumer Notifications |
|---|---|
Vendor Management |
Vendor Contract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
Up to $150,000 per breach
BreachReporting |
Consumer Notifications |
|---|---|
Vendor Management |
VendorContract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
Up to $150,000 per breach
BreachReporting |
Consumer Notifications |
|---|---|
Vendor Management |
VendorContract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Breach reporting to all consumer reporting agencies that compile and maintain files on a nationwide basis is required if more than 1,000 persons are affected by a breach of security, without unreasonable delay. The Organization will be responsible to complete any required regulatory reporting and consumer notification.
There is specifically defined information that must be included in the consumer notification. If any state residents are affected by a breach of security, the breached Organization must give notice without delay to each individual affected by the breach.
Vendors must notify Organizations as soon as possible after the discovery of a breach or suspected breach.
There are industry-specific laws governing the protection of personal data for health, insurance, and education.
The Attorney General may bring an action to enforce repeated and willful violations of the breach requirements, with civil penalties assessed up to $150,000. Violations of the breach notification requirements constitute an unfair or deceptive act or practice.
West Virginia
West Virginia health information network/privacy; protection of information
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |

