ATTACHMENT E-Personal Information Security & Breach Investigation Act-HB5- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf
PDF 303 KB Posted
- Attached to
- Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
- Solicitation number
- RFP-758-2500000171-5
- Issued by
- Kentucky
About this file
This document is Attachment E from the Kentucky Analytics Platform Solution (KAPS) Request for Proposal (RFP 758 2500000171), which details the Protection of Personal Information Security and Breach Investigation Procedures and Practices Act for vendors. The attachment outlines specific requirements for vendors who receive personal information from the Commonwealth of Kentucky, mandating strict compliance with the state's Personal Information Security and Breach Investigation Procedures and Practices Act (KRS 61.931).
The document comprehensively defines "Personal Information" and establishes vendor responsibilities for securing, protecting, and reporting potential data breaches. Key vendor obligations include immediately notifying relevant agencies within 72 hours of a breach determination, cooperating with Commonwealth investigation and mitigation efforts, implementing robust security procedures, and agreeing to potential payment withholdings for violations of identity theft prevention reporting requirements. Vendors must adhere to security standards at least as stringent as those established by the Commonwealth Office of Technology, with specific focus on protecting sensitive data elements such as Social Security numbers, account numbers, driver's licenses, and other personally identifiable information.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Protection of Personal Information Security and Breach Investigation Procedures and Practices Act
Vendors that receive Personal Information as defined by and in accordance with Kentucky’s Personal Information Security and Breach Investigation Procedures and Practices Act, KRS 61.931, et seq., (the “Act”), shall secure and protect the Personal Information by, without limitation, complying with all requirements applicable to non-affiliated third parties set forth in the Act.
“Personal Information” is defined in accordance with KRS 61.931(6) as “an individual’s first name or first initial and last name; personal mark; or unique biometric or genetic print or image, in combination with one (1) or more of the following data elements:
a) An account number, credit card number, or debit card number that, in combination with any required security code, access code or password, would permit access to an account;
b) A Social Security number;
c) A taxpayer identification number that incorporates a Social Security number;
d) A driver’s license number, state identification card number or other individual identification number issued by an agency;
e) A passport number or other identification number issued by the United States government; or
f) Individually Identifiable Information as defined in 45 C.F.R. sec. 160.013 (of the
Health Insurance Portability and Accountability Act), except for education records covered by the Family Education Rights and Privacy Act, as amended 20 U.S.C. sec 1232g.”
As provided in KRS 61.931(5), a “non-affiliated third party” means “any person or entity that has a contract or agreement with the Commonwealth and receives (accesses, collects or maintains) personal information from the Commonwealth pursuant to the contract or agreement.”
The vendor hereby agrees to cooperate with the Commonwealth in complying with the response, mitigation, correction, investigation, and notification requirements of the Act.
The vendor shall immediately notify as soon as possible, but not to exceed seventy-two (72) hours, the contracting agency, the Office of Procurement Services, the Commonwealth Office of Technology and the NG-KIH Program Office of a determination of or knowledge of a breach, unless the exception set forth in KRS 61.932(2)(b)2 applies and the vendor abides by the requirements set forth in that exception.
Attachment E
RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS) susan.noland Cross-Out
The vendor hereby agrees that the Commonwealth may withhold payment(s) owed to the vendor for any violation of the Identity Theft Prevention Reporting Requirements.
The vendor hereby agrees to undertake a prompt and reasonable investigation of any breach as required by KRS 61.933.
Upon conclusion of an investigation of a security breach of Personal Information as required by KRS 61.933, the vendor hereby agrees to an apportionment of the costs of the notification, investigation, and mitigation of the security breach.
In accordance with KRS 61.932(2)(a) the vendor shall implement, maintain, and update security and breach investigation procedures that are appropriate to the nature of the information disclosed, that are at least as stringent as the security and breach investigation procedures and practices established by the Commonwealth Office of Technology:
https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProc edures.aspx https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx
File details come from the government source that posted it. Updated .