ATTACHMENT E-Personal Information Security & Breach Investigation Act-HB5- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf
PDF 303 KB Posted
- Attached to
- Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
- Solicitation number
- RFP-758-2500000171-6
- Issued by
- Kentucky
About this file
This document is Attachment E for RFP 758 2500000171, the Kentucky Analytics Platform Solution (KAPS), detailing the Commonwealth of Kentucky's Protection of Personal Information Security and Breach Investigation Procedures and Practices Act requirements for vendors. The attachment outlines specific obligations for non-affiliated third parties that receive personal information from the Commonwealth, mandating strict security protocols and immediate breach notification procedures.
The document defines "Personal Information" comprehensively, including elements such as names, biometric data, account numbers, Social Security numbers, identification numbers, and other sensitive identifiers. Vendors are required to implement and maintain security procedures at least as stringent as those established by the Commonwealth Office of Technology, with potential financial penalties for non-compliance, including the withholding of payments for violations of identity theft prevention reporting requirements. The vendor must also agree to promptly investigate any security breaches, cooperate with the Commonwealth in mitigation efforts, and share in the costs of notification, investigation, and breach resolution.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Protection of Personal Information Security and Breach Investigation Procedures and Practices Act
Vendors that receive Personal Information as defined by and in accordance with Kentucky’s Personal Information Security and Breach Investigation Procedures and Practices Act, KRS 61.931, et seq., (the “Act”), shall secure and protect the Personal Information by, without limitation, complying with all requirements applicable to non-affiliated third parties set forth in the Act.
“Personal Information” is defined in accordance with KRS 61.931(6) as “an individual’s first name or first initial and last name; personal mark; or unique biometric or genetic print or image, in combination with one (1) or more of the following data elements:
a) An account number, credit card number, or debit card number that, in combination with any required security code, access code or password, would permit access to an account;
b) A Social Security number;
c) A taxpayer identification number that incorporates a Social Security number;
d) A driver’s license number, state identification card number or other individual identification number issued by an agency;
e) A passport number or other identification number issued by the United States government; or
f) Individually Identifiable Information as defined in 45 C.F.R. sec. 160.013 (of the
Health Insurance Portability and Accountability Act), except for education records covered by the Family Education Rights and Privacy Act, as amended 20 U.S.C. sec 1232g.”
As provided in KRS 61.931(5), a “non-affiliated third party” means “any person or entity that has a contract or agreement with the Commonwealth and receives (accesses, collects or maintains) personal information from the Commonwealth pursuant to the contract or agreement.”
The vendor hereby agrees to cooperate with the Commonwealth in complying with the response, mitigation, correction, investigation, and notification requirements of the Act.
The vendor shall immediately notify as soon as possible, but not to exceed seventy-two (72) hours, the contracting agency, the Office of Procurement Services, the Commonwealth Office of Technology and the NG-KIH Program Office of a determination of or knowledge of a breach, unless the exception set forth in KRS 61.932(2)(b)2 applies and the vendor abides by the requirements set forth in that exception.
Attachment E
RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS) susan.noland Cross-Out
The vendor hereby agrees that the Commonwealth may withhold payment(s) owed to the vendor for any violation of the Identity Theft Prevention Reporting Requirements.
The vendor hereby agrees to undertake a prompt and reasonable investigation of any breach as required by KRS 61.933.
Upon conclusion of an investigation of a security breach of Personal Information as required by KRS 61.933, the vendor hereby agrees to an apportionment of the costs of the notification, investigation, and mitigation of the security breach.
In accordance with KRS 61.932(2)(a) the vendor shall implement, maintain, and update security and breach investigation procedures that are appropriate to the nature of the information disclosed, that are at least as stringent as the security and breach investigation procedures and practices established by the Commonwealth Office of Technology:
https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProc edures.aspx https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx
File details come from the government source that posted it. Updated .