ATTACHMENT E Personal Information Security & Breach Investigation Act-HB5 RFP 758 2500000347.pdf

PDF 186 KB Posted

Attached to
IT Peripherals, Components & Services Online Ordering System State and local contract opportunity
Solicitation number
RFP-758-2500000347-1
Issued by
Elliott County, Kentucky

About this file

This document is Attachment E of a Kentucky state contract opportunity, specifically addressing the Protection of Personal Information Security and Breach Investigation Procedures and Practices Act. The attachment outlines comprehensive requirements for vendors who receive Personal Information as defined by Kentucky's statutory regulations (KRS 61.931). The document details specific obligations for non-affiliated third parties regarding the secure handling, protection, and reporting of personal data, including precise definitions of what constitutes Personal Information and the vendor's responsibilities in the event of a potential security breach.

The attachment mandates that vendors must immediately notify multiple state agencies (including the contracting agency, Office of Procurement Services, Commonwealth Office of Technology, and NG-KIH Program Office) within 72 hours of any detected breach, with potential financial penalties including withholding of payments for non-compliance. Vendors are required to implement security procedures at least as stringent as those established by the Commonwealth Office of Technology, maintain appropriate investigation protocols, and agree to share costs associated with notification, investigation, and mitigation of any security incidents. The document provides a detailed web link to the specific information security policies, standards, and procedures that vendors must follow.

View the file

Other files for this state and local contract opportunity

Other files attached to IT Peripherals, Components & Services Online Ordering System, newest first.
File Type Posted
ATTACHMENT D VENDORS QUESTION FORM RFP 758 2500000347.xlsx XLSX spreadsheet
Attachment B - Cost Proposal Form RFP 758 2500000347.docx DOCX document
Attachment F Mandatory Requirements Checklist RFP 758 2500000347.xlsx XLSX spreadsheet
Attachment A RFP 758 2500000347 .pdf PDF
ATTACHMENT C Annual Affidavit and Other Affidavits RFP 758 2500000347.docx DOCX document
Final_RFP_758_2500000347_1_SO_FORM.PDF PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Vendors that receive Personal Information as defined by and in accordance with Kentucky’s Personal Information Security and Breach Investigation Procedures and Practices Act, KRS 61.931, et seq., (the “Act”), shall secure and protect the Personal Information by, without limitation, complying with all requirements applicable to non-affiliated third parties set forth in the Act.

“Personal Information” is defined in accordance with KRS 61.931(6) as “an individual’s first name or first initial and last name; personal mark; or unique biometric or genetic print or image, in combination with one (1) or more of the following data elements:

a) An account number, credit card number, or debit card number that, in combination with any required security code, access code or password, would permit access to an account;

b) A Social Security number;

c) A taxpayer identification number that incorporates a Social Security number;

d) A driver’s license number, state identification card number or other individual identification number issued by an agency;

e) A passport number or other identification number issued by the United States government; or

f) Individually Identifiable Information as defined in 45 C.F.R. sec. 160.013 (of the

Health Insurance Portability and Accountability Act), except for education records covered by the Family Education Rights and Privacy Act, as amended 20 U.S.C. sec 1232g.”

As provided in KRS 61.931(5), a “non-affiliated third party” means “any person or entity that has a contract or agreement with the Commonwealth and receives (accesses, collects or maintains) personal information from the Commonwealth pursuant to the contract or agreement.”

The vendor hereby agrees to cooperate with the Commonwealth in complying with the response, mitigation, correction, investigation, and notification requirements of the Act.

The vendor shall immediately notify as soon as possible, but not to exceed seventy-two (72) hours, the contracting agency, the Office of Procurement Services, the Commonwealth Office of Technology and the NG-KIH Program Office of a determination of or knowledge of a breach, unless the exception set forth in KRS 61.932(2)(b)2 applies and the vendor abides by the requirements set

Attachment E Protection of Personal Information Security and Breach

Investigation Procedures and Practices Act forth in that exception.

The vendor hereby agrees that the Commonwealth may withhold payment(s) owed to the vendor for any violation of the Identity Theft Prevention Reporting Requirements.

susan.noland Cross-Out as required by KRS 61.933, the vendor hereby agrees to an apportionment of the costs of the notification, investigation, and mitigation of the security breach.

In accordance with KRS 61.932(2)(a) the vendor shall implement, maintain, and update security and breach investigation procedures that are appropriate to the nature of the information disclosed, that are at least as stringent as the security and breach investigation procedures and practices established by the Commonwealth Office of Technology:

https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProc edures.aspx

The vendor hereby agrees to undertake a prompt and reasonable investigation of any breach as required by KRS 61.933.

Upon conclusion of an investigation of a security breach of Personal Information https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx https://technology.ky.gov/OCISO/Pages/InformationSecurityPolicies,StandardsandProcedures.aspx

File details come from the government source that posted it. Updated .