An Act To Protect Public Employees from Identity Theft
Be it enacted by the People of the State of Maine as follows:
Sec. 1. 26 MRSA c. 43 is enacted to read:
CHAPTER 43
EMPLOYEE PERSONAL INFORMATION
§ 3501. Public employer notice upon breach of confidentiality of employee personal information
1. Definitions. As used in this chapter, unless the context otherwise indicates, the following terms have the following meanings.
A. "Personal information" means information listed under Title 5, section 7070, subsection 2.
B. "Public employer" means the State, including an executive, legislative or judicial agency, department, bureau, division, board or commission, a public postsecondary educational institution or an entity listed in section 962, subsection 7, paragraph A.
2. Breach of employee personal information. If a public employer determines or suspects that there has been a breach of confidentiality or theft of personal information of an employee of the public employer due to cyber activity or other means, the public employer shall:
A. Notify the employee within 24 hours of being notified of or discovering the breach or theft; and
B. Provide financial counseling to the employee.
SUMMARY
This bill requires a public employer, if the public employer determines or suspects there has been a breach of confidentiality or theft of an employee's personal information due to cyber activity or other means, to notify the employee within 24 hours of being notified of or discovering the breach or theft and to provide the employee financial counseling.