Loading chat...

MI SB0360

Bill

Status

Engrossed

8/26/2025

Primary Sponsor

Rosemary Bayer

Click for details

Origin

Senate

103rd Legislature

AI Summary

  • Requires persons and agencies that own, possess, collect, or access personal information to implement and maintain reasonable security procedures, including designating a security coordinator, identifying risks, and contractually requiring service providers to follow cybersecurity frameworks like NIST 2.0

  • Expands the definition of "personal information" to include medical history, health insurance identifiers, usernames/passwords for online accounts, genetic information, and biometric data such as fingerprints and iris images

  • Mandates that entities discovering a security breach notify affected Michigan residents within 45 days and notify the attorney general if 100 or more residents are affected, with specific required content including breach description and remediation steps

  • Requires entities to offer at least 24 months of free identity theft prevention and mitigation services when Social Security numbers or taxpayer identification numbers are compromised in a breach

  • Grants the attorney general expanded enforcement powers including authority to issue investigative demands, accept assurances of discontinuance, and seek civil fines up to $750,000 for failure to provide required breach notifications

Legislative Description

Consumer protection: identity theft; identity theft protection act; modify. Amends ses. 3, 12 & 12b of 2004 PA 452 (MCL 445.63 et seq.); adds secs. 11a, 11b, 20, 20a, 20b & 20c & repeals secs. 15 & 17 of 2004 PA 452 (MCL 445.75 & 445.77).

Consumer protection: identity theft

Last Action

Referred To Committee On Government Operations

8/26/2025

Committee Referrals

Government Operations8/26/2025
Finance, Insurance, And Consumer Protection6/5/2025

Full Bill Text

No bill text available