Maryland Personal Information Protection Act
MPIPA
Breach notification · Data security · Health · Genetic · Biometric
Maryland's data security and breach notification law requires businesses holding Maryland residents' personal information to keep reasonable security, destroy records securely, and flow security requirements down to service providers. After a breach, a business must investigate and, unless misuse is not likely, notify affected residents within 45 days, notifying the Attorney General first. The 2022 revisions added genetic information and set the 45-day and 10-day deadlines.
- Where
- Maryland
- Citation
- Md. Code, Com. Law §§ 14-3501 to 14-3508
- Status
- In force
- Last amended
- 2022-10-01
- Enforced by
- Consumer Protection Division, Office of the Attorney General (14-3508; Com. Law Title 13)
- People can sue
- Yes
- Penalties
- A violation is an unfair or deceptive trade practice subject to all Title 13 enforcement and penalty provisions (14-3508), including civil penalties up to $10,000 per violation and $25,000 per repeat violation (13-410) and the private action for actual injury or loss under 13-408.
- Applies to
- Businesses (for-profit or nonprofit, including financial institutions) that own, license, or maintain personal information of Maryland residents (14-3501(b), 14-3503, 14-3504)
- Personal information: name plus SSN/ITIN/passport or other federal ID number, driver's license or state ID number, financial account or card number with access code, health or mental health information, health insurance ID with identifier, biometric data, or genetic information; also a username or email plus password or security Q&A (14-3501(e))
- Businesses complying with their primary federal or state regulator's rules, or with GLBA/FACTA interagency guidance, or HIPAA, are deemed compliant (14-3507)
Security duties
- Require nonaffiliated service providers receiving personal information under written contracts (entered on or after 2009-01-01) to maintain appropriate, reasonably designed security procedures.Com. Law 14-3503(b)
- When destroying customer, employee, or former-employee records containing personal information, take reasonable steps to protect against unauthorized access or use.Com. Law 14-3502(b)
- Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and the business.Com. Law 14-3503(a)
Breach duties
- For breaches involving only email account credentials, notice may prompt a password or security-question change but generally may not be sent to the compromised email account.Com. Law 14-3504(i)
- Notice must describe the categories of information acquired, give business contact information, list the consumer reporting agencies, and give FTC and Attorney General contact information with an identity-theft statement.Com. Law 14-3504(e)-(g)
- Notify the Office of the Attorney General before notifying individuals, including the number of affected residents, how the breach occurred, remedial steps, and a sample notice.Com. Law 14-3504(h)
- If 1,000 or more individuals must be notified, also notify nationwide consumer reporting agencies without unreasonable delay.Com. Law 14-3506(a)
- On discovering a breach, conduct a good-faith, reasonable, and prompt investigation; if notice is not required, keep a record of that determination for 3 years.Com. Law 14-3504(b)(1), (b)(4)
- Notify affected Maryland residents as soon as reasonably practicable and no later than 45 days after discovery, unless the business reasonably determines misuse is not likely; delays allowed for law enforcement or to determine scope.Com. Law 14-3504(b)(2)-(3), (d)
- A business that maintains but does not own the data must notify the owner or licensee within 10 days of discovering the breach and share breach information without charge.Com. Law 14-3504(c)
Sources
- Official text
- Md. Code, Com. Law § 14-3501 (definitions)
- Md. Code, Com. Law § 14-3502 (destruction of records)
- Md. Code, Com. Law § 14-3503 (security procedures)
- Md. Code, Com. Law § 14-3504 (breach notification)
- Md. Code, Com. Law § 14-3506 (consumer reporting agency notice)
- Md. Code, Com. Law § 14-3507 (deemed compliance)
- Md. Code, Com. Law § 14-3508 (enforcement)
- 2022 Md. Laws ch. 502 (HB 962), effective 2022-10-01
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Original enactment (2007 session) and first effective date could not be confirmed on mgaleg.maryland.gov, whose chapter archive for 2007 returned errors; effective_date left null (commonly reported as 2008-01-01).
Research reference, not legal advice.