Privacy Law Library

Health Insurance Carrier Encryption of Personal Information

NJ Health Carrier Encryption Law

Health · Data security

Health insurance carriers may not keep personal information (name plus SSN, driver's license number, address, or identifiable health information) on laptops, desktops, mobile devices, or removable media, or send it over public networks, unless it is encrypted or otherwise unreadable. Password protection alone is not enough.

Where
New Jersey
Citation
N.J.S.A. 56:8-196 to 56:8-198; P.L.2014, c.88
Status
In force
In force since
2015-08-01
Enforced by
New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
People can sue
Limited
Penalties
Violations are unlawful practices under the Consumer Fraud Act, with civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13) and injunctive relief; a person with an ascertainable loss may sue for treble damages and attorney's fees (56:8-19).
Applies to
  • Health insurance carriers (insurance companies, health, hospital and medical service corporations, and HMOs) authorized to issue health benefits plans in New Jersey (56:8-196)
  • Only end user computer systems (desktops, laptops, tablets, mobile devices, removable media) and computerized records sent across public networks (56:8-197(b))

Security duties

  • Encrypt, or otherwise render unreadable to unauthorized persons, computerized records containing personal information on end user computer systems and in transit across public networks.N.J.S.A. 56:8-197(a)-(b)
  • A password program that only blocks general access, without making the data itself unreadable, does not satisfy the requirement.N.J.S.A. 56:8-197(a)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.