Disclosure of Security Breach (data breach notification and data security)
IN Breach Notification
Breach notification · Data security
Indiana's breach law requires data base owners to notify affected Indiana residents, and the Attorney General, when a breach of computerized personal information could result in identity theft, identity deception, or fraud. Notice must go out without unreasonable delay and within 45 days of discovery. The article also requires reasonable security procedures and secure disposal of records containing personal information.
- Where
- Indiana
- Citation
- Ind. Code art. 24-4.9 (IC 24-4.9-1-1 to 24-4.9-5-1)
- Status
- In force
- In force since
- 2006-07-01
- Last amended
- 2026-07-01
- Enforced by
- Indiana Attorney General (actionable only by the AG, IC 24-4.9-4-1, 24-4.9-3-3.5(e))
- People can sue
- No
- Penalties
- For failing to notify: injunction, civil penalty up to $150,000 per deceptive act (a related series of breaches counts as one act), and costs (IC 24-4.9-4-2). For failing to keep reasonable security or to dispose of data properly: injunction, up to $5,000 per deceptive act, and costs (IC 24-4.9-3-3.5(f)).
- Applies to
- Any person (including nonprofits) that owns or licenses computerized data including personal information of Indiana residents ('data base owner'); persons that maintain such data for others must notify the owner (IC 24-4.9-2-3, 24-4.9-3-2)
- Does not apply to state agencies or the judicial or legislative departments (IC 24-4.9-1-1); state agencies are covered separately by IC 4-1-11
- Personal information: unencrypted and unredacted SSN; name plus driver's license, state ID, credit card, or financial account/debit card number with access code; and, since July 1, 2024, information collected by adult-website operators for age verification under IC 24-4-23 (IC 24-4.9-2-10)
Security duties
- Do not dispose of or abandon records with unencrypted, unredacted personal information without shredding, incinerating, mutilating, erasing, or otherwise making it unreadable.IC 24-4.9-3-3.5(d)
- Implement and maintain reasonable procedures, including appropriate corrective action, to protect Indiana residents' personal information from unlawful use or disclosure.IC 24-4.9-3-3.5(c) · Only if: Subsection (c) does not apply to owners that comply with their own security plans under the PATRIOT Act, EO 13224, DPPA, FCRA, GLBA, or HIPAA, with a carve-back for former HIPAA health care providers (IC 24-4.9-3-3.5(a)-(b))
Breach duties
- The Attorney General's Data Breach Notification Form (State Form 57435) is the channel for AG notice, sent by email to DataBreach@atg.in.gov or by mail or fax, with a sample consumer notice.IC 24-4.9-3-1(c) (AG practice per the AG website)
- Notify the Attorney General whenever resident notice is given.IC 24-4.9-3-1(c)
- If more than 1,000 consumers must be notified, also give each nationwide consumer reporting agency the information needed to help prevent fraud.IC 24-4.9-3-1(b) · Only if: More than 1,000 consumers notified
- Notify without unreasonable delay and no later than 45 days after discovery, except for delay needed to restore systems, determine scope, or at law enforcement or AG request.IC 24-4.9-3-3
- A person that maintains data it does not own must notify the data base owner of a breach.IC 24-4.9-3-2 · Only if: Service providers or other non-owners
- Give notice by mail, telephone, fax, or email; substitute notice (website posting plus news media) is allowed if more than 500,000 residents are affected or cost exceeds $250,000.IC 24-4.9-3-4(a)-(b)
- Notify affected Indiana residents of a breach of unencrypted personal information (or of encrypted data where the key was also taken) if the owner knows or should know it could result in identity deception, identity theft, or fraud.IC 24-4.9-3-1(a)
Other duties
- Entities that follow their own notice procedures under GLBA, HIPAA, FCRA, and similar federal regimes, or federal interagency banking guidance, are deemed compliant if those procedures are at least as protective.IC 24-4.9-3-4(c)-(e)
Sources
- Official text
- Indiana Code 2026, Title 24, Article 4.9 (Indiana General Assembly)
- HEA 1351 (2022), P.L.171-2022, adding the 45-day outer limit to IC 24-4.9-3-3, effective July 1, 2022
- SEA 17 (2024), P.L.98-2024, SECTION 2 adding age-verification data to 'personal information', effective July 1, 2024
- HEA 1088 (2026), P.L.23-2026, SECTION 247 technical amendment to IC 24-4.9-3-4, effective July 1, 2026
- SEA 169 (2026), P.L.115-2026, SECTION 26 amending the 'financial institution' definition, effective July 1, 2026
- Indiana Attorney General, Security Breach FAQs and Notification Form for Businesses (effective July 1, 2006; AG notice via State Form 57435 to DataBreach@atg.in.gov)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The Attorney General's business FAQ page still says only 'without unreasonable delay' and does not mention the 45-day outer limit added by P.L.171-2022; the statute (IC 24-4.9-3-3) controls.
Research reference, not legal advice.