Privacy Law Library

Disclosure of Security Breach (data breach notification and data security)

IN Breach Notification

Breach notification · Data security

Indiana's breach law requires data base owners to notify affected Indiana residents, and the Attorney General, when a breach of computerized personal information could result in identity theft, identity deception, or fraud. Notice must go out without unreasonable delay and within 45 days of discovery. The article also requires reasonable security procedures and secure disposal of records containing personal information.

Where
Indiana
Citation
Ind. Code art. 24-4.9 (IC 24-4.9-1-1 to 24-4.9-5-1)
Status
In force
In force since
2006-07-01
Last amended
2026-07-01
Enforced by
Indiana Attorney General (actionable only by the AG, IC 24-4.9-4-1, 24-4.9-3-3.5(e))
People can sue
No
Penalties
For failing to notify: injunction, civil penalty up to $150,000 per deceptive act (a related series of breaches counts as one act), and costs (IC 24-4.9-4-2). For failing to keep reasonable security or to dispose of data properly: injunction, up to $5,000 per deceptive act, and costs (IC 24-4.9-3-3.5(f)).
Applies to
  • Any person (including nonprofits) that owns or licenses computerized data including personal information of Indiana residents ('data base owner'); persons that maintain such data for others must notify the owner (IC 24-4.9-2-3, 24-4.9-3-2)
  • Does not apply to state agencies or the judicial or legislative departments (IC 24-4.9-1-1); state agencies are covered separately by IC 4-1-11
  • Personal information: unencrypted and unredacted SSN; name plus driver's license, state ID, credit card, or financial account/debit card number with access code; and, since July 1, 2024, information collected by adult-website operators for age verification under IC 24-4-23 (IC 24-4.9-2-10)

Security duties

  • Do not dispose of or abandon records with unencrypted, unredacted personal information without shredding, incinerating, mutilating, erasing, or otherwise making it unreadable.IC 24-4.9-3-3.5(d)
  • Implement and maintain reasonable procedures, including appropriate corrective action, to protect Indiana residents' personal information from unlawful use or disclosure.IC 24-4.9-3-3.5(c) · Only if: Subsection (c) does not apply to owners that comply with their own security plans under the PATRIOT Act, EO 13224, DPPA, FCRA, GLBA, or HIPAA, with a carve-back for former HIPAA health care providers (IC 24-4.9-3-3.5(a)-(b))

Breach duties

  • The Attorney General's Data Breach Notification Form (State Form 57435) is the channel for AG notice, sent by email to DataBreach@atg.in.gov or by mail or fax, with a sample consumer notice.IC 24-4.9-3-1(c) (AG practice per the AG website)
  • Notify the Attorney General whenever resident notice is given.IC 24-4.9-3-1(c)
  • If more than 1,000 consumers must be notified, also give each nationwide consumer reporting agency the information needed to help prevent fraud.IC 24-4.9-3-1(b) · Only if: More than 1,000 consumers notified
  • Notify without unreasonable delay and no later than 45 days after discovery, except for delay needed to restore systems, determine scope, or at law enforcement or AG request.IC 24-4.9-3-3
  • A person that maintains data it does not own must notify the data base owner of a breach.IC 24-4.9-3-2 · Only if: Service providers or other non-owners
  • Give notice by mail, telephone, fax, or email; substitute notice (website posting plus news media) is allowed if more than 500,000 residents are affected or cost exceeds $250,000.IC 24-4.9-3-4(a)-(b)
  • Notify affected Indiana residents of a breach of unencrypted personal information (or of encrypted data where the key was also taken) if the owner knows or should know it could result in identity deception, identity theft, or fraud.IC 24-4.9-3-1(a)

Other duties

  • Entities that follow their own notice procedures under GLBA, HIPAA, FCRA, and similar federal regimes, or federal interagency banking guidance, are deemed compliant if those procedures are at least as protective.IC 24-4.9-3-4(c)-(e)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The Attorney General's business FAQ page still says only 'without unreasonable delay' and does not mention the 45-day outer limit added by P.L.171-2022; the statute (IC 24-4.9-3-3) controls.

Research reference, not legal advice.