Health Insurance Carrier Encryption of Personal Information
NJ Health Carrier Encryption Law
Health · Data security
Health insurance carriers may not keep personal information (name plus SSN, driver's license number, address, or identifiable health information) on laptops, desktops, mobile devices, or removable media, or send it over public networks, unless it is encrypted or otherwise unreadable. Password protection alone is not enough.
- Where
- New Jersey
- Citation
- N.J.S.A. 56:8-196 to 56:8-198; P.L.2014, c.88
- Status
- In force
- In force since
- 2015-08-01
- Enforced by
- New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
- People can sue
- Limited
- Penalties
- Violations are unlawful practices under the Consumer Fraud Act, with civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13) and injunctive relief; a person with an ascertainable loss may sue for treble damages and attorney's fees (56:8-19).
- Applies to
- Health insurance carriers (insurance companies, health, hospital and medical service corporations, and HMOs) authorized to issue health benefits plans in New Jersey (56:8-196)
- Only end user computer systems (desktops, laptops, tablets, mobile devices, removable media) and computerized records sent across public networks (56:8-197(b))
Security duties
- Encrypt, or otherwise render unreadable to unauthorized persons, computerized records containing personal information on end user computer systems and in transit across public networks.N.J.S.A. 56:8-197(a)-(b)
- A password program that only blocks general access, without making the data itself unreadable, does not satisfy the requirement.N.J.S.A. 56:8-197(a)
Sources
- Official text
- P.L.2014, c.88, chapter law text (New Jersey Legislature)
- Consumer Fraud Act courtesy copy, 56:8-196 to 56:8-198 (NJ Division of Consumer Affairs)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.