Cybersecurity Legal Obligations for Veterinary Practices

Share on Facebook
Share on X
Share on LinkedIn

Owners of vet practices have numerous regulatory compliance issues that they must address, including those involving cybersecurity obligations under applicable laws. These obligations can include implementing reasonable cybersecurity hardware and software, developing data security best practices, and reporting breaches of protected information. Practice owners must take these obligations seriously, as non-compliance with applicable laws could expose a veterinary practice to government enforcement or civil liability to clients. 

What Data Practices in Veterinary Offices Trigger Legal Exposure?

Vet offices may collect various categories of data from clients that can trigger legal obligations under cybersecurity laws and best practices, such as:

  • Client personal identifying information, including names, mailing or residential addresses, phone numbers, and email addresses 
  • Payment and financial information, including credit card or banking account numbers and tax identification numbers
  • Access information, such as usernames and passwords

FTC Safeguards Rule

Under federal regulations, the Federal Trade Commission has adopted the “Safeguards Rule.” This rule requires financial institutions subject to FTC jurisdiction to implement measures to protect customer information. However, the rule also requires institutions that work with affiliates and service providers to ensure that those third parties safeguard customer information in their custody. For vet practices that work with financial institutions to finance customers’ payment of services, the Safeguards Rule may also play a role in the practice’s cybersecurity requirements. 

State-Level Data Breach Notification Requirements

States have laws requiring businesses that collect and store customers’ personal information to notify customers when a data breach exposes that information to unauthorized parties. However, a business’s specific data breach notification requirements can vary from state to state. Each state has different laws governing what constitutes protected personal information, what qualifies as a data breach, and what a business must do when it experiences a breach. 

What Constitutes a Reportable Breach?

Although each state has different specific requirements for when a reportable data breach occurs, in general, a breach happens when an unauthorized party accesses, acquires, discloses, or causes the loss of protected information. Examples of scenarios that may constitute a breach include:

  • An employee copies clients’ personal financial information
  • An outside attacker installs encryption software onto devices containing protected information and demands money to provide the decryption key (i.e., ransomware attack)
  • An unauthorized party accesses databases containing protected information
  • An attacker copies, then deletes protected information from a business’s systems
  • An unauthorized party acquires protected information and then sells it to third parties or publishes the information

Vendor and Third-Party Software Liability

Veterinary practices should also ensure that the third-party software and electronic services vendors they use also implement reasonable cybersecurity practices. A practice can investigate a vendor’s cybersecurity practices or negotiate liability protections in a software, services, or SaaS agreement. 

Steps to Take After a Breach

Each state’s data privacy laws will specify the steps a covered veterinary practice must take when a data breach occurs. However, common best practices for responding to a breach include:

  • Isolate compromised devices and systems without inadvertently deleting data or digital evidence
  • Disable compromised user accounts or reset access details
  • Review legal duties under data breach laws and notify affected parties and (if required) government regulators
  • Retain IT experts to patch vulnerabilities and restore operations

The Basics of a Cybersecurity Policy Framework to Reduce Liability

Although the specifics of a cybersecurity policy can vary based on a veterinary practice’s particular operations, many policies should address matters such as:

  • Access control: Who can view protected information
  • Acceptable use: Permitted purposes for accessing and using protected data
  • Device security: Rules (including bring-your-own device regulations) to reduce the risk of breaches
  • Password rules: Requirements for login details and mandatory update policies
  • Data backup: Policies for saving and storing business data

Finally, vet practices can protect their legal interests by working with experienced counsel who can advise on cybersecurity requirements and best practices for responding to potential data breaches. 

Contact Our Firm Today for Knowledgeable Advice on Data Best Practices

Cybersecurity obligations can seem complex and confusing, but an experienced legal representative can walk you through your options and assist you with protecting your veterinary business’s interests. Contact Mahan Law today for an initial consultation with a veterinary attorney to learn more about the cybersecurity requirements applicable to your practice and for help developing a robust data security program for your practice. 

Cybersecurity Legal Obligations for Veterinary Practices

Owners of vet practices have numerous regulatory compliance issues that they must address, including those involving cybersecurity obligations under applicable laws. These obligations can include implementing reasonable cybersecurity hardware and software, developing data security best practices, and reporting breaches of protected information. Practice owners must take these obligations seriously, as non-compliance with applicable laws could expose a veterinary practice to government enforcement or civil liability to clients. 

What Data Practices in Veterinary Offices Trigger Legal Exposure?

Vet offices may collect various categories of data from clients that can trigger legal obligations under cybersecurity laws and best practices, such as:

  • Client personal identifying information, including names, mailing or residential addresses, phone numbers, and email addresses 
  • Payment and financial information, including credit card or banking account numbers and tax identification numbers
  • Access information, such as usernames and passwords

FTC Safeguards Rule

Under federal regulations, the Federal Trade Commission has adopted the “Safeguards Rule.” This rule requires financial institutions subject to FTC jurisdiction to implement measures to protect customer information. However, the rule also requires institutions that work with affiliates and service providers to ensure that those third parties safeguard customer information in their custody. For vet practices that work with financial institutions to finance customers’ payment of services, the Safeguards Rule may also play a role in the practice’s cybersecurity requirements. 

State-Level Data Breach Notification Requirements

States have laws requiring businesses that collect and store customers’ personal information to notify customers when a data breach exposes that information to unauthorized parties. However, a business’s specific data breach notification requirements can vary from state to state. Each state has different laws governing what constitutes protected personal information, what qualifies as a data breach, and what a business must do when it experiences a breach. 

What Constitutes a Reportable Breach?

Although each state has different specific requirements for when a reportable data breach occurs, in general, a breach happens when an unauthorized party accesses, acquires, discloses, or causes the loss of protected information. Examples of scenarios that may constitute a breach include:

  • An employee copies clients’ personal financial information
  • An outside attacker installs encryption software onto devices containing protected information and demands money to provide the decryption key (i.e., ransomware attack)
  • An unauthorized party accesses databases containing protected information
  • An attacker copies, then deletes protected information from a business’s systems
  • An unauthorized party acquires protected information and then sells it to third parties or publishes the information

Vendor and Third-Party Software Liability

Veterinary practices should also ensure that the third-party software and electronic services vendors they use also implement reasonable cybersecurity practices. A practice can investigate a vendor’s cybersecurity practices or negotiate liability protections in a software, services, or SaaS agreement. 

Steps to Take After a Breach

Each state’s data privacy laws will specify the steps a covered veterinary practice must take when a data breach occurs. However, common best practices for responding to a breach include:

  • Isolate compromised devices and systems without inadvertently deleting data or digital evidence
  • Disable compromised user accounts or reset access details
  • Review legal duties under data breach laws and notify affected parties and (if required) government regulators
  • Retain IT experts to patch vulnerabilities and restore operations

The Basics of a Cybersecurity Policy Framework to Reduce Liability

Although the specifics of a cybersecurity policy can vary based on a veterinary practice’s particular operations, many policies should address matters such as:

  • Access control: Who can view protected information
  • Acceptable use: Permitted purposes for accessing and using protected data
  • Device security: Rules (including bring-your-own device regulations) to reduce the risk of breaches
  • Password rules: Requirements for login details and mandatory update policies
  • Data backup: Policies for saving and storing business data

Finally, vet practices can protect their legal interests by working with experienced counsel who can advise on cybersecurity requirements and best practices for responding to potential data breaches. 

Contact Our Firm Today for Knowledgeable Advice on Data Best Practices

Cybersecurity obligations can seem complex and confusing, but an experienced legal representative can walk you through your options and assist you with protecting your veterinary business’s interests. Contact Mahan Law today for an initial consultation with a veterinary attorney to learn more about the cybersecurity requirements applicable to your practice and for help developing a robust data security program for your practice. 

Attorney Advertising
Website developed in accordance with Web Content Accessibility Guidelines 2.2.
If you encounter any issues while using this site, please contact us: 855.921.4440