D.C. Code § 41-164.07
This is the official text of D.C. Code § 41-164.07, part of District of Columbia’s Code — part of the compiled statutory law of District of Columbia, published by the state as "Code." Browse the sections below, each linked to its official government source.
Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.
§ 41-164.07. Security breach.
Official statutory text
(a) Except to the extent prohibited by law other than this chapter , the Administrator or Administrator's agent shall notify a holder as soon as practicable of:
(1) A suspected loss, misuse or unauthorized access, disclosure, modification, or destruction of confidential information obtained from the holder in the possession of the Administrator or an Administrator's agent; and
(2) Any interference with operations in any system hosting or housing confidential information that:
(A) Compromises the security, confidentiality, or integrity of the information; or
(B) Creates a substantial risk of identity fraud or theft.
(b) Except as necessary to inform an insurer, attorney, investigator, or others as required by law, the Administrator and an Administrator's agent may not disclose, without the express consent in a record of the holder, an event described in subsection (a) of this section to a person whose confidential information was supplied by the holder.
(c) If an event described in subsection (a) of this section occurs, the Administrator and the Administrator's agent shall:
(1) Take action necessary for the holder to understand and minimize the effect of the event and determine its scope; and
(2) Cooperate with the holder with respect to:
(A) Any notification required by law concerning a data or other security breach; and
(B) A regulatory inquiry, litigation, or similar action.
(1) A suspected loss, misuse or unauthorized access, disclosure, modification, or destruction of confidential information obtained from the holder in the possession of the Administrator or an Administrator's agent; and
(2) Any interference with operations in any system hosting or housing confidential information that:
(A) Compromises the security, confidentiality, or integrity of the information; or
(B) Creates a substantial risk of identity fraud or theft.
(b) Except as necessary to inform an insurer, attorney, investigator, or others as required by law, the Administrator and an Administrator's agent may not disclose, without the express consent in a record of the holder, an event described in subsection (a) of this section to a person whose confidential information was supplied by the holder.
(c) If an event described in subsection (a) of this section occurs, the Administrator and the Administrator's agent shall:
(1) Take action necessary for the holder to understand and minimize the effect of the event and determine its scope; and
(2) Cooperate with the holder with respect to:
(A) Any notification required by law concerning a data or other security breach; and
(B) A regulatory inquiry, litigation, or similar action.
Status: in_force · Read it on the official government site
Need a lawyer in District of Columbia?
Find a District of Columbia lawyer
About this page: Statute text is reproduced from official government publishers via the
Open US Law dataset
(Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine
(Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.