Tenn. Code Ann. § 56-2-1009

This is the official text of Tenn. Code Ann. § 56-2-1009, part of Tennessee’s Code Ann — part of the compiled statutory law of Tennessee, published by the state as "Code Ann." Browse the sections below, each linked to its official government source.

Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.

Exceptions

Official statutory text

(a) (1) This part does not apply to: (A) A licensee who employs less than twenty-five (25) individuals, regardless of whether the individuals are employees or independent contractors; (B) A licensee with less than five million dollars ($5,000,000) in gross annual revenue; or (C) A licensee with less than ten million dollars ($10,000,000) in year-end total assets. (2) A licensee subject to and governed by the privacy, security, and breach notification rules issued by the United States department of health and human services, 45 CFR Parts 160 and 164, established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 ( 42 U.S.C. § 1320d et seq.), and the federal Health Information Technology for Economic and Clinical Health (HITECH) Act ( 42 U.S.C. § 300jj et seq. and 42 U.S.C. § 17901 et seq.), and that maintains nonpublic information in the same manner as protected health information meets the requirements of §§ 56-2-1004 and 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, the federal Health Insurance Portability and Accountability Act of 1996 and the federal Health Information Technology for Economic and Clinical Health. (3) A licensee subject to Title V of the federal Gramm-Leach-Bliley Act of 1999 ( 15 U.S.C. §§ 6801 - 6809 and 6821 - 6827 ) that meets the requirements of § 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, Title V of the federal Gramm-Leach-Bliley Act of 1999. (4) An employee, agent, representative, or designee of a licensee, who is also a licensee, is exempt from § 56-2-1004 if the activities of the employee, agent, representative, or designee are covered by the other licensee's information security program. (b) If a licensee ceases to qualify for an exception under subsection (a), then the licensee has one hundred eighty (180) days from the time the licensee no longer qualifies for the exception to comply with this part. Added by 2021 Tenn. Acts, ch. 345, s 1, eff. 7/1/2021.
(a) (1) This part does not apply to: (A) A licensee who employs less than twenty-five (25) individuals, regardless of whether the individuals are employees or independent contractors; (B) A licensee with less than five million dollars ($5,000,000) in gross annual revenue; or (C) A licensee with less than ten million dollars ($10,000,000) in year-end total assets. (2) A licensee subject to and governed by the privacy, security, and breach notification rules issued by the United States department of health and human services, 45 CFR Parts 160 and 164, established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 ( 42 U.S.C. § 1320d et seq.), and the federal Health Information Technology for Economic and Clinical Health (HITECH) Act ( 42 U.S.C. § 300jj et seq. and 42 U.S.C. § 17901 et seq.), and that maintains nonpublic information in the same manner as protected health information meets the requirements of §§ 56-2-1004 and 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, the federal Health Insurance Portability and Accountability Act of 1996 and the federal Health Information Technology for Economic and Clinical Health. (3) A licensee subject to Title V of the federal Gramm-Leach-Bliley Act of 1999 ( 15 U.S.C. §§ 6801 - 6809 and 6821 - 6827 ) that meets the requirements of § 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, Title V of the federal Gramm-Leach-Bliley Act of 1999. (4) An employee, agent, representative, or designee of a licensee, who is also a licensee, is exempt from § 56-2-1004 if the activities of the employee, agent, representative, or designee are covered by the other licensee's information security program.
licensee is compliant with, and submits a written statement certifying its compliance with, Title V of the federal Gramm-Leach-Bliley Act of 1999. (4) An employee, agent, representative, or designee of a licensee, who is also a licensee, is exempt from § 56-2-1004 if the activities of the employee, agent, representative, or designee are covered by the other licensee's information security program.
(1) This part does not apply to: (A) A licensee who employs less than twenty-five (25) individuals, regardless of whether the individuals are employees or independent contractors; (B) A licensee with less than five million dollars ($5,000,000) in gross annual revenue; or (C) A licensee with less than ten million dollars ($10,000,000) in year-end total assets.
(A) A licensee who employs less than twenty-five (25) individuals, regardless of whether the individuals are employees or independent contractors;
(B) A licensee with less than five million dollars ($5,000,000) in gross annual revenue; or
(C) A licensee with less than ten million dollars ($10,000,000) in year-end total assets.
(2) A licensee subject to and governed by the privacy, security, and breach notification rules issued by the United States department of health and human services, 45 CFR Parts 160 and 164, established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 ( 42 U.S.C. § 1320d et seq.), and the federal Health Information Technology for Economic and Clinical Health (HITECH) Act ( 42 U.S.C. § 300jj et seq. and 42 U.S.C. § 17901 et seq.), and that maintains nonpublic information in the same manner as protected health information meets the requirements of §§ 56-2-1004 and 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, the federal Health Insurance Portability and Accountability Act of 1996 and the federal Health Information Technology for Economic and Clinical Health.
(3) A licensee subject to Title V of the federal Gramm-Leach-Bliley Act of 1999 ( 15 U.S.C. §§ 6801 - 6809 and 6821 - 6827 ) that meets the requirements of § 56-2-1006(c) if the licensee is compliant with, and submits a written statement certifying its compliance with, Title V of the federal Gramm-Leach-Bliley Act of 1999.
(4) An employee, agent, representative, or designee of a licensee, who is also a licensee, is exempt from § 56-2-1004 if the activities of the employee, agent, representative, or designee are covered by the other licensee's information security program.
(b) If a licensee ceases to qualify for an exception under subsection (a), then the licensee has one hundred eighty (180) days from the time the licensee no longer qualifies for the exception to comply with this part.
Added by 2021 Tenn. Acts, ch. 345, s 1, eff. 7/1/2021.

Status: in_force

Need a lawyer in Tennessee?

Find a Tennessee lawyer
About this page: Statute text is reproduced from official government publishers via the Open US Law dataset (Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine (Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.