Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Board asks staff to recommend breach‑notification timeline after reviewing district records policy
Summary
Trustees reviewed updated district‑records and cybersecurity language and asked staff to research statutory timelines and return in June with recommended notification windows (discussion favored an initial notice within several business days and fuller follow‑up once facts are known).
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Trustees reviewed proposed updates to the district records policy that clarify cybersecurity protections and breach notifications and asked staff to return with a recommended timeline for notifying affected individuals.
Staff pointed to existing legal reporting obligations and told trustees that notification is required to individuals reasonably believed to be affected, with additional reporting thresholds (e.g., the state's cybersecurity integration center) triggered if a breach involves 500 or more individuals. Board members debated whether an initial notification should go out as quickly as 48 hours or within about five business days, with several trustees urging transparency while staff cautioned against issuing speculative notices that could create unnecessary alarm if identity of affected individuals is not yet known.
The board directed staff to research legal timelines and best practices (including state and HIPAA comparators) and to return in June with proposed language and a communications plan for initial and follow‑up notifications. Staff emphasized the practical burden of large notifications and the need for accurate information before contacting families.

