What the Law Requires and Who It Applies To
Rhode Island’s data breach law is the Identity Theft Protection Act of 2015 (R.I. Gen. Laws § 11-49.3), whose notice rules were last amended in 2023. It applies to any organization that holds personal information about Rhode Island residents, including private businesses, nonprofits, schools, and every public agency from towns to state departments.
A breach of unencrypted personal information, such as Social Security numbers, driver’s license numbers, account numbers with their access codes, medical or health insurance information, or email logins, must be reported when it poses a significant risk of identity theft. Notice goes out in the most expedient time possible, and no later than 45 calendar days after the breach is confirmed for businesses, or 30 days for state and municipal agencies. If more than 500 residents are to be notified, the Attorney General and the major credit reporting agencies must be told as well.
Since 2023, state and municipal agencies must also notify the Rhode Island State Police within 24 hours of detecting any cybersecurity incident.
RIBridges and the 2025 Bill
Between July and November 2024, attackers used a stolen Deloitte credential to get into RIBridges, the benefits system Deloitte operated for the state, and took personal data belonging to more than 640,000 people. Deloitte hired Experian to run the call center and provided free credit monitoring, and in February 2025 the state received $5 million from Deloitte for costs tied to the attack. A 2026 settlement brought the state’s total recovery to $12 million.
In 2025, legislators proposed tightening the Act (S 1037A / H 6346): organizations would have had to follow a recognized cybersecurity framework, and breach notices would also have gone to the state’s Division of Enterprise Technology Strategy and Services. The bill passed the Senate but was held for further study in the House, so those changes are not law. The rules above are the law in force.
For businesses, the lesson from RIBridges is that the organization holding the data answers for it, even when a vendor’s credentials were the way in.
What You Need To Do Now
If you store records that pair a person’s name with a Social Security, driver’s license, account or medical detail, this law applies to you. First, make sure that any personal data you store is encrypted. If it isn’t, you are exposed. Second, write a formal breach response plan and be ready to follow it within 24 hours of any incident.
At Triton Technologies, we help clients avoid these situations before they start. We use Sophos firewalls to keep intrusions out and Office 365 security configurations that enforce safe access to email, files, and apps. Cisco Duo provides identity checks to make sure logins are real, and endpoint protection covers every device.
We go further with internal and external penetration testing, ongoing threat detection through SIEM systems, and full user training through Proofpoint to catch phishing attempts before they land.
All of this is reportable. If a breach ever happens, you’re able to show what was in place, how it was contained, and what steps were taken to notify the right parties.
The Bottom Line for Rhode Island Businesses
Compliance is no longer a checklist. It is a legal requirement that comes with specific deadlines, language, and reporting steps. You don’t get extra time because your systems were slow. You don’t get forgiveness because your vendor made a mistake.
Rhode Island’s law puts consumers first. If their data is exposed, they have the right to know fast. They also have a right to protection, and that burden falls on the organization that lost control of the data.
Whether you’re a school district, a nonprofit, or a small business, these rules apply to you. Start with better security and make sure your reporting process is ready to go. If you don’t have that yet, now is the time to build it before the fines start coming.
Related articles
- What Do the New Britain and Meriden Ransomware Attacks Mean for Connecticut Businesses? · Sep 29, 2026
- What Happened in the MetroWest Community Federal Credit Union Ransomware Breach in Framingham? · Sep 29, 2026
- What Happened in the Form Energy Ransomware Attack in Somerville, and What Should Employers Learn? · Sep 29, 2026


