The First File The First File
  • News & Cases
  • Federal Law
    • Taxes
    • Federal Courts & Procedure
      • Appeals
      • Civil Procedure
      • Criminal Procedure
      • Evidence
    • Constitution & Rights
    • Consumer Protection
    • Bankruptcy
    • Agencies & Administrative Law
    • Federal Employment Law
    • Health & Federal Benefits
  • State Law
    • Criminal Law & Procedure
    • Employment & Work
      • Unemployment Insurance
      • Wages & Pay
        • Minimum Wage & Local Rules
      • Workers’ Compensation
      • Workplace Rights
    • Family & Relationships
      • Divorce
      • Guardianship
      • Probate & Estates
    • Housing & Real Estate
      • Landlord–Tenant
      • Foreclosure
      • HOAs & Condominiums
      • Deeds & Property Records
    • Personal Injury & Torts
      • Auto Accidents
      • Negligence
    • Business & Contracts
      • Business Entities
      • Contracts
    • Money, Debt & Consumer
      • Consumer Protection
      • Debt Collection & Judgments
Reading: Personal information theft and how federal and state rules work
Share
FIRST FILEFIRST FILE
Font ResizerAa
Search
  • Federal Law
    • Constitution & Rights
    • Consumer Protection
    • Practice Areas
  • State Law
    • Criminal Law & Procedure
    • Employment & Work
    • Family & Relationships
    • Housing & Real Estate
    • Personal Injury & Torts
    • Money, Debt & Consumer
    • Business & Contracts
  • Legal Terms Glossary
Follow US
Copyright © 2014-2025 Ruby Theme Ltd. All Rights Reserved.
Home » Blog » Personal information theft and how federal and state rules work
Archives

Personal information theft and how federal and state rules work

By Lucas S.
Last updated: August 11, 2026
11 Min Read
SHARE

This content is for informational and educational purposes only and is not legal, financial, or tax advice. No attorney-client relationship is created by reading or using this article. Federal, state, and local rules may differ and may change without notice. A qualified professional can review specific circumstances. The author and publisher assume no liability for actions taken based on this content.

Key Facts
  1. Federal level: Federal criminal identity theft provisions in 18 U.S.C. § 1028 cover certain transfers, possessions, or uses of another person’s “means of identification” without lawful authority with intent tied to unlawful activity.
  2. Federal level: 18 U.S.C. § 1028A adds an extra term of imprisonment when the identification-related conduct occurs during and in relation to an enumerated felony violation.
  3. Federal level: Under 15 U.S.C. § 1681c-2, a consumer reporting agency must block identity-theft-related information within 4 business days after receiving specified proof.
  4. Federal level: The FTC Act, 15 U.S.C. § 45, makes unfair or deceptive acts or practices in or affecting commerce unlawful and empowers the FTC to prevent them.
  5. Federal level: HIPAA breach notification rules in 45 CFR Part 164 Subpart D presume a breach unless a “low probability” standard is met based on listed risk assessment factors, and require individual notice within 60 calendar days after discovery.
  6. Federal level: The GLBA Safeguards Rule in 16 CFR Part 314 imposes certain notice obligations for FTC-jurisdiction financial institutions for certain security notification events involving at least 500 consumers.
  7. National overview: State breach notification laws exist in all states plus DC, Puerto Rico, and the Virgin Islands, but details like what must be included and how notices work can vary by state.

Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.

Contents
  • Why “personal information theft” shows up in privacy discussions
  • The federal criminal track tied to “means of identification”
  • Aggravated identity theft as an enhanced federal penalty
  • The consumer reporting track blocking identity theft information
  • The FTC Act track unfair or deceptive acts or practices
  • How FTC privacy and security guidance ties “promises” to obligations
  • HIPAA breach notification presumed breach with a “low probability” demonstration
  • GLBA Safeguards Rule notification FTC jurisdiction financial institutions
  • Where state law fits, and how the tracks differ in real life
  • Sources

Why “personal information theft” shows up in privacy discussions

The phrase “personal information theft” often functions as a plain-language label for identity theft and other misuse of information that can identify a specific person, rather than describing one single federal statute. The legal landscape often breaks into separate “tracks,” including federal criminal statutes, federal consumer-protection and consumer-reporting rules, and industry-specific breach notification requirements that depend on the type of data and who holds it. For broader background on privacy concerns in technology, see the archive article technology raises significant privacy concerns.

The federal criminal track tied to “means of identification”

Federal criminal identity theft concepts focus on a “means of identification,” which federal law defines to include “any name or number” that may be used to identify a specific individual. Under 18 U.S.C. § 1028, that definition includes identifiers such as a Social Security number and an official driver’s license or identification number. The statute also reaches certain conduct connected to identification materials and, in the relevant clause, criminalizes knowingly transferring, possessing, or using another person’s “means of identification” without lawful authority when done with intent to commit, to aid or abet, or in connection with unlawful activity (see 18 U.S.C. § 1028&edition=prelim)).

Aggravated identity theft as an enhanced federal penalty

Aggravated identity theft is not a standalone definition of a “kind” of information theft so much as an enhanced federal sentencing layer for certain circumstances. Under 18 U.S.C. § 1028A, the law adds an additional term of imprisonment when a person, during and in relation to an enumerated felony violation, knowingly transfers, possesses, or uses another person’s means of identification without lawful authority. A common confusion is treating the aggravated provision as a standalone definition; instead, it builds on the underlying identification-related criminal conduct and attaches the extra penalty when the statutory felony-condition applies.

The consumer reporting track blocking identity theft information

Federal law also addresses identity theft in the credit and consumer-reporting system through an information-blocking requirement. Under 15 U.S.C. § 1681c-2, a consumer reporting agency must block reporting of information in a consumer’s file that the consumer identifies as information resulting from alleged identity theft. The rule sets a specific timing requirement: blocking must happen “not later than 4 business days” after the agency receives specified proof, which includes a copy of an identity theft report. This is a distinct legal mechanism from criminal prosecution and it targets what appears in consumer reports.

The FTC Act track unfair or deceptive acts or practices

Federal consumer-protection authority provides a different enforcement model from the criminal identity theft statutes. The FTC Act declares that “unfair or deceptive acts or practices” in or affecting commerce are unlawful and empowers the FTC to prevent those practices (see 15 U.S.C. § 45&edition=prelim)). In the data-and-privacy context, this statutory framework can become relevant when business conduct about data practices is alleged to be unfair or deceptive under the FTC Act.

How FTC privacy and security guidance ties “promises” to obligations

FTC guidance on privacy and security explains how the FTC expects businesses to treat privacy and security commitments in the FTC Act framework. On FTC privacy and security guidance, the FTC states that if a company makes privacy promises, the FTC Act requires the company to live up to those claims. The FTC also describes a security obligation even when the company does not make specific claims, stating that there is an obligation to maintain security appropriate in light of the nature of the data the business possesses.

HIPAA breach notification presumed breach with a “low probability” demonstration

For certain health-related data, federal breach notification obligations come from HIPAA’s breach notification rule. Under 45 CFR Part 164 Subpart D, a breach is generally presumed unless the covered entity or business associate demonstrates that there is a “low probability” that protected health information has been compromised, using a risk assessment based on listed factors. The regulation also sets a timing rule for individuals: notification to affected individuals must be provided “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.”

GLBA Safeguards Rule notification FTC jurisdiction financial institutions

For certain financial institutions and consumer/customer information, the GLBA Safeguards Rule sets a separate regulatory framework for security and, in specified circumstances, notification to the FTC. Under 16 CFR Part 314, the rule implements standards for developing, implementing, and maintaining reasonable safeguards to protect customer information, and it includes notification obligations for certain “notification events.” The notification timing provided in the rule is specific: for a notification event involving at least 500 consumers, the financial institution must notify the FTC “as soon as possible, and no later than 30 days after discovery of the event,” subject to the rule’s scope and exceptions.

Where state law fits, and how the tracks differ in real life

State law can add additional breach notification requirements, and state rules typically work alongside federal frameworks rather than replacing them. The FTC explains that all states plus the District of Columbia, Puerto Rico, and the Virgin Islands have enacted breach notification legislation requiring notification of security breaches involving personal information, and it notes that state breach notification laws typically specify what information must or must not be provided in breach notices (see FTC breach response guide). As a result, the same underlying personal information theft incident can trigger different duties depending on the data type and the holder’s legal obligations, and the content and timing of required notices can vary by state.

Legal track Controlling authority What it addresses Timing or mechanism emphasized in the rule
Criminal identity theft 18 U.S.C. § 1028; enhanced by 18 U.S.C. § 1028A Identification-related conduct without lawful authority Aggravated identity theft adds an additional term of imprisonment when the statutory felony condition applies
Consumer reporting 15 U.S.C. § 1681c-2 Identity-theft-related information appearing in consumer reports Consumer reporting agency must block within 4 business days after receiving specified proof
Health data breach notice (HIPAA) 45 CFR Part 164 Subpart D Breach notification for unsecured protected health information Notification to individuals within 60 calendar days after discovery; presumed breach unless “low probability” standard is met
Financial data breach notice / security notification 16 CFR Part 314 Safeguards and notification events for FTC-jurisdiction financial institutions For certain events involving at least 500 consumers, FTC notice no later than 30 days after discovery
State breach notices State breach-notification statutes (varies) Additional notification duties for certain security incidents State details (including what must be included) differ by state

A practical way to read the rules is to treat “personal information theft” as a topic umbrella and then ask which system the facts touch: a criminal-identity-theft prosecution, a consumer-reporting-block requirement, or a breach-notification/security obligation tied to a particular regulated industry or data type.

Sources

  • 18 U.S.C. § 1028
  • 18 U.S.C. § 1028A
  • 15 U.S.C. § 45
  • 15 U.S.C. § 1681c-2
  • 16 CFR Part 314
  • 45 CFR Part 164 Subpart D
  • FTC privacy and security guidance
  • FTC breach response guide

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
ByLucas S.
Follow:
I am an independent writer and researcher with a deep interest in law, public affairs, and how the U.S. legal system operates in the real world. Regarding the key facts about my work, my role consists of providing plain-English legal explanations and covering various lawsuits and legal disputes. My approach involves preparing articles using the primary sources listed on each page. I am not an attorney or a lawyer and I do not provide legal advice. The primary areas where I focus my research include explaining complex legal topics in plain English, translating official legal materials into accessible explanations, and following current lawsuits and court cases. You should consult a qualified professional for advice regarding your own situation.
Previous Article Contingent fees and what counts as necessary or excessive under Federal and State rules
Next Article American Bar Association election reform archive recovery and today’s federal rules
Most Popular
An unpaved road curves through a sunlit high-desert landscape toward two distant red-rock buttes.
Patagonia coalition asks court to revive Bears Ears challenge after Trump reduction
September 3, 2026
A broad daylight street view of a modern courthouse with palm trees, entrance steps, traffic lights and a few distant pedestrians.
Duane Davis Convicted in Tupac Shakur Murder Case: What the Verdict Decides
September 3, 2026
The White House stands beside fenced construction sites, cranes and partially built concrete structures in daylight.
Supreme Court Lets White House Ballroom Work Continue Without Deciding Its Legality
September 3, 2026
Pedestrians walk near the entrance of a modern federal courthouse complex in daylight.
Music Publishers Sue Anthropic Over Alleged Use of Thousands of Compositions
September 3, 2026
Pedestrians pass a large stone courthouse with tall windows and mature trees along an urban street.
FTC and 22 States Sue Amazon Over Sponsored Ads Pricing
September 1, 2026

You Might Also Like

The American Bar Association and the Gun Trafficking Prevention Act of 2013

6 Min Read

ABA 2013 Midyear Meeting Resolution 300 and 28 U.S.C. § 1500 Reform

5 Min Read

Notario fraud and immigration accreditation rules under federal law

6 Min Read

Mobile marketing for law firms is a rules question not an app mandate

11 Min Read

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!
The First File The First File

Our goal is to provide simple explanations of federal and state laws without the confusing jargon

Latest News

  • Federal Law
  • State Law
  • Legal Terms Glossary

Resouce

  • Business Contact Page
  • Corrections Policy
  • Editoral Policy
  • About
  • Sitemap

Legal Notice

The information on this website is for educational purposes only and does not constitute legal advice.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?