The short answer
The Florida Information Protection Act of 2014 (FIPA, Florida Statutes section 501.171) requires every business that keeps personal information about Florida residents to protect it with reasonable security, dispose of it properly, and give notice within 30 days if it's breached. Breaches affecting 500 or more Floridians must also be reported to the Florida Department of Legal Affairs, and breaches affecting more than 1,000 people require notice to the national credit reporting agencies. Late notice can cost up to $500,000 per breach.
There is no size exemption. A three-person insurance agency in Venice is covered the same way a hospital system is.
What counts as personal information
Under FIPA, personal information is a person's first name or first initial and last name combined with any of these:
- Social Security number
- Driver license, state ID, passport, or military ID number
- Financial account, credit card, or debit card number together with any code or password needed to access the account
- Medical history, condition, treatment, or diagnosis
- Health insurance policy or subscriber number
- Biometric data
- Geolocation information
A username or email address combined with a password or security question answer for an online account also counts on its own, with no name required.
Two exclusions matter. Information that's publicly available from government records doesn't count, and neither does data that's encrypted or otherwise made unreadable. That second one is the closest thing FIPA has to a safe harbor.
Who has to comply
FIPA applies to any "covered entity": sole proprietorships, partnerships, corporations, associations, and other commercial entities that acquire, maintain, store, or use personal information. If you keep customer files, run payroll, take card payments, store patient records, or keep copies of driver licenses, you're covered.
It also applies to third-party agents, meaning vendors that handle personal information on your behalf. That includes your IT provider, your cloud backup company, and your payroll service.
The deadlines that matter
| Who must be notified | When | Threshold |
|---|---|---|
| Affected Florida residents | No later than 30 days after determining a breach occurred | Any breach of personal information |
| Florida Department of Legal Affairs | No later than 30 days | 500 or more Floridians affected |
| Nationwide credit reporting agencies | Without unreasonable delay | More than 1,000 individuals |
| Your business, from a vendor | No later than 10 days after the vendor discovers it | Any breach at a third-party agent |
The 30-day clock starts when you determine a breach occurred or have reason to believe one did. You don't get to wait until the forensic report is finished. An extra 15 days is available only if you give the Department good cause in writing inside the first 30 days. Law enforcement can also request a delay if notice would interfere with an investigation.
What the notices must say
Notice to individuals can go by mail or email to the address in your records and must include:
- The date, estimated date, or date range of the breach
- A description of the personal information involved
- Contact information so the person can ask questions
Notice to the Department of Legal Affairs must include a synopsis of events, the number of Floridians affected, any free services offered (such as credit monitoring) and how to use them, a copy of the notice sent to individuals, and a named contact.
When you don't have to notify individuals
If, after an appropriate investigation and consultation with law enforcement, you reasonably determine the breach has not and will not likely result in identity theft or other financial harm, individual notice isn't required. You must put that determination in writing, keep it for five years, and send it to the Department within 30 days. This is not a shortcut to skip a hard conversation; it requires real investigation and documentation.
Penalties
Violations are treated as unfair or deceptive trade practices enforced by the Department of Legal Affairs. For failing to give required notice:
- $1,000 per day for the first 30 days
- $50,000 for each 30-day period after that, up to 180 days
- Up to $500,000 per breach if the violation continues past 180 days
FIPA itself doesn't let customers sue, but a breach can still lead to claims under other laws, plus the very real cost of lost trust.
How FIPA overlaps with HIPAA and the FTC Safeguards Rule
Many Southwest Florida businesses answer to more than one rule. Medical and dental practices are also covered by HIPAA. Auto dealerships, CPA firms, and other financial institutions are covered by the FTC Safeguards Rule. FIPA says notice given under the rules of your primary or functional federal regulator is deemed to satisfy its individual notice requirement, as long as you also send a copy to the Department on time. The safe approach is to plan your incident response around the strictest deadline that applies to you and to confirm the details with your attorney.
What to do now, before anything happens
- Know where personal information lives. Email, file shares, the practice-management or dealer system, scanned driver licenses, spreadsheets on desktops. You can't protect or report on what you can't find.
- Encrypt laptops, phones, and backups. Encrypted data that's lost or stolen generally isn't a reportable breach under FIPA.
- Turn on multi-factor authentication everywhere, especially email. Compromised email accounts are the most common source of small business breaches.
- Get rid of what you don't need. FIPA requires reasonable disposal. Old scans, former-employee files, and closed-account records are liability with no upside.
- Check your vendors. Your IT provider and other third-party agents must tell you about a breach within 10 days. Make sure your contracts say so and that you know who to call.
- Write a one-page incident plan. Who decides a breach occurred, who calls the attorney, who calls the insurer, who drafts the notice. The 30-day clock goes fast when nobody knows whose job it is.
This article summarizes the statute for business owners and is not legal advice. Talk to your attorney about your specific situation.
How we help
Every Network Gurus managed plan includes enforced MFA, email security, endpoint detection and response, staff training, a managed firewall, and tested backups: the core of the "reasonable measures" FIPA expects. If you'd like to know where your business stands, start with a free IT and compliance assessment. It's a 60-minute on-site visit that ends with a written list of gaps and priorities.




