With over 350 million records containing sensitive personal information having been compromised since 2005, it is evident that data breaches are an epidemic problem. After demonstrating the security breach problem, the Note begins by discussing California's pioneering data breach notifica-tion law, which requires breached entities to notify those affected that their personal information has been
... [Show full abstract] compromised. Drawing on various provi-sions found in California's notification law, the Note evaluates current state and federal data breach laws. To further explore the relationship be-tween federal and state enforcement, two recent data breaches, the Choice-Point and TJX breaches, are discussed in-depth. The Note then examines proposed federal and state legislation to strengthen the argument that da-ta breach laws, which currently focus on notification, must also advance to breach prevention. Finally, the Note proposes a solution for preventing da-ta breaches by increasing liability for merchants who fail to meet heigh-tened security standards based on those used in the credit card industry.