Hawaii's private-sector security law is a records-disposal duty rather than a product-security or general reasonable-security regime.
Haw. Rev. Stat. ch. 487R, the Destruction of Personal Information Records chapter, effective January 1, 2007 (Act 136 of the 2006 Regular Session, SB2292 SD2 HD1 CD1, approved May 25, 2006), requires any business or government agency that conducts business in Hawaii, or that maintains or otherwise possesses a Hawaii resident's personal information, to take reasonable measures to protect against unauthorized access to or use of that personal information in connection with or after its disposal, satisfied by burning, pulverizing, recycling or shredding paper records and destroying or erasing electronic and other nonpaper media so the information cannot practicably be read or reconstructed, or by exercising due diligence over a contracted records-destruction vendor; a financial institution subject to the Gramm-Leach-Bliley Act, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health plan or health care provider, and a Fair Credit Reporting Act-compliant consumer reporting agency are exempt.
A violating business is subject to a civil penalty of not more than $2,500 per violation, brought by the attorney general or the executive director of the office of consumer protection, and is separately liable to the injured party for actual damages and, at the court's discretion, reasonable attorneys' fees; no action under the chapter may be brought against a government agency, and the chapter carries no criminal exposure.
No enacted Hawaii statute is confirmed in the primary text consulted here to set security requirements a connected device or software product must meet before or after it reaches the market: a bill closely modeled on California's and Oregon's connected-device statutes, the Security of Connected Devices Act (identical companion bills HB739 and SB1002, 2021 Regular Session), was deferred by the House committee on Energy & Environmental Protection and Consumer Protection on February 5, 2021, carried over to the 2022 Regular Session on December 10, 2021, and never enacted in either chamber, so this is a researched absence rather than a gap in coverage.
Hawaii has no general private-sector duty to report a security incident or an exploited vulnerability to an authority.
The one sector-specific cyber-resilience regime this jurisdiction runs is the Insurance Data Security Law, Haw. Rev. Stat. secs. 431:3B-101 to 431:3B-306 (Act 112 of the 2021 Regular Session, approved June 28, 2021, effective July 1, 2021, adopting the National Association of Insurance Commissioners' Insurance Data Security Model Law), which requires every insurance licensee to develop, implement and maintain a comprehensive written information security program commensurate with its size and the sensitivity of the nonpublic information it holds, and requires notice to the insurance commissioner as promptly as possible, and in no event later than three business days, from a determination that a cybersecurity event affecting 250 or more consumers has occurred; a licensee with fewer than ten employees is exempt from the program duty, a licensee compliant with HIPAA's own information security program is deemed compliant, and a violation draws the insurance code's general enforcement provision, a fine of $100 to $10,000 per violation or imprisonment of not more than one year, in addition to license suspension, revocation or a monetary penalty and restitution under Haw. Rev. Stat. sec. 431:2-203.
Because the Insurance Data Security Law's bound party is an insurance licensee, a role no activity this profile can flag on expresses, it is recorded here in prose rather than filed as its own instrument, so that no false reach is published for a developer whose app is not an insurance licensee. The Security Breach of Personal Information Act, Haw. Rev. Stat. ch. 487N, is this jurisdiction's privacy-topic row for breach notification and is not repeated here.