House Bill 608 would expand North Carolina’s computer trespass law to give additional protection to two categories of sensitive data: protected health information and government employee personnel files. The bill amends the criminal computer trespass statute to make it unlawful to access certain government employee personnel-file data without authority, including situations where a person fails to follow the legal requirements governing access. It also clarifies that unauthorized copying of this information can fall within computer trespass even when the data is not physically altered or destroyed.
The bill also creates specific civil remedies for victims whose protected health information or government personnel-file data is involved in a computer trespass. In those cases, a person may recover the greater of actual damages or $5,000 per violation, plus court costs. The bill defines “personnel file” broadly to include employment-related and personal information such as salary, benefits, disciplinary actions, home address, Social Security number, medical history, and financial data, and it incorporates the federal HIPAA definition of protected health information. The act would take effect July 1, 2025, and apply only to offenses committed on or after that date.
HB608 would amend G.S. 14-458 and G.S. 1-539.2A, expanding both criminal and civil liability for unauthorized computer access involving protected health information and government employee personnel records. It would leave the baseline computer trespass offense in place, but add a statutory minimum civil recovery of $5,000 per violation for these two data categories and clarify that unauthorized access to personnel-file information by someone lacking legal authority is covered. The bill would affect individuals, employers, government agencies, health care providers, and anyone handling sensitive employee or medical data in electronic form.
The bill appears to be framed as a privacy and data-security measure, with its findings emphasizing the sensitivity of health and personnel information and the harm caused by unauthorized copying. Because there are no recorded committee transcripts or votes in the provided material, there is no direct evidence of debate or opposition in the record supplied. The overall tone of the bill text is protective and remedial, suggesting support for stronger safeguards around sensitive records.
The main potential points of contention are the expanded scope of computer trespass liability and the new $5,000 minimum civil recovery for each violation involving protected health information or personnel files. Critics could view the bill as broadening exposure for data access disputes, especially because it covers a wide range of personnel information and applies to both public and private actors who handle such records. Supporters would likely argue that the measure is narrowly targeted at unauthorized access to especially sensitive information and is needed because existing law does not provide an automatic minimum remedy for these harms.