Skip to content
Rapid Response

      Desks

      This library

      Breach Notification

      The Encryption Safe Harbor and Its Conditions

      Encryption is the one condition that keeps an incident outside most notification statutes altogether. It is also conditional on the key: where the key or credential was taken with the data, the protection is expressly withdrawn and the ordinary clock resumes.

      Breach Notification6 min readState lawEncryption safe harbors

      A brushed steel keypad with numbered buttons mounted above a round handle on a pale wooden door
      The exemption turns on the state of the data and on whether the means of unlocking it traveled alongside. — Khrystinasnell, CC0, source.

      The rule in short

      State statutes are written around unencrypted personal information, so data rendered unusable, unreadable or indecipherable by a generally accepted security technology falls outside the notification trigger altogether. Washington measures the standard against a national institute benchmark. Every version of the exemption fails where the key or security credential was also acquired. The federal rule reaches the same place by narrowing its subject to unsecured information.

      Almost every notification statute in this field is written around unencrypted data. The word does more work than any exemption clause, because it appears in the trigger itself: notice is owed when unencrypted personal information was acquired by an unauthorized person. Data outside that description never enters the statute, so there is no clock to run, no letter to draft and no threshold to count against. That is why the encryption question is answered before anything else.

      What the statutes mean by encrypted

      Two drafting styles are in use. The functional style defines encrypted as personal information rendered unusable, unreadable or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security. California uses that formulation and Delaware uses nearly identical words. It fixes no algorithm and no key length, which means the standard moves as professional practice moves and a method that has fallen out of acceptance stops qualifying without any amendment to the statute.

      The benchmarked style names an external reference. Washington defines secured personal information as information encrypted in a manner that meets or exceeds the national institute of standards and technology standard, or otherwise modified so that the information is rendered unreadable, unusable or undecipherable by an unauthorized person. The second branch is functional, so the two styles converge in practice, but the first gives an organization something concrete to test a configuration against.

      Both styles describe the condition of the data rather than the sophistication of the organization holding it. An entity with a mature encryption program and one unencrypted export gets no benefit from the program in respect of that export. The corollary is more useful: an entity with no program at all still gets the exemption for the records that happened to be encrypted.

      The condition that collapses the protection

      Every version of the exemption fails in the same circumstance. California requires notice where encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired as well, provided the entity has a reasonable belief that the key or credential could render the information readable or usable. Washington puts it directly: a breach of secured personal information must be disclosed if the confidential process, encryption key or other means to decipher the secured information was acquired by an unauthorized person. Delaware defines the encryption key as the confidential key or process designed to render the encrypted information useable, readable and decipherable, and conditions its exemption accordingly.

      That last definition is worth reading closely, because it is broader than a cryptographic key. A process designed to make the data readable includes an application account with a decryption function, a service credential held in a configuration file, or an administrative session that performs the decryption transparently. An intruder who never touched a key file but held credentials to a system that decrypts on read has acquired the means to decipher.

      California adds a qualifier the other two do not. Notice is required where the key or credential was acquired and the entity has a reasonable belief that it could render the information readable or usable. A key that was rotated before the acquisition, or that unlocks a different data set, does not satisfy that condition. The qualifier is genuine, but it puts the entity in the position of asserting a negative about what an intruder could do with what it took, and that assertion needs support from key management records rather than from confidence.

      RegimeTerm usedStandardWhat defeats it
      CaliforniaEncryptedGenerally accepted security technology or methodologyKey or security credential acquired with a reasonable belief it could unlock the data
      WashingtonSecuredMeets or exceeds a national institute standard, or equivalentConfidential process, key or other means to decipher acquired
      DelawareEncryptedGenerally accepted security technology or methodologyAcquisition that includes or is believed to include the encryption key
      Federal health ruleUnsecuredTechnology and methodology specified in published guidanceInformation not rendered unusable, unreadable or indecipherable at all

      How the federal health rule reaches the same place

      The health rule does not use an exemption. It narrows the subject matter instead. The notification duty applies to a breach of unsecured protected health information, and unsecured information is defined as information not rendered unusable, unreadable or indecipherable to unauthorized persons through a technology or methodology specified by the Secretary in published guidance. Information that has been secured to that standard is not the subject of the subpart at all, so the presumption of compromise never arises and no risk assessment is required.

      The mechanism differs from the state approach in one respect that matters. The state statutes accept any generally accepted method; the federal rule accepts what the guidance specifies. An entity relying on the federal route is therefore relying on a document outside the regulation, and the analysis has to identify which specified technology or methodology was applied to the particular records. Where it cannot, the entity is back inside the presumption described in the definitional analysis that decides whether a breach occurred.

      Partial coverage is the normal case

      Incidents rarely divide neatly. A single intrusion commonly touches an encrypted production database, an unencrypted reporting extract and a set of backups whose state nobody can immediately confirm. The exemption applies record by record, so the output of the analysis is a reduced population rather than a yes or no. Records whose encryption state cannot be established belong in the notified population, because the entity asserting the exemption is the party who has to establish it.

      Proving the exemption after the fact

      The exemption is an assertion about a past state of affairs, and it is examined with hindsight. The useful evidence is contemporaneous: configuration records showing the encryption in force on the affected systems, key management records showing where the keys were held and who could reach them, and forensic findings on whether the intruder held credentials capable of decryption. A policy document stating that all data is encrypted is not evidence that these records were.

      Timing complicates the proof. The exemption describes the state of the data at the moment of acquisition, and that moment is often established weeks later by inference from logs. Where an intrusion persisted across a period during which a system was rebuilt, re-keyed or migrated, the encryption state may have differed from one week to the next, and the population has to be divided accordingly. Entities that answer the question once, for the environment as it stands after remediation, are describing a system that did not exist when the data left.

      Because the exemption removes people from the notified population, it also removes them from the counts that drive regulator filings and from the schedule pressure described in the state clocks and where they differ. That makes it the highest-value analysis in the incident and the one most worth writing down at the time. The record that supports it belongs in the same file as the rest of the reasoning, which is the subject of documenting a decision not to notify.

      Points to carry away

      • California defines encrypted as rendered unusable, unreadable or indecipherable through a generally accepted security technology or methodology.
      • Washington defines secured data by reference to a national institute standard or an equivalent modification.
      • Where the encryption key or security credential is acquired with the data, the exemption does not apply.
      • Delaware defines the encryption key separately as the confidential key or process that makes the data readable again.
      • The federal health rule applies only to unsecured protected health information, defined by published guidance.
      • The exemption attaches to the state of the data, not to the state of the organization's encryption program.

      Questions readers ask

      Does full-disk encryption on a lost laptop end the inquiry?

      Often, but not by itself. The question is whether the personal information was rendered unusable, unreadable or indecipherable to an unauthorized person at the moment of the incident. A machine encrypted at rest but taken while running and unlocked was not in that state. Nor was one whose credential was written on a card in the bag. The exemption describes the condition of the data when it left, and the evidence for that condition is the device configuration and the session state, not the existence of an encryption policy.

      Does the exemption apply to the regulator filing as well?

      Yes, in the sense that the filing thresholds count residents who must be notified. If encryption removes a population from the notification duty, those people are not counted toward the five hundred resident thresholds that force an attorney general filing. That makes the encryption analysis the first step rather than a later one, because it changes the size of the population before any threshold is applied. Where the exemption is only partial, the counts have to be run on the residue.

      What standard does encryption have to meet?

      The wording varies. California and Delaware use a functional test: rendered unusable, unreadable or indecipherable through a security technology or methodology generally accepted in the field of information security. Washington names a benchmark, requiring encryption that meets or exceeds the national institute of standards and technology standard, or another modification producing the same result. The functional formulations are not a lower bar, because a method no longer accepted in the field stops satisfying them without any amendment to the statute.

      Sources

      1. California Civil Code section 1798.82Defines encrypted and requires notice for encrypted data where the key or security credential was also acquired.
      2. RCW 19.255.010 — Washington notice of security breachesRequires disclosure of a breach of secured information where the process, key or other means to decipher it was acquired.
      3. RCW 19.255.005 — Washington definitionsDefines secured by reference to the national institute of standards and technology standard or an equivalent modification.
      4. Delaware Code title 6, chapter 12BDefines encrypted and encryption key separately and conditions the exemption on the key not being acquired.
      5. 45 CFR 164.402 — DefinitionsDefines unsecured protected health information by reference to technology and methodology specified in published guidance.
      6. 45 CFR 164.404 — Notification to individualsLimits the federal notification duty to breaches of unsecured protected health information.

      Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Breach Notification

      Breach Notification

      The State Clocks and Where They Differ

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      7 min readState law

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law