Skip to content
Rapid Response

      Desks

      This library

      Area of law

      Breach Notification

      What counts as a breach and the analysis that decides it, the state notification statutes and the clocks they run, the federal health rule and its sixty-day outer limit, notifying a regulator and the threshold that triggers it, the substitute notice permitted when individuals cannot be reached, the encryption safe harbor, obligations a vendor owes the organization that hired it, and the record an organization must keep of the decision.

      Breach Notification

      The State Clocks and Where They Differ

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      7 min readState law

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law

      Breach Notification

      Substitute Notice When People Cannot Be Reached

      Where direct notice is not feasible, most state statutes permit a substitute consisting of email where addresses are held, a conspicuous posting on the entity's own website, and notification to major statewide media. The gateway is fixed: cost above two hundred fifty thousand dollars, an affected class above five hundred thousand, or insufficient contact information. The federal health rule uses a different gateway entirely, turning on whether contact details fail for ten or more individuals.

      6 min readState law

      Breach Notification

      Handling an Incident That Crosses Many States

      A multi-state incident is managed by building one residency-mapped population, applying each statute's definition and exemptions to it, and then sequencing every deadline on a single calendar. The earliest obligation is often a preliminary regulator filing rather than a consumer letter. Because the notices and filings are read side by side, the controlling discipline is a single account of the facts that every document draws from without variation.

      6 min readState law

      Breach Notification

      What a Vendor Owes the Organization That Hired It

      An entity holding personal information it does not own owes notice to the owner or licensee rather than to the individuals. California, Washington and Vermont require that notice immediately following discovery. Florida sets ten days for a third-party agent. The federal health rule allows a business associate sixty calendar days from its own discovery, the same period the covered entity has, which creates a conflict the contract rather than the regulation resolves.

      6 min readFederal and state

      Breach Notification

      What Counts as a Breach

      A breach is a defined term, not a description of how bad an incident felt. Most state statutes require unauthorized acquisition of computerized personal information; a minority require access and acquisition together, and several add a harm threshold. The federal health rule runs the other way, presuming a breach and requiring a four-factor risk assessment to rebut it. The data categories that trigger a statute are also defined, and information outside them is not covered.

      6 min readState law

      Breach Notification

      The Encryption Safe Harbor and Its Conditions

      State statutes are written around unencrypted personal information, so data rendered unusable, unreadable or indecipherable by a generally accepted security technology falls outside the notification trigger altogether. Washington measures the standard against a national institute benchmark. Every version of the exemption fails where the key or security credential was also acquired. The federal rule reaches the same place by narrowing its subject to unsecured information.

      6 min readState law

      Breach Notification

      Documenting a Decision Not to Notify

      Where an organization concludes that an incident is not a reportable breach, the statutes treat that conclusion as something to be proved rather than asserted. The federal health rule assigns the burden expressly and requires documentation sufficient to meet it, retained six years. New York and Florida require the written determination to be kept five years, and both require it to be sent to the regulator once the incident passes a resident count.

      7 min readFederal and state

      Breach Notification

      What the Notice to an Individual Must Say

      A breach notice is built from a common core: who is writing, what categories of information were involved, when the incident happened, and how to get more information. States then add in different directions. California prescribes a title, five headings, a ten-point minimum type size and a model form. Washington requires the credit bureau contacts. The federal health rule requires a description of the entity's own remediation.

      6 min readState law

      Breach Notification

      Delaying Notice at the Request of Law Enforcement

      State statutes permit notice to be delayed where a law enforcement agency determines that notification would impede a criminal investigation, and require notice once the agency determines it no longer would. Florida requires a written request specifying a period the agency considers reasonably necessary. The federal health rule is the most precise: a written statement fixes the period, while an oral statement supports no more than thirty days unless a written one follows inside that window.

      7 min readState law