Buyer guide

Responding to a data breach in the US: what notification laws require

There is no single US breach law. Every state has its own breach notification statute, and sector rules such as HIPAA, the FTC Safeguards Rule and SEC disclosure add their own triggers and deadlines. You need to know which apply before an incident, and keep a record of every incident whether or not you notify anyone.

The short answer

In the United States there is no single federal law covering every data breach. Instead, several layers can apply to the same incident, and you need to check each one:

  1. State breach notification laws. Every state has one. Triggers, definitions of personal information, deadlines and regulator-notice rules differ, and the laws generally apply based on where the affected individuals live, not where your business is based.
  2. Sector laws. HIPAA for health information, the FTC Safeguards Rule for non-bank financial institutions, banking regulators for banks and credit unions, and SEC disclosure rules for public companies.
  3. Contracts. Customer agreements, cyber insurance policies and payment card rules often require notice within a set time, sometimes shorter than the law.
  4. Records. Keep a record of every incident, including the ones you decide not to notify, with your reasoning.

This article summarizes published guidance in general terms. It is general information, not legal advice, and deadlines change, so confirm the current requirements with your legal adviser for any real incident.

What counts as a breach

Definitions differ by law, but most describe unauthorized access to, or acquisition or disclosure of, personal information. State laws typically define personal information as a person's name combined with an identifier such as a Social Security number, driver's license number, financial account number with an access code, or medical information, and some states add other data such as biometrics or online account credentials. Common examples:

  • A ransomware attack or intrusion that exposes customer or employee records.
  • An email sent to the wrong recipient with personal information attached.
  • A lost or stolen laptop, phone or USB drive.
  • A cloud folder or database left publicly accessible.
  • An employee viewing records without a business reason.

What makes an incident notifiable

Triggers vary, so do not assume one test fits all laws:

  • State laws commonly require notice when personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Some states add a risk-of-harm test that lets an organization conclude, after investigation, that misuse is unlikely. Others require notice regardless.
  • Encryption. Many state laws, and HIPAA, treat properly encrypted data as outside the notification duty when the encryption key was not compromised. Check the wording of each applicable law.
  • HIPAA presumes a breach of unsecured protected health information is reportable unless a documented risk assessment shows a low probability that the information was compromised.
  • Sensitivity and probability of misuse. Whichever law applies, the same facts matter: what type of information, who obtained it, how long it was exposed, whether there is evidence of malicious intent, and whether harm has already occurred.

Document your reasoning either way. If a regulator asks, your record needs to explain how you reached your conclusion.

Demonstration, not a client project

Two hypothetical lost laptops. In the first case, the laptop had full-disk encryption enabled, the key was not stored with it, and it was reported lost within an hour. The organization might reasonably conclude that the information was not accessible, record the incident and its assessment, and check whether any applicable law still requires notice. In the second case, the laptop was unencrypted and held a spreadsheet of client names, dates of birth and banking details. The information is sensitive and readily usable, so notification is likely required under state law: notify the clients, notify regulators where the law requires it, and consider notifying their banks. Your own assessment will depend on your facts and the laws that apply.

Key deadlines to know

These are examples of commonly relevant rules. Confirm the current text and any additional rules for your situation.

  • HIPAA Breach Notification Rule. Covered entities notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach. They also notify HHS, and notify the media if the breach affects more than 500 residents of a state or jurisdiction. Business associates must notify the covered entity (HHS).
  • FTC Safeguards Rule. Non-bank financial institutions covered by the rule must notify the FTC within 30 days of discovering a notification event involving the unencrypted information of 500 or more consumers (FTC).
  • SEC rules for public companies. A Form 8-K under Item 1.05 is due four business days after the company determines that a cybersecurity incident is material (SEC).
  • Texas. Individuals must be notified within 60 days of determining a breach occurred, and the Texas Attorney General must be notified within 30 days if 250 or more Texas residents are affected.
  • Other states. Timelines range from fixed numbers of days to "without unreasonable delay", and many states require notice to the state attorney general or another regulator above a threshold. Check every state where affected individuals live.

Notifying regulators

Report to each regulator whose rules apply, and update the report as you learn more rather than waiting for the investigation to finish. Typical content includes:

  • A description of what happened and, if known, its cause.
  • The date or period of the breach, and the date it was discovered.
  • The types of personal information involved.
  • The number of individuals affected, broken down by state where required.
  • The steps taken to contain the incident and reduce harm.
  • The steps taken, or planned, to notify affected individuals.
  • A contact person who can answer questions.

Ransomware, business email compromise and similar crimes can also be reported to law enforcement, for example through the FBI's Internet Crime Complaint Center (IC3). Some state laws allow a delay in notification when law enforcement asks for one.

Notifying individuals

Notice must be timely and written so people understand the significance of the breach and can protect themselves. State laws often prescribe contents and, in some cases, specific headings or formats. As a baseline, include:

  • What happened, and when (or approximately when).
  • What personal information was involved.
  • What your organization has done to reduce the risk of harm.
  • What individuals can do to reduce their own risk, such as credit monitoring or a security freeze where offered.
  • Contact information for questions.

Notify people directly (by mail, email or phone, as the law allows) in most cases. Many states permit substitute notice, such as a website posting and media notice, only in limited situations, for example when the cost of direct notice would be excessive or contact details are missing.

Notifying other organizations

If another organization may be able to reduce the risk of harm, tell it. Examples include law enforcement, a bank or payment processor that can monitor or block accounts, your cyber insurer (policies often require prompt notice), customers whose data you process on their behalf, and a service provider whose system was involved. Many states also require notice to the major consumer reporting agencies when a large number of residents are affected.

Keeping breach records

Keep a record of every security incident involving personal information, whether or not it met a notification threshold. Retention periods vary by law and contract. HIPAA, for example, requires covered entities and business associates to retain required documentation for six years. Your records may be requested by a regulator, an auditor, an insurer or a court.

Breach record template

  • Date or estimated date of the breach, and date discovered
  • General description of the circumstances and cause
  • Nature of the personal information involved
  • Number of individuals affected (or estimate), and their states of residence
  • Assessment of notification obligations under each applicable law, with reasoning
  • Which regulators were notified, and when
  • Whether individuals were notified, how and when
  • Other organizations notified (insurer, customers, banks, law enforcement)
  • Containment and corrective actions taken

Service providers and accountability

If a breach happens at a service provider that holds personal information on your behalf, such as a cloud host, payroll provider or IT provider, you generally remain responsible for notifying affected individuals, or at least for ensuring it happens. Your contracts should require providers to tell you promptly about breaches and to cooperate with your assessment and notifications. Where HIPAA applies, a business associate agreement must cover these duties.

Sector and state privacy laws

Breach notification is only part of the picture. Health data falls under HIPAA, student records under FERPA, financial data under GLBA and, for New York-regulated financial companies, NYDFS Part 500, which has its own incident notice rules. A growing number of state comprehensive privacy laws, such as California's CCPA as amended by the CPRA and the Texas Data Privacy and Security Act, add duties around data security and give individuals rights over their data. Public bodies are covered by separate public-sector rules. Check which laws apply to each type of information you hold, and plan for more than one notification if necessary.

A response sequence to prepare in advance

  1. Contain the breach: revoke access, isolate systems, recover devices or data where possible.
  2. Preserve evidence and start a timeline.
  3. Assess what information was involved, whose, and where those people live.
  4. Decide and document whether notification is required under each applicable law and contract, and calendar each deadline.
  5. Notify individuals, regulators and other organizations within the required times.
  6. Record the incident, even if no notice was required.
  7. Review what failed and fix it.

Assign an owner for each step before an incident happens, and rehearse the sequence with a tabletop exercise.

Limitations

This guide summarizes commonly relevant US requirements as of its review date. It does not cover every scenario, state or industry rule, and it is not legal advice. For a specific incident, involve legal counsel early. To prepare policies, an incident register and a response plan before you need them, see our privacy and compliance readiness service.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Breach Notification Rule, U.S. Department of Health and Human Services (HHS)
  2. Gramm-Leach-Bliley Act (GLBA) and the Safeguards Rule, Federal Trade Commission
  3. Data security guidance for businesses, Federal Trade Commission
  4. SEC adopts rules on cybersecurity risk management, strategy, governance and incident disclosure, U.S. Securities and Exchange Commission
  5. Internet Crime Complaint Center (IC3), Federal Bureau of Investigation

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in USD before any work starts