Data breach notification in the US
How US breach notification works across state and sector laws, which deadlines to watch, and a response sequence and record template to prepare in advance.
Privacy laws, sector rules, client contracts and cyber insurers all expect you to protect information properly and prove it. We help organizations understand the technical and operational side of those expectations, close the gaps and prepare the evidence. We work alongside your legal counsel; we do not give legal advice or certify compliance.
Compliance readiness means getting your privacy and security practices to the point where they meet the requirements that apply to you, and being able to show it. Promatics handles the technical and operational side: what data you hold, how it is protected, how breaches are handled, and what evidence exists. Your legal counsel interprets the law; independent bodies certify. We sit between the two and do the practical work.
The United States has no single federal privacy law, so requirements usually come from several sources at once.
These summaries are general and not legal advice. Your counsel should confirm what applies to you.
Many organizations need to satisfy someone other than a regulator. We prepare you for:
The first days after a breach are stressful, and decisions made then are hard to undo. A breach response plan sets out how an incident is contained, who assesses which notification laws are triggered and by when, who decides on reporting and notification, who speaks to your insurer and counsel, and how the incident record is kept. We build the plan with you and rehearse it in a tabletop exercise.
Readiness work goes faster when roles are clear. Your legal counsel decides which obligations apply and how to read them. Your auditor or certification body decides whether you meet a standard. We translate their requirements into systems, procedures and evidence, flag questions that need a legal answer instead of guessing, and keep a traceable list showing each requirement, the control that meets it, its owner and where the evidence lives. That list becomes the working document for everyone involved, and it stays with you after we finish.
Readiness often reveals technical work. Security assessments measure your controls in depth, and our wider cybersecurity services close the gaps, including EDR, email security and awareness training.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Each stage ends with something you can review before the next one starts.
Identify which laws, sector rules, contracts and frameworks are likely to apply, and confirm them with your counsel.
Output: Requirements map.
Inventory what personal information you collect, why, where it lives, who can see it and how long it is kept.
Output: Data inventory and flow diagram.
Compare your technical and organizational safeguards with the requirements and rank the gaps by risk.
Output: Gap report and remediation plan.
Update controls, procedures, contracts and training, and build the breach response plan and log.
Output: Updated safeguards and breach plan.
Assemble the documents and records an auditor, insurer or regulator would ask for, and rehearse a breach scenario.
Output: Evidence pack and tabletop results.
We do not publish package prices. Each estimate is based on an agreed scope, in US dollars, with taxes shown separately. These are the things that move the number most:
No. We explain the technical and operational side of privacy and security requirements and help you put them into practice. Your legal counsel should confirm which obligations apply and how to interpret them, and we are happy to work with them.
It depends on the data and where the affected people live. Every state has a breach notification law with its own triggers and timelines; Texas, for example, requires notice to individuals within 60 days and to the Texas Attorney General within 30 days when 250 or more Texans are affected. Health data falls under the HIPAA Breach Notification Rule, non-bank financial institutions may owe notice to the FTC under the Safeguards Rule, and public companies may need to file an SEC Form 8-K. Read more in our breach reporting overview.
No. Certification and attestation, such as SOC 2 reports, ISO/IEC 27001 certificates or CMMC 2.0 assessments, come from independent auditors, accredited registrars and authorized assessment organizations. We help you get ready for them and gather the evidence they will ask for.
Not on its own. Choosing a US region, such as AWS US East in Northern Virginia or Azure South Central US in Texas, supports data residency, but compliance also depends on access controls, contracts, support access and how data is backed up and transferred. We review the whole picture.
Some obligations, such as state breach notification laws, the FTC Act and HIPAA, apply regardless of size, while many state comprehensive privacy laws apply only above revenue or data-volume thresholds. Your counsel can confirm which apply to you. The work scales down, and a small organization usually needs a focused data inventory, a breach plan and a handful of well-run controls.
How US breach notification works across state and sector laws, which deadlines to watch, and a response sequence and record template to prepare in advance.
A clear look at your security: what could go wrong, how likely it is, and what to fix first, explained in plain language.
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
Tell us what has been asked and what information you handle. We will reply to arrange a conversation about getting ready.