Breach Notification
Breach notification is the legally required process of informing affected people, and often regulators, when their personal or sensitive information has been exposed or compromised. Many laws set out who must be told, what the notice should contain, and how quickly it must be sent. The specific rules vary depending on the type of data and the jurisdiction involved.
Breach notification refers to statutory and regulatory obligations to disclose a compromise of protected data to affected individuals and, where required, to regulators or other parties. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals following a breach of unsecured protected health information (PHI), where a breach is generally defined as an impermissible use or disclosure of unsecured PHI that may compromise its security or privacy. Comparable obligations exist across other regimes: all 50 U.S. states have enacted security breach laws requiring disclosure to consumers when personal information is compromised, and sector-specific rules such as the FCC's updated data breach notification requirements extend notice obligations to carriers when a consumer's PII is breached. A virtual CISO engagement may support an organization's breach notification readiness, including policy development and incident response planning, but legal and regulatory accountability for issuing required notifications typically remains with the client organization and its officers unless a contract specifies otherwise. Applicability, notification timelines, content requirements, and covered data types vary by regulation and jurisdiction, so obligations should be assessed against the specific laws governing a given organization.
Why it matters
Breach notification obligations transform a security incident from an internal technical problem into a set of externally enforceable legal duties. When protected data is compromised, organizations may be required to inform affected individuals and, in many cases, regulators, within timeframes and using content specified by law. Failing to notify properly, or notifying late, can expose an organization to regulatory scrutiny and enforcement in addition to the harm caused by the underlying breach itself. Because obligations vary by data type and jurisdiction, an organization can face multiple overlapping requirements from a single incident.
Who it's relevant to
Inside Breach Notification
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification.