Skip to main content
Category: Incident Response & Reporting

Breach Notification

Also known as: Data Breach Notification, Security Breach Notification
Simply put

Breach notification refers to the legal obligation for an organization to inform affected individuals, and often government regulators, when personal or sensitive information has been compromised. These requirements are intended to ensure that people whose information may have been exposed are told promptly so they can take protective steps. The specific rules vary depending on which law applies and what type of information was involved.

Formal definition

Breach notification is a set of statutory and regulatory obligations requiring an entity to disclose the unauthorized acquisition, access, use, or disclosure of protected data to affected individuals and, where applicable, to regulators and other parties. The governing authority and specific triggers vary by regime: under the HIPAA Breach Notification Rule, covered entities must notify affected individuals when their unsecured protected health information (PHI) is impermissibly used or disclosed, with breaches affecting 500 or more individuals reported to the Secretary of HHS without unreasonable delay and in no case later than 60 days, while breaches affecting fewer than 500 individuals are still reportable to HHS on an annual aggregated basis rather than only when 500 or more are affected. Separate frameworks impose their own requirements, including FCC data breach notification rules applicable to carriers when a consumer's PII is breached, and security breach notification laws enacted in all 50 states requiring disclosure to consumers when personal information is compromised. Because thresholds, definitions of covered data, notification timelines, and recipient requirements differ across these regimes and may be updated, practitioners should confirm the applicable law and its current authoritative text; this entry does not address defense-specific incident reporting obligations (such as those under DoD contractual clauses), which follow distinct requirements.

Why it matters

Breach notification obligations translate the abstract goal of protecting personal information into concrete, time-bound duties that carry legal and reputational consequences when ignored. When personal or sensitive data is compromised, affected individuals cannot take protective steps, such as monitoring accounts or changing credentials, unless they are told promptly. For organizations, failing to notify on time or to the correct recipients can expose them to regulatory enforcement, civil liability, and loss of public trust, which is why compliance officers treat these requirements as a distinct discipline rather than an afterthought to security operations.

A central complication is that no single breach notification standard governs all data. The HIPAA Breach Notification Rule applies to unsecured protected health information held by covered entities, the FCC has adopted rules requiring carriers to provide notice when a consumer's personally identifiable information is breached, and all 50 states have enacted their own security breach notification laws requiring disclosure to consumers when personal information is compromised. Because thresholds, definitions of covered data, timelines, and required recipients differ across these regimes, an incident that implicates multiple categories of data can trigger several overlapping notification obligations at once.

Practitioners should also avoid conflating breach notification with security. Meeting a notification deadline demonstrates that an organization followed a disclosure process; it does not establish that the underlying system was secure or that the breach was preventable. Notification is a downstream legal obligation, and treating it as evidence of a strong security posture is a common and consequential mistake.

Who it's relevant to

Privacy and Compliance Officers
Those responsible for privacy programs must map which notification regimes apply to the data their organization holds, HIPAA, FCC rules, applicable state laws, or several at once, and maintain processes to identify reportable breaches and meet each regime's timeline and recipient requirements. Because thresholds and definitions differ and may change, they should verify obligations against the current authoritative text for each applicable law.
Healthcare Covered Entities
Organizations subject to the HIPAA Breach Notification Rule must notify affected individuals when unsecured PHI is impermissibly used or disclosed. They should distinguish the immediate reporting path for breaches affecting 500 or more individuals, reportable to the Secretary of HHS without unreasonable delay and no later than 60 days, from smaller breaches, which are still reportable to HHS but on an annual aggregated basis.
Telecommunications Carriers
Carriers subject to the FCC's data breach notification rules must provide notice when a consumer's PII is breached. Given that these rules have been updated and expanded, carriers should confirm the current effective requirements rather than rely on prior versions.
Multi-State Organizations and Their Counsel
Entities operating across jurisdictions must account for the fact that all 50 states have enacted security breach notification laws requiring disclosure to consumers when personal information is compromised, with varying requirements. A single incident can trigger multiple state obligations, so coordinated legal analysis of each applicable law is generally necessary.
Auditors and Assessors
Those evaluating an organization's compliance should verify that breach notification procedures address all applicable regimes and their distinct timelines and recipients, and should not treat the presence of a notification process as evidence that underlying systems are secure, compliance with disclosure duties is separate from security effectiveness.

Inside Breach Notification

Triggering Event and Incident Determination
Breach notification obligations generally begin with a determination that a reportable event has occurred, which typically requires distinguishing a security incident from a confirmed breach involving unauthorized access, acquisition, use, or disclosure of protected information. The applicable definition of a 'breach' varies by governing authority, so practitioners should confirm the definition under the specific regime that applies to their systems and data.
Scope of Covered Information
Notification requirements attach to specific categories of information, and the covered data set differs across regimes. For example, obligations may cover personally identifiable information (PII), protected health information (PHI) under HIPAA, or Controlled Unclassified Information (CUI) under DoD and federal contracting requirements. Practitioners should verify which data category and which authority governs a given breach, as scope boundaries between federal civilian, defense, and national security systems differ.
Notification Recipients
Depending on the governing framework, notice may be owed to affected individuals, a federal agency or oversight body, contracting officers, and in some cases the public or media. The set of required recipients is regime-specific and should be confirmed against the current authoritative text applicable to the affected system or data.
Timelines and Reporting Windows
Most breach notification regimes impose time-bound reporting obligations, but the specific windows differ by authority and may vary by the number of individuals affected or the type of system involved. Practitioners should not assume a single universal deadline and should confirm the applicable timeframe in the current governing regulation, contract clause, or agency guidance.
HIPAA Reporting Thresholds and Aggregation
Under the HIPAA Breach Notification Rule, breaches of unsecured PHI are reportable to the U.S. Department of Health and Human Services (HHS). Breaches affecting 500 or more individuals are generally subject to more immediate notification obligations, while breaches affecting fewer than 500 individuals are still reportable to HHS, typically on an annual aggregated basis rather than only when a large threshold is reached. Covered entities and business associates should confirm the current thresholds, timing, and submission mechanisms in the applicable HHS guidance.
Content of the Notification
Notifications generally must convey enough information for recipients to understand what occurred and respond appropriately, which may include a description of the event, the categories of information involved, and remedial or protective steps. The required content elements are set by the governing regime and should be confirmed against current official sources.
Documentation and Recordkeeping
Breach notification processes typically require records demonstrating the determination made, the timeline followed, and the notices issued. Such documentation supports later assessment and audit, though the specific retention and evidentiary expectations depend on the applicable authority.

Common questions

Answers to the questions practitioners most commonly ask about Breach Notification.

Does a breach affecting fewer than 500 individuals need to be reported under HIPAA?
Yes. A common misconception is that only breaches affecting 500 or more individuals must be reported to HHS. Under the HIPAA Breach Notification Rule, breaches affecting fewer than 500 individuals are still reportable to HHS, but generally on an annual aggregated basis rather than immediately, while breaches affecting 500 or more individuals generally trigger more expedited notification obligations. Individual notification obligations may apply regardless of the number affected. Confirm the current thresholds, timelines, and procedures against the applicable HHS regulations, as requirements are subject to change and agency interpretation.
Is breach notification the same thing as an incident response requirement?
No. Breach notification and incident response are related but distinct. Incident response generally refers to the internal process of detecting, containing, analyzing, and remediating a security event, whereas breach notification refers to the separate legal or contractual obligation to notify affected individuals, oversight bodies, or other parties once certain criteria are met. An organization can have a robust incident response process and still fail its notification obligations if it does not track the applicable triggers, recipients, and timelines. Notification requirements vary by governing authority and should be verified against the specific framework or regulation that applies.
How do I determine which breach notification requirements apply to my organization?
Applicability generally depends on the type of information involved, the systems affected, and the governing authority. Requirements differ across, for example, CUI handled under DoD contract clauses, protected health information under HIPAA, federal civilian systems under FISMA, and classified systems under separate national security requirements. State, local, tribal, and territorial obligations may also differ and can apply concurrently. Map the categories of data you hold to each applicable framework and confirm the current requirements against the relevant official sources, since a single incident can trigger multiple, overlapping notification regimes.
What information should a breach notification generally include?
The specific content elements vary by governing authority, but notifications commonly address the nature of the information involved, the circumstances and timing of the incident to the extent known, steps taken to mitigate harm, and points of contact for further information. Because required content, format, and timing differ across frameworks and are subject to revision, confirm the exact elements against the applicable regulation or contract clause rather than relying on a generic template.
Who typically needs to be notified after a reportable breach?
Recipients depend on the applicable framework and may include affected individuals, a governing agency or oversight body, contracting officials, and in some cases media or the public. For DoD contractors, contractual clauses may specify reporting to a designated government portal or office. For health information, individuals and HHS are common recipients. Because required recipients and channels vary and can overlap when multiple regimes apply, identify each notification path in advance and verify current requirements against the governing sources.
How should timelines for breach notification be tracked?
Notification timelines are typically measured from a defined trigger point, such as discovery or determination of a reportable breach, and the permitted window varies by governing authority. Because different frameworks may define the trigger and the clock differently, organizations generally benefit from documenting, for each applicable requirement, when the clock starts, how long the window is, and who is responsible for acting. Confirm the current timelines against the specific regulation or contract clause, as these are subject to revision and agency-specific interpretation.

Common misconceptions

Under HIPAA, only breaches affecting 500 or more individuals must be reported to HHS.
Breaches affecting fewer than 500 individuals are still reportable to HHS; they are generally reported on an annual aggregated basis rather than only when 500 or more individuals are affected. Practitioners should confirm current HHS timing and submission requirements.
A single breach notification standard and timeline applies across all systems and data types.
Notification requirements are regime-specific. Obligations, recipients, and timelines differ across HIPAA, federal civilian systems under FISMA, DoD systems, and contracting requirements involving CUI. The definition of a reportable breach and the applicable deadline must be confirmed against the authority governing the affected data or system.
Once a security incident is detected, a breach notification is automatically required.
A security incident is not necessarily a reportable breach. Most regimes require a determination that the event meets the applicable definition of a breach before notification obligations attach. Confusing an incident with a confirmed breach can lead to either over-reporting or missed obligations, so the governing definition should be applied deliberately.

Best practices

Confirm which governing authority applies to the affected data or system before acting, since HIPAA, FISMA, DoD, and CUI-related contracting requirements impose different definitions, recipients, and timelines.
Maintain a documented process for distinguishing a security incident from a confirmed reportable breach, and record the basis for each determination.
For PHI, track both the immediate obligations for breaches affecting 500 or more individuals and the annual aggregated HHS reporting obligation for breaches affecting fewer than 500 individuals.
Establish and rehearse time-bound notification procedures aligned to the specific reporting windows in the applicable regime rather than relying on a single assumed deadline.
Retain thorough records of the determination, timeline, recipients, and content of each notification to support later assessment and audit.
Verify notification content, recipients, and submission mechanisms against the current authoritative text of the applicable rule or clause, as thresholds and requirements can change across revisions.