Breach Notification
Breach notification refers to the legal obligation for an organization to inform affected individuals, and often government regulators, when personal or sensitive information has been compromised. These requirements are intended to ensure that people whose information may have been exposed are told promptly so they can take protective steps. The specific rules vary depending on which law applies and what type of information was involved.
Breach notification is a set of statutory and regulatory obligations requiring an entity to disclose the unauthorized acquisition, access, use, or disclosure of protected data to affected individuals and, where applicable, to regulators and other parties. The governing authority and specific triggers vary by regime: under the HIPAA Breach Notification Rule, covered entities must notify affected individuals when their unsecured protected health information (PHI) is impermissibly used or disclosed, with breaches affecting 500 or more individuals reported to the Secretary of HHS without unreasonable delay and in no case later than 60 days, while breaches affecting fewer than 500 individuals are still reportable to HHS on an annual aggregated basis rather than only when 500 or more are affected. Separate frameworks impose their own requirements, including FCC data breach notification rules applicable to carriers when a consumer's PII is breached, and security breach notification laws enacted in all 50 states requiring disclosure to consumers when personal information is compromised. Because thresholds, definitions of covered data, notification timelines, and recipient requirements differ across these regimes and may be updated, practitioners should confirm the applicable law and its current authoritative text; this entry does not address defense-specific incident reporting obligations (such as those under DoD contractual clauses), which follow distinct requirements.
Why it matters
Breach notification obligations translate the abstract goal of protecting personal information into concrete, time-bound duties that carry legal and reputational consequences when ignored. When personal or sensitive data is compromised, affected individuals cannot take protective steps, such as monitoring accounts or changing credentials, unless they are told promptly. For organizations, failing to notify on time or to the correct recipients can expose them to regulatory enforcement, civil liability, and loss of public trust, which is why compliance officers treat these requirements as a distinct discipline rather than an afterthought to security operations.
A central complication is that no single breach notification standard governs all data. The HIPAA Breach Notification Rule applies to unsecured protected health information held by covered entities, the FCC has adopted rules requiring carriers to provide notice when a consumer's personally identifiable information is breached, and all 50 states have enacted their own security breach notification laws requiring disclosure to consumers when personal information is compromised. Because thresholds, definitions of covered data, timelines, and required recipients differ across these regimes, an incident that implicates multiple categories of data can trigger several overlapping notification obligations at once.
Practitioners should also avoid conflating breach notification with security. Meeting a notification deadline demonstrates that an organization followed a disclosure process; it does not establish that the underlying system was secure or that the breach was preventable. Notification is a downstream legal obligation, and treating it as evidence of a strong security posture is a common and consequential mistake.
Who it's relevant to
Inside Breach Notification
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification.