Skip to content
Rapid Response

      Desks

      This library

      Breach Notification

      Documenting a Decision Not to Notify

      A conclusion that no notice is owed is only as good as the file behind it. The federal rule puts the burden of demonstration on the organization and keeps the record for six years; two states require the written determination to be sent to the regulator.

      Breach Notification7 min readFederal and stateRecords of decision

      A narrow aisle between tall pale green rolling shelving units with crank handles under fluorescent lights
      The conclusion is the short part; what has to survive is the reasoning and the date it was reached. — Mojmir Churavy, CC0, source.

      The rule in short

      Where an organization concludes that an incident is not a reportable breach, the statutes treat that conclusion as something to be proved rather than asserted. The federal health rule assigns the burden expressly and requires documentation sufficient to meet it, retained six years. New York and Florida require the written determination to be kept five years, and both require it to be sent to the regulator once the incident passes a resident count.

      Most incidents end without letters. The population turns out to be encrypted, the data falls outside the statutory categories, or the assessment concludes that harm is unlikely. Each of those outcomes is lawful, and each of them is a position the organization will have to defend if the incident later becomes visible. The statutes anticipate this by converting the conclusion into a document with a required content, a keeper and a retention period.

      The burden sits with the organization

      The federal health rule states the allocation without qualification. In the event of a use or disclosure in violation of the privacy subpart, the covered entity or business associate has the burden of demonstrating that all notifications were made as required, or that the use or disclosure did not constitute a breach as defined. Nothing in the rule requires a regulator to show that notice was owed; the entity has to show that it was not.

      That allocation is reinforced by the documentation standard the breach subpart imports. A covered entity must maintain a written or electronic record of any action, activity or designation the subpart requires to be documented, and must maintain documentation sufficient to meet its burden of proof. The retention period is six years from the date of creation or the date when the document last was in effect, whichever is later, which is considerably longer than the operational memory of most incident response teams.

      What the assessment has to work through

      Under the federal rule the content is prescribed by the definition itself. An impermissible acquisition, access, use or disclosure is presumed to be a breach unless the entity demonstrates a low probability that the information has been compromised, based on a risk assessment of at least four factors: the nature and extent of the information involved, including the types of identifiers and the likelihood of re-identification; the unauthorized person who used the information or to whom the disclosure was made; whether the information was actually acquired or viewed; and the extent to which the risk has been mitigated.

      Each factor should appear as its own finding. A document that recites the four and then states a conclusion has not demonstrated anything, because the demonstration is the reasoning under each head. The third factor is the one that most often defeats a favorable conclusion: an entity that cannot establish what an intruder reached is not in a position to say the information was not viewed, and the absence of evidence is not evidence of absence. Where the exclusions apply instead, the file should identify which one and record the condition attached to it, since every exclusion depends on the information going no further.

      The state standards are looser in wording and no looser in practice. Florida asks whether the breach has not and will not likely result in identity theft or other financial harm; New York asks whether an inadvertent disclosure will not likely result in misuse or in financial or emotional harm. Both are predictions, and a prediction recorded without its basis is an opinion. The useful form states what categories of data were involved, who held them afterwards, what could be done with them, and why that is unlikely to translate into the harm the statute names.

      RequirementFederal health ruleNew YorkFlorida
      Standard appliedLow probability of compromise on four factorsInadvertent disclosure not likely to result in misuse or harmBreach not likely to result in identity theft or financial harm
      Written record requiredDocumentation sufficient to meet the burden of proofWritten determinationWritten determination
      RetentionSix years from creation or last in effectAt least five yearsAt least five years
      Filed with a regulatorNot as such; the annual log reports breachesTo the attorney general within ten days above five hundred residentsTo the department within thirty days after the determination
      Investigation prerequisiteRisk assessment requiredReasonable determination requiredAppropriate investigation and consultation required

      The states that ask to see it

      Two statutes turn the internal record into an external filing. New York permits an entity to decline notice where the exposure was an inadvertent disclosure by persons authorized to access the information and the entity reasonably determines it will not likely result in misuse or in financial or emotional harm; the determination must be documented in writing and maintained for at least five years, and where the incident affects more than five hundred New York residents the written determination goes to the attorney general within ten days.

      Florida permits notice to be withheld where, after an appropriate investigation and consultation with relevant law enforcement agencies, the covered entity reasonably determines that the breach has not and will not likely result in identity theft or other financial harm. That determination must be documented in writing, maintained for at least five years, and provided to the department within thirty days after it is made. Delaware does not require a filing but conditions its exemption on an appropriate investigation having preceded the determination, which is the same requirement expressed as a precondition rather than a deliverable.

      The two filing provisions repay close reading because they are not symmetrical. New York's runs from the determination and is measured in days, so an entity that reaches its conclusion early and files late has missed a deadline that nothing in the consumer timetable would have flagged. Florida's is longer but attaches to an exemption that already requires consultation with law enforcement, so the file has to show who was consulted and what they said before the determination was reached. Neither statute treats the filing as optional once the resident count is crossed.

      A decision not to notify is not a decision to stay silent

      In New York and Florida the exemption from notifying individuals is paired with an obligation to tell the regulator what was decided and why. An organization that quietly concludes no notice is required, and files nothing, has complied with neither branch. The count that triggers the filing is the same resident count used elsewhere, so it has to be run even in incidents where nobody will receive a letter, as described in notifying a regulator and the threshold that triggers it.

      What belongs in the file, and when

      A usable record has six parts. The forensic findings relied on, identified by source and date of receipt. The encryption state of each affected data set and the evidence for it, which is where the reasoning described in the encryption safe harbor and its conditions is written down. The categories of information involved, tested against each applicable statutory definition rather than against a generic notion of sensitive data. The count of affected residents by state, since the counts drive both filings and thresholds. Any communication with law enforcement, including the identity of the official and the terms of any request. And the conclusion, with the reasoning under whichever standard governs.

      Where the data was held by an outside processor, the file is incomplete without what that processor supplied and when, because the organization's own timing depends on it. The reporting duties that produce those inputs are set out in what a vendor owes the organization that hired it. And because the whole exercise depends on which definition is being applied, the file should say which one, a point developed in what counts as a breach.

      Points to carry away

      • The federal health rule places on the entity the burden of demonstrating that no breach occurred or that all notices were made.
      • Documentation must be sufficient to meet that burden and is retained six years from creation or from when it last was in effect.
      • New York requires a written determination of no likely misuse, kept at least five years.
      • Florida requires a written determination of no likely identity theft or financial harm, kept at least five years.
      • Both states require the determination to go to the regulator once a resident threshold is crossed.
      • Delaware conditions its exemption on an appropriate investigation having been carried out first.

      Questions readers ask

      Who should sign the determination?

      The statutes name no signatory, so the question is evidential rather than formal. What a later reader needs is a person who can be shown to have had the authority to decide and the information to decide on. In practice that means the individual accountable for privacy or security compliance, recording that they considered specified inputs and reached a stated conclusion. A determination signed by nobody, or attributed to a committee with no record of who was present, is harder to defend than one signed by a person who can explain it.

      Does the record have to exist before the deadline passes?

      It should. The obligation being discharged is a decision made inside the statutory period, and a document produced afterwards describes the decision rather than embodying it. Where a regulator asks why no notice was sent, a contemporaneous assessment carrying its own creation record answers the question directly; a reconstruction prepared during an inquiry invites a second question about what was actually considered at the time. Nothing prevents later supplementation as more facts emerge, and supplements should be added rather than substituted.

      What should the file contain besides the conclusion?

      The inputs, so that the conclusion can be tested. That means the forensic findings relied on, the encryption state of the affected records and the evidence for it, the categories of information involved measured against each applicable statutory definition, the count of affected residents by state, any law enforcement communication, and the reasoning under whichever standard applies. Where the federal health rule governs, the four regulatory factors should each be addressed separately rather than summarized, because the rule names them individually.

      Sources

      1. 45 CFR 164.414 — Administrative requirements and burden of proofPlaces the burden of demonstrating compliance on the entity and imports the documentation duties of the privacy rule.
      2. 45 CFR 164.530 — Administrative requirementsRequires documentation sufficient to meet the burden of proof and a six-year retention period.
      3. 45 CFR 164.402 — DefinitionsSupplies the four factors the risk assessment must address to rebut the presumption of compromise.
      4. New York General Business Law section 899-aaRequires a written determination kept five years and filed with the attorney general within ten days above five hundred residents.
      5. Florida Statutes section 501.171Requires a written determination kept five years and provided to the department within thirty days.
      6. Delaware Code title 6, chapter 12BConditions the no-harm exemption on an appropriate investigation preceding the determination.

      Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Breach Notification

      Breach Notification

      The State Clocks and Where They Differ

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      7 min readState law

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law