Skip to content
Rapid Response

      Desks

      This library

      Breach Notification

      What a Vendor Owes the Organization That Hired It

      A processor that holds someone else's data reports upward rather than outward. Several states require that report immediately on discovery, one sets ten days, and the federal health rule allows sixty, which is the whole of the period the organization above it has to work with.

      Breach Notification6 min readFederal and stateVendor obligations

      A white metal flat-file cabinet with its side doors swung open, standing in a gallery of glass display cases
      The regulation sets the floor; the timing that actually works is written into the agreement. — Myotus, CC0, source.

      The rule in short

      An entity holding personal information it does not own owes notice to the owner or licensee rather than to the individuals. California, Washington and Vermont require that notice immediately following discovery. Florida sets ten days for a third-party agent. The federal health rule allows a business associate sixty calendar days from its own discovery, the same period the covered entity has, which creates a conflict the contract rather than the regulation resolves.

      Most personal information sits somewhere other than the organization that collected it. Payroll processors, claims administrators, hosting providers and analytics platforms hold copies of records they do not own, and the statutes treat them as a distinct category with a distinct duty. That duty runs upward to the owner of the data rather than outward to the people described in it, and it is the hinge on which the whole notification schedule turns.

      The duty runs to the owner, not to individuals

      California requires an entity that maintains computerized data including personal information it does not own to notify the owner or licensee of the breach immediately following discovery, where the information was or is reasonably believed to have been acquired by an unauthorized person. Washington imposes the same duty in the same terms on a person or business that maintains or possesses data it does not own or license. Vermont applies the obligation to a data collector holding personally identifiable information or login credentials it does not own or license.

      Ohio words the standard differently, requiring a custodian of stored data acting on behalf of or at the direction of another person or a governmental entity to notify that person in an expeditious manner. Delaware combines the notice with an affirmative cooperation duty: the vendor must give notice to and cooperate with the owner or licensee immediately following determination, and cooperation is defined to include sharing information relevant to the breach. That definition matters, because the failure mode in vendor incidents is rarely silence; it is a notice with nothing usable in it.

      Two features of this upward duty are easy to overlook. It is owed even where the vendor concludes that the owner will not have to notify anyone, because the vendor is not the party entitled to make that call. And it attaches to the vendor's own discovery rather than to the owner's, so the vendor's internal detection date becomes the fact on which the owner's later defense of its schedule depends. An owner that cannot establish when its processor knew cannot establish when its own obligations began.

      Sixty days at both levels, running at once

      The federal health rule takes a different approach and creates the field's sharpest timing problem. A business associate must notify the covered entity of a breach of unsecured protected health information without unreasonable delay and in no case later than sixty calendar days after discovery, with discovery defined the same way it is for a covered entity: knowledge attributed to any employee, officer or other agent other than the person who committed the breach.

      The covered entity's own sixty days, described in the sixty-day rule for health information, runs from its own discovery. If the business associate is not an agent of the covered entity, the covered entity ordinarily discovers the breach when it is told. A business associate that uses its full period therefore hands over an incident on the day the covered entity's clock begins, having already consumed two months of elapsed time, and the covered entity must then investigate, decide and write to individuals inside its own sixty days.

      RegimeWho is notifiedDeadlineCounted from
      California and WashingtonThe owner or licensee of the dataImmediately following discoveryDiscovery by the maintaining entity
      DelawareThe owner or licensee, plus cooperationImmediately following determinationDetermination by the maintaining entity
      FloridaThe covered entity that engaged the agentNo later than ten daysDetermination or reason to believe
      OhioThe person or governmental entity servedIn an expeditious mannerAccess and acquisition believed to have occurred
      Federal health ruleThe covered entityNo later than sixty calendar daysDiscovery by the business associate

      What the upward report has to carry

      The federal rule sets the fullest content requirement. The business associate must include, to the extent possible, the identification of each individual whose unsecured protected health information has been, or is reasonably believed to have been, accessed, acquired, used or disclosed during the breach. It must also provide any other information the covered entity is required to include in its notice to individuals, either at the time of the report or promptly afterwards as information becomes available.

      The state statutes say less about content and more about cooperation, but the practical requirement converges. An owner cannot run the analysis described in the definitional test for a breach without knowing which records were touched, whether they were encrypted, and whether any key or credential was taken. A vendor report that describes an intrusion without identifying the affected data set leaves the owner unable to start, and the owner's clock is running regardless.

      Delaware's cooperation duty is the most useful state formulation for that reason. By defining cooperation to include sharing information relevant to the breach, it converts a reporting obligation into a continuing one, which is closer to what an owner actually needs. Most states say nothing equivalent, and in those jurisdictions the owner's only leverage after the first report is whatever the agreement provides. That is the main reason the contractual terms below are treated as the operative rules rather than as a supplement to them.

      Two organizations, one set of facts, two records

      Both parties carry their own obligations and both may later have to justify their own timing. A vendor's internal record of when it discovered the incident is not available to the owner unless the contract makes it so, and the owner's defense of its own schedule depends on it. Agreements that require the vendor to preserve and share the incident timeline, not merely to report the incident, are the ones that hold up when a regulator asks each party the same question separately.

      Where the contract does the work

      The statutory floors are too loose to run an incident on, so the operative terms are usually contractual. Common provisions compress the vendor's report to a short fixed period measured in hours or days, define discovery to include specified detection events rather than leaving it to the vendor's judgment, require preservation of forensic material, allocate the cost of notification, and prohibit the vendor from communicating with affected individuals or with regulators without the owner's approval. Florida's statute anticipates the last point in the other direction, permitting an agent to give notice on the covered entity's behalf while leaving the obligation with the covered entity if the agent does not.

      Two further clauses earn their place. The first requires the vendor to supply, in its first report, the categories of information involved and the count of affected records by jurisdiction, because those are the inputs to the threshold work described in notice to a state regulator and its thresholds. The second requires the vendor to identify its own subcontractors holding the same data, since the chain frequently runs further down than the owner's register shows, and each link has its own statutory duty to the link above it.

      Points to carry away

      • A processor's statutory duty runs to the owner or licensee of the data, not to affected individuals.
      • California and Washington require notice to the owner immediately following discovery.
      • Florida requires a third-party agent to notify the covered entity no later than ten days after determination.
      • The federal rule allows a business associate up to sixty calendar days, the same span the covered entity has.
      • Delaware requires the vendor to give notice and to cooperate, including by sharing information relevant to the breach.
      • A business associate must identify each affected individual and supply the content the covered entity needs.

      Questions readers ask

      Why would a contract shorten a period the regulation allows?

      Because the two periods are measured from different events and run in parallel rather than in sequence. A business associate that uses its full sixty days from its own discovery hands the covered entity a breach on the day the covered entity's own sixty days begins, and the covered entity then has to investigate, decide and notify with no margin. Contracts commonly compress the vendor's obligation to a short number of days or hours precisely because the regulation permits an outcome that leaves the party bearing the public obligation with nothing.

      Does a vendor ever notify individuals directly?

      Sometimes, by arrangement. Florida allows an agent to provide the required notices on behalf of the covered entity, while making clear that failure to do so leaves the covered entity's obligation intact. The pattern elsewhere is similar: the statutory duty stays with the owner of the data, and a vendor sending letters is acting for that owner rather than discharging a duty of its own. The practical risk is a vendor writing to an organization's customers in the vendor's own voice, which the owner usually has no wish to see.

      What must a business associate actually send?

      The federal rule sets a content minimum. The notification must include, to the extent possible, the identification of each individual whose unsecured protected health information has been, or is reasonably believed to have been, accessed, acquired, used or disclosed during the breach. The business associate must also supply any other information the covered entity needs for its own notice, either at the time or promptly as it becomes available. That second obligation is continuing, which means a first report that names no individuals does not end it.

      Sources

      1. 45 CFR 164.410 — Notification by a business associateSets sixty calendar days from the associate's own discovery and requires identification of each affected individual.
      2. Florida Statutes section 501.171Requires a third-party agent to notify the covered entity no later than ten days after determination and permits agent notice.
      3. California Civil Code section 1798.82Requires an entity maintaining data it does not own to notify the owner or licensee immediately following discovery.
      4. RCW 19.255.010 — Washington notice of security breachesImposes the same immediate upward duty on a person or business that maintains data it does not own or license.
      5. Delaware Code title 6, chapter 12BRequires notice and cooperation immediately following determination, and defines cooperation as sharing relevant information.
      6. Ohio Revised Code section 1349.19Requires a custodian of stored data to notify the person or governmental entity it acts for in an expeditious manner.

      Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Breach Notification

      Breach Notification

      The State Clocks and Where They Differ

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      7 min readState law

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law