Skip to content
Rapid Response

      Desks

      This library

      Breach Notification

      What Counts as a Breach

      No clock starts until an incident matches a statutory definition, and the definitions do not agree. One set of facts can be a reportable breach in one state, an exempt good-faith access in another, and a presumed breach under the federal health rule.

      Breach Notification6 min readState lawWhat counts as a breach

      A close, straight-on view of dense storage drive bays in a dark room, edged by a bright green column of indicator lights
      The question is rarely what the machines recorded, but which statutory definition the recorded facts match. — NOIRLab/NSF/AURA/T. Slovinský, CC BY 4.0, source.

      The rule in short

      A breach is a defined term, not a description of how bad an incident felt. Most state statutes require unauthorized acquisition of computerized personal information; a minority require access and acquisition together, and several add a harm threshold. The federal health rule runs the other way, presuming a breach and requiring a four-factor risk assessment to rebut it. The data categories that trigger a statute are also defined, and information outside them is not covered.

      A security incident becomes a notification event only when it matches a statutory definition. Every clock in this field starts from that finding, so the definition carries more weight than any deadline. The federal health rule and the state statutes draw the line differently, and an organization holding records about residents of several states will often find that one set of facts is a reportable breach in some of them and nothing at all in others.

      Acquisition, access, and the gap between them

      The older state statutes are built on acquisition. California requires notice when unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Acquisition suggests that data left the organization's control: copied, exfiltrated, carried out on a device. Access describes something weaker, an unauthorized person being in a position to read the data whether or not anything was taken. Statutes written only around acquisition do not reach the second situation on its own terms.

      Ohio takes the narrowest path of the three. Its definition requires unauthorized access to and acquisition of computerized data, both elements, and then adds a consequence: the incident must cause, or reasonably be believed to cause, a material risk of identity theft or other fraud. The statute also excludes good-faith acquisition by an employee or agent for the organization's own purposes, so long as the information is not used unlawfully and is not disclosed further.

      Maine splits the question by role. An entity that owns or licenses the information notifies when personal information has been, or is reasonably believed to have been, acquired by an unauthorized person. An entity that merely maintains information belonging to someone else notifies when misuse has occurred or when it is reasonably possible that misuse will occur. The same intrusion can therefore produce different answers depending on which side of the arrangement an organization sits, which is the point at which the duties a vendor owes the organization that hired it become a separate analysis rather than a footnote.

      The categories of data that trigger a statute

      Personal information is defined narrowly and enumerated. The common core is a name combined with a Social Security number, a driver's license or state identification number, or a financial account number with any code that would permit access to the account. States have added categories over time: passport and military identification numbers, medical and health insurance information, biometric data, and user names or email addresses paired with a password or a security question and answer.

      Two consequences follow. Data that sits outside the enumerated categories does not trigger the statute no matter how sensitive it feels, and a single incident may cross the definition in one state while falling short in a neighboring one. Where credentials are involved, several statutes prescribe a different notice method entirely rather than a different threshold, which is treated separately in the comparison of state notification clocks.

      RegimeTriggerHarm elementWho bears the burden
      California statuteAcquisition of unencrypted personal informationNone stated in the triggerEntity decides, no statutory presumption
      Ohio statuteAccess to and acquisition of computerized dataMaterial risk of identity theft or other fraudEntity, applying the statutory standard
      Washington statuteAcquisition by an unauthorized personNotice excused if no reasonable likelihood of risk of harmEntity, on the excusing condition
      Delaware statutePersonal information breached or believed breachedNotice excused if harm is unlikely after investigationEntity, and only after an appropriate investigation
      Federal health ruleImpermissible acquisition, access, use or disclosureCompromise presumed unless four factors show low probabilityCovered entity or business associate, expressly

      The presumption the health rule builds in

      The health rule reverses the ordinary posture. An acquisition, access, use or disclosure of protected health information that the privacy rule does not permit is presumed to be a breach. The presumption falls away only if the covered entity or business associate demonstrates a low probability that the information has been compromised, and that demonstration must rest on a risk assessment covering at least four factors.

      Those factors are the nature and extent of the information involved, including the identifiers present and the likelihood of re-identification; the identity of the unauthorized person who used the information or received the disclosure; whether the information was actually acquired or viewed; and the extent to which the risk has been mitigated. Three exclusions sit ahead of the presumption: unintentional good-faith acquisition by a workforce member within the scope of authority, inadvertent disclosure between two people authorized to access protected health information at the same entity, and a disclosure the entity in good faith believes the recipient could not reasonably have retained. Each exclusion carries a condition that the information go no further.

      The presumption is not a formality

      Because the rule places the burden of demonstration on the entity, an incident with no risk assessment on file is an unrebutted breach. The absence of evidence that data was viewed is not the same as evidence that it was not, and the third factor asks the second question. An entity that cannot say what an intruder reached will usually find that the factor cuts against it.

      Harm thresholds and how they are worded

      Several states permit an entity to conclude that no notice is owed, but they word the escape differently and the wording matters. Washington provides that notice is not required if the breach is not reasonably likely to subject consumers to a risk of harm. Delaware excuses notice where, after an appropriate investigation, the entity reasonably determines that the breach is unlikely to result in harm. Ohio builds the harm question into the definition itself rather than treating it as an exemption.

      The Delaware formulation is the most demanding on process, because it conditions the conclusion on an investigation having been performed. An entity that reaches the right answer without a record of how it got there has satisfied the standard in substance and not in form. That is the practical reason for treating the analysis as a document rather than a decision, a point taken up in the record supporting a decision not to notify.

      Where the analysis usually goes wrong

      Three errors recur. The first is treating encryption as a complete answer without checking the statute's conditions, including whether the key or credential was also taken; that is the subject of the encryption safe harbor and what defeats it. The second is applying one state's definition across a multi-state population, which produces both over-notification and gaps. The third is confusing the moment of discovery with the moment the definition is satisfied. Discovery starts the clock; the definitional analysis has to be completed inside it, not before it begins.

      A fourth error is subtler. Statutes speak of information that was acquired or is reasonably believed to have been acquired. Reasonable belief is a standard about the state of the evidence, not a license to wait for certainty. Forensic work that continues for weeks does not suspend the analysis; it informs a determination that the statutes expect to be made on the information available.

      Points to carry away

      • Most state statutes define a breach as unauthorized acquisition of computerized personal information that compromises its security or confidentiality.
      • Ohio requires unauthorized access to and acquisition of data plus a material risk of identity theft or other fraud.
      • Delaware excuses notice when an appropriate investigation shows the breach is unlikely to result in harm.
      • The federal health rule presumes a breach and places the burden on the entity to show a low probability of compromise.
      • That rebuttal must rest on four factors, including whether the information was actually acquired or viewed.
      • Data outside a statute's defined categories of personal information does not trigger notification at all.

      Questions readers ask

      Does a lost laptop always mean a breach has occurred?

      Not automatically. Under the state statutes, the question is whether personal information was acquired by an unauthorized person, or is reasonably believed to have been. A device that was encrypted to the standard the statute names, with the key intact, often falls outside the definition entirely. Under the federal health rule the analysis inverts: an impermissible disclosure is presumed to be a breach, and the entity must document a low probability of compromise using the four regulatory factors before it can decline to notify.

      Is paper covered, or only electronic records?

      The state statutes are almost uniformly written around computerized data, and paper records generally fall outside them. The federal health rule is not limited that way. It defines a breach by reference to protected health information acquired, accessed, used or disclosed in a manner the privacy rule does not permit, without regard to the medium. An organization that handles both should not assume a single answer covers the file room and the file server.

      What happens when an employee views records without permission?

      Several statutes carve this out. Ohio excludes good-faith acquisition by an employee or agent for the organization's purposes, provided the information is not used unlawfully or disclosed further. The federal rule has a parallel exclusion for unintentional acquisition by a workforce member acting in good faith and within the scope of authority, again on condition that nothing further happens to the data. Snooping that falls outside those conditions is not excluded, and the file should record why the carve-out does or does not apply.

      Sources

      1. 45 CFR 164.402 — Definitions, breach notification subpartDefines breach, lists the three exclusions and sets out the four-factor risk assessment that rebuts the presumption.
      2. California Civil Code section 1798.82An acquisition-based trigger keyed to unencrypted personal information acquired by an unauthorized person.
      3. Ohio Revised Code section 1349.19Requires access and acquisition together plus a material risk of identity theft or other fraud, and excludes good-faith employee acquisition.
      4. RCW 19.255.010 — Washington notice of security breachesStates that notice is not required where the breach is not reasonably likely to subject consumers to a risk of harm.
      5. Delaware Code title 6, chapter 12BExcuses notice where an appropriate investigation shows the breach is unlikely to result in harm to the affected individuals.
      6. 10 M.R.S. section 1348 — Maine notification of a breachSeparates the duty of an information owner from the duty of a maintainer, whose trigger is possible misuse.

      Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Breach Notification

      Breach Notification

      The State Clocks and Where They Differ

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      7 min readState law

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law