What Counts as a Breach
No clock starts until an incident matches a statutory definition, and the definitions do not agree. One set of facts can be a reportable breach in one state, an exempt good-faith access in another, and a presumed breach under the federal health rule.

The rule in short
A breach is a defined term, not a description of how bad an incident felt. Most state statutes require unauthorized acquisition of computerized personal information; a minority require access and acquisition together, and several add a harm threshold. The federal health rule runs the other way, presuming a breach and requiring a four-factor risk assessment to rebut it. The data categories that trigger a statute are also defined, and information outside them is not covered.
A security incident becomes a notification event only when it matches a statutory definition. Every clock in this field starts from that finding, so the definition carries more weight than any deadline. The federal health rule and the state statutes draw the line differently, and an organization holding records about residents of several states will often find that one set of facts is a reportable breach in some of them and nothing at all in others.
Acquisition, access, and the gap between them
The older state statutes are built on acquisition. California requires notice when unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Acquisition suggests that data left the organization's control: copied, exfiltrated, carried out on a device. Access describes something weaker, an unauthorized person being in a position to read the data whether or not anything was taken. Statutes written only around acquisition do not reach the second situation on its own terms.
Ohio takes the narrowest path of the three. Its definition requires unauthorized access to and acquisition of computerized data, both elements, and then adds a consequence: the incident must cause, or reasonably be believed to cause, a material risk of identity theft or other fraud. The statute also excludes good-faith acquisition by an employee or agent for the organization's own purposes, so long as the information is not used unlawfully and is not disclosed further.
Maine splits the question by role. An entity that owns or licenses the information notifies when personal information has been, or is reasonably believed to have been, acquired by an unauthorized person. An entity that merely maintains information belonging to someone else notifies when misuse has occurred or when it is reasonably possible that misuse will occur. The same intrusion can therefore produce different answers depending on which side of the arrangement an organization sits, which is the point at which the duties a vendor owes the organization that hired it become a separate analysis rather than a footnote.
The categories of data that trigger a statute
Personal information is defined narrowly and enumerated. The common core is a name combined with a Social Security number, a driver's license or state identification number, or a financial account number with any code that would permit access to the account. States have added categories over time: passport and military identification numbers, medical and health insurance information, biometric data, and user names or email addresses paired with a password or a security question and answer.
Two consequences follow. Data that sits outside the enumerated categories does not trigger the statute no matter how sensitive it feels, and a single incident may cross the definition in one state while falling short in a neighboring one. Where credentials are involved, several statutes prescribe a different notice method entirely rather than a different threshold, which is treated separately in the comparison of state notification clocks.
| Regime | Trigger | Harm element | Who bears the burden |
|---|---|---|---|
| California statute | Acquisition of unencrypted personal information | None stated in the trigger | Entity decides, no statutory presumption |
| Ohio statute | Access to and acquisition of computerized data | Material risk of identity theft or other fraud | Entity, applying the statutory standard |
| Washington statute | Acquisition by an unauthorized person | Notice excused if no reasonable likelihood of risk of harm | Entity, on the excusing condition |
| Delaware statute | Personal information breached or believed breached | Notice excused if harm is unlikely after investigation | Entity, and only after an appropriate investigation |
| Federal health rule | Impermissible acquisition, access, use or disclosure | Compromise presumed unless four factors show low probability | Covered entity or business associate, expressly |
The presumption the health rule builds in
The health rule reverses the ordinary posture. An acquisition, access, use or disclosure of protected health information that the privacy rule does not permit is presumed to be a breach. The presumption falls away only if the covered entity or business associate demonstrates a low probability that the information has been compromised, and that demonstration must rest on a risk assessment covering at least four factors.
Those factors are the nature and extent of the information involved, including the identifiers present and the likelihood of re-identification; the identity of the unauthorized person who used the information or received the disclosure; whether the information was actually acquired or viewed; and the extent to which the risk has been mitigated. Three exclusions sit ahead of the presumption: unintentional good-faith acquisition by a workforce member within the scope of authority, inadvertent disclosure between two people authorized to access protected health information at the same entity, and a disclosure the entity in good faith believes the recipient could not reasonably have retained. Each exclusion carries a condition that the information go no further.
Because the rule places the burden of demonstration on the entity, an incident with no risk assessment on file is an unrebutted breach. The absence of evidence that data was viewed is not the same as evidence that it was not, and the third factor asks the second question. An entity that cannot say what an intruder reached will usually find that the factor cuts against it.
Harm thresholds and how they are worded
Several states permit an entity to conclude that no notice is owed, but they word the escape differently and the wording matters. Washington provides that notice is not required if the breach is not reasonably likely to subject consumers to a risk of harm. Delaware excuses notice where, after an appropriate investigation, the entity reasonably determines that the breach is unlikely to result in harm. Ohio builds the harm question into the definition itself rather than treating it as an exemption.
The Delaware formulation is the most demanding on process, because it conditions the conclusion on an investigation having been performed. An entity that reaches the right answer without a record of how it got there has satisfied the standard in substance and not in form. That is the practical reason for treating the analysis as a document rather than a decision, a point taken up in the record supporting a decision not to notify.
Where the analysis usually goes wrong
Three errors recur. The first is treating encryption as a complete answer without checking the statute's conditions, including whether the key or credential was also taken; that is the subject of the encryption safe harbor and what defeats it. The second is applying one state's definition across a multi-state population, which produces both over-notification and gaps. The third is confusing the moment of discovery with the moment the definition is satisfied. Discovery starts the clock; the definitional analysis has to be completed inside it, not before it begins.
A fourth error is subtler. Statutes speak of information that was acquired or is reasonably believed to have been acquired. Reasonable belief is a standard about the state of the evidence, not a license to wait for certainty. Forensic work that continues for weeks does not suspend the analysis; it informs a determination that the statutes expect to be made on the information available.
Points to carry away
- Most state statutes define a breach as unauthorized acquisition of computerized personal information that compromises its security or confidentiality.
- Ohio requires unauthorized access to and acquisition of data plus a material risk of identity theft or other fraud.
- Delaware excuses notice when an appropriate investigation shows the breach is unlikely to result in harm.
- The federal health rule presumes a breach and places the burden on the entity to show a low probability of compromise.
- That rebuttal must rest on four factors, including whether the information was actually acquired or viewed.
- Data outside a statute's defined categories of personal information does not trigger notification at all.
Questions readers ask
Does a lost laptop always mean a breach has occurred?
Not automatically. Under the state statutes, the question is whether personal information was acquired by an unauthorized person, or is reasonably believed to have been. A device that was encrypted to the standard the statute names, with the key intact, often falls outside the definition entirely. Under the federal health rule the analysis inverts: an impermissible disclosure is presumed to be a breach, and the entity must document a low probability of compromise using the four regulatory factors before it can decline to notify.
Is paper covered, or only electronic records?
The state statutes are almost uniformly written around computerized data, and paper records generally fall outside them. The federal health rule is not limited that way. It defines a breach by reference to protected health information acquired, accessed, used or disclosed in a manner the privacy rule does not permit, without regard to the medium. An organization that handles both should not assume a single answer covers the file room and the file server.
What happens when an employee views records without permission?
Several statutes carve this out. Ohio excludes good-faith acquisition by an employee or agent for the organization's purposes, provided the information is not used unlawfully or disclosed further. The federal rule has a parallel exclusion for unintentional acquisition by a workforce member acting in good faith and within the scope of authority, again on condition that nothing further happens to the data. Snooping that falls outside those conditions is not excluded, and the file should record why the carve-out does or does not apply.
Sources
- 45 CFR 164.402 — Definitions, breach notification subpartDefines breach, lists the three exclusions and sets out the four-factor risk assessment that rebuts the presumption.
- California Civil Code section 1798.82An acquisition-based trigger keyed to unencrypted personal information acquired by an unauthorized person.
- Ohio Revised Code section 1349.19Requires access and acquisition together plus a material risk of identity theft or other fraud, and excludes good-faith employee acquisition.
- RCW 19.255.010 — Washington notice of security breachesStates that notice is not required where the breach is not reasonably likely to subject consumers to a risk of harm.
- Delaware Code title 6, chapter 12BExcuses notice where an appropriate investigation shows the breach is unlikely to result in harm to the affected individuals.
- 10 M.R.S. section 1348 — Maine notification of a breachSeparates the duty of an information owner from the duty of a maintainer, whose trigger is possible misuse.
Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Breach Notification
The State Clocks and Where They Differ
State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.
Notifying a Regulator and the Threshold That Triggers It
Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.
The Sixty-Day Rule for Health Information
A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.


