When Advantest disclosed a data breach months after its February ransomware attack, it highlighted a common challenge for legal teams: managing multi-jurisdiction compliance under tight timelines. You know you need to notify affected individuals, but the mechanics can paralyze even experienced counsel.
This checklist provides a practical guide to managing breach notification obligations across U.S. state laws. It's tailored for claims and coverage counsel who need to coordinate notifications quickly while meeting varying statutory requirements.
Purpose of the Checklist
This checklist helps you track and execute breach notification requirements when personal information has been compromised. It covers core decision points and documentation requirements for U.S. state breach notification laws, focusing on common trigger provisions and timing rules.
You'll use this when:
- You've confirmed unauthorized access to nonpublic information.
- The compromised data includes elements that trigger notification under one or more state laws.
- You need to coordinate notifications to individuals, state attorneys general, and potentially consumer reporting agencies.
The Advantest case shows the importance of timely notification. The company disclosed its ransomware attack in February but delayed individual notifications for months. This created uncertainty about when the "discovery" clock started and whether notification timing met statutory requirements in states like California, Massachusetts, and Vermont.
Prerequisites
Before using this checklist, ensure you have:
Confirmed data elements: A forensic report or investigation summary identifying what categories of personal information were accessed or acquired. Vague statements won't satisfy most state laws.
Affected jurisdiction list: States of residence for impacted individuals. Determine which state laws apply. If addresses are unknown, assume California, New York, and Texas as a baseline due to their strict requirements.
Discovery date documentation: A written record of when you first learned of unauthorized data acquisition. This starts your notification clock in most states.
Legal review authority: Confirmation of who can approve notification language and timing. Some state laws allow brief delays for law enforcement coordination, but you need documented approval.
Notification vendor or system: A method to send written notices (mail or email, depending on state requirements). If notifying more than 500 California residents, file with the California Attorney General.
The Checklist Template
Copy this into your matter management system and customize the bracketed sections:
BREACH NOTIFICATION COMPLIANCE CHECKLIST
Matter: [Incident name/number]
Discovery Date: [Date organization learned of unauthorized acquisition]
Data Elements Compromised: [SSN / Driver's license / Medical info / Financial account / Other - be specific]
Estimated Affected Individuals: [Number]
Lead Counsel: [Name]
Phase 1: Trigger Analysis (Complete within 48 hours of discovery)
- Confirm data elements meet statutory definition of "personal information" under applicable state laws.
- Document whether encryption/redaction was in place (affects notification requirement in many states).
- Identify states with affected residents (prioritize CA, NY, TX, MA, FL if counts unknown).
- Determine if breach affects >500 residents in any single state (triggers attorney general filing).
- Check if breach affects >1,000 individuals nationally (triggers consumer reporting agency notification).
- Review cyber insurance policy for Breach Notification Requirement coverage and insurer consent requirements.
Phase 2: Timing Determination (Complete within 72 hours of discovery)
- Document strictest applicable timeline (California: without unreasonable delay; New York: without unreasonable delay; Massachusetts: as soon as practicable but not later than [date]).
- Assess whether law enforcement delay is warranted (requires written request from agency).
- Set internal notification deadline: [Date - typically 30-45 days from discovery for most states].
- Calendar attorney general filing deadlines for states requiring advance or concurrent notice.
- Confirm substitute notice eligibility if mailing costs exceed $[amount] or addresses unavailable.
Phase 3: Content Preparation (Complete 10 days before notification deadline)
- Draft notice including required elements:
- Description of incident (date, nature of breach).
- Types of personal information involved.
- Steps organization has taken to protect information.
- Contact information for questions.
- Steps individuals can take to protect themselves.
- Whether notification is required by law (some states require this statement).
- Include state-specific additions:
- California: Reference to Cal. Civ. Code § 1798.82 if applicable.
- Massachusetts: Statement of individual's right to obtain police report.
- New York: Contact information for consumer reporting agencies if SSN involved.
- Translate notice if required by state law (California requires Spanish translation for certain counties).
- Prepare attorney general cover letter and sample notice copy.
Phase 4: Distribution (Execute by notification deadline)
- Send individual notices via [first-class mail / email if prior consent exists].
- File with California Attorney General if >500 CA residents affected (submit via [DATA BREACH REPORT portal]).
- File with other state attorneys general as required (check [state] requirements).
- Notify consumer reporting agencies if >1,000 individuals affected nationally.
- Post substitute notice on website homepage if using substitute notice method.
- Issue media release if substitute notice requires it (typically >500,000 affected or costs exceed $250,000).
- Document all transmission confirmations and filing receipts.
Phase 5: Post-Notification (Ongoing)
- Establish call center or response mechanism for individual inquiries.
- Monitor for regulatory inquiries from attorneys general.
- Track credit monitoring enrollment if offered.
- Update incident response documentation with lessons learned.
- Preserve all notification records for [6 years minimum, per state record retention laws].
- Submit notification documentation to cyber insurer for coverage claim if applicable.
Notes/Special Circumstances:
[Document any deviations from standard process, law enforcement coordination, or unique state requirements]
Customizing the Checklist
Adjust timing based on your state mix: If dealing only with California residents, your timeline is "without unreasonable delay" (courts interpret this as 30-60 days depending on complexity). If Massachusetts residents are involved, aim for "as soon as practicable," but some courts expect faster action. Document any delay beyond 30 days.
Modify data elements for your scenario: The template lists common triggers (SSN, driver's license, medical info, financial account numbers). If your breach involves biometric data, expand the trigger analysis section to address Illinois BIPA requirements. If it's health information, add HIPAA Breach Notification Rule steps.
Scale the vendor requirements: If notifying fewer than 100 people, you can often handle distribution in-house. For over 1,000 individuals, you'll want a specialized notification vendor. For over 10,000, you need a vendor with substitute notice experience.
Add insurance coordination steps: If you have Breach Notification Requirement coverage in your cyber policy, add a step in Phase 1 to notify your insurer and confirm whether they'll appoint vendors directly or reimburse your costs. Some policies require insurer consent before engaging a notification vendor.
Validation Steps
Before executing notifications:
Cross-check state counts: Verify your affected resident counts against attorney general filing thresholds. California requires filing if notifying more than 500 California residents. Missing this creates a separate compliance violation.
Test one notice: Send a draft notice to your legal team and one non-legal colleague. If they can't explain what happened and what they should do after reading it once, revise. Breach notices often fail because they're written for lawyers, not individuals.
Confirm discovery date documentation: Pull the email, investigation report, or meeting notes that establish when you first knew personal information was acquired. If challenged on timing, this is your evidence that the clock started when you say it did.
Review insurance consent requirements: Check your cyber policy's Insurer Consent Requirement provision. Some policies void coverage if you send notifications without advance insurer approval. Get written confirmation before mailing.
Validate translation requirements: If you have affected residents in California counties with significant non-English-speaking populations, confirm whether you need Spanish-language notices. Los Angeles County typically requires translation; rural counties may not.
The Advantest disclosure illustrates the reputational cost of delayed notification. The company stated it had "no information suggesting that your PII has been disclosed publicly or otherwise misused," but months of silence between the February attack and the eventual notification likely undermined that reassurance. Your checklist execution speed directly affects whether stakeholders view your response as transparent or evasive.
When facing a forensic report confirming unauthorized access, this checklist won't solve the problem, but it will help you meet your legal obligations without missing a filing deadline or triggering a separate violation for inadequate notice.




