Breach Notification Requirement
A breach notification requirement is a legal obligation to tell affected people (and sometimes regulators) when their personal or health information has been exposed or compromised. Different laws set their own rules about who must be notified, what counts as a breach, and how quickly notice must be given. It is a compliance duty triggered by an incident, not a form of insurance coverage or a security control that prevents breaches.
A breach notification requirement is a statutory or regulatory duty imposed on organizations to disclose, within specified timeframes and conditions, that protected or personal information has been improperly accessed, used, or disclosed. The obligation varies by regime: under HIPAA's Breach Notification Rule, covered entities must notify affected individuals when unsecured protected health information (PHI) is impermissibly used or disclosed, and business associates must notify as soon as possible but no more than 60 days; under the FTC's Health Breach Notification Rule, affected persons must be notified without unreasonable delay and within 60 calendar days of a breach of unsecured personal health information. In addition, all 50 U.S. states have enacted security breach notification laws requiring disclosure to consumers when personal information is compromised, each with sometimes unique triggers, definitions, and timing requirements. Whether a given event triggers notification, and to whom, depends on the applicable regime and the specific facts; this entry addresses the compliance obligation itself and does not address whether resulting notification costs are covered under a cyber insurance policy, which is a separate question governed by policy wording, sublimits, and conditions.
Why it matters
Breach notification requirements convert a security incident into a set of legally enforceable disclosure duties, often on tight timelines. Because all 50 U.S. states have enacted their own security breach notification laws, and because sector-specific federal regimes such as HIPAA's Breach Notification Rule and the FTC's Health Breach Notification Rule impose parallel obligations, a single incident affecting individuals across multiple jurisdictions can trigger several overlapping requirements at once. Each regime sets its own triggers, definitions of what counts as a breach, and timing rules, so determining who must be notified, and how quickly, is a fact-specific legal analysis rather than a mechanical one.
For risk managers and compliance professionals, the requirement matters because failure to notify correctly and on time can carry regulatory consequences independent of the harm caused by the breach itself. The obligation is triggered by an incident and does not prevent one; it is a compliance duty, not a security control. An organization can have strong preventive controls and still face substantial notification obligations once a qualifying event occurs.
It is important to separate this obligation from insurance. A breach notification requirement is a legal duty, not a form of coverage. Whether the costs of complying, such as notifying affected individuals, retaining counsel, or providing credit monitoring, are reimbursable under a cyber insurance policy is a separate question governed entirely by that policy's wording, sublimits, retentions, and conditions. The existence of the legal duty does not by itself establish that any resulting expense is insured.
Who it's relevant to
Inside Breach Notification Requirement
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification Requirement.
