Lesson 2 of 2 · 20 min read

Breach Notification Obligations — GDPR, HIPAA, and US State Laws

Breach notification is not optional and not a business decision — it is a legal obligation with specific timelines that begin the moment the organization becomes “aware” of the breach.


Breach Notification Decision Framework

BREACH NOTIFICATION ASSESSMENT
================================

Step 1: Was it a "breach" under the applicable law?
  GDPR: Was personal data of EU residents involved?
    → Yes: assess risk to individuals' rights
  HIPAA: Was PHI of covered entity patients involved?
    → Yes: conduct 4-factor risk assessment
  State laws: Was PII (name + SSN/DL/financial/medical/login) involved?
    → Yes: all applicable state laws triggered

Step 2: What data was involved?
  [ ] Names alone (usually not sufficient to trigger notification)
  [ ] Names + SSN → triggers all state laws + GDPR if EU residents
  [ ] Medical/health information → HIPAA triggered
  [ ] Financial account numbers → GLBA (financial sector) + state laws
  [ ] Login credentials → often explicit trigger in state laws
  [ ] EU resident data → GDPR regardless of organization location

Step 3: When did we "become aware"?
  Notification clocks start from organizational awareness, not breach date
  GDPR: 72 hours from awareness to notify supervisory authority
  HIPAA: 60 days from discovery (the clock has been running)
  State laws: vary — 30 days, 45 days, 60 days, "expedient"

Step 4: How many individuals affected?
  <500 US individuals: HIPAA annual report to HHS
  500+ in a single state: HIPAA → notify HHS + media in that state
  500+ in California: CCPA private right of action exposure
  Any EU residents: GDPR applies regardless of count

Step 5: Who must be notified?
  Regulators: GDPR supervisory authority, HHS/OCR, state AGs
  Individuals: affected data subjects
  Media: HIPAA 500+ per state; some state laws require media
  Business partners: if shared data is involved
  Cyber insurance carrier: policy typically requires prompt notification

GDPR 72-Hour Notification

GDPR SUPERVISORY AUTHORITY NOTIFICATION (WITHIN 72 HOURS)

Required information (Article 33(3)):
□ Nature of the breach: [description of what happened]
□ Categories and approximate number of data subjects: [e.g., 'approximately 5,000 EU customer accounts']
□ Categories and approximate number of personal data records: [types of data: name, email, purchase history]
□ Name and contact details of DPO: [Data Protection Officer contact]
□ Likely consequences of the breach: [risk of phishing, identity theft, financial fraud]
□ Measures taken or proposed: [containment actions, remediation steps, monitoring offered to individuals]

If investigation is incomplete at 72 hours:
→ File initial notification with available information
→ State explicitly: 'Investigation ongoing — supplements will follow'
→ GDPR permits phased notification; late notification does not — the 72-hour clock is hard

Where to notify:
→ Lead Supervisory Authority: the data protection authority in the EU member state
   where the organization has its main establishment (EU HQ) or where affected 
   individuals are located (for non-EU organizations)
→ UK ICO (separate from EU after Brexit)
→ Swiss FDPIC (if Swiss residents affected)

Notification to data subjects (Article 34):
→ Required only for HIGH risk to individuals
→ High risk = likely to result in discrimination, identity theft, financial loss,
   damage to reputation, loss of confidentiality of professional secrets
→ Content: plain language, specific steps individuals can take to protect themselves

HIPAA 4-Factor Risk Assessment

HIPAA requires a 4-factor risk assessment before concluding a breach occurred (the presumption is breach unless the 4 factors show low probability PHI was compromised):

HIPAA 4-FACTOR BREACH RISK ASSESSMENT

Factor 1: Nature and extent of PHI involved
  What types of PHI? (clinical data vs. demographic only)
  Did it include special categories? (SSNs, mental health, substance abuse)
  Amount of data and potential for re-identification?
  [Higher sensitivity = higher risk = more likely notification required]

Factor 2: Who used/accessed the PHI
  Was the person who accessed it likely to re-use or disclose it?
  Was it an unauthorized employee (low risk) vs. external actor (high risk)?
  Was the access intentional?
  [Criminal actor = high risk; misconfiguration viewed by single employee = lower risk]

Factor 3: Was the PHI actually acquired or viewed?
  Evidence of actual access (confirmed download, opened file, screenshot)?
  Or merely opportunity to access (system misconfiguration, unpatched vulnerability)?
  Forensic logs showing what was accessed vs. what was merely accessible?
  [Confirmed acquisition = likely breach; theoretical access = risk assessment required]

Factor 4: Mitigation
  Was the PHI returned and attestation received?
  Have technical safeguards reduced risk of further use/disclosure?
  [Encryption at rest that was not broken = strong mitigation; unencrypted = high risk]

If the 4-factor assessment shows LOW probability of compromise:
→ Document the assessment thoroughly — OCR may audit
→ No notification required, but maintain documentation for 6 years

If ANY factor shows HIGH probability:
→ Breach is presumed — notification required
→ Begin 60-day notification clock