Breach notification is not optional and not a business decision — it is a legal obligation with specific timelines that begin the moment the organization becomes “aware” of the breach.
Breach Notification Decision Framework
BREACH NOTIFICATION ASSESSMENT
================================
Step 1: Was it a "breach" under the applicable law?
GDPR: Was personal data of EU residents involved?
→ Yes: assess risk to individuals' rights
HIPAA: Was PHI of covered entity patients involved?
→ Yes: conduct 4-factor risk assessment
State laws: Was PII (name + SSN/DL/financial/medical/login) involved?
→ Yes: all applicable state laws triggered
Step 2: What data was involved?
[ ] Names alone (usually not sufficient to trigger notification)
[ ] Names + SSN → triggers all state laws + GDPR if EU residents
[ ] Medical/health information → HIPAA triggered
[ ] Financial account numbers → GLBA (financial sector) + state laws
[ ] Login credentials → often explicit trigger in state laws
[ ] EU resident data → GDPR regardless of organization location
Step 3: When did we "become aware"?
Notification clocks start from organizational awareness, not breach date
GDPR: 72 hours from awareness to notify supervisory authority
HIPAA: 60 days from discovery (the clock has been running)
State laws: vary — 30 days, 45 days, 60 days, "expedient"
Step 4: How many individuals affected?
<500 US individuals: HIPAA annual report to HHS
500+ in a single state: HIPAA → notify HHS + media in that state
500+ in California: CCPA private right of action exposure
Any EU residents: GDPR applies regardless of count
Step 5: Who must be notified?
Regulators: GDPR supervisory authority, HHS/OCR, state AGs
Individuals: affected data subjects
Media: HIPAA 500+ per state; some state laws require media
Business partners: if shared data is involved
Cyber insurance carrier: policy typically requires prompt notification
GDPR 72-Hour Notification
GDPR SUPERVISORY AUTHORITY NOTIFICATION (WITHIN 72 HOURS)
Required information (Article 33(3)):
□ Nature of the breach: [description of what happened]
□ Categories and approximate number of data subjects: [e.g., 'approximately 5,000 EU customer accounts']
□ Categories and approximate number of personal data records: [types of data: name, email, purchase history]
□ Name and contact details of DPO: [Data Protection Officer contact]
□ Likely consequences of the breach: [risk of phishing, identity theft, financial fraud]
□ Measures taken or proposed: [containment actions, remediation steps, monitoring offered to individuals]
If investigation is incomplete at 72 hours:
→ File initial notification with available information
→ State explicitly: 'Investigation ongoing — supplements will follow'
→ GDPR permits phased notification; late notification does not — the 72-hour clock is hard
Where to notify:
→ Lead Supervisory Authority: the data protection authority in the EU member state
where the organization has its main establishment (EU HQ) or where affected
individuals are located (for non-EU organizations)
→ UK ICO (separate from EU after Brexit)
→ Swiss FDPIC (if Swiss residents affected)
Notification to data subjects (Article 34):
→ Required only for HIGH risk to individuals
→ High risk = likely to result in discrimination, identity theft, financial loss,
damage to reputation, loss of confidentiality of professional secrets
→ Content: plain language, specific steps individuals can take to protect themselves
HIPAA 4-Factor Risk Assessment
HIPAA requires a 4-factor risk assessment before concluding a breach occurred (the presumption is breach unless the 4 factors show low probability PHI was compromised):
HIPAA 4-FACTOR BREACH RISK ASSESSMENT
Factor 1: Nature and extent of PHI involved
What types of PHI? (clinical data vs. demographic only)
Did it include special categories? (SSNs, mental health, substance abuse)
Amount of data and potential for re-identification?
[Higher sensitivity = higher risk = more likely notification required]
Factor 2: Who used/accessed the PHI
Was the person who accessed it likely to re-use or disclose it?
Was it an unauthorized employee (low risk) vs. external actor (high risk)?
Was the access intentional?
[Criminal actor = high risk; misconfiguration viewed by single employee = lower risk]
Factor 3: Was the PHI actually acquired or viewed?
Evidence of actual access (confirmed download, opened file, screenshot)?
Or merely opportunity to access (system misconfiguration, unpatched vulnerability)?
Forensic logs showing what was accessed vs. what was merely accessible?
[Confirmed acquisition = likely breach; theoretical access = risk assessment required]
Factor 4: Mitigation
Was the PHI returned and attestation received?
Have technical safeguards reduced risk of further use/disclosure?
[Encryption at rest that was not broken = strong mitigation; unencrypted = high risk]
If the 4-factor assessment shows LOW probability of compromise:
→ Document the assessment thoroughly — OCR may audit
→ No notification required, but maintain documentation for 6 years
If ANY factor shows HIGH probability:
→ Breach is presumed — notification required
→ Begin 60-day notification clock