What is Breach Notification?
Definition
Breach notification is the legal requirement for organizations to inform regulatory authorities and affected individuals when a security incident results in unauthorized access to protected data. Notification timelines and requirements vary significantly by framework and jurisdiction.
In Depth
Breach notification requirements exist across most compliance frameworks but differ significantly in their specifics. Under GDPR, data controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms; if the risk is high, affected individuals must also be notified without undue delay. HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI, with HHS Secretary and media notification required for breaches affecting 500 or more individuals. SOC 2 does not have a prescriptive notification timeline but requires that incident response procedures include communication protocols. A robust breach notification process includes predefined templates for regulatory and individual notifications, a decision tree for assessing notification obligations across jurisdictions, legal review procedures, and communication channel selection. Organizations operating across multiple frameworks must map their notification obligations to ensure the strictest timeline is met.
Related Terms
Incident Response
Incident response is a structured approach to detecting, containing, eradicating, and recovering from security incidents. A well-defined incident response plan outlines roles, communication procedures, escalation paths, and post-incident review processes.
GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that governs how personal data of EU residents is collected, processed, stored, and transferred. It became enforceable on May 25, 2018, and applies to any organization worldwide that processes EU resident data.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law that sets standards for protecting sensitive patient health information. It applies to covered entities (healthcare providers, health plans, clearinghouses) and their business associates who handle Protected Health Information.
Encryption at Rest
Encryption at rest refers to the protection of data stored on physical or virtual storage media using cryptographic algorithms. It ensures that data remains unreadable to unauthorized parties even if the storage medium is physically compromised or improperly decommissioned.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free