Frequently Asked Questions

What is required by data breach notification laws in the United States?

The HIPAA Breach Notification Rule, 45 CFR §§ 164.400-414, requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.

What are the requirements for breach notification?

When determining your obligations to comply with a particular data breach notification law, a key requirement is to determine whether the information involved qualifies as personal information, personal data, or other protected form of data or information under the relevant state’s data breach reporting law. What is a Reportable Breach?

What is the penalty for not complying with the Breach Notification Rule?

The remedies available for failure to comply with data breach notification laws include injunctions to prevent further violations, monetary penalties, and reasonable costs.

What is the purpose of the Data Security and Breach Notification Act?

Each state’s data breach notification law functions to protect the residents of their respective states. Under each state’s data breach notification laws, a resident of a state must receive notice of the breach according to the law of that particular state.

