Breach Notification Timelines: HIPAA, GDPR, State Laws, and More
Breach Notification Timelines: HIPAA, GDPR, State Laws, and More
On February 21, 2024, Change Healthcare detected unauthorized access. The ALPHV/BlackCat group had already exfiltrated records covering roughly one-third of Americans. What followed was not just a $2.4 billion operational catastrophe but a notification nightmare: HIPAA's 60-day clock, SEC's 4-business-day materiality filing, DFARS 72-hour requirements for defense-related data, state breach laws across all 50 states, and contractual obligations to thousands of healthcare providers -- all ticking simultaneously, each with different triggers, different recipients, and different penalties for failure.
Most organizations discover during a breach that they do not actually know which clocks are running. That gap between "we think we have 60 days" and "Colorado gave us 30 and we are already on day 22" is where regulatory penalties compound on top of breach costs.
This article maps every major notification timeline, explains what starts each clock, and provides the operational guidance to meet them all when multiple deadlines converge at once.
Why Now
Three regulatory shifts in 2023-2024 compressed notification timelines and raised the stakes for late disclosure:
- SEC Cybersecurity Rule (Dec 2023): Four business days from materiality determination. Public companies can no longer defer indefinitely while "investigating."
- Change Healthcare (Feb 2024): Individual notifications took months. HHS opened an investigation not just into the breach itself but into the notification process. The practical lesson: even HIPAA's generous 60-day window draws scrutiny when you approach the boundary.
- State law acceleration: Colorado, Florida, Maine, and Washington all moved to 30-day maximums. The trend is toward shorter deadlines, not longer ones.
The practical effect: any organization subject to multiple frameworks must operationally target the shortest applicable window, which means notification infrastructure must be pre-built, not improvised during an incident.
What Triggers a Notification Obligation
Before any clock starts, you need to understand what constitutes a reportable breach under each framework. The definitions vary more than most organizations expect.
HIPAA defines a breach as acquisition, access, use, or disclosure of unsecured PHI not permitted by the Privacy Rule. A risk assessment exception exists if you demonstrate low probability of compromise based on four factors -- but the burden of proof rests on the covered entity.
GDPR uses a broader definition: any security breach leading to unauthorized disclosure of, or access to, personal data. Report to the supervisory authority unless the breach is "unlikely to result in a risk to the rights and freedoms of natural persons."
SEC Rule requires disclosure of material cybersecurity incidents. The materiality determination is the trigger, not the incident itself -- but the SEC has warned against unreasonable delay in making this determination.
State laws generally trigger on unauthorized acquisition of personal information, though definitions and harm thresholds vary by state.
The Contrarian View: "Investigation Period" Defense
The "investigation period" defense is regulatory Russian roulette -- constructive knowledge kills you. Organizations routinely claim they did not "discover" the breach until forensics confirmed it, buying themselves weeks of additional runway. This works until it does not. Under HIPAA and most state laws, discovery occurs when the breach is known or, by exercising reasonable diligence, would have been known. If your SIEM generated an alert on day one that went uninvestigated for two weeks, regulators will backdate discovery to day one. Employee knowledge is organizational knowledge. A security analyst who notices anomalous activity and does not escalate has still triggered the organizational clock. The organizations that survive regulatory scrutiny are the ones that start their clock conservatively, not the ones that argue about when they "really" knew.
Notification Timelines by Regulation
HIPAA (Health Insurance Portability and Accountability Act)
- Notification to individuals: Without unreasonable delay, no later than 60 calendar days from the date the breach is discovered (not occurred). Discovery = first day the breach is known or would have been known with reasonable diligence.
- Notification to HHS: Breaches affecting 500+ individuals -- same 60-day window. Fewer than 500 -- annual log within 60 days of calendar year end.
- Notification to media: Breaches affecting 500+ residents of a single state -- prominent media outlets, same 60-day window.
- Business associates must notify the covered entity within 60 days of discovery.
Penalties: Tiered from $141 to $2,134,831 per violation (2024 adjusted), annual cap of $2,134,831 per identical provision. Willful neglect without 30-day correction carries the highest tier.
GDPR (General Data Protection Regulation)
The most aggressive major-regulation timeline.
- Supervisory authority: Without undue delay, where feasible within 72 hours of becoming aware. Delays past 72 hours require written justification.
- Data subjects: Without undue delay when "likely to result in a high risk to the rights and freedoms of natural persons." No specific day deadline, but "without undue delay" is interpreted strictly.
Penalties: Up to EUR 10 million or 2% of global annual turnover for failure to notify. Broader GDPR ceiling of EUR 20 million or 4% applies to underlying processing violations.
SEC Cybersecurity Disclosure Rule (Form 8-K Item 1.05)
Effective December 18, 2023 (most registrants); June 15, 2024 (smaller reporting companies).
- Form 8-K: Within 4 business days of determining an incident is material. Clock starts at materiality determination, not incident detection.
- Delayed disclosure: Attorney General may grant a 30-day delay (extendable to 60) if disclosure poses substantial risk to national security or public safety.
- Annual reporting (10-K): Must describe cybersecurity risk management processes and board oversight.
Penalties: Standard SEC enforcement for late or misleading filings -- civil penalties, disgorgement, injunctive relief.
DFARS 252.204-7012
Defense contractors handling Controlled Unclassified Information (CUI) face one of the shortest windows.
- Notification to DoD: Within 72 hours of discovery of a cyber incident affecting covered defense information or operational capability. Reports filed via DIBNet (DC3).
- Preservation: Images of affected systems and relevant monitoring/packet capture data preserved for at least 90 days.
Penalties: Contract termination, False Claims Act liability, debarment. See DFARS cyber incident reporting for implementation detail.
CCPA/CPRA (California)
- Individuals: "Most expedient time possible and without unreasonable delay." No fixed day count; 30-45 days is the practical ceiling based on enforcement history.
- California AG: Required when breach affects 500+ California residents.
Penalties: Statutory damages of $100-$750 per consumer per incident in private suits (for nonencrypted/nonredacted PI). Administrative fines of $2,500 (unintentional) or $7,500 (intentional) per violation.
PCI DSS
- Acquirer/payment brand: Immediately upon suspicion or detection. Brand rules generally expect notification within 24-72 hours at most.
- Forensic investigation: PCI Forensic Investigator engagement within 24-72 hours per brand requirements.
Penalties: Card brand fines of $5,000-$100,000/month for non-compliance, plus fraud reimbursement and card reissuance costs.
FTC Health Breach Notification Rule
Covers health data held by non-HIPAA entities (health apps, fitness trackers, DTC testing).
- FTC: Within 10 business days of discovery for breaches affecting 500+. Annual log (within 60 days of calendar year end) for fewer than 500.
- Individuals: Without unreasonable delay, no later than 60 days.
Actively enforced since 2023 (GoodRx $1.5M).
State Breach Notification Laws
All 50 states, DC, Guam, Puerto Rico, and USVI have enacted breach notification laws. Fastest explicit deadlines:
- Colorado: 30 days from determination
- Florida: 30 days from determination or reason to believe
- Maine: 30 days from knowledge or should-have-known
- Washington: 30 days from discovery
Many states use "without unreasonable delay" without specifying a maximum. A few allow 60 days (Connecticut, effective New York).
Comparison Table
| Regulation | Deadline | Clock Starts | Notify Whom | Key Nuance |
|---|---|---|---|---|
| HIPAA | 60 calendar days | Discovery (known or should-have-known) | Individuals, HHS, media (500+ in a state) | Employee knowledge = org knowledge |
| GDPR | 72 hours | Becoming aware | Supervisory authority; data subjects if high risk | Must justify delay past 72h |
| SEC (8-K) | 4 business days | Materiality determination | SEC (public filing) | Clock at materiality, not detection |
| DFARS | 72 hours | Discovery of cyber incident | DC3 (DoD) | 90-day evidence preservation |
| CCPA/CPRA | Without unreasonable delay | Discovery/knowledge | Individuals; CA AG if 500+ residents | 30-45 days practical ceiling |
| PCI DSS | Immediately / 24-72 hours | Suspicion or detection | Acquirer, payment brand | PFI within 24-72 hours |
| FTC Health | 60 days (individuals) / 10 business days (FTC, 500+) | Discovery | FTC, individuals | Non-HIPAA health data |
| State (fastest) | 30 days | Discovery / determination | Individuals, state AG | CO, FL, ME, WA |
What "Discovery" Actually Means
The single most litigated concept in breach notification law is when an organization "discovered" a breach. Every clock starts from some variant of this moment.
Constructive knowledge counts. Under HIPAA and most state laws, discovery occurs when the breach is known or, by exercising reasonable diligence, would have been known. If your SIEM generated an alert that an analyst did not review for two weeks, discovery may be backdated to the alert date.
Employee knowledge is organizational knowledge. If any employee or agent becomes aware, the organization is considered aware -- even without internal escalation.
Investigation periods are limited. Some statutes allow brief investigation before the clock starts, but this is narrowly construed. HIPAA gives no investigation period; the 60 days runs from discovery. The SEC separates discovery from materiality determination, providing investigation runway.
Practical Guidance for Multiple Simultaneous Deadlines
Build a Multi-Regulation Notification Matrix
Map every regulation applicable to your organization. Identify the shortest deadline. That becomes your operational target. If subject to both GDPR (72 hours) and HIPAA (60 days), target the 72-hour deadline -- satisfying it automatically satisfies the longer one.
Pre-Draft Notification Templates
Under a 72-hour deadline, you cannot draft from scratch. Maintain templates for each recipient type (individuals, regulators, media, payment brands) with blanks for incident-specific details.
Establish Clear Internal Escalation Paths
Employee knowledge is imputed to the organization. Every employee who might encounter breach evidence must know exactly who to contact and that delay creates legal exposure.
Document Everything Contemporaneously
Regulators evaluate whether your process was reasonable. Document the timeline from first indication through determination and notification -- this contemporaneous record is your best defense when questioned.
Engage Legal Counsel in Hour One
Breach notification triggers privilege considerations, law enforcement decisions, and multi-jurisdictional analysis. Counsel must be embedded in incident response from hour one.
Automate Deadline Tracking
Manual tracking is error-prone. GDPR's 72-hour window includes weekends and holidays. Automated tracking and regulatory mapping reduce missed-deadline risk while you manage technical response.
Test the Notification Workflow
If your team cannot complete GDPR supervisory authority notification within 72 hours during a tabletop drill, they will not manage it during an actual incident.
Common Mistakes
Waiting for certainty before starting the clock. Most regulations define discovery as reasonable belief, not confirmed certainty. Waiting for forensics to conclude before acknowledging discovery backfires under scrutiny.
Notifying individuals before the regulator. Under GDPR, the supervisory authority must be notified first. Under HIPAA, individual and HHS notifications share the same deadline, but operational best practice is HHS first or simultaneously.
Ignoring shorter state requirements. A HIPAA-covered entity breaching Colorado residents must comply with both HIPAA's 60-day and Colorado's 30-day timeline. The shorter deadline controls.
Treating "without unreasonable delay" as open-ended. Courts consistently hold that this language does not permit indefinite delay. If you have information needed to notify and choose to wait, you accumulate risk daily.
Assuming the SEC materiality determination buys unlimited time. The SEC has explicitly stated companies should not unreasonably delay materiality assessments. An "ongoing investigation" that conveniently never reaches a conclusion will draw enforcement action.
Key Takeaways
- Multiple notification clocks start simultaneously from a single breach event -- GDPR 72h, DFARS 72h, SEC 4 business days, state laws 30 days, HIPAA 60 days
- "Discovery" includes constructive knowledge: a SIEM alert not reviewed for two weeks may backdate your clock to the alert timestamp
- Employee knowledge is organizational knowledge regardless of whether internal escalation occurred
- Target your shortest applicable deadline operationally -- meeting the 72-hour GDPR requirement automatically satisfies all longer windows
- Pre-drafted notification templates and automated deadline tracking are operational necessities, not nice-to-haves
- The "investigation period" defense works until a regulator asks why your SIEM alert went uninvestigated -- then constructive knowledge kills it
- Change Healthcare's notification timeline drew separate regulatory scrutiny beyond the breach itself
Frequently Asked Questions
If we are subject to both GDPR and HIPAA, do we need to notify under both frameworks for the same breach?
Yes. Each framework has independent notification obligations with different recipients, different content requirements, and different triggers. A breach involving EU residents' health data requires GDPR supervisory authority notification (72 hours), GDPR data subject notification (if high risk), HIPAA HHS notification (60 days), and HIPAA individual notification (60 days). These are separate legal obligations -- satisfying one does not discharge the other. The operational approach is to target the shortest deadline (72 hours) and layer the other notifications onto the same response timeline.
What happens if we miss a notification deadline?
Consequences vary by framework. HIPAA penalties range from $141 to $2.1M per violation depending on culpability tier. GDPR fines up to EUR 10M or 2% of global turnover. SEC enforcement includes civil penalties and potential securities fraud charges if the delay is deemed materially misleading. State attorneys general can pursue injunctive relief and per-violation fines. Beyond direct penalties, late notification often triggers enhanced regulatory scrutiny of the underlying breach response, turning a single compliance failure into a comprehensive investigation.
Does encrypting data eliminate notification obligations?
Under HIPAA, yes -- if PHI is encrypted per NIST standards and the encryption key was not compromised, it is not "unsecured PHI" and no notification is required. Under GDPR, encryption is a mitigating factor that may eliminate the obligation to notify data subjects (but not the supervisory authority). Under most state laws, encrypted data is excluded from the definition of a breach only if the key was not also accessed. PCI DSS and DFARS have no encryption safe harbor for notification. The lesson: encryption reduces notification obligations but does not universally eliminate them, and the key must demonstrably remain uncompromised.
How do we handle notification when forensics is still ongoing and we do not know the full scope?
File the initial notification with what you know and supplement later. GDPR explicitly allows phased notification -- the initial 72-hour filing can state that the investigation is ongoing and that additional information will be provided. HIPAA allows supplemental notifications as new information becomes available. The SEC requires disclosure of what is material at the time of filing. The critical mistake is delaying the initial notification until you have complete information -- regulators penalize late notification far more harshly than incomplete-but-timely notification followed by supplements.
What is the practical difference between "discovery" and "occurrence" for notification purposes?
Occurrence is when the breach happened. Discovery is when the organization became aware (or should have become aware) of it. All notification clocks start from discovery, not occurrence. A breach that occurred in January but was not detected until April starts the HIPAA 60-day clock in April. However, a breach that occurred in January where a SIEM alert fired in January but was not reviewed until April may have its discovery backdated to January -- because the organization should have known when the alert fired. This distinction is why continuous monitoring and alert management directly affect notification compliance: uninvestigated alerts create constructive-knowledge risk.
How Advisedly Helps
Advisedly maps your organization to all applicable breach notification frameworks -- HIPAA, GDPR, SEC, DFARS, state laws, PCI DSS, and FTC Health -- and tracks notification deadlines automatically from incident discovery through completion. With 500+ compliance frameworks built in and integrated incident response workflows, you generate pre-populated notifications, track multi-jurisdictional deadlines on a single timeline, and maintain the audit trail that proves your notification process was timely and reasonable. Contact us at begin@advisedly.ai to see how multi-framework deadline tracking works.
<!-- LI hook: Change Healthcare's notification clock started ticking in February. Some notices went out in June. -->