Research · 12 min read
What a Breach Notice Has to Tell You, and How Soon
Two federal rules answer the same question and take their timing, method and content from one statute. They still differ, and one of the differences is whether the letter has to name whoever ended up with your information.
Key takeaways
- Both federal breach rules require notice without unreasonable delay and in no case later than sixty calendar days after discovery, so the number is a ceiling rather than a schedule.
- The statute behind the consumer-facing rule borrows the discovery, timeliness, methods and content subsections from the health privacy statute, which is why the two letters look alike.
- Discovery is imputed: the clock starts when any workforce member or agent other than the person responsible knew, or by reasonable diligence would have known.
- The health privacy rule fixes five content elements to the extent possible, and separately requires the notice to be written in plain language.
- The consumer-facing rule asks for the name or identity of any third parties that acquired the information, where known, which the other rule does not.
- Delivery defaults differ: paper unless you agreed to electronic notice under one rule, email where you specified it as your primary channel under the other.
- Where contact details are stale for ten or more people, substitute notice can be a ninety-day website posting or major media notice, with a toll-free line active for at least ninety days.
Answer first: sixty days is a ceiling, not a schedule
Both federal breach rules use the same sentence about timing. Notice goes out without unreasonable delay, and in no case later than sixty calendar days after discovery.
The first half is the operative half. Sixty days is the outer limit, not the target, and an entity that sat on a notice for fifty-nine days has not automatically complied.
Both rules also fix the contents of the letter. One of them requires something the other does not, and that difference is the most useful thing on this page.
Two rules, one statute underneath
The health privacy rule and the consumer-facing rule look like separate systems, and in scope they are. Their notice machinery is not separate.
The statute creating the second one says so directly. It provides that subsections (c), (d), (e) and (f) of the first statute apply to a notification required under it, in a manner specified by the Federal Trade Commission.
Those four subsections are discovery, timeliness, methods of notice and content of notice. So the clock, the delivery and the contents of both letters trace back to one text.
The Commission then wrote its own regulation, and it did not copy that text word for word. The places it departs are where the two letters actually differ.
The clock, and the day it starts
Discovery is defined, and the definition is what makes the deadline hard to game.
Under the health privacy rule a breach is treated as discovered as of the first day on which it is known to the covered entity, or by exercising reasonable diligence would have been known.
The next sentence closes the obvious gap. The entity is deemed to have knowledge if the breach is known, or by reasonable diligence would have been known, to any person other than the one committing it. That person has to be a workforce member or agent, determined in accordance with the federal common law of agency.
So the clock does not start when a decision-maker is briefed. It starts when a person the organization is responsible for knew, or should have.
Both rules carry an exception for law enforcement, and the health privacy rule states it as a cross-reference right inside the timing sentence.
What the health privacy rule's notice has to contain
The rule lists five elements and prefaces them with a qualifier: the notification must include them to the extent possible.
A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known.
A description of the types of unsecured protected health information involved. The regulation gives its own examples, among them full name, social security number, date of birth, home address, account number, diagnosis and disability code.
Any steps individuals should take to protect themselves from potential harm resulting from the breach.
A brief description of what the covered entity is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches.
And contact procedures for individuals to ask questions or learn additional information, which must include a toll-free telephone number, an email address, a website, or a postal address.
A separate paragraph adds one more requirement that is easy to overlook and easy to check. The notification must be written in plain language.
What the consumer rule adds, and one addition is a name
The Commission's rule lists the same ground and then goes further in four places.
Its first item asks for the description of what happened and the two dates, and then for something more. It asks for the full name or identity of any third parties that acquired the information as a result of the breach, if that is known to the entity.
The clause has its own escape valve, and it is narrow. Where providing the full name or identity would pose a risk to individuals or to the entity giving notice, a description may be given instead.
Its list of information types is written for software rather than for a clinic. It names health diagnosis or condition, lab results, medications, other treatment information, an individual's use of a health-related mobile application, and a device identifier in combination with another data element.
Its mitigation item names an example the other rule does not: what the entity is doing to protect affected individuals, such as offering credit monitoring or other services.
And its contact item is a count rather than a list. The contact procedures must include two or more of the following: a toll-free telephone number, an email address, a website, within-application contact, or a postal address.
Like the other rule, it requires the whole notice to be in plain language, and it applies that requirement regardless of the method by which notice is given.
How the notice is supposed to reach you
The default under the health privacy rule is paper. Written notification goes by first-class mail to the last known address, or by electronic mail if the individual agrees to electronic notice and that agreement has not been withdrawn.
The consumer rule inverts the condition. Written notice may be sent by email if the individual has specified email as the primary method of communication, and any written notice sent that way must be clear and conspicuous. Where email is not available or has not been specified, first-class mail is the route.
Both allow a notice to be provided in one or more mailings as information becomes available, which is worth knowing if a first letter seems thin.
Both also handle the case where the person has died, and they handle it differently. The health privacy rule directs written notice to a next of kin or personal representative where the entity knows of the death and has the address.
The consumer rule conditions the same step on something the individual did earlier. Notice goes to next of kin if the individual had provided contact information for them, along with authorization to contact them.
And both permit an extra channel where speed matters. Where the entity deems a case urgent because of possible imminent misuse, it may also provide information by telephone or other means.
What happens when a company cannot reach you
Contact details go stale, and both rules plan for it with a mechanism called substitute notice.
The health privacy rule splits it in two. Where contact information is insufficient or out of date for fewer than ten individuals, substitute notice may be an alternative form of written notice, a telephone call, or other means.
Where it is insufficient or out of date for ten or more, the form is fixed. Either a conspicuous posting for ninety days on the home page of the entity's website, or conspicuous notice in major print or broadcast media in the geographic areas where affected individuals likely reside.
That posting or media notice has to carry a toll-free number that remains active for at least ninety days, where a person can learn whether their information may be included in the breach.
The consumer rule reaches the same place with one threshold rather than two. After reasonable efforts to contact everyone, the same trigger applies where contact information for ten or more individuals is insufficient or out of date. Substitute notice is then required in one of the same two forms, with the same ninety-day toll-free number.
There is a practical consequence in that machinery. A notice you never received may still have been given, on a web page for ninety days, and the toll-free line is the part designed to answer the question afterwards.
What clear and conspicuous is required to look like
The consumer rule does not leave that phrase to the reader's imagination. It defines it, and the definition is unusually concrete for a regulation.
A notice is clear and conspicuous if it is reasonably understandable and designed to call attention to the nature and significance of the information in it.
Reasonably understandable is then broken into six instructions. Clear, concise sentences, paragraphs and sections. Short explanatory sentences or bullet lists wherever possible. Definite, concrete, everyday words and active voice wherever possible. No multiple negatives. No legal or highly technical business terminology wherever possible. And no explanations that are imprecise and readily subject to different interpretations.
Designed to call attention is five more. A plain-language heading. A typeface and type size that are easy to read. Wide margins and ample line spacing. Boldface or italics for key words. And, in a form that combines the notice with other information, distinctive type size, style and graphic devices such as shading or sidebars.
There is a paragraph for screens too. A notice on a web page or in an app must use text or visual cues that encourage scrolling where scrolling is needed, and other elements must not distract from it.
It must also sit somewhere people go. The rule asks for placement on a screen consumers frequently access, such as a page where transactions are conducted. A link on such a screen also works, where it connects directly to the notice and is labeled to convey its importance.
Which rule is speaking, and the definitions that decide it
None of this tells you which letter you would get, and that is the question with the largest consequences.
The health privacy rule's duty is written to a covered entity, in the first words of the section. The categories that phrase covers are set out elsewhere and are a subject of their own.
The consumer rule turns on two definitions. A personal health record means an electronic record of PHR identifiable health information on an individual. It has to have the technical capacity to draw information from multiple sources, and to be managed, shared and controlled by or primarily for the individual.
Read that definition to its end. Multiple sources, and controlled by or primarily for the individual, are both part of the test rather than description around it.
PHR identifiable health information carries a further element that summaries drop. Alongside relating to health and identifying the individual, the information must be created or received by a covered health care provider, a health plan, an employer, or a health care clearinghouse.
Whether a given service holds a record answering those definitions is a legal question about that business, and nothing here answers it. What the definitions do is show that the answer is not obvious from a website.
What this does not decide
It does not say which rule reaches any particular company, or that either one does. That is a legal conclusion about a specific business and depends on facts a homepage does not show.
It does not say that any company has sent, or failed to send, a notice. No such claim is made and none is implied.
It does not describe state notification statutes, which exist, vary and are not quoted here.
And it is not legal advice. It reports what one federal section, three sections of a federal rule and two statutes say.
Sources
- 45 CFR 164.404, "Notification to individuals"Paragraph (a)(2), treating a breach as discovered on the first day it is known to the covered entity or by exercising reasonable diligence would have been known, and deeming the entity to have knowledge where the breach is known or would have been known to any person other than the one committing it who is a workforce member or agent, determined in accordance with the federal common law of agency. Paragraph (b), requiring notification without unreasonable delay and in no case later than 60 calendar days after discovery, except as provided in the law enforcement delay section. Paragraph (c)(1), the five content elements required to the extent possible, including the two dates, the types of information with its own examples, steps individuals should take, what the entity is doing to investigate, mitigate and protect, and contact procedures including a toll-free telephone number, an email address, website or postal address. Paragraph (c)(2), the plain language requirement. Paragraph (d)(1), written notification by first-class mail or by electronic mail where the individual agrees and has not withdrawn the agreement, and the provision for a deceased individual's next of kin or personal representative. Paragraph (d)(2), substitute notice, with the fewer-than-ten and ten-or-more tiers, the ninety-day home page posting or major print or broadcast media alternative, and the toll-free number active for at least ninety days. Paragraph (d)(3), additional notice by telephone or other means in urgent situations.
- 16 CFR 318.2, "Definitions"The definition of clear and conspicuous, including the six reasonably-understandable instructions, the five call-attention instructions, and the paragraph on notices given on websites or through within-application messaging, with its scrolling cues, its bar on distracting elements and its two placement options. The definition of personal health record as an electronic record of PHR identifiable health information on an individual that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual. The definition of PHR identifiable health information, including the clause requiring that the information be created or received by a covered health care provider, a health plan, an employer, or a health care clearinghouse. The definition of electronic mail.
- 16 CFR 318.4, "Timeliness of notification"Paragraph (a), requiring the notifications to individuals, to the media and by third party service providers to be sent without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach of security, subject to the law enforcement exception. Paragraph (d), the law enforcement exception itself, delaying a notification, notice or posting where a law enforcement official determines it would impede a criminal investigation or cause damage to national security.
- 16 CFR 318.5, "Methods of notice"Paragraph (a)(1), written notice at the last known address, electronic mail where the individual has specified it as the primary method of communication with the requirement that any such notice be clear and conspicuous, first-class mail where electronic mail is not available or not specified, notice to next of kin only where the individual provided their contact information along with authorization to contact them, and the provision for notice in one or more mailings. Paragraph (a)(2), substitute notice after reasonable efforts where contact information for ten or more individuals is insufficient or out of date, in the form of a conspicuous ninety-day posting on the home page of the entity's website or notice in major print or broadcast media, each carrying a toll-free number that remains active for at least ninety days. Paragraph (a)(3), additional notice by telephone or other means where possible imminent misuse makes a case urgent.
- 16 CFR 318.6, "Content of notice"The opening sentence requiring the notice to be in plain language and to include the listed items to the extent possible, regardless of the method by which notice is provided. Paragraph (a), the brief description of what happened including the date of the breach and the date of discovery, and the full name or identity of any third parties that acquired the information as a result of the breach where known, with a description permitted instead where naming would pose a risk to individuals or to the entity providing notice. Paragraph (b), the description of the types of information involved, naming among its examples health diagnosis or condition, lab results, medications, other treatment information, the individual's use of a health-related mobile application, and a device identifier in combination with another data element. Paragraph (c), the steps individuals should take. Paragraph (d), the description of what the entity is doing to investigate, mitigate harm, prevent further breaches and protect affected individuals, such as by offering credit monitoring or other services. Paragraph (e), contact procedures that must include two or more of a toll-free telephone number, an email address, a website, within-application contact, or a postal address.
- 42 U.S.C. 17932, "Notification in the case of breach"Subsection (d)(1), requiring all notifications under the section to be made without unreasonable delay and in no case later than 60 calendar days after discovery. Subsection (e)(1), the methods of individual notice, including written notification by first-class mail to the individual or the next of kin of a deceased individual at the last known address, electronic mail where specified as a preference, the substitute notice provision with its ten-or-more threshold and its toll-free number, and the additional telephone route in urgent situations. Subsection (f), the content of notification, stating that regardless of the method by which notice is provided it must include the listed items to the extent possible. Subsection (g), the delay of notification authorized for law enforcement purposes.
- 42 U.S.C. 17937, "Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities"Subsection (c), applying subsections (c), (d), (e) and (f) of the health breach notification statute — discovery, timeliness, methods of notice and content of notice — to a notification required under this section, in a manner specified by the Federal Trade Commission.
Frequently asked questions
Is the deadline sixty days?
Sixty calendar days is the outer limit, not the schedule. Both rules use the same construction: without unreasonable delay, and in no case later than sixty calendar days after discovery. The first clause is the operative one, so a delay inside the window can still be unreasonable. Both rules also carry an exception where a law enforcement official says a notice would impede a criminal investigation or cause damage to national security. The health privacy rule cross-references that exception inside the timing sentence itself.
When does the clock actually start?
On discovery, and discovery is defined rather than left open. Under the health privacy rule a breach is treated as discovered on the first day it is known to the covered entity, or by exercising reasonable diligence would have been known. The rule then deems the entity to have knowledge if the breach is known, or by reasonable diligence would have been known, to any person other than the one committing it. That person has to be a workforce member or agent, determined in accordance with the federal common law of agency. So the clock does not wait for an executive briefing.
Does a breach letter have to say who got my information?
Under the consumer-facing rule, yes, where it is known. That rule's first content item asks for the full name or identity of any third parties that acquired the information as a result of the breach, if that is known to the entity. A description is permitted instead where naming would pose a risk to individuals or to the entity giving notice. The health privacy rule's content list has no equivalent item. Its first element asks for a brief description of what happened, including the date of the breach and the date of discovery, if known.
What has to be in the letter?
The health privacy rule lists five elements, each required to the extent possible. A brief description of what happened with the two dates. A description of the types of information involved, with examples including full name, social security number, date of birth, home address, account number, diagnosis and disability code. Steps individuals should take to protect themselves. A description of what the entity is doing to investigate, mitigate harm and prevent further breaches. And contact procedures including a toll-free number, an email address, a website, or a postal address. A separate paragraph requires the whole notice to be written in plain language.
What if the company has my old address?
Both rules provide substitute notice. The health privacy rule has two tiers. For fewer than ten individuals with insufficient or out-of-date contact information, substitute notice may be an alternative written notice, a telephone call or other means. For ten or more, it is either a conspicuous ninety-day posting on the home page of the entity's website, or conspicuous notice in major print or broadcast media where affected people likely reside. Either route must carry a toll-free number that stays active for at least ninety days. The consumer rule uses the ten-or-more threshold and the same two forms, after reasonable efforts to make contact.
How can a rule require a notice to be clear and conspicuous?
By defining the phrase. The consumer rule says a notice is clear and conspicuous if it is reasonably understandable and designed to call attention to the nature and significance of the information in it. It then supplies concrete instructions. Clear and concise sentences, short sentences or bullet lists, definite everyday words and active voice, no multiple negatives, and no legal or highly technical terminology. Then a plain-language heading, readable typeface and size, wide margins and line spacing, and boldface or italics for key words. For a web page or an app it asks for cues that encourage scrolling and for placement on a screen consumers frequently access.