All fifty states require breach notification and none of them agree on the deadline, the trigger, or the regulator threshold. This hub tracks amendments to those rules and the enforcement that follows late or inadequate notice.
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
Data Security Rules
September 14, 2026
The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.
Read more →
GLBA
September 1, 2026
The FTC amended the Safeguards Rule in November 2023 to add a reporting duty at 16 CFR 314.4(j). It turns on acquisition of unencrypted customer information rather than on any assessment of harm, applies at 500 consumers, runs 30 days from discovery, and carries no small-institution exemption.
Read more →
Breach Notification
August 24, 2026
Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →
HIPAA
August 12, 2026
HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.
Read more →