Breach Notification Requirements: 5 Steps for SMBs

by The Creator | Jul 16, 2026

Business owner reviewing breach notification requirements checklist and compliance deadlines after data security incident

What are breach notification requirements and do they apply to my business?

Breach notification requirements are legal obligations that force your business to tell people when their personal information has been stolen, exposed, or accessed without authorization. If your company stores names paired with Social Security numbers, credit card data, health records, or even email addresses with passwords, you’re likely covered.

A Japanese construction software company, Kaneko, recently appeared on a ransomware leak site after attackers compromised their systems. Whether they operate in Tokyo or Texas, the compliance math is identical: once you know about a breach, the clock starts ticking.

Every state has its own breach notification law. Some give you 30 days. Others demand notification within 72 hours. California requires it “without unreasonable delay.” HIPAA gives covered entities 60 days for individuals but only 72 hours to tell the Department of Health and Human Services if more than 500 people are affected. The FTC Safeguards Rule now requires financial institutions to notify the FTC within 30 days if unencrypted customer data is exposed.

The common thread: silence is expensive. New York fined Zoetis $3 million in part for delayed breach notifications. Premera Blue Cross paid $10 million after waiting months to disclose a breach affecting 10.4 million people.

How quickly do I have to report a data breach?

Speed matters more than perfection. Most breach notification requirements give you a narrow window, but the countdown begins the moment you discover the breach (not when it started).

HIPAA-covered entities must notify affected individuals within 60 days. But if the breach affects 500 or more people, you have just 72 hours to file with HHS. For breaches under 500 people, you can batch them into an annual report.

State laws vary wildly. Florida and Ohio allow 30 days. South Dakota says 60. Colorado demands “without unreasonable delay,” which courts have interpreted as fast as logistically possible, not fast as convenient.

The EU’s GDPR, which applies if you serve European customers, sets the bar at 72 hours to notify the supervisory authority. Miss that window and regulators assume you were negligent or hiding something.

Here’s the practical problem: most SMBs don’t realize they’ve been breached until weeks later. By then, the notification deadline has passed. Attackers often lurk inside networks for 21 days on average before launching ransomware or exfiltrating data. If you discover the breach on day 22 and your state gives you 30 days, you’re compliant. If your state says 72 hours, you’re already in violation.

This is why compliance and regulatory exposure planning can’t wait until after an incident. You need detection tools that shrink that 21-day dwell time and a documented process that starts the moment an alert fires.

Who exactly do I need to notify after a breach?

Three audiences require notification, and each has different deadlines and content requirements.

First, the affected individuals. You must contact everyone whose personal information was exposed. Email is acceptable in most states, but if you lack current contact information for more than 10% of victims, you may also need to post a notice on your website or take out a newspaper ad. Your notification must be written in plain language (not legalese) and include: the date or estimated date of the breach, the types of information exposed, what you’re doing to investigate, what steps you’ve taken to prevent future breaches, and contact information for major credit bureaus if Social Security numbers were involved.

Second, state regulators. Most states require you to notify the attorney general’s office if the breach affects a certain number of residents (often 500 or 1,000). Some states want a copy of the consumer notice. Others want a separate filing with details you don’t share publicly, like the number of affected residents and whether law enforcement is investigating.

Third, consumer reporting agencies. If a breach affects more than 1,000 people, you must notify the big three credit bureaus (Equifax, Experian, TransUnion) so they can watch for fraud patterns.

Industry-specific rules add more parties. HIPAA requires notifying the media if a breach affects more than 500 people in a state or jurisdiction. The FTC Safeguards Rule requires financial services firms to notify the FTC itself. Some cyber insurance policies require immediate notification to the carrier or they’ll deny your claim.

What happens if I miss the breach notification deadline?

The penalty structure depends on which law applies, but the floor is $100 per affected individual in many states. The ceiling can reach $50,000 per violation.

HIPAA penalties tier by culpability. If you didn’t know and couldn’t have known about the breach, fines start at $100 per violation (capped at $25,000 per year). If you knew or should have known, they jump to $1,000 to $50,000 per violation, capped at $1.5 million annually per violation type. Late or missing breach notifications fall into the “should have known” category because the law is clear.

State attorneys general can also sue under state consumer protection laws. In 2020, Zoom paid $85 million to settle claims that included inadequate breach disclosures. Marriott paid $23.8 million across multiple states after a breach exposed 300 million guest records and notifications were deemed insufficient.

Beyond fines, late notification breeds class-action lawsuits. Plaintiffs argue that delays gave criminals extra time to exploit stolen data, increasing harm. Even if you win, defense costs run into six figures.

Then there’s the reputational math. Customers forgive mistakes, but they don’t forgive cover-ups. A construction firm that discloses a breach within days and offers credit monitoring keeps most clients. One that waits months and gets outed by regulators loses bids and referrals for years. Professional services firms that handle sensitive client data face the same calculus. Trust, once lost, doesn’t return on a payment plan.

How do I prepare for breach notification requirements before an incident?

The best time to draft your breach notification is before you need it. Start with an incident response plan that includes decision trees: if X data type is exposed, notify these parties within Y hours.

Create notification templates for each audience. Write the individual notification in plain English, leaving blanks for the breach date, affected data types, and specific actions. Draft the state AG notification with the details regulators expect: root cause, number of affected residents, remediation steps. Have legal counsel review both.

Assign roles now. Who investigates? Who talks to law enforcement? Who sends the emails? Who handles the press? In the middle of a ransomware attack, nobody has time to debate whether IT or legal owns breach notification. Make one person (usually your IT director or compliance officer) the incident commander.

Test your contact lists quarterly. Employee email lists go stale. Customer databases contain typos. If 20% of your notifications bounce, you may trigger the “substitute notice” requirement (website posting, media notice) even for a small breach, multiplying your costs.

Consider cyber insurance that covers breach notification expenses. Policies typically pay for forensics, legal review, notification costs, credit monitoring, call center services, and public relations. A notification to 5,000 people, with credit monitoring and a call center, can cost $200,000. Insurance turns that into a $5,000 deductible.

Document your data inventory. You can’t notify people about exposed data if you don’t know what data you have or where it lives. Map every database, file share, and cloud application that stores personal information. Tag each with the applicable regulation (HIPAA, FTC Safeguards, state breach law). When a breach hits one server, you’ll know immediately which rules apply and which notifications to trigger. This work feeds directly into broader IT and compliance planning that prevents breaches in the first place.

Do breach notification requirements apply if no data was actually stolen?

Maybe. The trigger isn’t theft, it’s unauthorized access or acquisition. Some states require notification if an unauthorized person simply viewed the data, even if they didn’t copy it. Others require notification only if there’s a reasonable likelihood of harm.

HIPAA uses a four-factor risk assessment: the nature and extent of the protected health information involved, who accessed it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. If an employee accidentally emails a patient list to the wrong internal department, that’s low risk. If a hacker breaks into your server and opens a file of Social Security numbers, that’s high risk, even if you have no proof they exfiltrated it.

Most state laws define a breach as unauthorized acquisition, not just access. But “acquisition” is broadly interpreted. If an attacker has the technical ability to copy data (they’re inside your network with admin rights), courts often presume acquisition occurred.

Ransomware complicates the picture. Older ransomware strains just encrypted files. Newer ones exfiltrate data first, then encrypt, then threaten to publish unless you pay. If you’re hit with encryption-only ransomware and your forensics firm finds no evidence of exfiltration, some states may not require notification. But HIPAA still might, because the risk assessment could show potential access. And if the attackers later post your data on a leak site, you’ll face lawsuits arguing you should have notified immediately.

The safe path: treat any unauthorized access to sensitive data as presumed acquisition. Notify unless your forensics team can conclusively prove otherwise. The cost of unnecessary notification (a few thousand dollars) is lower than the cost of failing to notify when required (hundreds of thousands in fines and lawsuits).

What should manufacturers and construction firms know about breach notification?

You’re not exempt just because you don’t handle credit cards or health records. If you store employee Social Security numbers, customer contact information paired with purchase history, or vendor payment details, state breach laws apply.

Manufacturers increasingly face breach notification obligations tied to supply chain attacks. If a compromised vendor exposes your customer list or your employee data flows through a third-party payroll system that gets breached, you may still need to notify. Some state laws make you liable if your vendor fails to notify.

Construction firms often underestimate their exposure. Project management software, bid portals, and client intake forms collect enough personal information to trigger breach notification laws. If you store homeowner data for residential projects or employee I-9 forms, you’re covered.

The Kaneko incident shows how attackers target software used by manufacturers and construction firms. Attackers know these industries handle valuable intellectual property (blueprints, supplier contracts, project budgets) and often lack the security budgets of hospitals or banks. A breach that exposes bid data can cost you the next contract even if it doesn’t trigger regulatory fines.

Bottom line: sector doesn’t matter. Data does. If you have it, you must protect it and disclose when it’s compromised.

Can I avoid breach notification if I pay the ransom?

Paying a ransom doesn’t erase your notification obligation. Even if attackers promise to delete stolen data, you have no way to verify they did. Regulators and courts treat ransom payments as irrelevant to the legal duty to notify.

HIPAA explicitly states that paying a ransom doesn’t reduce the breach notification requirement. Several state attorneys general have issued guidance saying the same. The FBI discourages ransom payments and has said doing so may violate sanctions if the attackers are on a prohibited list.

Some businesses pay, get a “proof of deletion” video from the attackers, and use that to argue against notification. But forensic experts can’t authenticate such videos, and regulators don’t accept them. In one case, a healthcare provider paid, received deletion proof, skipped notification, and then saw its data posted online six months later. The resulting fines and lawsuits dwarfed the ransom.

If you pay and the attackers decrypt your files, you’ve solved the downtime problem. But you haven’t solved the compliance problem. The data was still acquired without authorization. Notification is still required.

How does breach notification fit into my overall compliance program?

Breach notification is the back end of a compliance program. The front end is prevention: access controls, encryption, employee training, vendor management, and monitoring. When prevention fails, detection kicks in: intrusion detection, log monitoring, endpoint protection. When detection succeeds, response activates: containment, forensics, and notification.

Many SMBs focus all their energy on prevention and skip the response planning. That’s like buying a fire extinguisher but never reading the instructions. When the fire starts, panic and delay make everything worse.

Your compliance program should document how each regulation’s breach notification requirements intersect. If you’re a dental practice covered by HIPAA but also subject to your state’s breach law, map out which deadlines apply and which regulator gets notified first. If you’re a financial advisor covered by the FTC Safeguards Rule and also licensed in multiple states, identify the strictest deadline (that’s your real deadline) and the most detailed disclosure requirement (that’s your template).

Annual tabletop exercises keep the plan current. Gather your team, simulate a breach scenario, and walk through each notification step. Who drafts the email? Who reviews it? Who approves it? Who sends it? How do we get the contact list? Where are the templates stored? Can we access them if our network is encrypted? These questions take 10 minutes to answer in a conference room and 10 hours to answer during an active incident.

What are the most common breach notification mistakes SMBs make?

First, waiting for perfect information. You’ll never have complete forensics in the first 48 hours, but most laws require notification based on what you know at the time. You can always send a supplemental notice later with additional details. Waiting until you understand the full scope often means missing your deadline.

Second, assuming cyber insurance handles everything. Insurance pays costs, but it doesn’t draft your notice, research applicable laws, or click send. You still own the process. Some policies require you to use their breach coach (a lawyer provided by the carrier), which is fine, but ultimate responsibility stays with you.

Third, treating notification as a legal document instead of a customer communication. Notifications stuffed with liability waivers and indecipherable language make people angrier and more likely to sue. Plain language builds trust. “We’re sorry this happened. Here’s what we know. Here’s what we’re doing. Here’s how you can protect yourself.” That’s the structure.

Fourth, notifying individuals but forgetting the regulators. State AG offices often learn about breaches from news reports, not from the company itself. That’s an automatic penalty.

Fifth, storing notification templates and contact lists in the same system that gets encrypted during a ransomware attack. Keep an offline or cloud-based copy of your incident response binder, including templates, contact lists, and regulator phone numbers. If your email is down, you need a way to notify people via a third-party service or your website.

FAQ

Do I need a lawyer to handle breach notification?

For breaches affecting more than a few dozen people, yes. Breach notification laws overlap and conflict, and a misstep can double your liability. A lawyer experienced in data breach response can navigate privilege issues (keeping forensic findings confidential), advise on which laws apply, and review your notification language. Cyber insurance often provides a breach coach at no extra cost. Use them. The $10,000 you spend on legal guidance can save you $500,000 in fines and settlements.

What if I discover the breach months after it happened?

The notification clock starts when you discover the breach, not when it occurred. But regulators will ask why it took so long to discover. If the delay was due to negligence (no monitoring, ignored alerts, no logging), they may impose higher fines. If it was due to sophisticated attacker tradecraft, they’re more lenient. Document your security controls and detection capabilities so you can show you were looking. That turns “we didn’t know” into “we couldn’t have known sooner,” which is a much better legal position.

Can I notify people by posting a notice on my website instead of sending individual emails?

Only if individual notification is impossible or cost-prohibitive. Most states allow “substitute notice” (website posting, press release, or statewide media notice) if you lack contact information for more than 10% of affected individuals or if the cost of individual notice exceeds $250,000. But substitute notice is a fallback, not a first choice. Regulators and plaintiffs’ lawyers view it as evidence you didn’t care enough to reach people directly. Email is cheap. Use it unless you truly can’t.

What counts as personal information that triggers breach notification?

It varies by state, but the core is any combination of name plus Social Security number, driver’s license number, financial account number, or credit card number. Many states have expanded the definition to include medical information, biometric data, email plus password, or even online credentials alone. Some states include any information that could be used for identity theft, which courts have interpreted broadly. If in doubt, assume it’s covered. Over-notification is safer than under-notification.

Does encryption protect me from breach notification requirements?

If the stolen data was encrypted and you still control the encryption key, most laws provide a safe harbor: no notification required. But the encryption must be strong (AES-256, for example, not a password-protected zip file), and the key must be stored separately from the data. If attackers stole the encrypted data and the key, or if the key is weak enough to crack, the safe harbor disappears. HIPAA has a similar rule: if protected health information is encrypted per NIST standards, it’s not considered a breach. Encryption is your best defense against both breaches and breach notification.

Keep reading

Sources

Source: 🏴‍☠️ Thegentlemen has just published a new victim : Kaneko