# Breach notification

The legal duty to tell people when their data has gotten out.

Every state imposes one, and a practice holding health records carries a federal duty on top. Under 45 CFR 164.404 the limit is sixty calendar days from discovery. Discovery is dated from when anyone on the staff should reasonably have known, not from when the owner was told. The buyer's exposure is the incident that already happened and was never reported, since the duty travels with the entity in a stock deal and the facts travel either way. Ask what incidents have been logged, who assessed each one, and whether any of it is written down outside one person's memory.

In numbers: A practice that discovers a breach on the first of the month has 60 days to notify the people in it. At 500 or more it tells the Secretary at the same time, and the media too where more than 500 live in one state.

Source: https://searchspheresource.com/glossary/breach-notification
Not dated: A definition is editorial: what a term means, why it matters, and an example. None of it reads a source that can go stale, so there is no date to take and a stamped one would be the build time wearing a costume.

Site index for machines: https://searchspheresource.com/llms.txt
