Data Breach Notification
A Data-Breach-Notification is a formal communication sent by an organization to individuals, regulatory authorities, and other stakeholders after a Security-Breach results in the unauthorized access or disclosure of sensitive data. This process is a fundamental aspect of Cybersecurity and Incident-Response management. According to the General Data Protection Regulation (GDPR), organizations operating within the European-Union must notify the relevant supervisory authority within 72 hours of becoming aware of a breach that risks the rights of individuals.
In the United-States, Data-Privacy laws are largely sector-specific or state-mandated. For example, the Health-Insurance-Portability-and-Accountability-Act (HIPAA) requires healthcare providers to notify patients and the Department-of-Health-and-Human-Services when Protected-Health-Information is compromised. Additionally, the Federal Trade Commission (FTC) provides guidance for businesses on how to properly execute a Data-Breach-Notification to mitigate harm and maintain Consumer-Trust.
The contents of a notification typically include the date of the incident, the specific types of Personally-Identifiable-Information involved, and the steps the organization is taking to secure its systems. Organizations may also implement Encryption or Multi-Factor-Authentication as remedial actions. To assist affected individuals, companies often provide Credit-Monitoring services to prevent Identity-Theft.