Desk live·
ForensicPost
Breaches/Method/File 26-0419

All Fifty US States Now Impose Breach Notification Duties on a Single Incident

Breach notification statutes now apply across all fifty US states, with statutory windows ranging from 30 to 90 days and differing triggers. A single incident produces fifty compliance problems.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS breach notification regime
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

State attorney general breach-notification statutes now apply consistently across all fifty US states, requiring disclosure of breaches involving Social Security numbers, financial information and, in some states, health information — within statutory windows ranging from 30 to 90 days.

Universal coverage is progress. Fifty different specifications of the same obligation is the part worth examining.

Divergent Triggers, Not Just Divergent Clocks

The variation is not simply how many days. States differ on which data types trigger notification, whether encryption provides a safe harbour, whether a risk-of-harm assessment can excuse notice, what the notice must contain, and whether regulators must be told alongside individuals.

A national organisation therefore does not have one obligation with fifty deadlines. It has fifty obligations that happen to overlap, and it must determine residency for every affected person to know which apply.

Who This Actually Disadvantages

A large company has counsel who do this routinely. The burden falls hardest on organisations of the kind this desk keeps writing about: school districts, regional health networks, municipal utilities, small processors.

They face the same fifty-jurisdiction analysis with none of the capability, which reliably delays notification — and delayed notification is worse for the affected people the statutes exist to protect.

Why The Counts Keep Moving

This regime also helps explain a pattern visible throughout our database: affected figures that climb across successive disclosures, as at Conduent in 26-0731.

An organisation facing a 30-day clock in one state must notify before it knows the full scope, then revise as the review completes. The first number is not a lie and the last is not a cover-up. The clock started before the answer existed.

How we reported this

This is a standards file compiled from published analysis, listed below. It is not legal advice; specific obligations vary and change. Corrections: corrections@forensicpost.com.

Sources
  1. Education cybersecurity statistics 2026: school breaches, ransomware, and student data riskDeepstrike
  2. Vendor compliance 2026 checklist: evaluating EdTech vendors under new privacy lawsCybernut
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary