State attorney general breach-notification statutes now apply consistently across all fifty US states, requiring disclosure of breaches involving Social Security numbers, financial information and, in some states, health information — within statutory windows ranging from 30 to 90 days.
Universal coverage is progress. Fifty different specifications of the same obligation is the part worth examining.
Divergent Triggers, Not Just Divergent Clocks
The variation is not simply how many days. States differ on which data types trigger notification, whether encryption provides a safe harbour, whether a risk-of-harm assessment can excuse notice, what the notice must contain, and whether regulators must be told alongside individuals.
A national organisation therefore does not have one obligation with fifty deadlines. It has fifty obligations that happen to overlap, and it must determine residency for every affected person to know which apply.
Who This Actually Disadvantages
A large company has counsel who do this routinely. The burden falls hardest on organisations of the kind this desk keeps writing about: school districts, regional health networks, municipal utilities, small processors.
They face the same fifty-jurisdiction analysis with none of the capability, which reliably delays notification — and delayed notification is worse for the affected people the statutes exist to protect.
Why The Counts Keep Moving
This regime also helps explain a pattern visible throughout our database: affected figures that climb across successive disclosures, as at Conduent in 26-0731.
An organisation facing a 30-day clock in one state must notify before it knows the full scope, then revise as the review completes. The first number is not a lie and the last is not a cover-up. The clock started before the answer existed.
This is a standards file compiled from published analysis, listed below. It is not legal advice; specific obligations vary and change. Corrections: corrections@forensicpost.com.