Delaware Breach Law Adds Early AG Notice, Narrows Safe Harbor
An amendment to Delaware's data breach notification law requires earlier notice to the Attorney General in some cases and narrows the compliance safe harbor for entities regulated by GLBA and HIPAA.
Delaware has amended its data breach notification statute, effective immediately, creating new obligations for companies holding personal information of state residents. The law, HB 381, introduces an early reporting requirement, obligating entities to notify the Attorney General within 60 days of discovering a breach if they cannot identify the specific affected residents within that timeframe. This change could accelerate regulatory reporting deadlines, particularly in complex incidents requiring prolonged forensic analysis.
Critically, the amendment narrows a compliance safe harbor for financial and healthcare organizations. Previously, entities regulated by the Gramm-Leach-Bliley Act (GLBA) or HIPAA who followed their federal breach notification procedures were deemed compliant with Delaware's entire law. Under the revised statute, that safe harbor is now limited only to the rules governing the timing of individual notices. These regulated entities must now separately evaluate and ensure compliance with other Delaware-specific requirements, including the 500-resident threshold for AG notification and mandates for credit monitoring after breaches involving Social Security numbers. Incident response plans and compliance checklists should be updated immediately.