Breach notification: definition for WISP compliance
Breach notification is the legal and operational process of notifying affected people, regulators, or other parties after certain unauthorized access to protected data. State timelines vary, so a WISP should route incidents through a state-specific review instead of relying on one generic deadline. 16 CFR 314.4(j) requires FTC notice for certain notification events involving unencrypted customer information of at least 500 consumers.
Key facts
- Breach notification is the legal and operational process of notifying affected people, regulators, or other parties after certain unauthorized access to protected data.
- State timelines vary, so a WISP should route incidents through a state-specific review instead of relying on one generic deadline.
- The term should be used consistently in the WISP, incident response plan, and access control policy.
Key takeaways
- Breach notification is the legal and operational process of notifying affected people, regulators, or other parties after certain unauthorized access to protected data.
- State timelines vary, so a WISP should route incidents through a state-specific review instead of relying on one generic deadline.
- The term should be used consistently in the WISP, incident response plan, and access control policy.
- Definitions are operational: they should help a small firm decide what to do and what evidence to keep.
What does breach notification mean?
Breach notification is the legal and operational process of notifying affected people, regulators, or other parties after certain unauthorized access to protected data.
State timelines vary, so a WISP should route incidents through a state-specific review instead of relying on one generic deadline.
16 CFR 314.4(j) requires FTC notice for certain notification events involving unencrypted customer information of at least 500 consumers.
Worked example
A lost unencrypted laptop with borrower files triggers a record of discovery date, encryption status, affected-consumer count, FTC 30-day analysis, state-law review, and insurer notice.
The example belongs in the policy packet only if it matches the firm's actual systems, vendors, and evidence records. Otherwise, it should become a remediation or counsel-review note.
What small firms get wrong
Firms often treat breach notification as one state deadline and miss the federal FTC trigger, vendor notice timing, consumer-count threshold, or state-specific regulator filing.
The fix is to tie the term to a concrete record: a system inventory, access list, vendor list, incident log, training record, or dated control screenshot.
| Where it appears | Why it matters | Proof example |
|---|---|---|
| WISP | 16 CFR 314.4(j) requires FTC notice for certain notification events involving unencrypted customer information of at least 500 consumers. | Annual review record |
| Access Control Policy | Connects roles to permissions | User access list |
| Incident Response Plan | Guides escalation and notice decisions | Incident log |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Explore this cluster
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
Turn definitions into working policies.
Policywright uses clear terms and source-cited clauses across the full policy packet.
See a sample