Delaware trims its safe harbor for HIPAA breach notices

A new Delaware law narrows the HIPAA safe harbor and pushes organizations to tell the attorney general sooner when breach reviews drag on.

MedRisk Staff
By
1 Min Read

A fresh amendment to Delaware’s breach notification law reaches HIPAA-regulated providers and business associates, and it took effect the moment it was signed. Governor Matt Meyer put his name to House Bill 381 on September 2, 2026. The core shift is a narrower safe harbor: financial institutions regulated under the Gramm-Leach-Bliley Act and HIPAA-covered entities can no longer treat those federal regimes as a broad shield from the state’s notice duties, so organizations that leaned on the exemption need to revisit it.

The other change tests the calendar. Delaware already required attorney general notice when a breach touched more than 500 residents, timed to resident notice. The amendment adds an earlier trigger: when a forensic review cannot establish which residents were caught up, the attorney general must hear about it inside the original 60-day window rather than waiting for a final list. Substitute notice now carries an attorney general step too.

For compliance teams, the takeaway is procedural: update notification matrices and escalation paths so a slow forensic review does not blow the tightened clock.

Share This Article