Crime and Justice Atlas

How Justice Is Served
Sign In
Text size
100%
Theme
Offense

Data Breach

Cyber and Technology-Enabled Offenses

The unauthorized access, exfiltration or exposure of protected, sensitive or confidential information held by an organization, whether achieved through hacking, insider misuse, or the exploitation of inadequate security controls. As a criminal offense it typically involves an outside actor deliberately breaching a computer system to steal personal, financial or proprietary data, which may then be sold, published, or used to facilitate further crimes such as identity theft or fraud. Many countries have enacted mandatory breach notification laws obligating organizations to disclose a breach to affected individuals and regulators.

Facts
Classification Code
United States: the HIPAA Breach Notification Rule, enacted as part of the HITECH Act in 2009, governs breaches of protected health information; European Union: the General Data Protection Regulation, in force since 2018, governs personal data breaches generally; separately, all 50 US states maintain their own general data breach notification laws. 1
Typical Penalty
Enforcement works chiefly through notification duty rather than a fixed criminal term: the GDPR requires notification within 72 hours of discovery, with very high fines possible for noncompliant large companies; the HIPAA Breach Notification Rule requires notice to affected individuals within 60 days of discovery, with breaches of 500 or more individuals also reported to the Office for Civil Rights and to media outlets and posted on the public HHS breach portal. 1
Elements of Offense
The National Institute of Standards and Technology defines a data breach as an occurrence that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system, or that violates or imminently threatens security policies, procedures or acceptable use policies; the UK National Cyber Security Centre defines it more narrowly as information held by an organization being stolen or accessed without authorization. 1
Notable Example
The February 2024 Change Healthcare cyberattack exposed the data of approximately 100 million individuals, highlighting the scale of healthcare data breach risk and leading to increased scrutiny of cybersecurity practices across the healthcare sector. 1
Jurisdiction Variation
As of 2022 the only United States federal law requiring data breach notification was limited to medical data regulated under HIPAA; all 50 states, since Alabama passed a law in 2018, maintain their own general data breach notification laws instead of relying on a single federal standard. 1
Classification
Offense Grade
Serious or Indictable Offense 1
Connections

Associated With

Source Wikipedia: Cybercrime

Has Offense Grade

Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.

In the Other Atlases
Sources
1. Data Breach (Wikipedia)
Wikipedia
  • Lead paragraph, Data breach
    A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information".
  • Legal aspects, HIPAA Breach Notification Rule paragraph
    In healthcare, the HIPAA Breach Notification Rule, enacted in the United States as part of the HITECH Act in 2009, requires covered entities and business associates to notify affected individuals within 60 days of discovering a breach of unsecured protected health information (PHI).
  • Definition section, NIST and NCSC paragraph
    An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or that constitutes a violation or imminent threat of violating security policies, security procedures, or acceptable use policies.
  • Legal aspects, GDPR paragraph
    The GDPR requires notification within 72 hours, with very high fines possible for large companies not in compliance.
  • Legal aspects, Change Healthcare paragraph
    The February 2024 Change Healthcare cyberattack, which exposed the data of approximately 100 million individuals, highlighted the scale of healthcare data breach risks and led to increased scrutiny of cybersecurity practices across the healthcare sector.
  • Legal aspects, US federal law paragraph
    As of 2022, the only United States federal law requiring notification for data breaches is limited to medical data regulated under HIPAA, but all 50 states (since Alabama passed a law in 2018) have their own general data breach notification laws.
View the Source
Wikipedia: Cybercrime
Associated With: Cybercrime, Lead and law-enforcement sections
Quote, Associated With: Cybercrime, Lead and law-enforcement sections
Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks.
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.