The unauthorized access, exfiltration or exposure of protected, sensitive or confidential information held by an organization, whether achieved through hacking, insider misuse, or the exploitation of inadequate security controls. As a criminal offense it typically involves an outside actor deliberately breaching a computer system to steal personal, financial or proprietary data, which may then be sold, published, or used to facilitate further crimes such as identity theft or fraud. Many countries have enacted mandatory breach notification laws obligating organizations to disclose a breach to affected individuals and regulators.
Facts
Classification CodeUnited States: the HIPAA Breach Notification Rule, enacted as part of the HITECH Act in 2009, governs breaches of protected health information; European Union: the General Data Protection Regulation, in force since 2018, governs personal data breaches generally; separately, all 50 US states maintain their own general data breach notification laws. 1 Typical PenaltyEnforcement works chiefly through notification duty rather than a fixed criminal term: the GDPR requires notification within 72 hours of discovery, with very high fines possible for noncompliant large companies; the HIPAA Breach Notification Rule requires notice to affected individuals within 60 days of discovery, with breaches of 500 or more individuals also reported to the Office for Civil Rights and to media outlets and posted on the public HHS breach portal. 1 Elements of OffenseThe National Institute of Standards and Technology defines a data breach as an occurrence that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system, or that violates or imminently threatens security policies, procedures or acceptable use policies; the UK National Cyber Security Centre defines it more narrowly as information held by an organization being stolen or accessed without authorization. 1 Notable ExampleThe February 2024 Change Healthcare cyberattack exposed the data of approximately 100 million individuals, highlighting the scale of healthcare data breach risk and leading to increased scrutiny of cybersecurity practices across the healthcare sector. 1 Jurisdiction VariationAs of 2022 the only United States federal law requiring data breach notification was limited to medical data regulated under HIPAA; all 50 states, since Alabama passed a law in 2018, maintain their own general data breach notification laws instead of relying on a single federal standard. 1 Classification
Offense GradeSerious or Indictable Offense 1 Connections
Associated With
Source Wikipedia: Cybercrime
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
In the Other Atlases
Sources
1. Data Breach (Wikipedia)
WikipediaLead paragraph, Data breach
A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information".
Legal aspects, HIPAA Breach Notification Rule paragraph
In healthcare, the HIPAA Breach Notification Rule, enacted in the United States as part of the HITECH Act in 2009, requires covered entities and business associates to notify affected individuals within 60 days of discovering a breach of unsecured protected health information (PHI).
Definition section, NIST and NCSC paragraph
An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or that constitutes a violation or imminent threat of violating security policies, security procedures, or acceptable use policies.
Legal aspects, GDPR paragraph
The GDPR requires notification within 72 hours, with very high fines possible for large companies not in compliance.
Legal aspects, Change Healthcare paragraph
The February 2024 Change Healthcare cyberattack, which exposed the data of approximately 100 million individuals, highlighted the scale of healthcare data breach risks and led to increased scrutiny of cybersecurity practices across the healthcare sector.
Legal aspects, US federal law paragraph
As of 2022, the only United States federal law requiring notification for data breaches is limited to medical data regulated under HIPAA, but all 50 states (since Alabama passed a law in 2018) have their own general data breach notification laws.
View the Source Wikipedia: Cybercrime
Associated With: Cybercrime, Lead and law-enforcement sectionsQuote, Associated With: Cybercrime, Lead and law-enforcement sections
Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks.
View the Source Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.