US Breach Response Checklist
A structured checklist for US-regulated organisations covering state notification laws, SEC filing requirements, HIPAA, and FTC obligations. Work through it on screen during an incident, or print it empty for your incident response binder.
First 4 Hours: Containment and Triage
Phase 1
Hour 0–4: Containment & Triage
Hours 4–24: Scope and Assessment
Phase 2
Hour 4–24: Scope & Assessment
Hours 24–48: State and Federal Notification Preparation
Phase 3
Hour 24–48: Notification Preparation
Execute Notifications
Phase 4
Execute Notifications (per state timeline)
Post-Notification: Remediation and Review
Phase 5
Post-Notification: Remediation & Review
Incident Notes
Key Legal References
Key Legal References
- FTC Data Breach Response Guide — ftc.gov/business-guidance
- SEC Form 8-K, Item 1.05 — Material cybersecurity incident disclosure (4 business days from materiality determination)
- HIPAA Breach Notification Rule — 45 CFR 164.400–414 (60 days for breaches affecting 500+ individuals)
- State breach notification laws — All 50 states + DC, Guam, Puerto Rico, and US Virgin Islands have enacted statutes
- NIST Cybersecurity Framework — Incident response guidance (Respond and Recover functions)
- Article source — Corporate Breach Response Checklist: The First 72 Hours
This checklist is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific situation. Your checklist data is stored locally in your browser and is never transmitted to our servers.
← EU/GDPR Breach Response Checklist