Arkansas Breach Notification Timelines After a Radiation Oncology DICOM Archive Ransomware Attack

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Arkansas Breach Notification Timelines After a Radiation Oncology DICOM Archive Ransomware Attack

Kevin Henry

Data Breaches

September 09, 2026

7 minutes read
Share this article
Arkansas Breach Notification Timelines After a Radiation Oncology DICOM Archive Ransomware Attack

Arkansas Data Breach Notification Law Overview

Scope and who must comply

Arkansas’s data breach framework applies to any person or business that acquires, owns, licenses, or maintains computerized data about Arkansas residents. If you maintain data you do not own (for example, a cloud PACS/VNA or managed service holding a DICOM archive), you must notify the data owner immediately after discovery of a breach affecting that information.

What counts as a breach and personal information

A breach is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Personal information includes a resident’s name plus one or more elements such as Social Security number, driver’s license number, financial account credentials, medical information, or biometric data. For radiation oncology, DICOM archives typically contain patient names and medical information, so they fit squarely within this definition.

Risk-of-harm standard

Arkansas uses a Reasonable Likelihood of Harm threshold. After a reasonable investigation, if you determine there is no reasonable likelihood of harm to customers, notification is not required. Document your analysis thoroughly because it drives every downstream deadline.

Timeliness baseline

When notification is required, you must notify affected Arkansas residents in the most expedient time and manner possible and without unreasonable delay. This timing must account for law enforcement needs and the steps necessary to scope the incident and restore system integrity.

Notification Requirements for Affected Individuals

When and how to notify

Notify impacted individuals without unreasonable delay once your investigation indicates a breach involving Unencrypted Personal Information and a reasonable likelihood of harm. Acceptable methods include written notice by mail or electronic mail consistent with federal e‑signature standards. Use clear language that explains what happened, what information was involved, what you are doing in response, and how individuals can protect themselves.

Healthcare overlay to your timeline

Radiation oncology providers are typically subject to federal healthcare breach rules in parallel with Arkansas law. In practice, you should align your state notification efforts with the federal requirement to notify individuals without unreasonable delay and within 60 calendar days of discovery, ensuring both regimes are satisfied.

Notification to Arkansas Attorney General

Trigger and deadline

If a breach affects the personal information of more than 1,000 individuals, you must notify the Arkansas Attorney General at the same time you notify affected individuals or within 45 days after determining there is a Reasonable Likelihood of Harm—whichever occurs first. Plan your work so AG notice does not lag behind resident notice.

What to retain and provide

Retain your written breach determination and supporting documentation for five years. If the Attorney General requests these materials, you must provide them within 30 days. These records are confidential under Arkansas law, which encourages candid, well-documented analyses.

Encryption Safe Harbor Provisions

How encryption affects notice duties

Arkansas focuses on Unencrypted Personal Information. If the compromised data were encrypted or redacted, notification under state law is generally not required. In a DICOM context, full‑disk or database encryption that protects patient identifiers and medical information can be decisive.

Practical cautions for ransomware

In ransomware events, evaluate whether attackers accessed keys, credentials, or decrypted data in memory or during exfiltration. If keys or plaintext were exposed—or logs suggest exfiltration—treat the data as effectively unencrypted for your harm analysis. Also consider federal healthcare breach standards, which may still require notification even when encryption is in place.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Substitute Notice Procedures

When you may use substitute notice

Substitute notice is permitted if any one of the following is true: the cost of notice exceeds $250,000, the affected class exceeds 500,000 individuals, or you lack sufficient contact information for affected persons.

Substitute Notice Requirements

  • Email notice to affected individuals for whom you have addresses.
  • Conspicuous posting of the notice on your website.
  • Notification by statewide media within Arkansas.

All three components are required when using substitute notice. Prepare templates and media plans in advance so you can execute quickly if thresholds are met.

Law Enforcement Delay Provisions

Coordinating with investigators

You may delay notification if a law enforcement agency determines that notice will impede a criminal investigation. Once law enforcement advises that notice will not compromise the investigation, you must proceed without unreasonable delay.

Documentation to protect your timeline

Secure and retain written confirmation of any Law Enforcement Notification Delay, including dates of the request and release. Track these dates in your breach log to demonstrate why and how your notification timeline was adjusted.

Compliance Best Practices for Radiation Oncology Archives

First 24–72 hours after a DICOM ransomware attack

  • Contain and preserve: isolate affected PACS/VNA nodes, preserve volatile data, and safeguard audit logs and DICOM C‑STORE/C‑MOVE histories.
  • Inventory exposure: enumerate DICOM tags carrying identifiers (for example, PatientName, PatientID, AccessionNumber) and map which studies were accessible to the threat actor.
  • Begin Ransomware Incident Reporting workstreams: coordinate internal counsel, privacy, security, and clinical operations to align state and federal notifications.

Risk-of-harm analysis tailored to Arkansas

  • Decide whether Unencrypted Personal Information was accessed and whether there is a Reasonable Likelihood of Harm; memorialize the rationale.
  • If more than 1,000 individuals are affected, plan Arkansas Attorney General notice to occur alongside resident notice or within 45 days of your harm determination, whichever comes first.

Notification execution and recordkeeping

  • Use direct mail or compliant email; pivot to substitute notice only if statutory thresholds are met, executing all required components.
  • Retain breach determinations and supporting documentation for five years and be prepared to produce them within 30 days of an AG request.

Radiation Oncology Data Security hardening

  • Encrypt DICOM archives and backups, segregate keys, enforce MFA for clinical systems, and segment treatment planning networks from general IT.
  • Validate immutable/offline backups and test rapid restoration of critical oncology services to minimize patient care disruption.
  • Align policies with Arkansas Data Protection Act principles (practically, the state’s personal information protection requirements) and your federal healthcare obligations.

Summary

After a radiation oncology DICOM ransomware attack, Arkansas timelines hinge on two pivots: whether Unencrypted Personal Information was involved and whether there is a Reasonable Likelihood of Harm. Notify residents without unreasonable delay, notify the Attorney General if more than 1,000 individuals are affected (no later than 45 days from your harm determination or at the time of resident notice, whichever comes first), and leverage substitute notice only when its statutory prerequisites are met. Strong encryption, disciplined documentation, and coordinated incident response keep you compliant and patient‑centric.

FAQs.

What is the timeline for notifying affected individuals in Arkansas?

You must notify affected residents in the most expedient time and manner possible and without unreasonable delay, accounting for law enforcement needs and remediation. For healthcare providers, also meet the federal requirement to notify individuals without unreasonable delay and within 60 calendar days of discovery.

When must the Arkansas Attorney General be notified?

If more than 1,000 individuals are affected, notify the Attorney General at the same time as resident notice or within 45 days after you determine there is a reasonable likelihood of harm—whichever occurs first.

Does encryption exempt breach notification requirements?

Generally, yes. Arkansas focuses on Unencrypted Personal Information. If the data were encrypted or redacted, state notification is typically not required. However, if encryption keys or credentials were compromised—or if federal healthcare rules still require notice—you should proceed with notifications.

What are the procedures for substitute notice under Arkansas law?

You may use substitute notice if the cost exceeds $250,000, the affected class exceeds 500,000, or you lack sufficient contact information. Substitute notice must include all of the following: email notice (where available), conspicuous website posting, and notification by statewide media.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles