Delaware Health Data Breach Rules for Cataract ASCs After a Whiteboard Photo Incident

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Delaware Health Data Breach Rules for Cataract ASCs After a Whiteboard Photo Incident

Kevin Henry

Data Breaches

September 07, 2026

7 minutes read
Share this article
Delaware Health Data Breach Rules for Cataract ASCs After a Whiteboard Photo Incident

A quick smartphone photo of an OR whiteboard that shows patient names and cataract procedures can trigger Delaware’s data breach rules for ambulatory surgery centers (ASCs). Because a photo is computerized data, and names paired with treatment details count as personal information, you must evaluate the incident under Delaware’s breach statute and coordinate with HIPAA timelines and content requirements.

This guide explains how Delaware’s law defines a “breach of security,” the encryption safe harbor, who must be notified and when, and what has changed as of September 2, 2026, including new Delaware Attorney General notification triggers and the narrowed HIPAA safe-harbor provision.

Delaware Data Breach Notification Law

Delaware’s breach law applies to any person or entity that conducts business in the state and owns, licenses, or maintains personal information about Delaware residents. “Personal information” includes a resident’s name in combination with specific data elements—importantly for ASCs, medical history, treatment, or diagnosis are explicitly listed, as are health insurance identifiers and biometric data. A whiteboard photo that shows a patient’s name alongside the planned cataract procedure therefore implicates personal information. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Delaware defines “determination of the breach” as the point when you have sufficient evidence to conclude a breach occurred. From that determination, consumer notice must go out without unreasonable delay and no later than 60 days, subject to limited exceptions described below. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Definition of Breach of Security

A breach of security generally means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Good-faith acquisition by an employee or agent for the entity’s purposes is not a breach if the information is neither misused nor further disclosed. In a whiteboard photo scenario, taking or sharing the image for non-work reasons—or any external disclosure—typically meets the definition of unauthorized acquisition. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/title6.pdf?utm_source=openai))

Because the image is a digital file, it is “computerized data.” If the image captured names with treatment details, personal information confidentiality has been compromised, and you should proceed with your breach analysis and response. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Encryption Safe Harbor

Delaware’s encryption safe harbor provides that acquisition of encrypted personal information is not a breach unless the encryption key was also acquired or is reasonably believed to have been compromised. Practically, a plain photo of a whiteboard is not encrypted data, so this safe harbor will rarely apply to the incident described. It is far more relevant to databases or exports that are strongly encrypted with no encryption key compromise. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

If you rely on the safe harbor, document your encryption method and why you concluded no encryption key compromise occurred. This protects your position if the decision is later questioned. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Notification Requirements for ASCs

Data breach notification timing

Once you determine a breach occurred, you must notify affected Delaware residents without unreasonable delay and within 60 days, unless law enforcement requests a delay or federal law requires a shorter timeline. Delaware also recognizes that you may not be able to identify all affected residents within 60 days; in that case, you must notify each resident as soon as practicable after you identify them. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

What to include and how HIPAA fits

As a healthcare provider, you also follow HIPAA’s Breach Notification Rule. HIPAA requires notice to individuals without unreasonable delay and no later than 60 days from discovery, and it specifies notice content (description of the breach, types of data involved, steps to protect themselves, what you are doing, and contact information). Align your Delaware notice with these elements for healthcare provider data compliance. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))

If Social Security numbers are involved

If the breach includes Social Security numbers, Delaware requires you to offer at least one year of free credit monitoring and to provide information on placing a credit freeze. This is not usually implicated by a whiteboard photo, but confirm whether SSNs were exposed through any related images or files. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Using model notification forms

The Delaware Department of Justice (DOJ) provides model notification forms. While you can customize your content, using the model structure helps ensure clarity and completeness for affected residents. ([attorneygeneral.delaware.gov](https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/))

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Reporting to the Attorney General

When a breach affects more than 500 Delaware residents, you must notify the Delaware Attorney General at or before the time you notify residents. The DOJ offers an online reporting portal and a fillable form; using these model formats is deemed appropriate written notice. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Two important updates took effect on September 2, 2026: (1) if you use substitute notice (for example, because you lack sufficient contact information), you must also provide notice to the Attorney General; and (2) if you could not identify affected residents within 60 days, you must still notify the Attorney General within 60 days after determining a breach occurred. Additionally, Delaware narrowed the HIPAA/GLBA safe harbor so that compliance is deemed only with the state’s 60-day timing requirement, not with all other Delaware-specific obligations such as Attorney General notification. ([legis.delaware.gov](https://www.legis.delaware.gov/json/BillDetail/GeneratePdfDocument?docTypeId=2&legislationId=143107&legislationName=HB381&legislationTypeId=1))

Exemptions from Breach Definition

Delaware recognizes two key exemptions that matter in this scenario:

  • Good-faith employee or agent access for the entity’s purposes, provided there is no unauthorized use or further disclosure.
  • Encrypted data with no reasonable belief of encryption key compromise.

Separately, even when a breach occurred, notification is not required if, after an appropriate investigation, you reasonably determine the incident is unlikely to result in harm to the affected individuals. Document your harm analysis thoroughly if you rely on this exception. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Enforcement and Penalties

The Delaware Attorney General, through the Consumer Protection Unit, may bring actions in law or equity to ensure compliance and to recover direct economic damages resulting from violations. Delaware also maintains a public database of reported breaches, underscoring the importance of timely, accurate reporting. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

For a whiteboard photo incident, your best defense is a disciplined response: promptly secure and remove the image, preserve evidence, complete your risk and harm assessment, meet data breach notification timing, provide Delaware Attorney General notification when required, and use model notification forms to speed accurate communications. ([attorneygeneral.delaware.gov](https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/))

FAQs

What constitutes a breach of security under Delaware law?

It’s the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. A staff member capturing and sharing a whiteboard photo with patient names and treatment details outside authorized purposes typically qualifies. Good-faith access for work, without misuse or further disclosure, is not a breach. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/title6.pdf?utm_source=openai))

When must Delaware ASCs notify affected individuals of a data breach?

You must notify without unreasonable delay and no later than 60 days after determining a breach occurred, subject to limited law-enforcement delays or shorter federal timelines. If you cannot identify all affected individuals within 60 days, notify newly identified individuals as soon as practicable once identified. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Are there exemptions to data breach notification requirements?

Yes. Notification is not required if, after an appropriate investigation, you reasonably determine the breach is unlikely to result in harm. Also, encrypted data is exempt unless there is an encryption key compromise; and good-faith employee acquisition without misuse or further disclosure is not a breach. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

What penalties apply for failing to comply with notification rules?

The Attorney General can pursue actions to enforce compliance and recover direct economic damages. The state’s enforcement authority is in addition to other applicable laws, so noncompliance can also create regulatory and reputational exposure for healthcare providers. ([delcode.delaware.gov](https://delcode.delaware.gov/title6/c012b/))

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles