Hawaii Breach Notice Deadlines for Hospitals After a Ransomware Attack Affecting the Neighbor Islands

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Hawaii Breach Notice Deadlines for Hospitals After a Ransomware Attack Affecting the Neighbor Islands

Kevin Henry

Data Breaches

August 09, 2026

7 minutes read
Share this article
Hawaii Breach Notice Deadlines for Hospitals After a Ransomware Attack Affecting the Neighbor Islands

Hawaii Data Breach Notification Law Overview

If ransomware compromises patient or employee data across the Neighbor Islands, Hawaii’s breach statute (HRS Chapter 487N) requires you to notify affected residents “without unreasonable delay” after discovery, while allowing limited postponement for law enforcement and restoration of system integrity. Hospitals that are HIPAA-covered must also meet HIPAA’s 60‑day outer deadline, which functions as a hard cap even when your forensic investigation is ongoing. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Hawaii defines a “security breach” as unauthorized access to and acquisition of unencrypted or unredacted personal information when illegal use has occurred or is reasonably likely to occur and the incident creates a risk of harm. Good‑faith acquisition by an employee for a legitimate purpose is not a breach; encrypted data is generally exempt unless the key is also compromised. ([law.justia.com](https://law.justia.com/codes/hawaii/title-26/chapter-487n/section-487n-1/))

HIPAA‑regulated hospitals that comply with HIPAA’s privacy and security standards are deemed compliant with HRS §487N‑2; however, state‑specific obligations—such as notifying the Office of Consumer Protection (OCP) when you notify 1,000+ residents—still apply in practice. Plan for both HIPAA notifications and Hawaii’s OCP filing when thresholds are met. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Notification Requirements to Office of Consumer Protection

When your hospital sends breach notices to more than 1,000 Hawaii residents at one time, Hawaii law requires written notice to the Office of Consumer Protection (and to nationwide consumer reporting agencies) describing the timing, distribution, and content of the resident notice. Provide this OCP notification “without unreasonable delay” in addition to the notices you send to affected individuals. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

What to include and coordinate

  • Submit the OCP notice in writing and include when, how, and to whom you distributed resident notices. If the ransomware incident spans Maui, Hawaiʻi Island, Kauaʻi, Molokaʻi, or Lānaʻi, ensure your distribution plan reaches those communities. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))
  • For very large events, be prepared to alert the major consumer reporting agencies at the same time you notify OCP. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Government hospitals: Security Breach Written Report (HRS §487N‑4)

Government agencies must also deliver a Security Breach Written Report to the Hawaii Legislature within 20 days after discovering a breach. The report describes the breach, the number of people affected, the notice issued, whether any delay was due to law enforcement, and steps taken to prevent recurrence. If law enforcement says disclosure could impede an investigation or jeopardize national security, the report may be delayed until 20 days after that restriction is lifted. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Definition of Personal Information in Hawaii

Under HRS §487N‑1, “personal information” means a resident’s first name or initial and last name combined with any one of the following, when either element is not encrypted: Social Security number; Hawaii driver’s license or state ID number; or an account, credit, or debit card number with any required access code or password that would permit access to a financial account. Publicly available government records are excluded. ([law.justia.com](https://law.justia.com/codes/hawaii/title-26/chapter-487n/section-487n-1/))

Hawaii’s statutory definition does not list medical information, health insurance information, online account credentials, or biometric data as “personal information.” Even so, a Protected Health Information breach under HIPAA still triggers federal breach notification obligations for hospitals, independent of Hawaii’s narrower PI definition. ([law.justia.com](https://law.justia.com/codes/hawaii/title-26/chapter-487n/section-487n-1/))

Approved Methods of Breach Notification

Hawaii allows several notice channels so you can quickly reach impacted residents—crucial when ransomware disrupts services across the Neighbor Islands. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Primary methods

  • Written notice to the last known address. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))
  • Email notice if the person agreed to electronic communications and the message satisfies E‑SIGN Act requirements (15 U.S.C. §7001). This is your “E‑SIGN Act Compliance” pathway. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))
  • Telephone notice, if you directly reach the affected person. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Substitute Notice Criteria

  • Use substitute notice if: providing notice would cost over $100,000; the affected class exceeds 200,000 people; you lack sufficient contact information or consent (only for those individuals); or you cannot identify particular affected persons. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))
  • Substitute notice must include: email (when available), a conspicuous posting on your website, and notice to major statewide media—consider island‑specific outlets to reach residents on Maui, Hawaiʻi Island, Kauaʻi, Molokaʻi, and Lānaʻi. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Content Requirements for Breach Notices

Hawaii requires a clear and conspicuous notice that, in plain terms, describes: (1) the incident in general terms; (2) the types of personal information involved; (3) steps your hospital is taking to protect data from further unauthorized access; (4) a phone number for more information; and (5) advice to stay vigilant by reviewing account statements and monitoring free credit reports. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

Risk of Harm and Notification Exceptions

Hawaii’s “security breach” definition builds in a risk‑of‑harm test: if illegal use of unencrypted personal information has not occurred and is not reasonably likely to occur—and the incident does not create a risk of harm—it may fall outside the statutory breach definition. Good‑faith employee acquisition for a lawful purpose is excluded, and encrypted data is generally exempt unless the decryption key was also compromised. ([law.justia.com](https://law.justia.com/codes/hawaii/title-26/chapter-487n/section-487n-1/))

Law enforcement can request a temporary delay of notices; you must document the request and resume notification without unreasonable delay once the restriction is lifted. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

For ransomware incident notification under HIPAA, a ransomware attack is usually presumed to be a breach of unsecured Protected Health Information unless your risk assessment shows a low probability that PHI was compromised. That presumption, plus HIPAA’s 60‑day deadline, makes early incident assessment and parallel notice drafting essential. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html?utm_source=openai))

Federal HIPAA Breach Notification Requirements

Hospitals must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. The notice must explain what happened (including dates), what types of PHI were involved, steps individuals should take, what your hospital is doing to mitigate harm and prevent recurrences, and how to contact you (toll‑free phone, email, website, or postal address). ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.404))

Media notice is required if a breach involves 500 or more residents of a state or jurisdiction; provide it without unreasonable delay and within 60 days. For Neighbor Islands impacts, use prominent statewide and island‑serving outlets to reach affected communities. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.406?utm_source=openai))

Report to HHS: for breaches affecting 500 or more individuals, notify the Secretary within 60 days of discovery; for fewer than 500, file with HHS no later than 60 days after the end of the calendar year in which you discovered the breach. Submit via the HHS breach portal. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html?utm_source=openai))

Conclusion

After a Neighbor Islands ransomware event, move on two tracks: comply with Hawaii’s “without unreasonable delay” standard (including OCP notification when 1,000+ residents are notified) and meet HIPAA’s 60‑day cap to individuals, HHS, and—if 500+ residents are affected—prominent media. Use approved notice methods (with E‑SIGN Act‑compliant email where appropriate), include Hawaii‑required content, and document any risk‑of‑harm analyses or law‑enforcement delays. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

FAQs

What is the deadline for hospitals to notify affected individuals in Hawaii?

Hawaii requires notification “without unreasonable delay” after discovery, subject to limited law‑enforcement delay. Because hospitals are HIPAA‑covered, you must also meet HIPAA’s outside limit of 60 calendar days from discovery for individual notices. In practice, start drafting quickly and do not wait for the full forensic report if you can provide a meaningful notice sooner. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

How does Hawaii law define personal information in breach notifications?

“Personal information” is a resident’s first name or initial and last name plus any one of: Social Security number; driver’s license or Hawaii ID number; or a financial account, credit, or debit card number with an access code or password that permits account access. Publicly available government records are excluded. ([law.justia.com](https://law.justia.com/codes/hawaii/title-26/chapter-487n/section-487n-1/))

When is substitute notice allowed under Hawaii breach laws?

Use substitute notice if direct notice would cost more than $100,000, the affected class exceeds 200,000 people, you lack sufficient contact information or consent for certain individuals, or you cannot identify particular affected persons. It must include email (if available), a conspicuous web posting, and notice to major statewide media. ([data.capitol.hawaii.gov](https://data.capitol.hawaii.gov/sessions/session2017/HRS-Chapter-PDF%27s/HRS_0487N.pdf))

What are the federal HIPAA notification requirements for healthcare breaches?

Notify affected individuals without unreasonable delay and within 60 days; include required content elements. If 500+ residents of a state or jurisdiction are affected, also notify prominent media within 60 days. Report to HHS within 60 days for breaches affecting 500+ individuals, or within 60 days after the end of the calendar year for smaller breaches. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.404))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles