Maryland Healthcare Data Breach Notification Law: Requirements, Deadlines, and HIPAA Compliance
Maryland Data Breach Notification Law Overview
Maryland’s Personal Information Protection Act (PIPA) requires businesses to investigate potential breaches and notify Maryland residents when their personal information is at risk of misuse. “Personal information” includes classic identifiers such as Social Security numbers and, importantly for healthcare, certain health and insurance data; for example, “health information” is defined and can be a trigger when combined with a name. These rules sit alongside broader healthcare data security obligations you already manage. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?archived=False&article=gcl&enactments=False§ion=14-3501&utm_source=openai))
Healthcare organizations must also make a Maryland Office of the Attorney General Notification before notifying consumers. That OAG notice must include the number of affected residents, a description of what happened, the steps taken or planned, and a sample consumer letter—an “AG-first” step that is unique among some states. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
Notification Procedures and Deadlines
Maryland PIPA workflow and breach notification deadlines
- Investigate promptly. If you determine the breach is likely to result in misuse, you must notify affected Maryland residents “as soon as reasonably practicable,” and no later than 45 days after discovery or notice of the breach. Maintain records for three years if you conclude notice is not required. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- Notify the Maryland Office of the Attorney General before sending consumer notices, providing the required details and a sample letter. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- If a vendor/business associate maintains the data, it must notify the data owner or licensee within 10 days of discovery. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- Law-enforcement delay is permitted; if the 45-day period has elapsed, you must notify within seven days of the agency’s determination that notice won’t impede the investigation. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- If 1,000+ Maryland residents are notified, you must also notify each nationwide consumer reporting agency without unreasonable delay. ([codes.findlaw.com](https://codes.findlaw.com/md/commercial-law/md-code-coml-sect-14-3506.html?utm_source=openai))
HIPAA timelines you must meet in parallel
- Individuals: Without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
- HHS/OCR: For breaches affecting 500+ individuals, notify within 60 days of discovery; for fewer than 500, report to HHS within 60 days after the end of the calendar year. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html?utm_source=openai))
- Media: If 500+ residents of a state or jurisdiction are affected, notify prominent media outlets within the same 60-day window. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
HIPAA Breach Notification Rule in Healthcare
The HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414) applies to HIPAA covered entities and business associates. A breach is presumed reportable unless a documented four-factor risk assessment shows a low probability that PHI has been compromised. You must notify individuals, and in larger events, HHS and the media, all within HIPAA’s fixed deadlines. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
Business associates must provide notice to the covered entity without unreasonable delay so the covered entity can meet its obligations. HHS specifies the submission process and timing for notices to the Secretary. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html?utm_source=openai))
Content Requirements for Consumer Notifications
What Maryland PIPA requires in consumer notices
- Description of the categories of personal information reasonably believed to have been acquired. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- Contact information for your organization, including address, phone, and toll-free number (if maintained). ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- Toll-free telephone numbers and addresses for the major consumer reporting agencies. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
- Toll-free numbers, addresses, and websites for the Federal Trade Commission and the Maryland Office of the Attorney General, plus a statement that people can obtain identity-theft prevention information from those sources. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
For breaches granting access to an email account only, the law permits specialized electronic notice with specific instructions (for example, to change passwords), subject to delivery limitations. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
What HIPAA requires in individual notices
- A brief description of what happened, including breach and discovery dates. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
- The types of unsecured PHI involved. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
- Steps individuals should take to protect themselves. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
- What you are doing to investigate, mitigate harm, and prevent recurrence, and how to contact you for more information. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
Maryland Personal Information Protection Act Implications
PIPA is broader than HIPAA: it covers non-PHI personal information such as Social Security numbers, financial account data, login credentials, and certain health and insurance identifiers tied to a name. A healthcare organization can trigger PIPA even when the incident doesn’t involve medical records—for example, if employee payroll data or patient portal credentials are exposed. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?archived=False&article=gcl&enactments=False§ion=14-3501&utm_source=openai))
When an incident involves PHI and you are a HIPAA Covered Entity (or business associate), compliance with HIPAA’s breach notification rule deems you in compliance with PIPA for that event—though Maryland’s “AG-first” notice and content specifics still warrant operational attention. ([law.justia.com](https://law.justia.com/codes/maryland/commercial-law/title-14/subtitle-35/section-14-3507/?utm_source=openai))
Confidentiality of Medical Records Act Compliance
Maryland’s Confidentiality of Medical Records Act (Health–General, Title 4, Subtitle 3) requires providers to maintain the confidentiality of medical records and permits disclosure only under defined circumstances. Your HIPAA policies should be harmonized with these state rules on access, use, and redisclosure to avoid inconsistent practices. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=ghg&enactments=false§ion=4-302&utm_source=openai))
For Health Information Exchanges and related activities, COMAR provisions (often referenced as “Confidentiality of Medical Records Act COMAR”) reinforce privacy and security, require alignment with HIPAA/HITECH, and mandate recordkeeping for investigations of breaches and non-HIPAA violations for at least five years. ([regs.maryland.gov](https://regs.maryland.gov/us/md/exec/comar/10.25.18/index.full.html?utm_source=openai))
Penalties and Enforcement for Non-Compliance
PIPA violations are deemed unfair or deceptive trade practices under Maryland’s Consumer Protection Act (Title 13), making you subject to the Act’s enforcement and penalty framework. Civil penalties can reach up to $10,000 per violation and up to $25,000 for subsequent repeats of the same violation, assessed by the Consumer Protection Division or courts. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/laws/StatuteText?article=gcl§ion=14-3508&utm_source=openai))
Consumers may also bring private actions under Title 13 for actual damages (with potential attorney’s fees), creating additional exposure when breach handling causes demonstrable harm. Separately, HIPAA violations can lead to OCR investigations, corrective action plans, and significant civil monetary penalties for covered entities and business associates. These data breach notification penalties underscore the value of mature incident response and documentation. ([law.justia.com](https://law.justia.com/codes/maryland/2024/commercial-law/title-13/subtitle-4/section-13-408/?utm_source=openai))
Conclusion
In healthcare, you must manage two synchronized regimes: Maryland’s PIPA—with its AG-first notice, 45-day deadline, and specific letter content—and HIPAA’s Breach Notification Rule, with its 60-day clock and federal reporting. Aligning these frameworks, tightening vendor oversight, and integrating Confidentiality of Medical Records Act and COMAR requirements will keep your breach response compliant and patient-centered.
FAQs
What are the notification deadlines under Maryland law?
Notify affected Maryland residents as soon as reasonably practicable but no later than 45 days after discovering or being notified of a breach; vendors maintaining data must notify the data owner within 10 days. Law-enforcement delays are allowed, with a seven-day catch-up if the 45-day window has run. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
How does Maryland law interact with HIPAA for healthcare breaches?
If you are subject to and comply with HIPAA’s Breach Notification Rule, you are deemed in compliance with PIPA for that incident. You still must operationalize Maryland’s AG notification sequence and ensure timely, consistent notices across both regimes. ([law.justia.com](https://law.justia.com/codes/maryland/commercial-law/title-14/subtitle-35/section-14-3507/?utm_source=openai))
What information must be included in breach notifications?
Under Maryland PIPA, include the categories of information involved, your contact details (including toll-free number, if any), the major credit bureaus’ toll-free numbers/addresses, and FTC and Maryland OAG contact information with an identity-theft prevention statement. HIPAA letters must describe what happened, the PHI involved, steps people should take, and your mitigation and contact details. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
Who must be notified besides affected individuals?
Before notifying consumers, you must notify the Maryland Office of the Attorney General and include required details with a sample letter. If 1,000+ residents are notified, you must also notify the nationwide consumer reporting agencies. Under HIPAA, you must notify HHS/OCR—and, for large breaches, the media. ([mgaleg.maryland.gov](https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=gcl§ion=14-3504))
Table of Contents
- Maryland Data Breach Notification Law Overview
- Notification Procedures and Deadlines
- HIPAA Breach Notification Rule in Healthcare
- Content Requirements for Consumer Notifications
- Maryland Personal Information Protection Act Implications
- Confidentiality of Medical Records Act Compliance
- Penalties and Enforcement for Non-Compliance
- FAQs
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.