North Carolina Identity Theft Protection Act: Hospital Breach Notification Rules, Deadlines, and Requirements
Definition of Security Breach
Under North Carolina’s Identity Theft Protection Act, a “security breach” means the unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information when illegal use has occurred or is reasonably likely to occur, or when the incident creates a material risk of harm. Encrypted data is covered only if the confidential process or key was also compromised. Good‑faith access by an employee or agent is not a breach if used lawfully and not further disclosed. Redaction means rendering data unreadable or truncating identifiers so no more than the last four digits are accessible. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Personal Information Covered
For a hospital or health system, a North Carolina “personal information breach” is triggered when a resident’s first name or first initial and last name appear in combination with one or more “identifying information” data elements. Publicly available directory information and government records lawfully available to the public are excluded. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Data elements that commonly trigger notification
- Social Security number or employer taxpayer identification number. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
- Driver’s license, state ID, or passport number. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
- Financial account, credit card, or debit card numbers (especially when an access code, PIN, or password is involved). ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
- Digital signatures and passwords. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
- Biometric identifiers such as fingerprints or other biometric data. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
- Any other number or information that can be used to access a person’s financial resources. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bysection/chapter_14/gs_14-113.20.html))
For breach-notification purposes, state law expressly excludes electronic identification numbers, email addresses, internet account numbers or usernames, a parent’s legal surname prior to marriage, and passwords—unless those items would permit access to a financial account or resources. This means many clinical identifiers alone (for example, a medical record number) may not trigger state notice, even though HIPAA may still require action. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Notification Requirements and Deadlines
If your hospital owns or licenses personal information of North Carolina residents and discovers a breach, you must notify affected individuals without unreasonable delay. Third‑party vendors (business associates, service providers) that maintain or possess personal information on your behalf must notify you—the data owner—immediately following discovery, subject to any lawful law‑enforcement delay. The Act applies to personal information in any form (computerized, paper, or otherwise). ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
HIPAA still governs healthcare data security. When unsecured protected health information (PHI) is involved, hospitals must meet the HIPAA Breach Notification Rule: notify affected individuals without unreasonable delay and in no case later than 60 days after discovery; notify prominent media if a breach affects more than 500 residents of a state; and notify HHS (immediately—no later than 60 days—for breaches affecting 500+ individuals, and within 60 days after the end of the calendar year for smaller breaches). These HIPAA duties apply in addition to North Carolina’s notification compliance obligations. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Content and Method of Notification
What the individual notice must include
- A general description of the incident. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- The type of personal information involved. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- The general acts taken to protect information from further unauthorized access. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- A telephone number for more information, if one exists. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- Advice directing the person to remain vigilant by reviewing account statements and monitoring free credit reports. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- The toll‑free numbers and addresses for the major consumer reporting agencies. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- The toll‑free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, with a statement that the individual can obtain identity theft prevention information from those sources. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Permitted delivery methods
- Written notice by mail. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- Electronic notice to individuals who have consented to receive electronic communications (consistent with E‑SIGN). ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
- Telephone notice, if contact is made directly with the affected person. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Substitute Notice Conditions
You may use substitute notice only if: the cost of direct notice would exceed $250,000; or the affected class exceeds 500,000 persons; or you lack sufficient contact information or consent for certain affected individuals (or cannot identify particular affected persons). Substitute notice must include all of the following: email notice (where you have an email address), conspicuous posting on your website, and notification to major statewide media. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Reporting to Authorities
Whenever you provide individual notice of a personal information breach, you must also notify—without unreasonable delay—the North Carolina Attorney General’s Consumer Protection Division and provide the nature of the breach, number of consumers affected, investigative steps, mitigation and prevention steps, and the timing, distribution, and content of your consumer notice. If you notify more than 1,000 individuals at once, you must also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the consumer notice. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
The state also expects your consumer notice to include contact information for the major consumer reporting agencies, the FTC, and the North Carolina Attorney General’s Office, so patients can act promptly to reduce identity theft risk (for example, security freezes and fraud alerts). ([ncdoj.gov](https://ncdoj.gov/protecting-consumers/protecting-your-identity/protect-your-business-from-id-theft/security-breach-information/))
Law Enforcement Delay and Enforcement Penalties
You must delay notice if a law‑enforcement agency states that notification would impede a criminal investigation or jeopardize national or homeland security. The request must be in writing (or you must contemporaneously document the officer’s name, agency, and the request). Once law enforcement lifts the hold, provide notice without unreasonable delay. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Noncompliance is an unfair or deceptive act under G.S. 75‑1.1. The Attorney General may seek injunctive relief and, for knowing statutory violations, civil penalties of up to $5,000 per violation. Individuals injured by a violation may bring a private action and recover treble damages under G.S. 75‑16. Together, these remedies make breach‑notification failures high‑stakes unfair trade practices for healthcare entities. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
FAQs.
What personal information triggers breach notification under the Act?
North Carolina generally requires a name (first name or first initial plus last name) combined with one or more “identifying information” elements—such as SSN, driver’s license/state ID/passport number, financial account or card numbers with any access code, digital signature, password, biometric data, or other information that can access financial resources. For breach‑notification specifically, items like email addresses, usernames, certain electronic identifiers, a parent’s legal surname prior to marriage, and passwords are excluded unless they would permit access to a financial account. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
How soon must hospitals notify patients of a breach?
Under the North Carolina Identity Theft Protection Act, notify affected individuals without unreasonable delay after discovery (and third‑party processors must notify the data owner immediately following discovery). If PHI is involved, HIPAA also requires notice without unreasonable delay and in no case later than 60 days after discovery, plus required media and HHS notifications when thresholds are met. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Can notification be delayed for law enforcement reasons?
Yes. You must delay notice if law enforcement states that notification would impede an investigation or jeopardize security. The request should be in writing or documented by you (including the officer’s name and agency). After law enforcement lifts the hold, send notices without unreasonable delay. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
What penalties apply for non-compliance?
Failure to comply constitutes an unfair trade practice. The Attorney General can seek injunctions and civil penalties up to $5,000 per knowing violation, and injured individuals may recover treble damages under G.S. 75‑16. These remedies apply in addition to any federal HIPAA enforcement exposure for PHI breaches. ([ncleg.gov](https://www.ncleg.gov/enactedlegislation/statutes/html/bychapter/chapter_75.html))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.