Home Glossary What is a Data Breach?
Glossary · Cybersecurity 101

What is a Data Breach?

A data breach is unauthorized access to sensitive data — triggering HIPAA notification, Tennessee state law requirements, and costs averaging $4.44M per incident in 2025.

Glossary · Data breach

A data breach is any unauthorized access to or disclosure of sensitive information — triggering regulatory notification requirements in most cases.

A data breach is a security incident in which sensitive, protected, or confidential information is accessed, disclosed, or stolen by an unauthorized party. Data breaches may involve personal information (names, Social Security numbers, financial records), protected health information (PHI under HIPAA), payment card data (covered by PCI-DSS), or any other category of sensitive business or personal data.

The term "breach" is often used loosely — but for regulatory purposes, a breach has a specific legal definition that varies by applicable framework and jurisdiction. Understanding when an incident legally qualifies as a reportable breach, and what the notification requirements are, is critical for regulated organizations in Tennessee.

Regulatory breach notification requirements

  • HIPAA: Covered entities and business associates must notify affected individuals within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500 or more individuals also require notification to HHS and prominent media notice.
  • Tennessee Identity Theft Deterrence Act: Organizations that maintain personal information about Tennessee residents must notify affected individuals "in the most expedient time possible" following discovery of a breach. No specific timeframe is mandated but delays must be justified.
  • PCI-DSS: Organizations that experience a breach of cardholder data must notify their acquiring bank and card brands (Visa, Mastercard) immediately. Card brand requirements may mandate forensic investigation by a PCI Forensic Investigator (PFI).
  • SEC Rule: Public companies must disclose material cybersecurity incidents within four business days of determining materiality.

Average breach costs in 2025

The IBM Cost of a Data Breach Report 2025 found the global average cost of a data breach reached $4.44 million — the highest ever recorded. Healthcare breaches average $10.93 million, making healthcare the most expensive industry for the 13th consecutive year. Financial services ($6.08M) and pharmaceuticals ($5.82M) rank second and third.

For small businesses, the absolute dollar amounts may be lower, but the relative impact is often more severe — 60% of small businesses close within six months of a major data breach (National Cyber Security Alliance).

Tennessee's Identity Theft Deterrence Act requires notification 'in the most expedient time possible' — there is no specific fixed deadline, unlike some other states. However, delays must be justified, and law enforcement requests may extend timelines. HIPAA-covered entities have a separate 60-day window. SignalPoint's incident response service includes regulatory notification guidance.

The IBM 2025 report shows global averages of $4.44M, but SMB breaches are typically smaller in absolute terms while being proportionally more damaging. Breach costs include forensics, legal fees, regulatory fines, customer notification, credit monitoring services, reputational damage, and business interruption. The National Cyber Security Alliance reports 60% of small businesses close within six months of a major breach.

Stop the next attack before it starts.

Free 30-minute consultation — no commitment, no jargon, no sales pressure.

Schedule nowView pricing
Free monthly threat briefing
Chattanooga-specific threat intelligence, delivered to your inbox. No spam, unsubscribe anytime.