FTC Issues Guide for Businesses on Handling Data Breaches
Time 2 Minute Read

On October 25, 2016, the Federal Trade Commission released a guide for businesses on how to handle and respond to data breaches (the “Guide”). The 16-page Guide details steps businesses should take once they become aware of a potential breach. The Guide also underscores the need for cyber-specific insurance to help offset potentially significant response costs.

The Guide lists several actions for a business to take if it suspects or confirms it has experienced a data breach. These include securing operations, fixing vulnerabilities and notifying appropriate parties. According to the Guide, businesses should consider “assembl[ing] a team of experts to conduct a comprehensive breach response,” including independent forensic investigators and outside legal counsel.

The Guide also emphasizes the importance of breach notification and stresses that notification should be made to individuals, other affected businesses, regulators and law enforcement, taking into account all applicable state data breach notification laws and federal regulations (e.g., the HIPAA Breach Notification Rule or the Gramm-Leach-Bliley Act). The Guide also highlights the need for expedient notification to allow affected parties to take steps to protect their information as soon as possible, and provides a model breach notification letter.

Finally, the Guide serves as yet another reminder to businesses to ensure that their cybersecurity programs include both adequate cybersecurity safeguards and appropriate insurance coverages, including first-party and third-party cyber/crime insurance coverages. Failure to maintain either component may hinder an appropriate cyber response as well as limit or preclude coverage for any resulting cyber losses and expenses.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 2 Minute Read

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit held that the 2024 amendment to Illinois’ Biometric Information Privacy Act, limiting damages, applies retroactively to pending cases.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page