Three breach disclosures in eight days, three very different delays, one converging outcome.
RTX Corporation was breached on June 25, 2026 and began notifying victims on July 23 — 28 days. A class action followed almost immediately, alleging RTX “kept class members in the dark and deprived them of an opportunity to timely mitigate.”
CareCloud was breached March 10–16, 2026, confirmed the affected data types on June 24, and began notifying at least 345,000 people on August 3 — 140 days from intrusion.
Origin Energy publicly characterised the threat as not credible, then confirmed 900,000 customers exposed three weeks later.
The interesting case is RTX, because 28 days is not obviously slow — and nobody can say authoritatively whether it was.
Nobody Measures the Thing Being Litigated
The industry’s best current breach-timing data comes from IBM’s Cost of a Data Breach 2026, which the Ponemon Institute built by interviewing staff at more than 600 organisations breached between March 2025 and February 2026. Its headline timing figure:
- 247 days mean time to identify and contain a breach — up six days, reversing five consecutive years of decline
- Average breach cost of $4.99 million globally, a record and a 10% year-over-year increase
- US organisations averaged more than twice the global cost figure
- Roughly 40% of breached organisations achieved complete recovery; fewer than 5% recovered within seven weeks
Those are real, current, and measured. They also do not answer the question in front of RTX’s court, because identify-and-contain is a different clock than notify. An organisation can contain an intrusion in a week and take four months to work out whose records were in it. CareCloud appears to have done roughly that — access ended March 16, and the data-type determination did not land until June 24.
Search for a current, authoritative measure of incident-to-notification time across industries and there isn’t one. The most-cited attempt is a Radar analysis published via the IAPP covering January 2016 to June 2017 — it put occurrence-to-discovery at 13.2 days and discovery-to-notification at 29.1. That dataset is a decade old, drawn from organisations running automated incident-decisioning software, and its own author flagged that this skews it faster than the field. It cannot tell you what normal looks like in 2026, and it should not be used to grade anyone.
So the honest position on RTX is narrower than a verdict: it took 28 days, it notified victims on July 23 and the Massachusetts regulator on July 24 — putting affected individuals a day ahead of the regulator — and it was sued anyway.
That absence of a benchmark is not a gap in this article. It is the mechanism driving the litigation.
Thirty-one states require notification “without unreasonable delay” and there is no measured baseline for what reasonable means. When a standard is defined by a word and no data anchors the word, the definition gets set somewhere — and the venue that has volunteered is the complaint, argued case by case, in front of juries with no industry median to compare against. Every defendant is graded against an unstated norm that the plaintiff gets to characterise first.
A company can execute breach response competently, prioritise victims over regulators, and still find the four weeks it spent on forensics reframed as the injury itself.
What the Delay Is Actually Made Of
The defence of any notification gap is that the work is real, and it is.
An organisation that detects an intrusion cannot notify anyone on day one because it does not yet know who to notify. The sequence is unavoidable: contain, image the affected systems, determine what the attacker accessed versus what they merely could have accessed, map accessed records back to identifiable people, deduplicate the resulting list across business units and legacy systems that identify the same person three different ways, determine jurisdiction for each person because notification content differs by state, then stand up a notification vendor and a call centre before the first letter lands.
Notifying early and wrongly has its own costs, and a correction never reaches everyone who received the first letter. Conduent’s breach went from a stated 10 million victims to 25 million over the course of its disclosure — the opposite failure, and no better for the people caught in the revision.
CareCloud’s 140 days illustrate the legitimate version of slow. As a business associate serving more than 45,000 healthcare providers, CareCloud generally cannot notify patients directly. Under HIPAA the covered entities — the practices and hospitals — usually carry that duty, and they cannot discharge it until CareCloud tells each of them which of their patients are in scope. CareCloud has not said how many of its provider clients were affected, but the scoping work runs per client, and the notification chain cannot start at any one of them until it finishes.
The work is real. The question the courts are now answering is whether the person whose Social Security number was in circulation for those 140 days should bear the cost of it.
The Answer Courts Are Converging On
Delayed notification has moved from context to claim.
Courts have found that delaying notification can constitute a plausible breach of the defendant’s duty to protect personal and protected health information — a standalone theory, independent of whether the underlying security was negligent. More consequentially, plaintiffs use delay to argue willful or grossly negligent conduct, which in several statutory schemes opens the door to treble damages.
That is the mechanism converting a defensible forensic timeline into a multiplier.
Standing remains genuinely unsettled, and defendants still win on it. The circuits split sharply on whether increased risk of future identity theft is an injury-in-fact: the Sixth, Seventh, Ninth and D.C. Circuits have accepted it at the pleading stage, while the Second, Fourth, Eighth and Eleventh have generally rejected it. The Supreme Court’s decision in LabCorp v. Davis (2025) left open the related question of whether a damages class may include uninjured members, and that fight is ongoing.
But delay-based theories partly route around the standing problem, because they supply something the pure risk-of-future-harm theory lacks: a concrete window during which the plaintiff demonstrably could have frozen credit, filed a fraud alert, or requested an IRS Identity Protection PIN, and did not, because nobody told them. That is a specific lost opportunity with a start date and an end date, which is a far more comfortable shape for an Article III analysis than a probabilistic future.
Four Clocks, None of Them Synchronised
The regulatory environment is tightening around the gap, unevenly, with deadlines that trigger on different events:
| Regime | Deadline | Clock starts at |
|---|---|---|
| California SB 446 (eff. Jan 1, 2026) | 30 calendar days | Discovery of, or being informed of, the breach |
| HIPAA Breach Notification Rule | 60 days | Discovery |
| SEC Item 1.05 | 4 business days | Determination that the incident is material |
| GDPR Art. 33 | 72 hours | Awareness (to the supervisory authority) |
| CIRCIA (not yet in force) | 72 hours; 24 hours for ransom payments | Reasonable belief a covered incident occurred |
California’s SB 446 is the significant 2026 change, replacing a flexible “without unreasonable delay” standard with a hard 30-day countdown, plus a requirement to send the AG a sample notice within 15 days of individual notices going out where more than 500 California residents are affected. It permits delay for law enforcement needs or to determine scope and restore system integrity — but the burden of justifying that has shifted onto the company.
Twenty states now specify numeric deadlines between 30 and 60 days. The remaining thirty-one still say “without unreasonable delay,” which is the language plaintiffs’ counsel most wants to litigate because it means whatever a jury decides it means. Our US state breach notification requirements tracker maps the full patchwork.
CIRCIA remains the outstanding federal piece. Its 72-hour incident and 24-hour ransom-payment reporting requirements for the 16 critical infrastructure sectors have slipped repeatedly; the 2026 Unified Agenda points to a final rule in September 2026, after a DHS funding lapse disrupted stakeholder engagement earlier in the year. Reporting on its status has been inconsistent, and operators should treat any specific date as provisional.
The Structural Problem Nobody Is Fixing
Note what the SEC clock measures. Item 1.05 starts on the materiality determination — a judgement about impact on investors — and it runs in four business days, by far the fastest deadline on the list.
Amgen filed its 8-K on July 29 describing a cloud breach that reached patient PHI, intellectual property and R&D data, while stating it did not expect any impact on its financial position, products or operations. That filing satisfies the SEC. It tells not one affected patient anything.
So the fastest mandatory disclosure in American breach regulation is the one aimed at shareholders, and the slowest are the ones aimed at the people whose Social Security numbers were taken. An investor learns in four business days that an incident occurred; a victim learns in thirty to sixty days, or a hundred and forty, who they are.
The second structural gap is the vendor chain. Every notification regime was written assuming a direct relationship between the breached organisation and the affected person. That assumption no longer describes how data is held. CareCloud’s patients have no relationship with CareCloud. The 2,000 hospitals reached through Craneware did not choose their billing vendor’s security posture. When the breached entity is three parties removed from the data subject, the notification duty lands on whoever is closest to the individual — and that party learns last, is smallest, and has the least capacity to act.
What Would Actually Close the Gap
The reflex fix is a shorter deadline, and it is the wrong one. Cutting 60 days to 30 does not make forensics faster; it makes notices vaguer, and a notice that cannot say what was taken gives its recipient nothing to act on.
Three changes would do more:
- Staged notification as the standard, not the exception. An early notice that says “we were breached, we do not yet know if you are affected, freeze your credit now” is more useful on day five than a precise notice on day ninety. GDPR already separates the 72-hour regulator notification from the individual notification for exactly this reason; US regimes largely do not.
- A contractual notification clock in vendor agreements. The business-associate chain is where the time goes. Contracts that specify how fast a processor must deliver scoped affected-person lists to each controller would compress the largest component of the delay, and it requires no legislation.
- Treat the notification window as a control to be tested. Organisations rehearse containment and recovery. Almost none rehearse the mapping from “records accessed” to “people notified,” which is where the weeks actually accumulate. It is a data-inventory problem wearing a legal costume.
RTX’s 28 days may or may not have been reasonable. The point is that no one can currently answer that from data — and a standard nobody measures will be set by whoever files first.
Further Reading
- IBM / Ponemon Institute, Cost of a Data Breach Report 2026 — 600+ organisations breached March 2025–February 2026; measures identify-and-contain, not notification
- IAPP, From incident to discovery to breach notification: Average time frames — Radar data, January 2016–June 2017; the most-cited notification-timing analysis, and now a decade out of date
- California SB 446, effective January 1, 2026
- Privacy Rights Clearinghouse, Data Breach Notification Laws: A 50-State Survey (2026 Edition)
- CISA, Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
- Duane Morris, Class Action Defense — Data Breach Class Actions



