Delaware’s HB 381: Updated Data Breach Notification Obligations for Health Care Organizations
Delaware House Bill 381, signed into law on Sept. 2, 2026, amends Delaware’s data breach notification statute in Chapter 12B of Title 6 and is particularly significant for health care providers experiencing a growing volume of cybersecurity incidents and ransomware attacks. The legislation clarifies when organizations must notify the Delaware Attorney General following a computer security breach and strengthens state oversight of breach-response activities.
Although health care providers are already subject to the federal breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA), HB 381 narrows certain exemptions that previously applied to HIPAA-regulated entities. Legal analyses of the bill indicate that health care organizations may no longer be able to rely solely on HIPAA compliance to satisfy all Delaware notification obligations. Instead, providers must independently evaluate whether Delaware state reporting requirements are triggered following a cybersecurity event.
The change comes at a time when hospitals, physician groups, health systems and business associates continue to face increasing cyber threats targeting protected health information (PHI). In many health care breaches, organizations may require weeks or months to determine precisely which patients were affected. HB 381 addresses this reality by clarifying Attorney General notification obligations when affected Delaware residents cannot be readily identified after a breach has been determined. The law therefore places greater emphasis on early engagement with state regulators, even while a forensic investigation remains ongoing.
For Delaware health care providers, the practical implication is that incident-response plans should be reviewed to ensure coordination between HIPAA breach notification requirements and Delaware’s revised state-law obligations. Compliance teams, privacy officers, information security personnel and legal counsel should evaluate whether existing breach-response protocols adequately address Attorney General notification, timing considerations, and substitute-notice procedures under Delaware law. HB 381 also underscores the importance of documenting investigative efforts, patient-impact assessments, and decision-making processes during a cybersecurity incident.
Overall, HB 381 reflects a broader regulatory trend toward heightened governmental oversight of cybersecurity incidents in the health care sector. For providers that maintain sensitive patient information, the bill increases the likelihood that a significant breach will involve not only federal HIPAA reporting requirements but also direct scrutiny from Delaware regulators, making a coordinated and well-documented response more critical than ever.

