Must Every Health Data Breach Be Reported Under GDPR Within 72 Hours?
No. The GDPR does not require every breach involving health data to be reported through the same channel within 72 hours. Article 33 requires a controller to notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after awareness, unless the breach is unlikely to result in a risk to people’s rights and freedoms. Article 34 uses a separate high-risk test for communication to affected people.
Health data is sensitive, so its nature can weigh heavily in the risk assessment. Sensitivity does not remove the need to examine what happened, whose data was affected, whether anyone could identify the people, what safeguards worked, and what consequences are reasonably possible. Every personal data breach still needs an internal record, including breaches that do not cross a notification threshold.
What counts as a personal data breach?
Article 4(12) defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. The definition covers confidentiality, integrity, and availability. A breach is not limited to an attacker downloading a database.
A mistaken disclosure can be a confidentiality breach. An unauthorized change can be an integrity breach. Loss of access can be an availability breach, including a temporary loss when the circumstances can affect people’s rights and freedoms. Planned maintenance is not automatically a personal data breach merely because a system is unavailable.
Not every security incident involves personal data. An outage affecting only a public marketing page may be a security or reliability event without compromising personal data. The response process should classify the incident before applying Articles 33 and 34, while avoiding delay in investigation.
When does the 72-hour period begin?
The clock starts when the controller becomes aware of the personal data breach, not necessarily when the first alert appears or when a processor finishes a full investigation. The European Data Protection Board says a controller is aware when it has a reasonable degree of certainty that a security incident occurred and personal data was compromised.
Some alerts remain uncertain at first. The controller may need a short investigation to establish whether personal data was involved. The EDPB still stresses prompt action. An organization cannot avoid awareness by leaving alerts unreviewed or waiting for complete forensic certainty before making the threshold decision.
Record the alert time, escalation time, facts that established reasonable certainty, and person who made the awareness decision. Audit evidence matters here. The guide to Google Cloud Data Access audit logs explains why seeing administrative changes does not prove that the needed data-access events were captured.
When must the supervisory authority be notified?
Article 33 requires notification unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is required, the controller acts without undue delay and, where feasible, within 72 hours after awareness. A notification made later must include reasons for the delay.
The test is not whether harm has already occurred. It considers the likelihood and severity of possible effects. The EDPB identifies consequences such as loss of control, discrimination, identity fraud, financial loss, damage to reputation, and loss of confidentiality for information protected by professional secrecy.
Health data can increase possible severity because it is a special category and can reveal private conditions or care. The broader GDPR treatment of health data also appears in the review of automated appointment eligibility under Article 22. Neither topic supports a shortcut that labels every health-data event identical. Context still controls the notification assessment.
When must affected people be informed?
Article 34 uses a higher threshold. The controller communicates the breach to affected people without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Authority notification under Article 33 and individual communication under Article 34 are therefore related but distinct decisions.
Article 34 also lists conditions where individual communication is not required. One concerns appropriate protection measures that made the affected personal data unintelligible to unauthorized people, such as effective encryption. Another applies when later measures ensure that the high risk is no longer likely to materialize. A third addresses disproportionate effort and requires an equally effective public communication or similar measure.
Do not turn encryption into a universal exemption. Verify whether the affected data was encrypted, whether the relevant key remained protected, whether readable copies or credentials were also exposed, and whether integrity or availability consequences remain. The answer belongs to the incident facts.
How do controller and processor duties differ?
The controller decides whether the Article 33 and Article 34 thresholds are met and makes the required notifications. A processor that becomes aware of a personal data breach must notify the controller without undue delay. Article 33 does not give the processor its own 72-hour waiting period before informing the controller.
The processing contract should support fast escalation, evidence preservation, contact routes, and phased updates. It cannot transfer the controller’s legal decision entirely to a cloud provider or another processor. The controller needs enough information to assess risk and meet its own deadline.
Cloud log location and access can affect that investigation. CloudTrail multi-region audit data shows why event contents, destination, keys, and lifecycle need an approved evidence zone. An incident team should not copy health content into a separate ticket merely to centralize evidence.
What information goes into an Article 33 notification?
The notification describes the nature of the breach and, where possible, the categories and approximate numbers of affected people and personal data records. It provides the data protection officer or other contact point, describes likely consequences, and describes measures taken or proposed to address and mitigate the breach.
The GDPR allows information to be provided in phases when everything cannot be supplied at once. That provision supports timely initial notification followed by facts as the investigation develops. It does not justify an empty notice when known information can already be provided.
Keep estimates labeled as estimates and preserve the method used. If later evidence changes the scope, record the revision. Avoid patient names, appointment details, diagnostic information, or raw access logs in the notification workflow unless they are necessary, authorized, and transmitted through an approved route.
What must be documented when no notification is sent?
Article 33(5) requires the controller to document any personal data breach. The record covers facts, effects, and remedial action. It must allow the supervisory authority to verify compliance with Article 33. A decision not to notify therefore needs a reasoned record, not silence.
Document the breach classification, awareness time, data categories, approximate scope, affected groups, safeguards, likely consequences, risk decision, notifications considered, measures taken, and reviewers. Record what remains unknown and when it will be checked again. Keep the report free of unnecessary health content.
Marketing and operational datasets also need separation. The article on measuring clinic show rate without appointment details demonstrates a minimization pattern: retain the state needed for the purpose without sending consultation content into the reporting path.
How can an incident team run the decision process?
- Contain the incident while preserving relevant technical evidence.
- Determine whether personal data suffered a confidentiality, integrity, or availability breach.
- Identify the controller, processors, systems, jurisdictions, and competent escalation contacts.
- Record when the controller reached reasonable certainty that personal data was compromised.
- Assess likelihood and severity for affected people’s rights and freedoms.
- Decide Article 33 authority notification and Article 34 individual communication separately.
- Notify with known facts, use phased updates where needed, and explain any delay.
- Document the breach, decisions, remediation, and later scope changes.
Operational inference: run legal assessment and technical investigation in parallel once personal-data compromise is reasonably certain. This reduces the risk that a team treats complete forensics as a prerequisite for the first notification. The exact workflow, authority, and additional deadlines still depend on establishment, cross-border processing, Member State rules, contracts, and sector duties.
Frequently asked questions
Does every breach involving health data require authority notification?
No universal answer applies. Article 33 requires notification unless the breach is unlikely to create a risk. Health data can increase severity, but the controller must assess the incident’s actual likelihood and consequences.
Does the 72-hour period begin when a processor completes its report?
No. The controller’s period is tied to controller awareness. A processor must tell the controller without undue delay after becoming aware of a breach.
Must affected people always be contacted within 72 hours?
No. Article 34 requires communication without undue delay when high risk is likely. It does not use the same 72-hour wording as Article 33.
Can a controller skip the internal record when notification is unnecessary?
No. Article 33(5) requires documentation of every personal data breach, including the facts, effects, and remedial action.
References
- European Union, “Regulation (EU) 2016/679, General Data Protection Regulation,” retrieved August 16, 2026, https://eur-lex.europa.eu/eli/reg/2016/679/oj?locale=EN
- European Data Protection Board, “Guidelines 9/2022 on personal data breach notification under GDPR,” final version, retrieved August 16, 2026, https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en
Related articles
Does CloudWatch Logs Data Protection Permanently Redact PHI Already Stored?
No. An Amazon CloudWatch Logs data protection policy does not permanently redact PHI that was already stored before the policy took effect.…
Does a Cloud Provider Need a HIPAA BAA If It Cannot Decrypt the ePHI?
Yes. A cloud provider can be a HIPAA business associate even when it stores only encrypted ePHI and never receives the decryption key. HHS…
Why Does Google Calendar events.list Return an Appointment That Starts Before timeMin?
Google Calendar can return an event that starts before timeMin because events.list uses overlap boundaries. The API defines timeMin as an…