← All jurisdictions
PA · data breach notification
medPennsylvania
73 Pa. Stat. §2301 et seq.
Individual deadline
No fixed limit
Trigger standard
Any breach
AG / regulator
Not required
| Notice to individuals | in the most expedient time possible and without unreasonable delay |
| Risk-of-harm standard | None, notice required on any qualifying breach of covered personal information. |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Not required for private-entity breaches. |
| Credit reporting agencies | Notify CRAs above 500 residents. |
| Credit monitoring | >500 affected: 12 months credit monitoring + free credit report (2023 amendment) |
| Substitute notice | Available if cost exceeds $100,000 or more than 175,000 affected. |
| Private right of action | Yes. |
| Penalties | UTPCPL enforcement |
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Pennsylvania breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →