← All jurisdictions
VA · data breach notification
medVirginia
Va. Code §18.2-186.6
Individual deadline
No fixed limit
Trigger standard
Risk of harm
AG / regulator
Required
| Notice to individuals | in the most expedient time possible and without unreasonable delay |
| Risk-of-harm standard | notice where breach causes or will cause identity theft or other fraud |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Virginia Attorney General, required for any affected resident; without unreasonable delay Written notice to AG |
| Credit reporting agencies | No CRA-notice requirement. |
| Substitute notice | Available if cost exceeds $50,000 or more than 100,000 affected. |
| Private right of action | No, enforcement by the state. |
Notes
※ Separate payroll/income-tax-data rule (employers/payroll providers notify AG with FEIN)
※ Separate medical-information statute (§32.1-127.1:05)
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Virginia breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →