← All jurisdictions
VT · data breach notification
medVermont
9 V.S.A. §§2430, 2435
Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Required
| Notice to individuals | 45 calendar days from discovery |
| Risk-of-harm standard | no notice if misuse not reasonably possible (notice of that determination to AG) |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Vermont Attorney General (or Dept. of Financial Regulation), required for any affected resident; within 14 business days Preliminary notice to AG, then copy of consumer notice Preliminary description within 14 business days of discovery |
| Credit reporting agencies | No CRA-notice requirement. |
| Substitute notice | Available if cost exceeds $10,000 or more than 500,000 affected. |
| Private right of action | No, enforcement by the state. |
| Notable PI definitions | Includes biometric, credentials, medical, health insurance. |
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Vermont breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →