Delaware Governor Signs HB 381, Tightening Data Breach Rules And Narrowing HIPAA And GLBA Safe Harbours

Delaware Governor Matt Meyer signed House Bill 381 on September 2, 2026, immediately amending the state’s existing data breach notification law with significant new requirements.

The legislation introduces an early reporting obligation to the Attorney General when organisations cannot identify specific affected Delaware residents within 60 days of determining a breach has occurred.

HB 381 also formally adds Attorney General notice as a required component of Delaware’s substitute notice process, closing a gap that previously existed in the law.

Additionally, the bill narrows the compliance safe harbour previously available to entities regulated under HIPAA and the Gramm-Leach-Bliley Act, which is commonly known as GLBA.

Under the updated law, when a breach affects more than 500 Delaware residents, businesses must notify the Delaware Attorney General’s Fraud and Consumer Protection Division no later than the time individual notices are sent to affected residents.

Organisations that cannot identify all affected residents within 60 days must notify the Attorney General within that same 60-day window, unless substitute notice has already been provided.

The narrowing of the GLBA and HIPAA safe harbour represents a notable shift in how federally regulated entities must approach Delaware’s breach notification obligations going forward.

Previously, compliance with regulator-established breach procedures effectively satisfied the entire scope of Delaware’s breach notification law, but HB 381 changes that position significantly.

Under the amended Section 12B-103, following a primary or functional regulator’s procedures now satisfies only Delaware’s 60-day timing requirement, rather than the full range of obligations under Chapter 12B.

This means that GLBA-regulated financial institutions and HIPAA-regulated entities must separately comply with the Attorney General notice duty and the credit monitoring requirement that applies to Social Security number breaches.

Governor Meyer signed HB 381 alongside House Bill 380, which separately amends the Delaware Personal Data Privacy Act that was enacted in 2023 and became effective January 1, 2025.

Together, the two bills expand the businesses and categories of data covered under existing Delaware law, while increasing protections for sensitive personal information.

The paired legislation also imposes new vendor-management and automated decision-making requirements on businesses operating in or collecting data from Delaware residents.

The HB 380 amendments to the Delaware Personal Data Privacy Act are set to take effect January 1, 2027, while HB 381’s changes to breach notification law were effective immediately upon signing.

Legal and compliance teams at organisations holding personal data of Delaware residents should review and update their incident response plans to reflect the new Attorney General notification timelines and the narrowed safe harbour provisions.