Rhode Island Data Breach Notification: When the Clock Actually Starts

Most Rhode Island business owners learn that this state has a breach notification law on the worst possible day, in the middle of an incident, from somebody who is not happy with them. So here is the part that gets misunderstood most often: the clock does not start the moment somebody clicks a phishing email. For a private Rhode Island business, the law generally requires notification no later than 45 days after the business has confirmed a qualifying breach and can determine the information required for the notice.

That distinction matters. It is also not an excuse to wait around. I am not an attorney and none of this is legal advice, but I have sat through enough of these to know where the real damage happens, and it is almost never the 45 days.

What Rhode Island's law actually turns on

Rhode Island's law focuses on personal information acquired, or reasonably believed to have been acquired, by an unauthorized party where there is a significant risk of identity theft. Read that twice, because it has two halves. Something has to have happened, and it has to have involved that kind of information about real people. An incident that fails either half is still a security problem you need to fix. It is not automatically a notification event.

The word doing most of the work is confirmed. You do not get to the legal clock until you have established what happened, and you cannot establish what happened unless the investigation starts immediately. Logs age out. Sessions expire. Attackers clean up after themselves. The legal deadline is generous compared to how fast the evidence disappears, which is why the practical clock starts the same hour you get suspicious.

There are also additional notification obligations when more than 500 Rhode Island residents are affected, which is a threshold a surprising number of small companies can cross with one mailbox. And because notification duties generally follow where the affected people live rather than where your office is, a Providence company with customers in Massachusetts and Connecticut may be looking at more than one state's rules at once. That is a legal question, not an IT question, and it is one more reason not to guess your way through it.

Getting phished and having a reportable breach are not the same thing

Someone clicking a link does not automatically mean notification is required. But resetting the password and declaring victory can be just as dangerous. Both of those are guesses dressed up as decisions.

What you actually need to answer, in order:

  • Was the account actually accessed, or did the credentials just get typed into a fake page and never used?
  • What could that account see once it was in - mailbox, shared files, other connected systems?
  • Was anything downloaded, exported, or forwarded out of the environment?
  • What kind of information was in reach, and whose was it?
  • Did the attacker leave anything behind - a mail forwarding rule, an added MFA method, a permission change?

I see businesses guess wrong in both directions. Some assume every security incident is a reportable breach and start drafting letters over a blocked login attempt. Others assume no notification is necessary because nothing looks missing. Nothing looks missing is not a finding. It is the absence of one.

Would you even know if you had a breach?

When a prospect asks me that, my honest answer is that it depends almost entirely on what visibility they have. If nobody is monitoring Microsoft 365 sign-ins, endpoint security, firewall activity, alerts, and administrative changes, you may never know exactly what happened. That becomes a serious problem after an incident, because now we are trying to reconstruct events without enough evidence.

This is the distinction I wish more owners heard before they needed it. Security tools are important, but logging and monitoring are what let you answer the question, what did the attacker actually do? A company can spend real money on prevention and still be unable to answer that question, and the inability to answer it is what turns a contained incident into an expensive one. If you cannot prove what was not touched, you are often left treating everything as if it was.

It is also the part of an incident where having an IT provider based in Rhode Island helps in a way that is hard to replicate remotely. Containing an incident properly sometimes means getting a machine off the network without wiping the evidence on it, and somebody has to be standing in front of that machine to do it right.

Three things a 20-person Rhode Island company should do this year

If a 20-person company here only did three things, these are the three:

  1. Put proper MFA and managed endpoint detection on every user and every computer. Every one, including the owner and the person who has been here 22 years and hates it.
  2. Make sure Microsoft 365 and the rest of the environment are generating and retaining enough security logs to investigate an incident. Find out today what is being captured and for how long, because after an incident is the wrong time to discover the answer was not much and not long.
  3. Write down a simple incident response process that says who calls the insurance carrier, the attorney, the IT provider, and management when something happens. One page is fine. A page that exists beats a plan that someone intends to write.

None of that is exotic, and none of it is a security program in the abstract. Those three things dramatically improve the chances that you can determine what happened instead of guessing afterward, and guessing afterward is what costs money.

Who should own the notification decision

Not the IT provider. I want to be direct about that, because it is a line some IT companies are happy to cross and should not. Our job is to preserve evidence, contain the incident, determine what systems and accounts were affected, and give the people making that decision accurate technical information.

The owner needs to be involved. The cyber insurance carrier should usually be contacted quickly according to the terms of the policy. And breach counsel should determine the legal notification obligations. Rhode Island law has specific triggers and notice requirements, including the additional obligations once more than 500 Rhode Island residents are affected, so this is one area where I want the attorney making the legal call, not the IT company.

Put it this way: if your IT provider tells you confidently that you do not have to notify anyone, they have just given you a legal opinion they are not qualified to give, and you are the one who carries it.

The useful question is not whether you will ever have an incident. It is whether, on the day you do, you could write down truthfully what happened and hand it to a lawyer. If you are not sure you could, the fix starts with what you are logging and who you would call, and that is a short conversation. If you want a second set of eyes on either one, get in touch and we will take a look at what you actually have.