District of Columbia
District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 12 primary sources cited on this page. How we verify our legal content

Businesses that collect personal information about District of Columbia residents must notify affected individuals in the most expedient time possible and without unreasonable delay after a qualifying breach, under D.C. Code 28-3852. Organizations reaching 50 or more affected DC residents must also notify the Attorney General.
The District of Columbia has one of the more aggressive data breach notification laws in the country. While many states set AG reporting thresholds at 250, 500, or even 1,000 affected residents, DC triggers that obligation at just 50 people. Combined with a private right of action that allows consumers to pursue actual damages, attorney fees, and punitive damages, plus a mandatory 18-month identity theft protection requirement for SSN breaches, the District gives residents real tools to hold organizations accountable.
This guide covers every key provision of DC's breach notification framework, from who must comply and what triggers a notification to enforcement mechanisms and consumer remedies. For the broader picture of DC privacy protections, see the parent guide on District of Columbia Data Privacy Laws.
The Governing Statute: DC Code 28-3851 Through 28-3853
DC's breach notification requirements are found in Subchapter II of Chapter 38 of Title 28 of the DC Code. The original law was enacted in 2007 and significantly strengthened by the Security Breach Protection Amendment Act of 2020 (D.C. Law 23-98), which took effect on June 17, 2020.
The subchapter now contains six sections:
- DC Code 28-3851: Definitions
- DC Code 28-3852: Notification of security breach
- DC Code 28-3852.01: Security requirements
- DC Code 28-3852.02: Remedies (identity theft protection)
- DC Code 28-3852.03: Rulemaking authority
- DC Code 28-3853: Enforcement
The 2020 amendment expanded the definition of personal information, added mandatory security requirements, created the AG notification obligation, and established remedies for breaches involving Social Security numbers.
Who Must Comply
The law applies to any person or entity that conducts business in the District of Columbia and owns or licenses computerized or other electronic data that includes personal information of DC residents. It also applies to entities that maintain, handle, or otherwise possess such data on behalf of the data owner.
DC government agencies are excluded from the definition of "person or entity" under the statute, though they may be subject to separate data protection requirements.
If you are a third-party service provider holding personal information on behalf of another organization, you must notify the data owner or licensee when you discover a breach. The data owner then bears the responsibility for notifying affected residents.
What Counts as Personal Information

DC Code 28-3851 defines personal information broadly. It includes an individual's first name, first initial and last name, or any other personal identifier, combined with any of the following data elements:
- Social Security number
- Driver's license or DC identification card number
- Passport number
- Taxpayer identification number
- Military ID number
- Financial account number (credit or debit card number with any required security code, access code, or password)
- Medical information (any data about dental, medical, or mental health treatment or diagnosis by a health care provider)
- Genetic information (defined by reference to HIPAA; note that the codified DC text at 28-3851(1A) cites "45 C.F.R. Section 106.103," which does not exist, while the operative HIPAA definition of genetic information sits at 45 C.F.R. 160.103)
- Health insurance information (policy number or subscriber ID combined with a unique identifier used by the insurer)
- Biometric data (fingerprints, voice prints, retina or iris images, or other unique biological characteristics used for authentication)
- Email address combined with a password, security question answer, or other authenticating data
This is one of the broader definitions among US jurisdictions. The inclusion of biometric data, genetic information, medical records, and email credentials goes well beyond the name-plus-SSN model that older state laws used.
Publicly available information lawfully accessible from federal, state, or local government records is excluded.
What Triggers a Notification
A notification obligation arises when there is a "breach of the security of the system," defined as the unauthorized acquisition of computerized or other electronic data, or any equipment or device storing such data, that compromises the security, confidentiality, or integrity of personal information.
Three situations are excluded from the definition:
- Good-faith employee access. If an employee or agent accesses personal information in the course of their duties and does not use or disclose it in an unauthorized way, that is not a breach.
- Encrypted or redacted data. Acquisition of data that has been rendered secure through encryption or redaction is not a breach, unless the encryption keys or redaction methods were also compromised.
- No likely harm, but only after consulting the AG and federal law enforcement. Under DC Code 28-3851(1)(B)(iii), the acquisition is excluded only where the entity reasonably determines, "after a reasonable investigation and consultation with the Office of the Attorney General for the District of Columbia and federal law enforcement agencies," that it will likely not result in harm to the individual. DC is unusual on this point. In most states the risk-of-harm assessment is an internal judgment call; in the District the statute makes the consultation a required step, so an entity cannot self-certify its way out of notification without contacting the OAG and federal law enforcement first.
The encryption safe harbor is significant. If your organization encrypts personal information at rest and in transit, and an unauthorized party gains access to the encrypted data but not the decryption keys, you are not required to notify.
Notification Timeline and Requirements
When to Notify
DC Code 28-3852 requires notification "in the most expedient time possible and without unreasonable delay." The statute does not set a hard deadline measured in calendar days, unlike states that specify 30, 45, or 60 days.
The timeline must be consistent with:
- The legitimate needs of law enforcement (notification can be delayed if law enforcement determines it would impede a criminal investigation)
- Measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system
Once any law enforcement delay is lifted, notification must proceed as soon as possible.
What the Notice Must Include
Written breach notifications to affected DC residents must contain:
- A description of the categories of personal information that were, or are reasonably believed to have been, compromised
- Contact information for the notifying entity
- Phone numbers for major consumer reporting agencies
- Information about how to place a security freeze on credit reports
- Contact information for the Federal Trade Commission and the DC Office of the Attorney General
- Guidance on identity theft prevention from the FTC and the AG
Methods of Notice
Notification can be delivered through:
- Written notice sent to the last known postal address of the affected individual
- Electronic notice if the entity has a valid email address and the individual has consented to electronic communication
- Substitute notice if the cost of direct notice would exceed $50,000, the affected group exceeds 100,000 individuals, or the entity lacks sufficient contact information (substitute notice requires email to known addresses, conspicuous website posting, and notice to major local and, if applicable, national media)
There is also a tailored route for credential-only breaches. Under DC Code 28-3852(a-2), where the breach involves only the personal information defined at 28-3851(3)(A)(ii), meaning a username or email address combined with a password, security question and answer, or other means of authentication, the entity may comply by delivering notice in electronic format or another form that directs the person to change the password and security question or answer, or to take other steps to protect the affected email account and every other online account using the same credentials.
The 50-Resident AG Notification Threshold

One of DC's most distinctive provisions is its low threshold for notifying the Attorney General. Under DC Code 28-3852(b-1), when a breach affects 50 or more District residents, the entity must send written notice to the Office of the Attorney General.
For comparison, many states set this threshold at 250 or 500, and some have no AG notification requirement at all. DC's low bar means that even a relatively small breach involving personal information of DC residents will require a formal report to the AG.
The AG notice must be provided "in the most expedient manner possible, without unreasonable delay" and no later than the time at which notice is sent to affected residents. DC Code 28-3852(b-1) enumerates eleven items the notice to the AG must include:
- The name and contact information of the person or entity submitting the report
- The name and contact information of the entity that experienced the breach
- The nature of the breach
- The types of personal information compromised
- The number of DC residents affected
- The cause of the breach, including the relationship of the responsible party to the entity, if known
- Remedial action taken to assist affected residents
- The date and time frame of the breach
- The address of corporate headquarters if the entity is located outside the District
- Any knowledge of foreign country involvement
- A sample of the notice to be provided to District residents
The last item is easy to miss and is an operational deliverable: the consumer notice has to be drafted before the AG filing goes out, not after.
When more than 1,000 individuals are notified, the entity must also inform nationwide consumer reporting agencies about the timing, distribution, and content of the notifications. DC Code 28-3852(c) carves out entities already required to notify consumer reporting agencies of a breach under Title V of the Gramm-Leach-Bliley Act, so a GLBA-covered financial institution does not owe a second, duplicate CRA notice under DC law.
Mandatory Identity Theft Protection

DC Code 28-3852.02 requires that when a breach includes or is reasonably believed to include a Social Security number or taxpayer identification number, the entity must offer each affected DC resident identity theft protection services at no cost for at least 18 months.
The entity must also provide all information necessary for residents to enroll in those services. This is not optional or discretionary. Any breach involving SSNs or taxpayer IDs automatically triggers this obligation.
This 18-month requirement is longer than the 12-month standard that many states use, giving DC residents an extended period of monitoring after their most sensitive identifiers are compromised.
Data Security Requirements
The 2020 amendment added DC Code 28-3852.01, which imposes affirmative security obligations. Any entity that possesses personal information of DC residents must "implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information."
This standard requires organizations to consider the sensitivity of the data and the size and complexity of their operations when designing security measures. The law does not prescribe specific technical controls, instead using the "reasonable" standard common in data security regulation.
Third-Party Service Providers
When entities engage third-party service providers that will handle personal information, they must execute written agreements requiring those providers to maintain reasonable security procedures and practices appropriate to the nature of the data.
Records Destruction
When destroying physical or digital records containing personal information, entities must take reasonable steps to prevent unauthorized access. Factors to consider include the sensitivity of the records, the size of the business, available technology, and the cost of destruction methods.
Federal Compliance Safe Harbor
Organizations that comply with the data security requirements of the Gramm-Leach-Bliley Act (Title V), HIPAA, or the HITECH Act are deemed to satisfy DC's security requirements automatically. This safe harbor applies to the security provisions only. It does not exempt organizations from the separate notification requirements, and entities that qualify for the security safe harbor must still notify the AG when 50 or more DC residents are affected by a breach.
Enforcement and Penalties
Unfair or Deceptive Trade Practice Classification
DC Code 28-3853 classifies any violation of the breach notification subchapter as an unfair or deceptive trade practice under DC Code 28-3904(kk). This is a powerful enforcement mechanism because it opens up all the remedies available under DC's Consumer Protection Procedures Act.
Private Right of Action
DC residents have a private right of action under DC Code 28-3905(k). Consumers injured by a violation of the breach notification law can file suit in DC Superior Court and recover:
- Actual damages, not the treble damages/$1,500-per-violation minimum otherwise available for Consumer Protection Procedures Act claims. DC Code 28-3853(b) classifies any violation of the breach notification subchapter, including both the Section 28-3852 notification duties and the Section 28-3852.01 security requirements, as an unfair or deceptive trade practice specifically under Section 28-3904(kk), and Section 28-3905(k)(2)(A)(ii) carves out (kk) violations from the general treble-damages rule, limiting them to actual damages. Actual damages do not include dignitary damages, such as pain and suffering
- Reasonable attorney fees
- Punitive damages in appropriate cases
- Injunctive relief to stop ongoing violations
- Any other relief the court determines proper
This combination of guaranteed actual-damages recovery and attorney fee shifting still creates a meaningful incentive for private enforcement, even when individual losses from a breach are relatively small.
Attorney General Enforcement
The DC Attorney General can bring enforcement actions in DC Superior Court seeking injunctive relief and restitution. The AG is not required to prove damages to obtain an injunction, and no bond is required. Under DC Code 28-3909(b), the AG may also recover a civil penalty of up to $5,000 per violation for a first violation and up to $10,000 per violation for a repeat violation, plus economic damages and the costs of the action and reasonable attorney's fees. The AG's office has actively pursued data breach enforcement actions.
Recent enforcement actions include a settlement of over $350,000 against software firm Blackbaud in a multistate action involving a ransomware attack that exposed personal information of nonprofits and schools. DC also participated in the $600 million Equifax settlement and a $148 million Uber settlement over delayed breach notification.
Cumulative Remedies
The statute specifies that the rights and remedies available under the breach notification law are cumulative to each other and to any other rights and remedies available under law. This means consumers can pursue claims under both the breach notification statute and any other applicable laws simultaneously.
Federal Compliance and Preemption
Entities that comply with the breach notification provisions of the Gramm-Leach-Bliley Act or HIPAA are deemed to be in compliance with DC's resident notification requirements under DC Code 28-3852. However, this safe harbor does not exempt those entities from the AG notification requirement. Even HIPAA-covered entities must notify the DC Attorney General when a breach affects 50 or more DC residents.
There is no federal preemption of DC's breach notification law. The federal safe harbor provisions are additive, not preemptive, meaning organizations must still meet DC-specific requirements that go beyond federal mandates.
This article provides general legal information about District of Columbia data breach notification laws and is not legal advice. Data breach notification requirements involve time-sensitive obligations and potential penalties. Consult a licensed attorney in the District of Columbia for guidance on your specific situation.
Frequently Asked Questions
How quickly must I notify DC residents after a data breach?
DC law requires notification in the most expedient time possible and without unreasonable delay. Unlike some states that set a specific deadline (such as 30 or 60 days), DC uses a reasonableness standard. You may delay notification only if law enforcement determines it would impede a criminal investigation, or if you need time to determine the scope of the breach and restore data system integrity.
When do I need to notify the DC Attorney General about a breach?
You must notify the DC Attorney General whenever a breach affects 50 or more District of Columbia residents. This is one of the lowest AG notification thresholds in the country. The written notice to the AG must be sent no later than when you notify affected residents. DC Code 28-3852(b-1) lists eleven required items, including the nature of the breach, the types of personal information compromised, the number of affected residents, the cause of the breach, remedial action taken, the date and time frame of the breach, contact information for both the reporting entity and the breached entity, any knowledge of foreign country involvement, and a sample of the notice you will send to residents.
Does DC law require me to offer free identity theft protection after a breach?
Yes, but only when the breach involves Social Security numbers or taxpayer identification numbers. In those cases, you must offer affected DC residents free identity theft protection services for at least 18 months and provide all information necessary for enrollment. This requirement is longer than the 12-month standard used by many states.
Can DC residents sue a company for a data breach?
Yes. DC classifies breach notification violations as unfair or deceptive trade practices under DC Code 28-3904(kk). Affected consumers can file suit in DC Superior Court and recover actual damages, not the treble damages/$1,500-per-violation minimum available for other consumer protection claims, which DC Code 28-3905(k)(2) specifically carves out for 28-3904(kk) violations, plus reasonable attorney fees, punitive damages, and injunctive relief.
Does encryption protect my organization from DC breach notification requirements?
DC provides an encryption safe harbor. If personal information was encrypted or redacted and the unauthorized party did not also obtain the decryption keys or means to undo the redaction, the acquisition does not constitute a breach under DC law, and you are not required to notify. However, if the encryption keys were also compromised, the safe harbor does not apply.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected and expanded the breach-notification detail: the risk-of-harm exclusion now states the required consultation with the DC Attorney General and federal law enforcement, the Attorney General notice list is complete at all eleven statutory items, substitute notice covers national as well as local media, the consumer reporting agency duty notes its Gramm-Leach-Bliley carve-out, and the tailored notice route for username or email credential breaches was added.
Fixed a dead statute link for DC Code 28-3852.02, corrected the personal-information definition to match the statute's actual 'first name, first initial and last name, or any other personal identifier' language (removing an invented phone/address alternative), fixed the consumer-reporting-agency notice threshold to 'more than 1,000' individuals, and added the Attorney General's $5,000/$10,000 per-violation civil penalty authority under DC Code 28-3909(b).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the private-right-of-action remedy: DC Code 28-3853(b) classifies ALL breach-notification-subchapter violations (both notification and security-requirement failures) as an unfair trade practice specifically under 28-3904(kk), and 28-3905(k)(2)(A)(ii) limits (kk) violations to actual damages, not the treble damages/$1,500 minimum the article had described.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 38: Consumer Protections. - Subchapter II: Consumer Security Breach Notification.
§ 28-3852Notification of security breach.In forcecited in 4 of our articles
(a) Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information, and who discovers a breach of the security of the system, shall promptly notify any District of Columbia resident whose personal information was included in the breach. The notification shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (d) of this section, and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at github.com
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Solomon v. Allstate Property and Casualty Insurance (District Court, District of Columbia 2024)“…to dismiss, Plaintiffs argue that their claims arise under D.C. Code sections 28-3852 and 28-3852(a), provisions governing ma…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: District of Columbia Data Privacy Laws: Breach Rules & Consumer Rights (2026), DC Employee Monitoring Laws: Notice, GPS, and Privacy Rules (2026), District of Columbia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 28-3851Definitions.In forcecited in 4 of our articles
For purposes of this subchapter, the term: (A) "Breach of the security of the system" means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. (B) The term "breach of the security of the system" does not include: (i) A good-faith acquisition of personal information by an employee or agency of the person or entity for the purposes of the person or entity if the personal information is not used improperly or subject to further unauthorized disclosure; (ii) Acquisition of data that has been rendered secure, including through encryption or redaction of such data, so as to be unusable by an unauthorized third party unless any information obtained has the potential to compromise the effectiveness of the security protection preventing unauthorized access; or (iii) Acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at github.com
§ 28-3853Enforcement.In forcecited in 3 of our articles
(a) [Repealed]. (b) A violation of this subchapter, or any rule issued pursuant to the authority of this subchapter, is an unfair or deceptive trade practice pursuant to § 28-3904(kk). (c) The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at github.com
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Attias v. Carefirst, Inc. (Court of Appeals for the D.C. Circuit 2019, 365 F. Supp. 3d 1)“…include dignitary damages, including pain and suffering." D.C. Code Ann. § 28-3853 (a). 2. Four theories of actual dam…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 39: Consumer Protection Procedures.
§ 28-3904Unfair or deceptive trade practices.In forcecited in 2 of our articles
It shall be a violation of this chapter for any person to engage in an unfair or deceptive trade practice, whether or not any consumer is in fact misled, deceived, or damaged thereby, including to: (a) represent that goods or services have a source, sponsorship, approval, certification, accessories, characteristics, ingredients, uses, benefits, or quantities that they do not have; (b) represent that the person has a sponsorship, approval, status, affiliation, certification, or connection that the person does not have; (c) represent that goods are original or new if in fact they are deteriorated, altered, reconditioned, reclaimed, or second hand, or have been used; (d) represent that goods or services are of particular standard, quality, grade, style, or model, if in fact they are of another; (e) misrepresent as to a material fact which has a tendency to mislead; (e-1) represent that a transaction confers or involves rights, remedies, or obligations which it does not have or involve, or which are prohibited by law; (f) fail to state a material fact if such failure tends to mislead; (f-1) use innuendo or ambiguity as to a material fact, which has a tendency to mislead; (g)…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at github.com
Cited in 157 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Grayson v. AT & T CORP. (District of Columbia Court of Appeals 2011, 15 A.3d 219)“…at Mr. Grayson failed to allege legally viable claims under D.C.Code § 28-3904(a), (e), (f), (h), and (r). According…”
- Daniel Logan v. LaSalle Bank National Association (District of Columbia Court of Appeals 2013, 80 A.3d 1014)“…of unlawful trade practices — specifically, violations of D.C. Code § 28-3904 (e), which prohibits “mispresent[ation…”
- Galvin v. Ruppert Nurseries, Inc. (District of Columbia Court of Appeals 2025)“…ppert violated various provisions of the CPPA, specifically D.C. Code § 28-3904(a), (d), (e), and (f). Her CPPA claims…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 28-3905Complaint procedures.In force
(a) A case is begun by filing with the Department a complaint plainly describing a trade practice and stating the complainant’s (and, if different, the consumer’s) name and address, the name and address (if known) of the respondent, and such other information as the Director may require. The complaint must be in or reduced by the Director to writing. The filing of a complaint with the Department shall toll the periods for limitation of time for bringing an action as set out in section 12-301 until the complaint has been resolved through an administrative order, consent decree, or dismissal in accordance with this section or until an opportunity to arbitrate has been provided in Chapter 5 of Title 50. (1) Except as provided in paragraph (2) of this subsection, the Director shall investigate each such complaint and determine: (A) What trade practice actually occurred; and (B) Whether the trade practice which occurred violates any statute, regulation, rule of common law, or other law of the District of Columbia. (2) The Director may, in his or her discretion, decline to prosecute certain cases as necessary to manage the Department’s caseload and control program costs.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at github.com
Cited in 104 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Grayson v. AT & T CORP. (District of Columbia Court of Appeals 2011, 15 A.3d 219)“…AMENDMENTS At issue in these cases is whether in amending D.C.Code § 28-3905(k) in 2000, the Council intended to eli…”
- Adam A. Weschler & Son, Inc. v. Klank (District of Columbia Court of Appeals 1989, 561 A.2d 1003)“…Weschler. Klank then filed a motion to dismiss pursuant to D.C.Code § 28-3905(k)(4). 1 The trial court g…”
- DONALD ROTUNDA v. MARRIOTT INTERNATIONAL, INC. (District of Columbia Court of Appeals 2015, 123 A.3d 980)“…pellant Donald Rotunda brought this suit for damages under D.C. Code § 28-3905 (k)(1) (2012 Repl.) part of the Distric…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Federal Regulations Title 45
§ 160.103Definitions.In forcecited in 10 of our articles
Except as otherwise provided, the following definitions apply to this subchapter: Act means the Social Security Act. Administrative simplification provision means any requirement or prohibition established by: (1) 42 U.S.C. 1320d-1320d-4, 1320d-7, 1320d-8, and 1320d-9; (2) Section 264 of Pub. L. 104-191; (3) Sections 13400-13424 of Public Law 111-5; or (4) This subchapter. ALJ means Administrative Law Judge. ANSI stands for the American National Standards Institute. Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in this section) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 374 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts apply the Section 160.103 definitions inside and outside HIPAA. Zani v. Rite Aid Headquarters Corp. (2017) used its health care definition to hold pharmacy flu shot calls fell within the TCPA health care exemption. Kenneth Wilson v. UnitedHealthcare Insurance Co (2022) applied its individually identifiable health information test.
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…mation” as “individually identifiable health information.” 45 C.F.R. § 160.103 . Both Congress and HHS define “individ…”
- Florida Ex Rel. Attorney General v. United States Department of Health & Human Services (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1235)“…is paid for health care in the normal course of business.” 45 C.F.R. § 160.103. And in 2009, Congress expanded HIPAA’s…”
- Zani v. Rite Aid Headquarters Corp. (District Court, S.D. New York 2017, 246 F. Supp. 3d 835)✓Rite Aid sent a prerecorded flu shot reminder to a pharmacy customer's cell phone. Reading the TCPA health care exemption against 160.103, the court held the call conveyed a health care message made on behalf of a covered entity, and granted Rite Aid summary judgment.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, When Is a Business Associate Agreement Required? (2026), South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- DC Code 28-3851 - Definitions(code.dccouncil.gov).gov
- DC Code 28-3852 - Notification of security breach(code.dccouncil.gov).gov
- DC Code 28-3852.01 - Security requirements(code.dccouncil.gov).gov
- DC Code 28-3852.02 - Remedies(code.dccouncil.gov).gov
- DC Code 28-3853 - Enforcement(code.dccouncil.gov).gov
- DC Code 28-3904 - Unfair or deceptive trade practices(code.dccouncil.gov).gov
- DC Code 28-3905 - Complaint procedures(code.dccouncil.gov).gov
- D.C. Law 23-98 - Security Breach Protection Amendment Act of 2020(code.dccouncil.gov).gov
- DC OAG Consumer Privacy Information(oag.dc.gov).gov
- AG Schwalb Blackbaud Data Breach Settlement(oag.dc.gov).gov
- Equifax Data Breach Settlement(oag.dc.gov).gov
- Uber Data Breach Settlement(oag.dc.gov).gov
- 45 C.F.R. 160.103 - HIPAA definitions (genetic information)(ecfr.gov)