DisclosureLens
Feed News/Research · The Discovery-Date Audit

The Breach Letter Has Three Dates. The Law's Clock Runs on One. We Audited Which One Gets Filed.

Every US breach-notification deadline runs from the day the organization discovered the incident — but a notification letter routinely dates three different events: the attack, the first alarm, and what the investigation later found. We audited the discovery date behind 32,572 filings. Where a state collects it as a form field, it is exact — 3,781 of 3,781 re-checked against the source. Where it must be read out of letter prose, roughly one date in eight is the wrong event entirely, and the errors are not small: the corrections we applied moved dates by a median of 92 days, three times the length of a typical 30-day notification window.

By DisclosureLens · August 2026 · Data snapshot 2026-08-24
Form fields
3,781/3,781
labelled discovery fields re-checked: exact
Letter prose
87.6%
correct concept · 162 of 185 gold cases
Median correction
92 d
how far a corrected date moved
Verdicts withdrawn
129
our own, unprompted — 88 withheld, 41 re-derived

This report grades our own data, not any company. No organization is named; day gaps describe our corrections, never a filer's conduct. Figures are a frozen 2026-08-24 snapshot of an ongoing audit whose counts only grow. Method & limitations below.

Key findings

  1. A breach letter routinely dates three different events, and only one of them starts the statutory clock. The attack, the first alarm, and the investigation's later finding all carry dates — often in the same sentence — and a deadline computed from the wrong one is wrong by months while every character is transcribed faithfully.
  2. Where a state collects discovery as a labelled form field, the recorded date is exact. We re-read every archived Washington, Oregon and Texas register row against its source: 3,781 of 3,781 match, zero mismatches, plus 470 of 470 in an earlier Maine pass. There is no inference to get wrong.
  3. Where the date exists only in letter prose, roughly one date in eight is the wrong event entirely. Against a hand-labelled sample of 210 randomly drawn filings, prose-read discovery dates carry the correct concept 87.6% of the time (95% CI 82.0–91.6%).
  4. The errors are bigger than the deadlines. The 150 dates we corrected after reading each letter moved by a median of 92 days — three times a typical 30-day notification window — and 7 moved by more than a year. In one filing, the stated discovery date fell 524 days after the filer's own first-detection date.
  5. Both directions of the error exist, and they cut opposite ways. A post-investigation date makes a slow responder look fast; an attack date makes a fast responder look slow. We withdrew 129 of our own published verdicts rather than let either stand on a date the letter does not support.

Three dates in one sentence

Every US breach-notification law starts its clock the same way: from the day the organization discovered the incident. Thirty days to tell the attorney general in some states, sixty to tell residents in others — but always counted from discovery. Which makes one field in every breach filing load-bearing: the discovery date decides whether the filing reads as prompt or late.

Here is the problem. A breach-notification letter is written months after the fact, by counsel, summarizing a forensic investigation — and it routinely dates three different events. The day the attacker got in. The day something first looked wrong. And the day the investigation finally determined what was taken. A sentence like this one, which appears in near-identical form across dozens of unrelated letters, carries two of them at once:

“After an extensive forensic investigation and manual document review, we discovered on [DATE A] that the email accounts accessed by the unauthorized party between [DATE B] and [DATE C] contained personal information.”

Date A is when the investigation finished its document review — weeks or months after anyone first noticed a problem. Dates B and C bound the intrusion itself. The day the organization actually became aware — the one the statute wants — may appear in a different paragraph, or nowhere at all. Whichever date ends up in a regulator's register becomes the official clock. Copy it perfectly and the clock can still be wrong by a quarter.

Four states solved this with a form field

Washington's register publishes a column literally named dateaware. Oregon publishes discovery_dates_raw; Texas, Breach_Discovered_Date__c; Maine's intake form asks for “Date Breach Discovered” outright. In these states the filer answers the statute's question directly, in a box, under the state's own label. There is no prose to interpret and no inference to get wrong.

We verified that the obvious holds: every Washington, Oregon and Texas register row in our archive was re-read from its source document and compared against what we stored. 3,781 rows, 3,781 exact matches, zero mismatches — and an earlier pass on Maine's form rows found 470 of 470. When the regulator asks for the date as a field, the date in the record is the date the filer swore to.

Figure 1 · How the discovery date arrives, and how often it is the right concept

Form-field share: 3,781 of 3,781 register rows re-checked exact against archived sources (WA, OR, TX), plus 470/470 in an earlier Maine form pass. Prose share: 162 of 185 decidable cases in a hand-labelled sample of 210 randomly drawn filings across nine states (95% CI 82.0–91.6%). Row counts are dated state-registry filings in our archive, snapshot 2026-08-24.

The other 22,457 dated filings in the state registries we track come from jurisdictions where the discovery date exists only inside the notification letter. For those, someone — a regulator, a researcher, a data vendor, us — has to read prose and decide which of the letter's dates the statute means.

How often prose gets it wrong

We measured our own reading first. Against a hand-labelled gold set — 210 filings drawn at random across nine prose jurisdictions, each read by a human against the letter — the discovery dates we extract carry the correct concept 87.6% of the time (162 of 185 decidable cases; the remaining 25 are genuinely ambiguous in the source itself). Per-state precision runs from 81.6% in New Hampshire to 100% in Vermont, with the smaller samples carrying wide intervals.

The failures are not random noise. They are two specific substitutions, and they cut in opposite directions:

  • The confirmation date — the day the investigation determined what was taken. It falls after first awareness, so the measured interval shrinks, and an organization that took a long time to notify can read as compliant.
  • The occurrence date — the day of the intrusion itself. It falls before first awareness, so the interval stretches, and an organization that responded promptly can read as late.

The second error turns out to be rarer than it looks, for an interesting reason: when we audited 119 filings whose stored date matched the attack, 92 of them were incidents the organization caught in the act — ransomware detonations, service disruptions, same-day alerts — where the attack date and the awareness date are legitimately the same day. The date wears the wrong sentence but carries the right value. The confirmation-date error has no such excuse, and it is the common one.

What the corrections measured

Over five audit rounds we built detectors for both substitution shapes, refused to use any version that had not cleared a measured precision floor on hand-read samples, and then had a human read every filing the detectors selected against its archived letter — 1,196 filings so far, each with a recorded verdict and evidence sentence. Where the letter states a real first-awareness date, we corrected the record: 150 corrections across 121 distinct letters. Where the letter never says when the filer first knew, we marked the record instead — 708 filings now carry that mark — because replacing one wrong date with a guess would be a second error, not a fix.

Figure 2 · How far the 150 corrected dates moved once the letter was read

Absolute day-shift between the stored discovery date and the letter's stated first-awareness date, for every correction across the five audit rounds. Median 92 days; 73% moved more than 30 days — the full length of a typical statutory notification window; 7 corrections moved more than a year, the largest 524 days. These figures describe our corrections, not any filer's conduct.

The consequential number is what those corrections did to published conclusions. A compliance verdict computed from a wrong-concept date is not a small error with a big asterisk — it is the wrong verdict about a named company. So the audit withdrew 129 of our own published verdicts: 41 because the corrected date changed the answer, and 88 by declining to grade the filing at all. Those 88 records now show a visible “Clock withheld” marker in place of a verdict — a statement about our data, not about the filer — and the withholding is directional: a too-late date may not exculpate, a too-early date may not accuse, and whichever half of the verdict still holds regardless is kept.

And the honest coda: the detectors do not find everything. Our own estimate puts the confirmation-date defect at 1,100–2,100 filings; the 858 corrected or marked so far are part of it, not all of it. A monthly sweep now reads only filings no human has seen — the most recent surfaced eight — and an unmarked filing means nobody has examined it, not that it has been verified.

The one-line fix

The striking thing about this defect is how precisely its boundary follows a design decision made by regulators. The states that ask for discovery in a labelled box get a clean answer every time — our re-checks found literally zero mismatches. The states that accept a letter get, embedded in boilerplate, three candidate dates and no marking of which is which. In those states, no one — not a data vendor, not a researcher, and not the regulator itself — can compute the statute's own deadline from the record without a human reading each letter.

That makes the fix unusually cheap as policy interventions go: one required field on an intake form, labelled the way Washington already labels it — dateaware, the date the organization first became aware. The statute already turns on that concept. The form just has to ask for it.

Method & limitations

  • Snapshot. All figures as of 2026-08-24. The audit is ongoing; counts are floors and grow monotonically.
  • Form-field verification. Every Washington, Oregon and Texas register row in our archive was re-read from its archived source document and byte-compared to the stored date (3,781 rows). Maine's form majority was verified in an earlier 470-row pass. This measures our pipeline against the register, not the filer's truthfulness — a filer who mis-states discovery on a form is invisible to every method here.
  • Prose measurement. The gold set is 210 filings drawn at random per jurisdiction across nine prose states, each labelled by a human reading the archived letter; 185 are decidable, 25 genuinely ambiguous. Precision 162/185 = 87.6%, Wilson 95% CI 82.0–91.6%. “One date in eight” refers to this sample's failure share (23/185), not a corpus-wide measurement.
  • Detection and adjudication. The lexical detectors were held to a 0.90 Wilson-lower-bound precision gate on hand-read out-of-sample draws before use (the widening that produced the occurrence-date queue validated at 97/100 on a pre-registered draw). Every flagged filing was read by a human before any change; detector output alone never altered a record. All verdicts, evidence sentences and reasoning are recorded.
  • Recall. Detector recall is deliberately partial (precision was prioritized). The 1,100–2,100 estimate for the confirmation-date population derives from measured recall on the gold set and the observed base rate; the corrected-plus-marked set covers 41–78% of that range.
  • No verdicts about filers. Day-shift figures describe corrections to our records. They are not claims that any organization notified late, and no organization is named in this report.

Related reports

Sources

Corrections: corrections@disclosurelens.com — 48-hour SLA. This report is itself the product of a corrections process: every figure derives from committed, auditable adjudication records, and the same process that withdrew 129 of our own verdicts applies to anything a reader can show is wrong here.

Cite this report

DisclosureLens, “The Breach Letter Has Three Dates. The Law's Clock Runs on One. We Audited Which One Gets Filed.,” August 2026. https://disclosurelens.com/news/breach-discovery-date-audit

You may quote this report and reproduce its charts and excerpts with attribution to DisclosureLens and a link to this page. Republishing data or statistics obtained from the platform itself carries the same condition — see the data license in our terms.

The Disclosure Clock · weekly briefing

Everything on this page starts as a weekly measurement: the race between the criminals who post a breach and the regulators who record it, and the health of the registries themselves. Get the reading in your inbox.

Weekly. Double opt-in, one-click unsubscribe, and the address goes nowhere else.