DisclosureLens
Feed News/Research · Washington 2020–2026

The Washington Clock: The State Published the Deadline Data. We Read It.

Washington law gives a breached organization 30 days to tell the Attorney General. Alone among the breach registries we track, Washington also publishes the arithmetic — a days-elapsed column on 1,606 of the 1,629 notices it has received. Read against the state's own deadline, 82.6% of notices for breaches discovered under the 30-day rule arrived late, and the median took 77 days. In 2024, the Attorney General proposed cutting the deadline to three days — a bar the state's own record shows has been met six times since the rule took effect.

By DisclosureLens · August 2026 · Data snapshot 2026-08-16
Late
82.6%
1,099 of 1,331 notices, >30 days
Median
77 d
discovery to AG notice; p90 282
Records
79.4%
32.0M of 40.4M behind late notices
Within 3 days
0.5%
would meet the 3-day deadline the AG proposed

Day counts are the AG record's own arithmetic, never legal verdicts — state law permits delayed notice at law-enforcement request or while a breach's scope is determined, and the dataset does not record when those grounds were invoked. The clock measured is notice to the Attorney General; counts are Washington resident records, not people. Method & limitations below.

Key findings

  1. 82.6% of breach notices filed under Washington's 30-day rule reached the Attorney General more than 30 days after the filer's own discovery date. The median took 77 days; one in ten took more than 282. Even at triple the deadline, 44.2% of notices are late.
  2. Delays are growing, on every honest cut. Assigned by the year the breach was discovered — immune to the drift that inflates submission-year trends — the median rose from 75 days (2021) to 122 days (2024), and 2024 is a floor.
  3. 79.4% of all affected Washington resident records — 32.0 million of 40.4 million — sat behind a late notice. Not an outlier artifact: the largest late filing carries a tenth of that mass, and reaching half of it takes fourteen separate notices.
  4. The office charts every other day-count in this dataset except the one measuring its own deadline. None of the three AGO Data Breach Reports we reviewed analyzes notification timing. The 2024 edition instead asked the Legislature to cut the deadline to three days — a bar six notices out of 1,331 have met since the current rule took effect.
  5. Speed is demonstrably possible at scale. The largest on-time filing in the record covered 2.08 million resident records and arrived in 7 days.

The column nobody read

There is a column in a Washington state government dataset that, as far as we can tell, nobody had ever read all the way down. The Attorney General's Office publishes every data-breach notice it receives — it has for a decade — and its public dataset does something no other registry we track does: for each notice, it computes the number of days between the date the organization says it discovered the breach and the date the notice reached the AG. The column is called DaysElapsedBeforeNotification. It is the state's own arithmetic for the exact deadline the state's own law sets.

That deadline is among the strictest consumer-notification clocks in the country, and it is the Attorney General's own work. In 2019, the office proposed — and the Legislature passed — the bill that cut Washington's notification window from 45 days to 30, effective March 1, 2020, for notices to affected consumers and, when a breach touches more than 500 Washington residents, to the Attorney General. A parallel statute applies the same 30-day structure to government agencies. By the AGO's own count only three other states set a 30-day consumer clock — Colorado, Florida and Maine — though the same footnote concedes that for notice to a regulator, Vermont allows 14 days and Puerto Rico ten. It is Washington's consumer clock that is among the country's strictest; the Attorney-General clock this report measures is 30 days, but not the shortest anywhere.

We downloaded all 1,629 rows of the dataset and checked the state's arithmetic first: on every one of the 1,606 notices that carry both dates, the published day-count equals the date difference exactly. Then we read the column against the deadline.

Four out of five notices are late

Among the 1,331 notices for breaches discovered on or after March 1, 2020 — every breach that lived its whole life under the 30-day rule — 1,099, or 82.6%, reached the Attorney General more than 30 days after the organization's own discovery date. Some of that is narrow. Sixty-nine notices land between 31 and 35 days, and between them they cover 5.0 million resident records — a cancer center at 33 days, the state's own Auditor's Office at 31, the Department of Licensing at 31. One day past a deadline is not a scandal, and the 82.6% counts every one of them; a reader who wants a harsher test than the statute's will find one in the ladder below. But the bulk of it is not close. The median notice took 77 days — two and a half times the window the law allows. A quarter took more than 166 days. One in ten took more than 282 days: over nine months.

Figure 1 · How late is late

Share of the 1,331 clean-scope notices exceeding each threshold. Seven in ten of these notices also exceeded the 45-day deadline Washington replaced in 2020 — a comparison of today's filings against the old bar, not a forecast of how filers would behave under it. Median 77 · p25 39 · p75 166 · p90 282 days.

Data table — Figure 1
Share of notices exceeding each threshold
ThresholdNoticesShare
>30 days (the deadline)1,09982.6%
>45 days (pre-2020 deadline)92869.7%
>60 days (double)76357.3%
>90 days (triple)58844.2%

It is getting slower

Delays are not just large; they are growing, on both ways of cutting the same notices. By submission year: those submitted in 2021 arrived a median of 69 days after discovery, those submitted in 2025 134 days — nearly double. (Notices submitted in the first half of 2026 sit at 95 days; on a partial year we do not read that as a turn.) Submission-year figures can flatter a trend like this (a very late notice lands, by definition, in a later year), so we also assigned every notice to the year the breach was discovered — an assignment immune to that drift. The picture holds: breaches discovered in 2021 were reported at a median of 75 days; breaches discovered in 2024 — the most recent cohort old enough to measure — at a median of 122 days. And the 2024 figure is a floor: the slowest notices for 2024 discoveries may not have been filed yet.

Nor is this a change in the kinds of breaches being reported. Within cyberattack notices alone, the discovery-cohort median rose from 40 days (2020) to 142 days (2024). Ransomware breaches discovered in 2024–25 were reported at a median of 163 days, up from 96 in 2021–22.

Figure 2 · Median days from discovery to notice, by discovery year

Clean-scope notices assigned to the year the filer says it discovered the breach. Hollow, dashed cohorts (†) are right-truncated: their slowest notices cannot have arrived yet, so their bias runs downward and the apparent decline is not improvement — 2024's 122 is itself a floor. The 2022 dip is real; the trend claim is 2021 versus the last mature cohort, not year-on-year monotonicity.

Data table — Figure 2
Median days from discovery to AG notice by discovery-year cohort
Discovery yearNoticesMedian days
2020 (from Mar 1)23442
202119275
202214763
202331684
2024226122
2025 (truncated)15893
2026 (truncated)5865.5

The records behind the late notices

Record-weighting does not rescue the picture — the notices past the deadline are not merely the small ones: 79.4% of all affected resident records — 32.0 million of 40.4 million — sat behind a notice that took more than 30 days. That share is a shade below the 82.6% of notices, which is the honest way to read it: weighting by people moves the figure barely at all. Weighted by records rather than notices, the median wait is 53 days, and 57.4% of the late-notice records sit in the 31-to-60-day band. A note on units: these are resident records, not residents. The 40.4 million sum is roughly five times Washington's population, because the same person appears in many breaches — a point the AG's own annual report also makes.

This is not the work of one giant filing. The largest single notice past the 30-day mark — Change Healthcare's, covering 3.1 million resident records and filed 164 days after discovery — accounts for about a tenth of that total. Getting to half of it takes fourteen separate notices. The median notice in this group covers about two thousand resident records.

Figure 3 · Affected resident records, late vs on-time
behind late noticeson time

Washington resident records as reported by filers, clean scope, summed per notice — records, not distinct people. The amber mass is records behind >30-day notices. Fragility we checked rather than hid, and in the filers' favour: 69 notices in the 31–35-day band hold 4.99 million records, so treating anything within five days of the deadline as on time — a looser test than the statute's — moves the figures to 77.4% of notices and 67.0% of records. The headline applies the statutory >30 test, nothing harsher.

Data table — Figure 3
Affected resident records by notice timeliness
TimelinessNoticesResident recordsShare of records
Past 30 days1,09932,045,51379.4%
Within 30 days2328,317,98320.6%

The tail

The state's record includes delays that are hard to read without checking them twice — and one that does not survive the second check. Below is every notice in this cohort at 590 days or more, with one exclusion stated below the table. Every figure is the AG dataset's own day-count, running from the organization's own reported discovery date; none of them is a legal verdict (more on that below).

Notices in the clean-scope record at 590 days or more, excluding Abri Credit Union
OrganizationDaysResident recordsDiscovered → filed
U.S.Vision, Inc.1,0438,308May 2021 → Mar 2024
Impac Mortgage Holdings7581,206Mar 2024 → Apr 2026
Your Patient Advisor by Captify Health65836,364Mar 2021 → Dec 2022
Johnson Controls6454,903Sep 2023 → Jun 2025
Apria Healthcare62869,686Sep 2021 → May 2023
UA Sprinkler Fitters Local 669 JATC624518May 2024 → Feb 2026
Grandview School District6169,414Oct 2024 → Jun 2026
Clark County, WA59058,168Oct 2023 → Jun 2025

U.S.Vision's 1,043 days is the longest gap in the record, and it is worth unpacking, because it is not 1,043 days of silence. The company detected the intrusion on May 12, 2021, and by September 3 — 114 days — it had posted a public notice, told the federal Office for Civil Rights, and filed with Delaware. Washington's Attorney General heard about the breach in October 2022, when an affiliated practice group filed for the 700 Washington residents it had identified by then.

What arrived in March 2024 was a second, far larger group of people. In its filings the company says it spent two years working out whose data was in the stolen files: “it was not until recently that USV determined the individuals that required notice.” That review finished, and notices went out across several states at once — 412,565 people nationally, 8,308 of them in Washington. So the 1,043 days is a real measurement of the AG clock, and those 8,308 people really did wait that long to hear anything; what they were waiting on was not a decision to disclose but a two-year effort to find their names in the files. It is the exact situation the statute's update duty addresses — notify on time, and supplement as the picture fills in.

It is not the only row of that shape. The training committee of UA Sprinkler Fitters Local 669, at 624 days, says its investigation concluded on January 28, 2026; its Washington notice was filed nine days later. So two of the eight longest waits in the record are cases where what took the time was working out whose data was in the files — which is worth knowing before reading the rest of the table as foot-dragging.

Clark County is the county government itself. Its record shows a breach discovered on October 21, 2023 — the day its systems were publicly reported crippled by ransomware — and a notice covering 58,168 resident records reaching the AG in June 2025: the largest county-government entry in the record. Grandview School District reported discovering its breach on October 7, 2024; a ransomware crew's leak site claimed the district as a victim 51 days later — a criminal allegation, but a public one — and the AG filing followed more than eighteen months after that.

One row is excluded from the table above. The dataset records Abri Credit Union at 605 days, which would rank eighth. Abri's own published notice says it became aware of the incident on or about December 1, 2025 and began mailing on December 30 — about four weeks. The date in the state's file is when the intrusion occurred, in May 2024, not when anyone knew about it. Its 605 days is therefore not a notification delay, and we found it only by reading the company's notice. That is now our rule: no organization is named off this dataset without that check.

Speed, meanwhile, is demonstrably possible at any scale. T-Mobile's 2021 notice — 2.08 million resident records, the largest on-time filing in the dataset — reached the AG in 7 days. (Speed is not everything: the AG sued T-Mobile in January 2025 over what those notices said, alleging they downplayed the breach — a dispute about content, not the clock.) AT&T filed in 15 days; MGM Resorts, mid-way through a highly public 2023 incident, in 27.

What a late notice does not mean

A notice past 30 days is not automatically a violation, and this matters for every name above. Washington law lets notice be delayed when a law-enforcement agency determines it would impede a criminal investigation — the one ground the statute writes so as to reach notice to the Attorney General. A second ground, for “measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system,” appears in the subsection governing notice to consumers; whether it reaches the AG clock is arguable on the text, and we do not resolve it. The dataset records neither, so no row in it can be read as a finding of unlawfulness — and we don't.

What the statute does foreclose is the open-ended version of the second defence. The AG notice “must be updated if any of the information identified in (a) of this subsection is unknown at the time notice is due” — the law contemplates filing on time with what you have and supplementing later, not waiting until the picture is complete.

A third provision changes the deadline rather than excusing a delay. Under RCW 19.255.030, a HIPAA covered entity that complied with the federal HITECH breach-notification rule notifies the Attorney General on the federal 60-day timeline, expressly notwithstanding the state's 30 days. 284 of these 1,331 notices come from the Health industry. Grading every one of them at 60 days instead — an assumption in the filers' favour, since deemed compliance also requires having actually met the federal rule — the share past deadline is 76.2% of notices and 67.9% of records, against 82.6% and 79.4% at face value. The headline figures in this report apply the statutory 30-day test to every notice; this is the sensitivity, and it does not change the shape.

Two limits on all of it. The clock starts at the organization's own reported discovery date, which no one audits, and the error runs in both directions: a company that knew earlier than it says looks faster than it was, while a filer that enters the date the intrusion happened instead of the date it found out — as the excluded row above did — looks far slower. 35.8% of these notices carry a discovery date identical to the recorded end of the intrusion, the shape that permits the second error; for ransomware, discovered the day it detonates, that shape is usually just true, and we did not attempt to correct any of them. And the dataset holds only breaches affecting more than 500 Washington residents that were reported at all; organizations that never filed are invisible to it.

The check nobody published

What makes this measurable is also what makes it strange. The AGO's annual Data Breach Report — ten editions and counting — analyzes breach causes, industries and compromised data types, and its charts draw on this very dataset's other day-count columns: how long breaches ran, how long they took to identify, how long to contain. The one day-count it does not chart is the one that measures the office's own deadline. The 2023 edition describes the 30-day rule in a single background sentence; the 2025 edition does not contain the word “deadline” at all. None of the three editions we reviewed — 2023, 2024 and 2025 — analyzes notification timing.

The office's fair reply is that it publishes the raw data precisely so that others can do this, and that reply has some force: researchers have used Washington's filings before, modelling the lag from breach to report across several states for insurance-reserving purposes. But that work runs on different date fields and never grades a filing against the statute. So far as we can find, the column the state computes for its own deadline has not been read against that deadline in public — by the office or by anyone else.

The 2024 edition does something else. It asks the Legislature to make the deadline dramatically shorter: “To address the urgency of the threat, the Legislature must reduce the deadline for data breach notifications to three days. This would make Washington the first state in the country with a three-day deadline and reiterate our state's commitment to cybersecurity and consumer protection.” The report cites GDPR's 72-hour rule and pending federal rules for critical infrastructure. It does not mention how filers are performing against the existing 30-day rule. The proposal targets the consumer clock; the AG clock is the only one the state measures, and the two share a trigger and a start date, so it is the available proxy. On that proxy, the office's own dataset answers the question: since the 30-day rule took effect, six notices out of 1,331 — one half of one percent — arrived within three days. A shorter deadline is meant to change behaviour, not to grade the behaviour that came before it, so that 0.5% is not an argument against the proposal. It is a measure of the distance the proposal would have to close — and of how little the office knows, from its own published analysis, about where filers stand today. The 2025 edition quietly drops the proposal, referring readers back to 2024's recommendations.

Enforcement history completes the picture. Washington has filed exactly one standalone lawsuit over notification timing in the statute's two decades: Uber, in 2017–18, over a breach the state's suit charged was concealed for 372 days — under the old, 45-day version of the law. Its one involvement since is not its own case: in October 2023 it was one of 49 states signing a multistate assurance with Blackbaud whose common recitals allege that notification to affected consumers was significantly delayed or never happened. That conduct — discovery in May 2020, notice in July 2020, 63 days — falls inside the 30-day era. Washington announced no release of its own, and no Washington-filed case under the 30-day law has tested the clock.

This is also why the story stops at Washington's border. Oregon and Delaware publish both dates, so a determined reader could build the subtraction; Washington is the only registry we track that hands you the answer, and no regulator we track has published the resulting rate. Whether 82.6% is unusual is therefore still unknown. That is the policy takeaway, and it is cheap: a regulator already holding a discovery date and a notice date is one spreadsheet column away from letting the public grade its own deadline. Washington proved a state can hand its citizens the ruler. It also proved that publishing the ruler, by itself, changes little.

Method & limitations

Source: “Data Breach Notifications Affecting Washington Residents,” data.wa.gov (dataset sb4j-ca4h), downloaded August 16, 2026 — 1,629 notices, 2015–2026. We verified the published DaysElapsedBeforeNotification equals the date difference between DateAware and DateSubmitted on all 1,606 notices carrying both dates. Headline figures cover the 1,331 notices whose breaches were discovered on or after March 1, 2020, the effective date of the 30-day requirement (2019 c 241; previously 45 days); “late” means a published day-count strictly greater than 30, and percentiles are linear-interpolated. What the dataset measures is the clock on notice to the Attorney General; the consumer-notice duty shares the 30-day window but is a distinct obligation, and nothing here measures it. Affected-record sums are Washington resident records as reported by filers, not distinct people. Trend figures label their cohort basis; discovery cohorts after 2024 are right-truncated and read as floors. Delay figures are the AG record's arithmetic, not findings of law: the statute permits delayed notice at law-enforcement request or for measures necessary to determine a breach's scope and restore system integrity, and the dataset does not record when those grounds were invoked. RCW 19.255.030 substitutes the federal 60-day HITECH deadline for HIPAA covered entities that complied with it; graded at 60 days, the 284 Health-industry notices move the totals to 76.2% of notices and 67.9% of records — reported above as a sensitivity rather than folded into the headline.

Reproduce this in the product

Nearly every Washington notice in this report is also a record in our corpus: we hold 1,624 of the dataset's 1,629 rows, and 1,601 of those carry both the discovery date and the filing date the AG's day-count is built from, so the same arithmetic can be run against our copy.

Sources

Corrections: corrections@disclosurelens.com — 48-hour SLA. Every figure in this report derives from the Washington Attorney General's own public dataset and documents, was independently re-derived before publication, and was human-audited.

Cite this report

DisclosureLens, “The Washington Clock: The State Published the Deadline Data. We Read It.,” August 2026. https://disclosurelens.com/news/washington-clock-breach-notification

You may quote this report and reproduce its charts and excerpts with attribution to DisclosureLens and a link to this page. Republishing data or statistics obtained from the platform itself carries the same condition — see the data license in our terms.