How Long Organizations Take to Report a Breach After They Discover It
Most breach statistics measure the distance from the breach to the notice, which bundles together two very different problems: not knowing, and not telling. Washington State's official breach register records both endpoints. Across 1,615 filings, the median interval from the day an organization recorded becoming aware of a breach to the day it notified the Attorney General is 67 days, and 85 days across 2021–2025.
Two things about the register itself turn out to matter more than the headline: one incident can produce a hundred separate filings, and slightly over half of Washington's filings are incidents that also appear in California's register. These are descriptive intervals computed from dates the filers reported, and they measure no organization's compliance with anything.
Reviewed by Dor Israel, Founder · Updated
The headline numbers
Washington requires notice to the Attorney General when a single breach reaches more than five hundred Washington residents, and the AGO republishes every notice as a machine-readable register. Its rows carry a discovery date as well as a submission date, and most carry the incident's start and end dates too.
California's register, which we tabulate separately, carries no discovery-date column in its structured export, so it cannot show this at all. The interval this page is about is the stretch that begins after the organization already knows. Washington publishes that day count on every individual row. What it does not publish is the tabulation: the AGO's annual reports measure identification and containment time, both of which stop before a notice is ever written, and that timing section is absent from the 2023, 2024 and 2025 reports entirely.
Discovery to Attorney General notice (snapshot 2026-08-20)
| Population | Filings | Median | Middle half of filings |
|---|---|---|---|
| All filings carrying both dates (2016–present) | 1,615 | 67 days | 34.5–151.5 days |
| 2021–2025 | 1,044 | 85 days | 45–177.3 days |
| Most recent twelve months (2025-08-10 to 2026-08-10) | 194 | 101 days | — |
Source: Washington State Attorney General data-breach register, "Data Breach Notifications Affecting Washington Residents" (data.wa.gov open-data export), snapshot 2026-08-20. Quantiles are computed by linear interpolation between order statistics, so a median can land on a half-day. Computed by ComplianceDocs; method below.
One breach, a hundred filings
A register of notices is not a register of breaches, and on this register the gap is large enough to move a headline number. Washington's own documentation for the filer-name column explains why: the notice comes from the owner of the data, "whether or not they were the entity to be breached," so when a service provider is compromised, each downstream customer files separately.
The effect is visible in the dates. 15 groups of filings share an identical incident window across four or more distinct filers, together covering 217 filings. The largest single window, 2020-02-07 to 2020-05-20, carries 108 filings from 108 different organizations — on its own, more than one filing in twenty across the entire register.
Counting one filing per shared window instead of all of them moves the all-time median from 67 to 77 days, and it moves 2020 from 36 to 50 days, because a single incident supplied half that year's filings. Any statistic drawn from a state breach register — including ours, and including the year figures in the table further down — is a statistic about filings unless someone does this work.
The grouping rule is ours. The register does not label shared incidents, does not name the service provider behind any of them, and does not state that two filings describe the same event; identical dates are evidence of a common incident, not proof of one. We have not named any vendor behind these clusters, because the register does not name one and inferring it from outside the source would not be reporting the register. Both tabulations are published side by side and in the CSV, and neither is presented as the correct one.
Two state registers are not two samples
We came to Washington's register expecting it to serve as a second opinion on our California tabulation, and checked whether it can. It cannot — because the two registers hold substantially the same incidents.
Matching normalized organization names across both registers, 53.5% of Washington's 1,638 filings name an organization that also appears in California's 5,266-row register, and 50.6% match one whose report date lands within 90 days of the Washington submission. Of the 702 matched pairs where both registers carry an occurrence date, 91% carry the identical date and 94% agree within a week.
The mechanism is not mysterious: a breach large enough to clear Washington's five-hundred-resident threshold usually clears California's too, so the same organization files the same incident in both places. The consequence is that treating two state registers as two separate readings — and pooling several of them, as multi-state breach studies do — counts one body of self-reported data more than once. We have not seen this overlap quantified elsewhere, and we would rather publish it against our own earlier framing than leave it unstated.
Name matching cannot tell two genuinely different organizations apart when they normalize to the same short name, so the match counts above are an upper bound; the occurrence-date agreement is reported as the check on that, and it is the stronger of the two figures.
Overlap between the Washington and California breach registers
| Measure | Filings | Share |
|---|---|---|
| Washington filings naming an organization also in the California register | 877 | 53.5% |
| …and matching a California row reported within 90 days | 829 | 50.6% |
| Of matched pairs carrying an occurrence date on both sides: identical date | 639 | 91% |
| Of the same pairs: occurrence dates within seven days | 660 | 94% |
Computed by ComplianceDocs from both registers at snapshots 2026-08-20 and 2026-08-20. Organization names in both registers were normalized (lowercased, punctuation stripped, common corporate suffixes removed) and matched exactly. A Washington filing counts as matched when a California row carries the same normalized name and a report date within 90 days of the Washington submission date. Name matching cannot distinguish two genuinely different organizations that normalize to the same short name, so these counts are an upper bound on shared incidents; the occurrence-date agreement below is reported as the check on that.
What moved in the register, and what that does not show
Between 2021 and 2025 the median for this interval read 70.5 days and 134 days. It is tempting to read those two numbers as a multiple and conclude that organizations have become slower at reporting. Three things in the register argue against reading it that way, and all three are in the data on this page.
First, the series does not rise steadily — an intermediate year sits back at the 2021 level, so the two endpoint years are a comparison of two years, not a trend. Second, and most importantly, the change sits almost entirely inside one stratum. The register flags whether an incident was discovered while it was still in progress; among filings without that flag the median went from 61 days to 60.5 days — essentially unchanged — while among flagged filings it went from 93 days to 159 days.
Over the same period the share carrying the flag rose from 47.3% to 74.9%. Hold that mix constant at the 2021 level and the 2025 median becomes 94 days rather than 134 days. Much of what looks like a change in behavior is a change in which incidents get reported and how they are recorded.
Third, the register has already moved off that figure: across the most recent complete twelve months it reads 101 days across 194 filings. A single year's peak is a fragile thing to quote.
What can be said with the whole series rather than two years of it: fitting a robust trend across every individual filing from 2021 onward — the median of all pairwise slopes, which no single year can swing — gives about 9.2 days per year. That is a real upward drift, it is smaller than the endpoint gap implies, and it is the number worth quoting.
Median days from discovery to Attorney General notice, by year of submission
| Submission year | Filings | Median | Middle half | One filing per shared incident | Discovered in progress |
|---|---|---|---|---|---|
| 2016 | 49 | 34 days | 20–54 days | 34 (n=49) | 30.6% |
| 2017 | 83 | 36.5 days | 22.5–57 days | 42 (n=66) | 30.1% |
| 2018 | 63 | 43 days | 24.8–83.8 days | 43 (n=63) | 38.1% |
| 2019 | 60 | 43 days | 29–70 days | 43 (n=60) | 40% |
| 2020 | 204 | 36 days | 29–73.5 days | 50 (n=104) | 21.6% |
| 2021 | 186 | 70.5 days | 34.3–143.5 days | 73 (n=179) | 47.3% |
| 2022 | 171 | 83 days | 44–183 days | 85 (n=165) | 53.2% |
| 2023 | 252 | 68 days | 40.8–130 days | 74 (n=207) | 49.6% |
| 2024 | 228 | 109.5 days | 52–213 days | 112 (n=201) | 75% |
| 2025 | 207 | 134 days | 53.5–228.5 days | 134 (n=207) | 74.9% |
| 2026 (partial year) | 121 | 96 days | 58–195 days | 96 (n=121) | 75.2% |
Year = the calendar year the notice reached the AGO. The register's "Year" column is an AGO reporting year running July 24 to July 23, not a calendar year. All tabulations on this page bucket by the calendar year of DateSubmitted. Washington's notification statute was amended effective March 1, 2020, and the register's field composition shifts across that boundary — the share of incidents recorded as discovered while still in progress runs 27.9% before 2021 and 60.3% from 2021 on. Trend statements are therefore made within the 2021-and-later window rather than across the whole register. The current year is partial and its figures will move.
The date the register does not let you use
Washington's register carries an incident start date as well as a discovery date, which looks like it should let anyone split the whole breach-to-notice distance into "time to find it" and "time to tell." We built that split, checked it, and are not publishing it.
The reason is that the occurrence-side values move with recording conventions rather than with events. Across the register, the share of filings where the incident end date equals the discovery date roughly quadruples, a growing share record the start date as the discovery date, coverage of the start-date field itself climbs steeply, and the discovered-in-progress flag rises from about a fifth of filings to about three-quarters. Each of those shortens the measured find-it half by construction. A page reporting that organizations now detect breaches in under a week, down from months, would be reporting a change in data entry.
This is worth stating plainly because the split is the obvious thing to want from this register and, as far as we can tell, it cannot be had cleanly from it. What would close the question is documentation from the AGO on when and how the intake form changed, or a field distinguishing an entity's own breach from one it learned about through a service provider. Neither exists in the published register.
Locate your own response time
For a team pressure-testing an incident-response plan, the register works as a benchmark population. Take the distance your last incident or tabletop exercise produced between the moment the organization knew and the moment the state was notified, and the shares below locate it among Washington filings.
This is a performance benchmark against a published register and nothing more. The register cannot say whether any filing met any obligation, and neither can this table. Building the plan that shortens the distance is covered in our guide to writing an incident response plan at /learn/how-to-write-incident-response-plan.
Where a discovery-to-notice distance falls among Washington filings
| If the distance was under… | Shorter than (all filings) | Shorter than (2023–2025) |
|---|---|---|
| 60 days | 53.1% | 63.9% |
| 90 days | 40.6% | 50.1% |
| 1 year | 4.7% | 6.1% |
"Shorter than" = the share of register filings whose interval exceeded that threshold. Descriptive only.
For journalists: quotable findings and media kit
Quotable, with the caveat attached: “Across 1,615 filings in Washington State's official breach register, the median organization took 67 days from the day it recorded becoming aware of a breach to the day it notified the Attorney General. Across the most recent complete twelve months the figure is 101 days. These are dates the filers reported.”
The two findings we would lead with are about the register rather than the interval. First: 15 groups of filings share an identical incident window across four or more filers, the largest covering 108 filings from 108 organizations — so a count of notices is not a count of breaches, and collapsing them moves the all-time median from 67 to 77 days. Second: 53.5% of Washington's filings name an organization that also filed in California, and 91% of the matched pairs carrying occurrence dates on both sides carry the identical date — so two state registers are not two independent samples, and studies that pool several of them are counting some incidents more than once.
On the year-on-year rise, please do not turn the two endpoint years into a multiple. That comparison is not robust: the series is not monotone, the change is concentrated among filings the register flags as discovered while still in progress, and standardizing for that mix cuts the gap substantially. The robust figure is a drift of roughly 9.2 days per year fitted across individual filings.
The charts below are publication-ready (SVG, source credit rendered in), the per-year dataset is downloadable as CSV, and the full methodology is on this page. For a cut of the data by year, sector or size, or to check a figure before publication, write to support@compliancedocshq.com.
Method, exclusions and the dataset
Every row of the Washington AGO breach-register export was pulled from the Socrata API on the as-of date (row count asserted against the API's own count(*)). Three intervals are recomputed from the raw dates on each row, never read from the register's derived day-count columns: occurrence-to-discovery (DateStart to DateAware), discovery-to-notification (DateAware to DateSubmitted), and occurrence-to-notification (DateStart to DateSubmitted, the same axis California's register measures). The recomputation is asserted against the register's own DaysElapsedBeforeNotification column and the build fails on any disagreement.
Rows are bucketed by the CALENDAR year of DateSubmitted, because the register's own "Year" column is an AGO reporting year running July 24 to July 23; figures here therefore will not match the AGO's annual report. Rows excluded and counted: no DateSubmitted, no DateAware, negative intervals, and intervals over 3650 days. An interval is reported on an axis only when both of that axis's dates are present, so the three axes have different denominators.
None of these intervals is a measure of compliance with any notification deadline: the register reports dates as the notifying entity stated them, it does not record whether a statutory clock was tolled, and it does not distinguish an entity's own breach from one it learned about through a service provider.
Of the register's 1,638 rows at the snapshot date, 1,615 carried both a discovery date and a submission date and are the basis of every interval figure above; 23 carried no discovery date. No filing was excluded as a negative interval and none exceeded the ten-year cap on this axis. Each axis in the frozen dataset is computed from only its own two dates, so the denominators differ between axes by design. Quantiles are type-7 (linear interpolation between order statistics), which is why some medians land on a half-day; the same definition is used for every figure and in the CSV.
On field definitions, quoted rather than inferred: the register defines its discovery date as the date "the notifying entity became aware that a breach impacting Washington residents had occurred," and defines the notifying entity as the owner of the data rather than necessarily the breached party. Its derived day-count column for notification is described only as the days that elapsed before notice was submitted and does not state its own starting anchor; that the anchor is the discovery date is established here by arithmetic — recomputing the column from the raw dates reproduces all 1,615 values exactly — and not by any statement of the AGO's.
The register is filing-level, not incident-level: when a service provider is breached, every downstream organization files its own notice and all of those filings carry the same incident window. A second tabulation is therefore published alongside the filing-level one. Filings sharing an identical DateStart-to-DateEnd window and coming from at least 4 distinct filers are treated as one incident and represented by that group's median filing; all other filings stand alone. This grouping rule is ComplianceDocs's, not the register's — the register does not label shared incidents, does not name the service provider behind them, and does not state that any two filings describe the same event.
The year series is not monotone and the endpoints are not a trend: an intermediate year sits at or below the 2021 level. The change between the two endpoint years is also concentrated in one stratum — filings the register flags as discovered while the incident was still in progress — while the median among filings without that flag barely moves; because the share carrying the flag itself rose sharply, holding the mix constant shrinks the endpoint gap substantially. The register has since moved off the 2025 figure. The drift statistic published is a Theil-Sen slope over individual filings, which does not depend on the choice of endpoint years.
This tabulation is deliberately not the AGO's. The AGO's annual reports publish a "life cycle" figure that sums identification and containment time and stops before notification, and they publish it as a mean; nothing on this page should be compared against those numbers, and the same caution applies to the widely quoted industry "breach lifecycle" figures, which also end at containment rather than at notification. Every Washington AGO annual Data Breach Report from 2016 through 2025 and the AGO's live statistics page were checked on the snapshot date: the register carries a per-filing day count for notification, and no report or chart aggregates it.
What has already been published, so this page is not read as claiming more than it does. Xu and Nguyen (arXiv:2209.07306, 2022) decomposed breach timing into three intervals using the California register through 2020. Avanzi, Tan, Taylor and Wong (arXiv:2310.04786, 2024) analyzed eight state registers jointly, Washington and California among them. Neither the measurement nor the multi-register idea originates here. What this page adds is a current snapshot, a calendar-year tabulation, the shared-incident collapse, and the cross-register overlap measurement above.
One point of tension worth flagging rather than resolving: the 2024 paper states that only Maine's register provides dates of discovery, while Washington's register documents a discovery-date field and publishes values in it. Both statements are reported here as found.
The per-year aggregate table is available as a CSV dataset at /datasets/wa-breach-notification-intervals.csv and may be cited with attribution to ComplianceDocs and the Washington State Attorney General's register as the underlying source. This page reports the register as published; it is not legal advice.
What Washington law requires, stated separately
This closing section is legal background. It is deliberately kept apart from every figure on this page, and the two should not be combined — not by us, and not by a reader doing arithmetic between sections.
Washington requires an entity to notify the Attorney General "no more than thirty days after the breach was discovered" once a single breach reaches "more than five hundred Washington residents." The identical requirement sits in two places, and the register is fed by both — RCW 19.255.010(7) for persons and businesses, and RCW 42.56.590(7) for state and local agencies. Consumer notice runs on its own thirty-calendar-day clock in the neighboring subsection of each.
That figure applies to breaches discovered on or after March 1, 2020, the effective date of 2019 c 241; the statute previously read forty-five calendar days, and before July 24, 2015 there was no duty to notify the Attorney General at all.
Several things stop the register from being readable against that requirement, which is why this page draws no such comparison anywhere. The statute allows notification to be delayed at the request of law enforcement or for "measures necessary to determine the scope of the breach," and the register carries no field recording which delays were excused. Covered entities under HIPAA notify the Attorney General on the federal HITECH timeline instead, expressly "notwithstanding the timeline in RCW 19.255.010(7)" (RCW 19.255.030). And the statute does not define "discovered," so how the register's discovery field relates to the statutory term is unknown and is not something we can establish from the published data.
Statute text read from app.leg.wa.gov and the session laws at leg.wa.gov on the snapshot date, and re-checked automatically whenever this page's dataset is rebuilt. This is statistical reporting, not legal advice.
Charts, dataset and reuse
The charts and the underlying tabulated dataset on this page are published under CC BY 4.0: reuse them in your own article, report or deck, with attribution to ComplianceDocs — a link back to this page is the attribution form we ask for. The underlying government register is public information; the license covers this tabulation and these charts.
Dataset: Washington breach intervals by submission year (CSV; snapshot-dated, methodology above).
Cite this data
ComplianceDocs, “Breach discovery-to-notification intervals, Washington State AG register,” https://compliancedocshq.com/learn/breach-discovery-to-notification-washington. Underlying register as named in the method note.
Embed a chart
Copy and paste — the snippet credits the source for you:
<a href="https://compliancedocshq.com/learn/breach-discovery-to-notification-washington"><img src="https://compliancedocshq.com/charts/wa-discovery-to-notification.svg" alt="Line chart of the median days from breach discovery to Attorney General notice in the Washington register, by calendar year of submission, with values ranging from the mid-thirties in the earlier years to the low hundreds in the later ones" width="720" style="max-width:100%;height:auto"></a> <p>Source: <a href="https://compliancedocshq.com/learn/breach-discovery-to-notification-washington">ComplianceDocs — How Long Organizations Take to Report a Breach After They Discover It</a></p>
Frequently asked questions
- How long do companies take to report a breach after they discover it?
- Measured from 1,615 filings in Washington State's official breach register (snapshot 2026-08-20), the median interval from the day an organization recorded becoming aware of a breach to the day it notified the Attorney General is 67 days, with the middle half of filings falling between 34.5 and 151.5 days. Across the most recent complete twelve months the median is 101 days. These are dates reported by the filers, and they describe filings rather than compliance.
- Is breach notification getting slower?
- The register shows an upward drift, but a far smaller one than comparing two endpoint years suggests. Fitting a robust trend across individual filings from 2021 onward gives roughly 9.2 days per year. The year series is not monotone, and the change between 2021 and 2025 sits almost entirely among filings the register flags as discovered while the incident was still in progress — among filings without that flag the median barely moved (61 to 60.5 days), while the share carrying the flag rose from 47.3% to 74.9%.
- Does one breach produce one row in the Washington register?
- No. The register records notices, not incidents, and Washington's own column documentation states that the filer is the owner of the data whether or not it was the breached party — so a service-provider breach produces one filing per downstream customer. 15 groups of filings share an identical incident window across four or more distinct filers, covering 217 filings in total; the largest window alone carries 108 filings. Counting one filing per shared window moves the all-time median from 67 to 77 days.
- Can you compare two states’ breach registers to check a figure?
- Not as independent sources. Matching organization names across the Washington and California registers, 53.5% of Washington's filings name an organization that also appears in California's, and of the matched pairs carrying an occurrence date on both sides, 91% carry the identical date. A breach large enough to clear one state's threshold usually clears the other's, so the same incident is filed twice. Pooling several state registers counts some incidents more than once.
- How much of the delay is discovery time rather than reporting time?
- We cannot answer that cleanly from this register, and we think nobody can. Washington publishes an incident start date as well as a discovery date, but the occurrence-side values move with recording conventions rather than events: coverage of the start-date field climbs steeply over the register's life, a growing share of filings record the start or end date as the discovery date, and the share flagged as discovered while still in progress rises from about a fifth to about three-quarters. Any split computed across those years would mostly measure changes in data entry, so this page publishes none.
- Where does this data come from?
- Every figure is computed from the Washington State Attorney General's public breach register, published as an open dataset at https://data.wa.gov/Consumer-Protection/Data-Breach-Notifications-Affecting-Washington-Resi/sb4j-ca4h and pulled through its API on 2026-08-20. Intervals are recomputed from the raw dates rather than read from the register's derived columns, rows are bucketed by the calendar year of submission rather than the AGO's July-to-July reporting year, quantiles use linear interpolation throughout, and every exclusion is stated on this page. The per-year aggregates are downloadable as CSV.
- What is the deadline to report a data breach in Washington State?
- Washington requires notice to the Attorney General "no more than thirty days after the breach was discovered" when a single breach reaches "more than five hundred Washington residents" — RCW 19.255.010(7) for persons and businesses, and RCW 42.56.590(7) for state and local agencies, with consumer notice on its own thirty-calendar-day clock. That figure applies to breaches discovered on or after March 1, 2020 (2019 c 241); the statute previously read forty-five calendar days. Notification may be delayed at the request of law enforcement or for measures needed to determine the scope of the breach, HIPAA covered entities notify on the federal HITECH timeline instead, and the statute does not define "discovered." This is statistical reporting, not legal advice.
Toolkits that help
ISO 27001 Complete Toolkit
All 24 policies and procedures plus the risk register, 93-control Statement of Applicability and audit evidence checklist.
SOC 2 Complete Toolkit
22 policies plus the risk register, full Trust Services Criteria mapping and audit evidence checklist — built for startups facing their first SOC 2.
HIPAA Compliance Toolkit — Medical Practices
18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for small medical practices and clinics.
GDPR Compliance Pack for Small Business
14 editable GDPR documents — privacy notices, DSAR procedure, DPIA, breach response, processor DPA checklist — plus a pre-filled Records of Processing Activities (Art. 30) workbook and evidence checklist.
Related articles
- How Long Breach Notification Actually Takes, Measured from California’s Register
- How Many Documents Each Compliance Framework Actually Requires
- How Long Compliance Documentation Actually Takes
- Compliance Documentation Benchmarks: What a Policy Library Actually Contains
- 2026 Compliance Template Pricing Index
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
