Reference · LeakTrace Intelligence Team
Compliance & disclosure framework reference.
The privacy, data-protection, and cyber-disclosure frameworks LeakTrace's B2B clients operate under. Each page tracks who the framework applies to, breach-reporting deadlines, key provisions, and recent amendments. Written as neutral reference; refreshed as the frameworks evolve.
US Federal
HIPAA
Health Insurance Portability and Accountability Act (45 CFR Parts 160, 162, and 164)
US federal healthcare privacy and security law. The Privacy, Security, and Breach Notification Rules govern covered entities and business associates handling Protected Health Information (PHI), with breach notification obligations to HHS, affected individuals, and (for large breaches) media.
60 days to affected individuals; 60 days to HHS for breaches of 500+ Updated Aug 2026
SEC Item 1.05
SEC Cybersecurity Disclosure Rules (Form 8-K Item 1.05 and Regulation S-K Item 106)
SEC rules requiring public companies to disclose material cybersecurity incidents on Form 8-K within four business days of materiality determination, and to describe cybersecurity risk management, strategy, and governance in annual reports.
4 business days from materiality determination Updated Aug 2026
SOC 2
SOC 2 — Trust Services Criteria (AICPA)
AICPA reporting framework for service organizations. Independent auditor examines controls against the Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Not a law; a de facto market requirement for enterprise SaaS.
Contractual — controlled by customer BAAs and MSAs Updated Aug 2026