Data breach prevention and notification training for employees

For employees who handle personal data and the supervisors who lead them: prevent breaches, report fast, and understand US notification duties under state laws, HIPAA, the FTC Safeguards Rule and SEC rules.

For: All employees who handle customer, patient or employee personal data, plus supervisors and managers who receive incident reports, in businesses, health care organizations, financial services, nonprofits and public companies.

  • 2 contact hours
  • 7 modules
  • 9 interactives
  • 4 job aids
  • Updated October 11, 2026

What you will be able to do

  • Explain what counts as a data breach under typical state laws and the HIPAA Breach Notification Rule, and distinguish a security incident from a notifiable breach.
  • Apply everyday prevention controls, including verifying recipients and requests, secure transfer, MFA, data minimization, secure disposal and device protection.
  • Recognize signs of a possible breach and report it immediately through the internal process while preserving evidence and avoiding do-it-yourself fixes.
  • Describe US notification duties under state laws, HIPAA (45 CFR 164.400-414), the FTC Safeguards Rule (16 CFR 314.4(j)) and SEC Form 8-K Item 1.05, including key deadlines and thresholds.
  • Support containment, notification, breach logging and lessons-learned reviews, and escalate legal and external communication questions to the right people.

Most data breaches start with an ordinary moment: an autocompleted email address, a laptop left in a car, a password typed into a fake page. This course shows you how breaches happen, the everyday controls that prevent them, how to recognize a possible breach, and exactly what to do in the first hour: report, preserve evidence and let the response team lead.

It then explains the US notification landscape in practical terms: state breach laws (definitions, deadlines, attorney general notice, encryption safe harbors) with verified examples, the HIPAA Breach Notification Rule, the FTC Safeguards Rule's 30-day notice to the FTC for events involving 500 or more consumers, and SEC Form 8-K disclosure for public companies. It finishes with containment, breach logs and blameless lessons-learned reviews.

Scenarios from a Texas auto dealership, a Michigan pediatric therapy clinic, a Florida staffing agency and a Nebraska public company make the rules concrete. You will practice with a decision tool, a state look-up, spot-the-problem exercises, a manager's dilemma and a full branching scenario, and leave with a checklist, a policy starter, a tabletop worksheet and a state quick reference.

What you’ll be able to do Monday morning

  1. Check recipients and attachments, and use the approved secure method, every time you send personal data.
  2. Verify any request to change payment details or send sensitive data by calling a known number.
  3. Save your organization's incident reporting contact and use it within minutes of any suspected incident, including your own mistakes.
  4. Preserve evidence: do not delete, wipe, restore or power off anything unless the security team tells you to.
  5. Leave decisions about legal notice, regulators and public statements to the privacy officer and counsel.
  6. As a manager, thank every person who reports and track post-incident fixes to completion.

Curriculum

7 modules · 28 lessons · about 2 contact hours

01What counts as a data breach?Free preview14 min
  1. What is a data breach, in plain terms?
  2. What is 'personal information' under state breach laws?
  3. How does HIPAA define a breach?
  4. Incident, breach, notifiable breach: why the words matter
  • Self-assessment: How breach-ready are my habits?

Diagram · In practice checklist · 2-question knowledge check

02How do breaches really happen?14 min
  1. What are the most common causes?
  2. Why is email the riskiest tool you use?
  3. What about texts, photos, screens and paper?
  4. What role do vendors and insiders play?
  • Sort activity: Report it, or safe practice?

Diagram · In practice checklist · 2-question knowledge check

03What controls prevent breaches, and what is your part?15 min
  1. Why do organizations need a security program?
  2. Which everyday controls depend on you?
  3. How do you protect data when working remotely or on the road?
  4. What is a strong reporting culture?
  • Spot the issue: Spot the risky practices in a manager's email

Diagram · In practice checklist · 2-question knowledge check

04How do you recognize a possible breach and report it fast?15 min
  1. What are the warning signs of a breach?
  2. Why does speed matter so much?
  3. How should you report, and what should you NOT do?
  4. What should you write down?
  • Decision tree: I think something went wrong with data: what now?

Diagram · In practice checklist · 2-question knowledge check

05What do state breach notification laws require?16 min
  1. Why do state laws matter so much?
  2. How fast must people be notified?
  3. What else do state laws commonly require?
  4. What does a good notice to individuals contain?
  • State rules selector: State breach notification quick look-up

Diagram · In practice checklist · 2-question knowledge check

06What do HIPAA, the FTC Safeguards Rule and SEC rules add?16 min
  1. What does the HIPAA Breach Notification Rule require?
  2. What does the FTC Safeguards Rule add for financial businesses?
  3. What do SEC rules require of public companies?
  4. How do the federal and state duties fit together?
  • Matching activity: Match the rule to its key requirement

Diagram · In practice checklist · 2-question knowledge check

07How do organizations contain, recover and learn from a breach?15 min
  1. What happens during containment and recovery?
  2. What is a breach log, and why keep one?
  3. How do lessons-learned reviews work?
  4. What should managers and supervisors do?
  • Ethics dilemma: The top performer's request
  • Spot the issue: Review a draft breach notice
  • Branching scenario: Friday afternoon at the Waco dealership

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 75% to pass, then your certificate

Try it now, no account needed

Friday afternoon at the Waco dealership

A branching scenario from this course. Your choices are not saved.

Free sample activity

Friday afternoon at the Waco dealership

You are Corbin Stroud, finance manager at a dealership in Waco, Texas. The dealership is covered by the FTC Safeguards Rule. It is 4:40 p.m. on a Friday.

Inside the course

Practice activities

  • Self-assessment1
  • Sort activity1
  • Spot the issue2
  • Decision tree1
  • State rules selector1
  • Matching activity1
  • Ethics dilemma1
  • Branching scenario1

Job aids you keep

  • Breach Prevention and First-Hour Response ChecklistChecklist
  • Security Incident Reporting Policy (Starter)Policy starter
  • Breach Scenario WorksheetWorksheet
  • State Breach Notification Quick Reference (verified states)Reference sheet

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not currently approved or accredited by any continuing education accreditor, professional association or state agency, and it does not provide CPE for accountants or privacy certification credit. Employers decide whether to accept it for internal training requirements. It is general awareness training and does not replace your organization's incident response plan or legal advice.

Pathways we may pursue include IACET-aligned continuing education units and NASBA-registered CPE, if approval is obtained. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

State notes

Every state, the District of Columbia, Puerto Rico and the Virgin Islands has a breach notification law, and the law of each affected person's state generally applies. The laws differ in:

  • Definitions: which data elements count (for example, biometric data in CO, DE, DC and NY; online credentials in AL, CA, CO, DE, FL, NY and DC).
  • Deadlines: 30 days in CA (Civ. Code 1798.82 as amended by SB 446, from 1/1/2026), CO (C.R.S. 6-1-716), FL (Fla. Stat. 501.171), ME (10 M.R.S. 1348) and NY (Gen. Bus. Law 899-aa); 45 days in AL (Ala. Code 8-38-1 et seq.) and AZ (A.R.S. 18-552); 60 days in CT (Gen. Stat. 36a-701b) and DE (6 Del. C. 12B-101 et seq.); 'without unreasonable delay' in IL, VA and DC.
  • Regulator notice: for example, the AG for 500+ residents in CA, CO, FL, DE and IL; 1,000+ in AL and AZ; 50+ in DC; any notifiable breach in CT, NY and VA.
  • Extras: credit monitoring duties (CT 24 months, DE 1 year when SSNs are involved); consumer reporting agency notice for large breaches.

What to check locally: your organization's incident response plan, which states your customers and employees live in, and current statutes, which counsel should confirm before any notice.

Questions about this course

Is this course approved for CPE or privacy certification credit?

No. It awards a certificate of completion for 2 contact hours. It is not approved by NASBA, IAPP, IACET or any state agency. Your employer decides whether it meets internal training requirements. If you need CPE or certification credit, check with the credentialing body before relying on this course.

Does this course tell me whether my organization must notify people?

No. It explains how the major laws work so you understand the process and act quickly. Whether a specific incident requires notice under state law, HIPAA, the FTC Safeguards Rule or SEC rules is a legal decision for your privacy officer and counsel.

Who should take it?

Any employee who handles customer, patient or employee personal data, including sales, finance, HR, payroll, customer service, billing and IT staff, and supervisors who receive incident reports. It is especially relevant in health care, auto sales and lending, staffing and public companies.

Does it cover my state's breach law?

It explains how state laws work and gives verified details for 14 jurisdictions in a look-up tool and quick reference: AL, AZ, CA, CO, CT, DC, DE, FL, HI, ID, IL, ME, NY and VA. Every state has a law; for others, check your state attorney general's site and ask counsel.

How long does it take, and how am I assessed?

Plan on about 2 hours for seven modules with interactive exercises, then a final assessment of 23 questions drawn from a larger bank. You need 75% to pass, and you receive a certificate of completion showing 2 contact hours.

How current is the legal content?

It was checked against official sources in October 2026, including California's SB 446 30-day rule effective January 1, 2026, and the FTC Safeguards Rule notice duty effective May 13, 2024. Breach laws change often; the course is reviewed at least every 12 months and after major changes.

This course is general education and training awareness from CE Courses Hub on data breach prevention and US notification laws. It is not legal or professional advice and does not replace your employer's policies or incident response plan, your licensing board's rules, or advice from a qualified attorney or security professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.