Breach Notification to Affected Individuals
Maturity Level

Level 0: Non-Existent
The practice is not implemented or acknowledged.
No breach notification procedures are in place.Example Strategies
- Identify individuals who can perform such functions in an ad hoc or as needed basis until permanent individuals are appointed.
Level 1: Ad Hoc
Practice may occur but is undocumented (no policies or procedures), application is reactive and not standardized.
In the event of a breach, notifications might be issued on an ad-hoc basis, lacking consistency or full compliance with Utah Code § 63A-19-406.Example Strategies
- Draft a "Data Breach Notification Letter" template.
Level 2: Defined
Practice is implemented and documented, but documentation may not cover all relevant aspects, and application may be informal and inconsistent.
A basic breach notification procedure is documented, but it might not cover all required elements (e.g., timing, content, recipients like the Utah Cyber Center/AG's Office for certain breaches).Example Strategies
- Notify affected individuals without unreasonable delay.
Level 3: Consistently Implemented
Practice is documented to cover all relevant aspects, application is formal and consistent.
The entity has a formal, documented, and consistently applied breach notification procedure that fully complies with all requirements of Utah Code § 63A-19-406, ensuring timely and accurate communication to affected individuals and authorities.Example Strategies
- Track "Notification Success" metrics and delivery rates.
Level 4: Managed
Practice is actively managed with metrics that are regularly reviewed to assess efficacy and facilitate improvement.
The entity tracks the timeliness and completeness of breach notifications, analyzes post-breach feedback, and refines notification templates and processes based on actual incident experience.Example Strategies
- Implement a "Crisis Communication Portal" for breaches.
Level 5: Optimized
Practice is fully embedded in the entity with recognition and understanding across the workforce through active training and awareness campaigns, and inclusion in operations and strategy.
The breach notification process is highly streamlined and automated where possible, with pre-approved templates and clear communication channels, minimizing impact and maintaining public trust.