The security policy a Illinois business is expected to have.
Every US state has its own data-breach notification law, and a generic template can’t say which one is yours. Answer 21 questions, including which state you’re in, and your incident response plan and security program name Illinois as the baseline — not a placeholder, not a 50-state table you have to interpret yourself.
Every US state has a data-breach notification law. If personal information is exposed, the duty to notify is set by the law of the state where each affected individual lives — not only the state the business operates from — so a single incident can engage several states’ rules at once. Notification is generally required without unreasonable delay; many states set an outside limit of 30 to 60 days from discovery, though several set no fixed outer deadline and rely on the “without unreasonable delay” standard alone. “Discovery” is itself statutorily defined in most states and can be imputed — the clock frequently starts when the breach reasonably should have been known, not when someone actually noticed it. A number of states also require notice to the state attorney general once a threshold number of residents is affected. Establishing which laws apply is part of the assessment step in the business’s Incident Response Plan, taken with counsel where the answer is not obvious.
Harborview Accounting LLC operates from Illinois and treats Illinois’s breach-notification statute as its baseline, alongside the law of any other state where an affected individual lives. The specific statute, its deadlines, and its attorney-general reporting threshold are confirmed with counsel rather than assumed — this program records that the obligation exists and who is responsible for meeting it, not the text of the statute.
What this does and doesn’t answer.
Does this mean my documents comply with Illinois’s law?
No, and nothing on this site claims otherwise. Your program records that the obligation exists and who at your business is responsible for meeting it — not the text of Illinois’s statute, its specific deadline, or its attorney-general filing threshold. Confirming those is a job for your counsel, not a generated document.
Why can’t the documents just say the deadline?
Notification is generally required without unreasonable delay; many states set an outside limit of 30 to 60 days from discovery, though several set no fixed outer deadline at all — and “discovery” is itself a statutory term that can be imputed rather than running from the day someone actually noticed. Stating one number as if it applied everywhere would be simpler and wrong. Your plan names the general shape and leaves the specific number to the advice it takes to get right.
What if a customer or employee lives somewhere else?
Then that person’s state law can apply too — the duty to notify runs by where each affected individual lives, not only where the business operates. Your incident response plan names Illinois as the baseline and says this explicitly, so a single incident touching people in several states isn’t a surprise on the day it happens.
Whether Illinois’s specific breach-notification deadline, its attorney-general filing threshold, or any other state or federal rule applies to a particular incident is a legal determination for the business and its counsel. Coverwright’s documents name Illinois as the baseline and record that the obligation exists; they are not a substitute for advice, and producing them doesn’t guarantee insurance acceptance, claim outcomes, or regulatory compliance.
What actually sends someone here.
Same 21-question engine, but what it asks of you depends on what your business does — not just which state it’s in:
For tax and accounting firms
The written security program your firm is expected to have
For clinics and healthcare practices
Security documentation for a practice without an IT department
For firms answering client security reviews
The security questionnaire your biggest client just sent you
For managed IT providers
The written security program you tell clients to have — for yourself
For online and retail stores
The security policy your payment processor already expects you to have
For contractors and trades businesses
The fraud that actually costs contractors money isn’t ransomware