Problem
Some states (U.S states) define a data and security breach as the loss and exposure of citizen privacy data in an unencrypted manner. If a state encountered a data and security breach, but no citizen's privacy data was compromised given that it was encrypted in a steady-state within a database, does the company or organization have to abide by the data and security breach notification law?