Data Breach Notification Monitor — 7 Sources, No Login
Pricing
from $20.00 / 1,000 breach notices
Data Breach Notification Monitor — 7 Sources, No Login
Watch state attorney general breach lists (CA, WA, OR, VT, DE, IA) and the HHS breach portal and get only NEW data breach notices since the last run: organization, breach and report dates, residents affected, data types, notice letter PDF. Daily schedule. No login. MCP-ready. $20 per 1,000 alerts.
Pricing
from $20.00 / 1,000 breach notices
Rating
0.0
(0)
Developer
Peter Skotte
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Data Breach Notification Monitor — state AG registries + HHS, daily alerts
Get a daily feed of only the new data breach notifications filed with US state attorneys general and the
HHS Office for Civil Rights: which organization was breached, when, how many people were affected, what data
was exposed, and a link to the sample consumer letter. The monitor remembers every notice it has already
reported, so a scheduled run emits just the delta (new, or updated when a source revises the affected
count), posts a summary to your webhook, and costs you only for what actually changed. No login, no API key.
Pairs with an SEC 8-K Item 1.05 (cybersecurity incident) watch: the state registries catch the thousands of breaches at private companies, hospitals, school districts and law firms that never file with the SEC.
Sources
| Key | Registry | What it publishes | Affected count | Posting lag |
|---|---|---|---|---|
ca | California AG — Data Security Breach list | Organization, breach date(s), date reported, sample letter PDF | none published | days |
wa | Washington AG — Data Breach Notifications | Organization, breach start date, Washingtonians affected, information compromised, letter PDF | state residents | days |
hhs | HHS OCR — HIPAA breach portal (cases under investigation, 500+ individuals) | Covered entity, state, entity type, individuals affected, breach type, location, submission date | total | days |
or | Oregon DOJ — Data Breach search | Organization, dates of breach, discovery date, notice-sent date, number affected | total (as published) | days |
vt | Vermont AG — Security Breach Notices | Organization, organization type, Vermont residents affected, categories of data breached | state residents | days |
de | Delaware AG — Data Security Breach Database (open-data API) | Organization, breach / discovered / notice dates, Delaware residents, total affected, data types, letter PDF, supplemental revisions | total + state | posted in batches, typically 4–8 weeks |
ia | Iowa AG — Security Breach Notifications | Organization, industry, date reported, letter PDF | none published | 2–4 weeks |
Default sources are ca, wa and hhs (the three fastest-posting). Pass ["all"] for every registry.
Not covered, and why: Maine took its public breach database offline after abuse of its reporting system; Texas moved its list into a Salesforce Lightning app with no guest data endpoint; Massachusetts, New Hampshire and Montana block automated access; Hawaii last posted in 2024; Indiana publishes an annual PDF only; Maryland, New Jersey, North Dakota removed their public lists.
How it works
- Loads each selected registry and keeps the notices reported within the last
lookbackDays. - Applies your
companyKeywordsandminAffectedfilters. - Compares each notice against the monitor's saved state (
source:noticeKey → affectedCount). - Emits a record when the notice is unseen (
changeType: "new") or its published affected count changed (changeType: "updated"), enriched with the sample-letter PDF for California whenincludeDetailsis on. - Saves the state, then POSTs a run summary to
webhookUrlif set.
State lives in a named key-value store breach-monitor-<hash of monitorId> in your Apify account, capped at
50,000 notices (oldest dropped). Delete the store to reset a monitor.
Input
| Field | Default | Notes |
|---|---|---|
sources | ["ca","wa","hhs"] | Any of ca, wa, hhs, or, vt, de, ia, or all |
companyKeywords | [] | Case-insensitive substrings matched against the organization name, OR-ed. Empty = all |
minAffected | 0 | Minimum published affected count (total or state residents, whichever is larger). California and Iowa publish no counts and are excluded when this is above 0 |
lookbackDays | 30 | Notices reported within N days. Registries post days to weeks after the filing, so keep this generous; the seen-state prevents duplicates |
maxNewPerSource | 5 | Cap per source per run; anything beyond stays unseen and comes out next run |
maxItems | 10 | Overall cap per run |
includeDetails | true | Fetch the California detail page for the sample letter PDF |
firstRunMode | emitAll | emitAll reports every current notice on the first run; baseline records them silently |
webhookUrl | "" | Optional POST target for the run summary |
monitorId | default | One state store per ID — run several watchlists side by side |
proxyConfiguration | none | Every source is reachable from Apify's cloud without a proxy |
Output
One record per new or updated notice:
{"source": "wa","state": "WA","organization": "zHealth, Inc.","organizationType": null,"breachStartDate": "2026-01-20","breachEndDate": null,"discoveredDate": null,"reportedDate": "2026-09-11","affectedTotal": null,"affectedStateResidents": 1332,"dataTypes": ["Name", "Health Insurance Policy or ID Number", "Medical Information"],"noticeUrl": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf","letterUrl": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf","description": null,"matchedKeyword": null,"changeType": "new","firstSeenAt": "2026-09-29T00:17:29.434Z","monitorId": "default"}
Fields a registry does not publish are null (or [] for dataTypes). noticeUrl is the registry's detail
page when one exists (California), otherwise the letter PDF or the listing page. description carries the
HHS breach type and location, the Oregon consumer-notice date, or the Delaware supplemental-filing date.
Recommended setup for a daily feed
- Create a task, pick your
sources, and setmonitorIdto something meaningful (healthcare-10k). - First run: set
firstRunModetobaselinewithlookbackDays60. This records everything currently listed, emits nothing, and stops day one from being a backlog dump. - Switch
firstRunModeback toemitAll(it only matters when the state is empty), keeplookbackDaysat 30–45 and raisemaxNewPerSource/maxItemsto 200+. - Schedule the task daily at 07:00 America/Los_Angeles. California, Washington and Oregon post during the Pacific business day; a morning run catches the previous day's postings across all time zones.
- Point
webhookUrlat Slack (incoming webhook), Zapier, Make, or your own endpoint. The payload is{monitorId, runAt, sources, newCount, updatedCount, scanned, seenTotal, notices[first 50]}.
The default settings ({}) run in emitAll mode and return the latest 10 notices so you see real output on
the first try.
Use cases
- Cyber insurers and brokers: flag insureds and applicants the day their notice lands;
updatedrecords catch upward revisions of the affected count. - Security vendors: outbound trigger lists — every breached organization with the data types exposed.
- Class-action and privacy law firms: first sight of breaches above a threshold (
minAffected: 10000). - Journalists and researchers: one normalized feed across seven registries instead of seven web pages.
- Third-party risk teams: watch your vendors by name with
companyKeywords.
Examples
Healthcare breaches over 10,000 individuals, all registries:
{ "sources": ["all"], "companyKeywords": ["health", "medical", "hospital", "clinic", "dental", "pharmacy"], "minAffected": 10000, "maxNewPerSource": 100, "maxItems": 500 }
Watch a vendor list:
{ "sources": ["all"], "companyKeywords": ["Quatrro", "zHealth", "DentaQuest"], "lookbackDays": 90, "firstRunMode": "baseline" }
Notes
- Counts are exactly as published:
affectedStateResidentsfor Washington and Vermont,affectedTotalfor HHS and Oregon, both for Delaware. California and Iowa publish no counts. - Notices are deduplicated per source, not across sources: a company that files in California, Washington and Oregon produces one record per registry, each with that state's figures.
- Pricing: $0.005 per run plus $0.02 per emitted notice. A daily schedule that finds nothing new costs the start fee only.