Data Breach Notification Monitor — 7 Sources, No Login avatar

Data Breach Notification Monitor — 7 Sources, No Login

Pricing

from $20.00 / 1,000 breach notices

Go to Apify Store
Data Breach Notification Monitor — 7 Sources, No Login

Data Breach Notification Monitor — 7 Sources, No Login

Watch state attorney general breach lists (CA, WA, OR, VT, DE, IA) and the HHS breach portal and get only NEW data breach notices since the last run: organization, breach and report dates, residents affected, data types, notice letter PDF. Daily schedule. No login. MCP-ready. $20 per 1,000 alerts.

Pricing

from $20.00 / 1,000 breach notices

Rating

0.0

(0)

Developer

Peter Skotte

Peter Skotte

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Data Breach Notification Monitor — state AG registries + HHS, daily alerts

Get a daily feed of only the new data breach notifications filed with US state attorneys general and the HHS Office for Civil Rights: which organization was breached, when, how many people were affected, what data was exposed, and a link to the sample consumer letter. The monitor remembers every notice it has already reported, so a scheduled run emits just the delta (new, or updated when a source revises the affected count), posts a summary to your webhook, and costs you only for what actually changed. No login, no API key.

Pairs with an SEC 8-K Item 1.05 (cybersecurity incident) watch: the state registries catch the thousands of breaches at private companies, hospitals, school districts and law firms that never file with the SEC.

Sources

KeyRegistryWhat it publishesAffected countPosting lag
caCalifornia AG — Data Security Breach listOrganization, breach date(s), date reported, sample letter PDFnone publisheddays
waWashington AG — Data Breach NotificationsOrganization, breach start date, Washingtonians affected, information compromised, letter PDFstate residentsdays
hhsHHS OCR — HIPAA breach portal (cases under investigation, 500+ individuals)Covered entity, state, entity type, individuals affected, breach type, location, submission datetotaldays
orOregon DOJ — Data Breach searchOrganization, dates of breach, discovery date, notice-sent date, number affectedtotal (as published)days
vtVermont AG — Security Breach NoticesOrganization, organization type, Vermont residents affected, categories of data breachedstate residentsdays
deDelaware AG — Data Security Breach Database (open-data API)Organization, breach / discovered / notice dates, Delaware residents, total affected, data types, letter PDF, supplemental revisionstotal + stateposted in batches, typically 4–8 weeks
iaIowa AG — Security Breach NotificationsOrganization, industry, date reported, letter PDFnone published2–4 weeks

Default sources are ca, wa and hhs (the three fastest-posting). Pass ["all"] for every registry.

Not covered, and why: Maine took its public breach database offline after abuse of its reporting system; Texas moved its list into a Salesforce Lightning app with no guest data endpoint; Massachusetts, New Hampshire and Montana block automated access; Hawaii last posted in 2024; Indiana publishes an annual PDF only; Maryland, New Jersey, North Dakota removed their public lists.

How it works

  1. Loads each selected registry and keeps the notices reported within the last lookbackDays.
  2. Applies your companyKeywords and minAffected filters.
  3. Compares each notice against the monitor's saved state (source:noticeKey → affectedCount).
  4. Emits a record when the notice is unseen (changeType: "new") or its published affected count changed (changeType: "updated"), enriched with the sample-letter PDF for California when includeDetails is on.
  5. Saves the state, then POSTs a run summary to webhookUrl if set.

State lives in a named key-value store breach-monitor-<hash of monitorId> in your Apify account, capped at 50,000 notices (oldest dropped). Delete the store to reset a monitor.

Input

FieldDefaultNotes
sources["ca","wa","hhs"]Any of ca, wa, hhs, or, vt, de, ia, or all
companyKeywords[]Case-insensitive substrings matched against the organization name, OR-ed. Empty = all
minAffected0Minimum published affected count (total or state residents, whichever is larger). California and Iowa publish no counts and are excluded when this is above 0
lookbackDays30Notices reported within N days. Registries post days to weeks after the filing, so keep this generous; the seen-state prevents duplicates
maxNewPerSource5Cap per source per run; anything beyond stays unseen and comes out next run
maxItems10Overall cap per run
includeDetailstrueFetch the California detail page for the sample letter PDF
firstRunModeemitAllemitAll reports every current notice on the first run; baseline records them silently
webhookUrl""Optional POST target for the run summary
monitorIddefaultOne state store per ID — run several watchlists side by side
proxyConfigurationnoneEvery source is reachable from Apify's cloud without a proxy

Output

One record per new or updated notice:

{
"source": "wa",
"state": "WA",
"organization": "zHealth, Inc.",
"organizationType": null,
"breachStartDate": "2026-01-20",
"breachEndDate": null,
"discoveredDate": null,
"reportedDate": "2026-09-11",
"affectedTotal": null,
"affectedStateResidents": 1332,
"dataTypes": ["Name", "Health Insurance Policy or ID Number", "Medical Information"],
"noticeUrl": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf",
"letterUrl": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf",
"description": null,
"matchedKeyword": null,
"changeType": "new",
"firstSeenAt": "2026-09-29T00:17:29.434Z",
"monitorId": "default"
}

Fields a registry does not publish are null (or [] for dataTypes). noticeUrl is the registry's detail page when one exists (California), otherwise the letter PDF or the listing page. description carries the HHS breach type and location, the Oregon consumer-notice date, or the Delaware supplemental-filing date.

  1. Create a task, pick your sources, and set monitorId to something meaningful (healthcare-10k).
  2. First run: set firstRunMode to baseline with lookbackDays 60. This records everything currently listed, emits nothing, and stops day one from being a backlog dump.
  3. Switch firstRunMode back to emitAll (it only matters when the state is empty), keep lookbackDays at 30–45 and raise maxNewPerSource / maxItems to 200+.
  4. Schedule the task daily at 07:00 America/Los_Angeles. California, Washington and Oregon post during the Pacific business day; a morning run catches the previous day's postings across all time zones.
  5. Point webhookUrl at Slack (incoming webhook), Zapier, Make, or your own endpoint. The payload is {monitorId, runAt, sources, newCount, updatedCount, scanned, seenTotal, notices[first 50]}.

The default settings ({}) run in emitAll mode and return the latest 10 notices so you see real output on the first try.

Use cases

  • Cyber insurers and brokers: flag insureds and applicants the day their notice lands; updated records catch upward revisions of the affected count.
  • Security vendors: outbound trigger lists — every breached organization with the data types exposed.
  • Class-action and privacy law firms: first sight of breaches above a threshold (minAffected: 10000).
  • Journalists and researchers: one normalized feed across seven registries instead of seven web pages.
  • Third-party risk teams: watch your vendors by name with companyKeywords.

Examples

Healthcare breaches over 10,000 individuals, all registries:

{ "sources": ["all"], "companyKeywords": ["health", "medical", "hospital", "clinic", "dental", "pharmacy"], "minAffected": 10000, "maxNewPerSource": 100, "maxItems": 500 }

Watch a vendor list:

{ "sources": ["all"], "companyKeywords": ["Quatrro", "zHealth", "DentaQuest"], "lookbackDays": 90, "firstRunMode": "baseline" }

Notes

  • Counts are exactly as published: affectedStateResidents for Washington and Vermont, affectedTotal for HHS and Oregon, both for Delaware. California and Iowa publish no counts.
  • Notices are deduplicated per source, not across sources: a company that files in California, Washington and Oregon produces one record per registry, each with that state's figures.
  • Pricing: $0.005 per run plus $0.02 per emitted notice. A daily schedule that finds nothing new costs the start fee only.