Starting Sept. 1, organizations in Colorado must notify victims of breaches of personal information - including health data - within 30 days of determination that a breach occurred. That's a tougher requirement than the HIPAA breach notification rule, which requires notification of individuals within 60 days of discovery.
David Holtzman shares his thoughts here.