OurHOA
Board & governance

How should an HOA board respond to a data breach of owner information?

By OurHOA · General information · Revised

What an HOA board does after a data breach: containment, who must be notified, Texas, Florida and Colorado deadlines, and a sample notice to owners.

Part of the HOA board handbook: residents and communication.

The short answer

In a small association a breach rarely looks like a movie hack. It is the treasurer's email account taken over by a phishing link, a laptop stolen from a car, a letter from the payment portal saying its systems were accessed, or a spreadsheet of bank drafts sent to the whole community by mistake. The board's job is the same each time. Stop the leak the same day. Work out what was exposed and whose it was. Decide with the association's attorney whether state law requires notice, then send it inside the deadline. Texas Business and Commerce Code section 521.053 allows 60 days to notify affected people after the breach is determined. Florida section 501.171 and Colorado section 6-1-716 allow 30 days. Each state also requires a report to the attorney general above a set number of affected residents. Florida's definition of a covered entity names an "association" outright. Have counsel confirm how the Texas and Colorado wording applies to your association, and treat the deadlines as the floor. Rules vary by state and by your governing documents, and this guide is education, not legal advice.

Decide whether the exposed data triggers the law

The three statutes protect a person's name combined with certain other items, not every piece of contact data. A roster of names, street addresses, phone numbers and emails is embarrassing to lose but generally does not trigger notice on its own. These items do, when paired with a name. Social Security numbers are the big one, and HOAs usually hold them on W-9s from sole-proprietor vendors. Driver's license and state ID numbers turn up on copies taken for pool passes, gate remotes and lease registration. A financial account or card number counts when a code or password that opens the account went with it. Medical information shows up in reasonable accommodation requests and assistance animal letters. In Florida and Colorado, a username or email address with its password or security answers also counts, which covers owner portal logins. A bank account and routing number on an ACH authorization form does not meet the financial account definition in any of the three states unless an access code went with it. The FTC still advises telling the bank that holds stolen account numbers so it can watch for fraud. Encrypted data is generally excluded, but Texas and Colorado count it when the key or password was taken too.

Contain it the same day

For a taken-over email account, change the password from a clean device, turn on two-factor sign-in, sign out every active session, and check for forwarding rules and filters the intruder added. Attackers often leave a rule that copies every new message to an outside address. Change any other account that shared the password. If the email was used to send payment requests or new bank instructions, call the association's bank and any vendor who may have received them. Our guide on protecting HOA bank accounts from fraud covers the payment controls. For a stolen laptop or phone, file a police report and remotely wipe the device if that was set up. For a vendor breach, ask the vendor in writing for its incident report, the list of affected records, and what it has fixed. Florida requires a vendor that stores data for the association to report a breach to it within 10 days. The FTC's advice is to preserve evidence while you contain the damage. Don't delete the phishing email or wipe the account history. Write down who found the problem, when, and what they saw. Then call the insurance agent before you hire anyone. Read the policy first, because some cyber coverage pays only for breach lawyers and forensic firms the carrier approves.

Build the list of affected people

Make a spreadsheet with one row per person, not per lot. A 150-home community with two owners on most deeds, plus tenants on file and a dozen vendors, can easily pass 300 people. For each row, record what data was exposed and the person's state of residence. Absentee owners and out-of-state vendors are generally covered by their own state's notice law, and Texas section 521.053(b-1) lets the association meet the Texas duty for those people by following their state's law. Keep the list itself locked down. It is now the most sensitive file the association has. The count matters for the next step. Texas requires an attorney general report once 250 Texas residents are affected. Florida and Colorado set the line at 500 residents. Credit bureau notice starts above 10,000 people in Texas and 1,000 in Florida and Colorado.

Deadlines and notice content in Texas, Florida and Colorado

Texas, section 521.053. Notify each affected person without unreasonable delay and no later than 60 days after determining the breach occurred, by mail or by electronic notice that meets the federal E-SIGN Act. If 250 or more Texans are affected, report to the attorney general within 30 days using the online form on the attorney general's site. Police can ask you to delay notice during an investigation. Florida, section 501.171. Notify affected people by mail or email no later than 30 days after determining a breach occurred or having reason to believe one did. The notice must give the date or estimated date range, what information was accessed, and how to contact the association. Report to the Department of Legal Affairs within 30 days if 500 or more Floridians are affected. Notice can be skipped only if, after investigating and consulting law enforcement, the association reasonably decides the breach is not likely to cause identity theft or financial harm. That decision must be written, kept for five years, and sent to the department within 30 days. The penalty for late notice can reach $500,000. Colorado, section 6-1-716. Investigate promptly, then notify within 30 days of determining a breach occurred unless the investigation shows misuse has not occurred and is not reasonably likely. The notice must include the date range, the information taken, a contact, the toll-free numbers, addresses and websites of the credit bureaus and the FTC, and a statement that residents can get information on fraud alerts and security freezes from them. If logins were taken, tell people to change that password and any matching password elsewhere. Report to the attorney general within 30 days if 500 or more Coloradans are affected. The association cannot charge residents for the notice.

Notice wording the board can adapt

This draft covers Colorado's content list, the longest of the three. Have counsel review it first. "On [date], the [Association name] learned that [a board member's email account was accessed by an unauthorized person / a laptop containing association records was stolen]. The incident happened between [date] and [date]. The records involved included your name and [describe the information]. We have [changed passwords and added two-step sign-in / reported the theft to the police] and [describe other steps]. We recommend that you watch your bank and card statements and consider a fraud alert or security freeze. The three credit bureaus are Equifax, 1-800-685-1111, equifax.com; Experian, 1-888-397-3742, experian.com; and TransUnion, 1-888-909-8872, transunion.com. You can get information about fraud alerts and security freezes from the Federal Trade Commission at IdentityTheft.gov, 1-877-438-4338, 600 Pennsylvania Avenue NW, Washington, DC 20580, and from the credit bureaus. If your portal password was involved, change it and any other account that uses the same password. Questions can go to [name] at [phone] and [email]." Send it by mail, or by email where the owner has consented to electronic notice. If the breached account was an email address the association issued, Colorado bars sending the notice there.

A 30-day board timeline

Day 0: whoever finds the problem tells the president and treasurer. Contain it that day and preserve evidence. Call the attorney and the insurance agent. Days 1 to 7: confirm what was exposed, build the affected-person list, and get the vendor's written report if a vendor was involved. Don't email the details of owners' exposed data around the board. That spreads it further. By day 10: hold a board meeting or act as your bylaws allow. A sample motion reads: "Move to approve the breach notice as reviewed by counsel, to send it to all affected persons by [date], to file the required attorney general reports, and to authorize up to $[amount] for mailing and related costs." Record the decision in the minutes without listing any owner's data. By day 25: mail the notices and file any attorney general report. This clears Florida and Colorado with a few days to spare, and Texas by a wide margin. Days 30 to 60: finish the fixes, route owner questions to one named contact, and file a one-page summary of what happened and what changed.

Mistakes boards make

Waiting for perfect facts. The clock runs from when the association determines a breach occurred, and in Florida from when it has reason to believe one did. Don't swing the other way and tell owners "no data was taken" before you know. Keeping data the association doesn't need. Old ACH forms, driver's license copies from 2015 and W-9s buried in a treasurer's personal inbox are what turn a nuisance into a notice event. Texas section 521.052(b) and Florida section 501.171(8) require records with protected information to be shredded, erased or made unreadable when they are no longer kept. Colorado section 6-1-713.5 requires reasonable security for this data, and the association generally must require vendors that receive it to do the same. Set a retention schedule and follow it. Running association business from personal accounts. When a director leaves, the data leaves on their laptop. Our guide on HOA board email and shared accounts covers setting up role accounts that stay with the association. Finally, write the plan down now. A one-page breach checklist with the attorney's and agent's numbers saves the first frantic day.

Sources

These guides are general education for HOA boards and residents, not legal, tax, or financial advice. Rules vary by state and by your community's governing documents - check with a professional for your situation.

Reach every homeowner without a reply-all thread

Announcements with email notifications, an opt-in resident directory, neighbor messaging and a community website. Free to start.