BreachRx finds that regulatory concurrency can produce more than 100 reporting obligations within a single organization, over 200 obligations across a small set of affected entities, and another 300+ obligations when incidents cascade across connected third-party systems.