http://www.kentucky.com/news/business/article178930896.html
And what's becoming a story that is all too common, Pizza Hut waited two weeks to notify affected customers. During that time, the credit card information was used by hackers or whoever the hackers sold the information to.
what are called "disclosure laws" vary from state to state... some have a maximum amount of time that may expire before publically disclosing, some also have a minimum statndard for what information is included. It takes time for an organization to wrap their head around what happened to them. 2 weeks is NO TIME at all.
there are also other regulatory bodies at work in the PCI (payment card industry). The Merchant Bank that issues merchant IDs to their customers (that accept their credit cards) have a plethora of rules on how data and information systems must be protected and how to report a breach, and to whom, and what it must include. these are not laws, but they are regulations that, if violated, can result in fines from the bank, or even the loss of ability to accept credit cards any more.