Breach Notification Risk Assessment
Start with the Overview to see how an incident routes through three legally distinct frameworks, then work each applicable module for a recommendation with rationale and citations. The Contact/Incident Information tab drafts an HHS OCR Breach Portal submission from the same incident facts.
Your combined action plan
Three legally distinct frameworks can apply to the same incident, often at the same time. Use this map to see how they relate, then open the module(s) that fit.
HIPAA Breach Rule
Applies if the entity is a HIPAA covered entity or business associate.
- 3 exceptions can take it out of "breach" entirely
- Otherwise presume a breach unless a documented assessment demonstrates low probability of compromise
- CE: individuals within 60 days; HHS timing depends on count. BA: notify covered entity.
CMIA / HSC §1280.15
Applies if California medical information (Civil Code §56.05) is involved, two parallel consequences, not one verdict.
- CMIA: civil-liability exposure (private right of action, statutory damages)
- §1280.15: licensed facilities only: 15-business-day CDPH + patient report
- A facility gets both analyses at once; other CMIA-covered entities get civil exposure only
Civil Code §1798.82
California's general breach statute, applies whenever "personal information" (medical or otherwise) is involved, regardless of CMIA/HIPAA status.
- Personal-info trigger → encryption safe harbor
- If reportable: individuals within 30 days
- More than 500 CA residents → AG notice; large/costly breaches → substitute notice
Reporting deadlines at a glance
Source-linked decision table and review limits, September 5, 2026
| Decision | Rule and required distinction | Source |
|---|---|---|
| HIPAA scope | Covered entity or business associate; unsecured PHI and impermissible use/disclosure. Confirm exceptions and a documented four-factor determination, not a numerical score. | HHS breach guidance |
| Discovery and recipients | Use the first known or reasonably discoverable day, not the end of an investigation. Individual notice: without unreasonable delay, within 60 calendar days. BA notice goes to the covered entity; shorter contracts may apply. | 45 CFR 164.404; HHS BA guidance |
| Different thresholds | HHS: 500 or more individuals, versus annual reporting for fewer than 500, due within 60 days after year-end. Media: more than 500 residents of one state/jurisdiction. Do not infer the state count from the total count. | HHS reporting thresholds |
| California owner / maintainer | Confirm computerized personal information, acquisition and resident/role scope. Owner/licensee: 30 calendar days after discovery or notification, subject to statutory delays. Maintainer: immediate owner/licensee notice. More than 500 CA residents: AG sample within 15 calendar days of resident notice. | Civil Code 1798.82(a), (b), (f), (g) |
| Licensed California facility | Specified licenses under 1204/1250/1725/1745; unlawful/unauthorized access, use or disclosure. CDPH and patient notices generally within 15 business days of detection. The statutory law-enforcement patient-notice delay is not a blanket CDPH reporting delay. | HSC 1280.15 |
| Facility exceptions / business days | Review the complete exclusions, first-business-day detection rule and listed holidays. No calendar-day conversion or due date is calculated. Official CDPH final-rule retrieval was unavailable in this pass; confirm current regulatory text before relying on an exception. | CDPH final-rule publication; 22 CCR 79901 reproduction |
| CMIA liability | Separate civil analysis, not a notice clock. Section 56.36(e) requires all statutory conditions and concerns nominal damages; notice compliance alone does not establish the defense. | Civil Code 56.36 |
This is a targeted rule review, not legal certification. Other-state references were not reverified in this batch. Confirm amendments, agency instructions and case-specific facts with qualified counsel.
| Framework | Notify whom | Deadline | Large-breach add-ons / notes |
|---|---|---|---|
| HSC §1280.15 | CDPH and affected patients (licensed clinics, health facilities, home health agencies, hospices only) | Within 15 business days after discovery (or reasonably-believed breach) independent clock | Penalties up to $25,000 per patient (first occurrence); up to $17,500 per patient thereafter. |
| Civil Code §1798.82 | Affected California residents | Within 30 calendar days of discovery or notification (only statutory delays for law enforcement, scope or reasonable system integrity) | More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents. Substitute notice if cost >$250,000, affected class >500,000, or contact info is lacking. |
| HIPAA Breach Rule | CE: individuals and HHS by count; BA: covered entity | Within 60 calendar days after discovery, without unreasonable delay | More than 500 residents of one state/jurisdiction → prominent media outlets, same 60-day bound. <500 → annual log to OCR, due within 60 days of the end of the calendar year. |
| CMIA | no notice deadline of its own | n/a (civil-liability statute) | Individual notice for CA residents runs through §1798.82's 30-day clock; the §56.36(e) nominal-damages defense requires all statutory conditions, not notice compliance alone. |
Contact / Incident Information
Prepare an HHS OCR breach-reporting worksheet here. Nothing is submitted. Use "Copy worksheet" to transfer your draft into the real portal at https://ocrportal.hhs.gov; confirm its current fields, instructions, filing role and attestation before submission.
Report Type: what type of breach report are you filing?
Which describes your role in this filing?
Type of Covered Entity
Breach Information, Notice & Actions Taken, and Attestation Screens.
Breach Affecting: how many individuals are affected?
Type of Breach (select all that apply)
Location of Breach (select all that apply)
Type of PHI Involved · Clinical (select all that apply)
Type of PHI Involved · Demographic (select all that apply)
Type of PHI Involved · Financial (select all that apply)
Type of PHI Involved · Other
Safeguards in Place Prior to Breach (select all that apply)
Was Substitute Notice Required?
Was Media Notice Required?
Actions Taken in Response to Breach (select all that apply)
HIPAA Breach Rule
Which HIPAA role does this assessment cover?
Does this involve an impermissible use or disclosure of unsecured PHI? Confirm HIPAA scope and HHS encryption/destruction guidance, including key security.
Federal floor under 45 CFR §§164.402–408. First check whether one of three regulatory exceptions takes this outside the definition of "breach" entirely. If none apply, the disclosure is presumed a breach unless a 4-factor risk assessment shows a low probability the PHI was compromised.
Was the access unintentional, made in good faith by a workforce member/person acting under the covered entity's authority and within the scope of their authority, with no further impermissible use or disclosure?
Was this an inadvertent disclosure between two people both authorized to access PHI at the same covered entity/business associate (or organized health care arrangement), with no further impermissible use or disclosure?
Do you have a good-faith belief that the unauthorized recipient would not reasonably have been able to retain the PHI (e.g., misdirected item returned unopened, confirmed undelivered)?
If all four factors suggest low risk: has the responsible privacy official documented evidence supporting a low probability of compromise?
CMIA / HSC §1280.15
CMIA (Civil Code §56 et seq.) and Health & Safety Code §1280.15 are one medical-information framework with two separate consequences: §1280.15 explicitly borrows CMIA's definition of "medical information" (§56.05) and its breach-exceptions structure now mirrors HIPAA's. CMIA is civil-liability exposure (private right of action, statutory damages); §1280.15 is a regulatory reporting duty that applies only to licensed facilities. A facility gets both analyses from the same incident; other CMIA-covered entities get the civil-exposure analysis only.
Which best describes the reporting entity?
For this licensed facility, was there unlawful/unauthorized access, use or disclosure of patient medical information, or a reasonable belief it occurred?
These prompts are not an exhaustive statement of 22 CCR §79901. If another regulatory exclusion may apply, including a qualifying care-coordination misdirection to another covered entity, obtain a documented review before relying on the result. HIPAA and facility determinations must each address the applicable facts.
Internal misdirection: was this paper/email/fax inadvertently accessed within the same facility, with no further disclosure?
Good-faith belief the unauthorized recipient could not retain the medical information?
Was the access permitted or required by state or federal law?
Was the data encrypted, and lost/stolen without being actually accessed, used, or disclosed in an unlawful/unauthorized manner?
Does a HIPAA-style 4-factor analysis show low probability the medical information was compromised? (See the HIPAA tab for the full analysis.)
California Civil Code §1798.82
Confirm the role and scope for this incident involving computerized personal information and California residents.
Was there unauthorized acquisition, or a reasonable belief of acquisition, compromising the computerized personal information? A good-faith employee/agent acquisition for business purposes with no further unauthorized use/disclosure is excluded.
California's general breach notification statute. Walk the flow below: does the incident involve "personal information" as the statute defines it → does the encryption safe harbor apply → what notice obligations follow.
Name combined with an unencrypted data element, or a username/email combined with a password/security answer:
California and federal HIPAA are covered by full interactive modules above. The table below is a quick reference for other states' breach notification statutes, not a guided assessment.
| State | Individual-notice deadline | Harm / risk-of-harm threshold | AG-notification threshold | CRA notice | Substitute notice | Source |
|---|
This tool draws on publicly available primary regulatory sources (45 CFR §§164.400–414; California Civil Code §§56.05, 56.36, 1798.82; Health & Safety Code §1280.15; and the 2026 California Supreme Court decision in J.M. v. Illuminate Education, Inc.) and is provided for general compliance-learning purposes. It is not legal advice. Brandon Goulter is not an attorney, and using this tool creates no professional advisory relationship. Breach determinations are fact-specific and ultimately require documented judgment by a licensed privacy attorney, verify current requirements against primary sources before acting on an actual incident.