This tool runs entirely in your browser. Nothing you enter is transmitted to or stored on Goulter Compliance Advisory's server, and using this tool does not make Goulter Compliance Advisory a HIPAA business associate. Your answers, including anything typed on the Contact/Incident Information tab, are saved only in this browser (via localStorage) so you can resume later. On a shared device, other people using this browser profile may be able to reopen your answers. Avoid patient-identifying details. Export or record anything sensitive before closing this tab or clearing your browser data.
Compliance Tool · Privacy & Breach Notification

Breach Notification Risk Assessment

Start with the Overview to see how an incident routes through three legally distinct frameworks, then work each applicable module for a recommendation with rationale and citations. The Contact/Incident Information tab drafts an HHS OCR Breach Portal submission from the same incident facts.

Your combined action plan

Answer questions in any module above to see your personalized combined action plan here.

Three legally distinct frameworks can apply to the same incident, often at the same time. Use this map to see how they relate, then open the module(s) that fit.

Incident Detected
Triage: who's involved, what data, where, and how it was exposed
Independent obligations HIPAA, CMIA/§1280.15, and Civil Code §1798.82 are triggered separately and can all apply to the same incident. A "not reportable" result under one does not exempt the incident from the others, work through every module that could apply.

HIPAA Breach Rule

Applies if the entity is a HIPAA covered entity or business associate.

  • 3 exceptions can take it out of "breach" entirely
  • Otherwise presume a breach unless a documented assessment demonstrates low probability of compromise
  • CE: individuals within 60 days; HHS timing depends on count. BA: notify covered entity.

CMIA / HSC §1280.15

Applies if California medical information (Civil Code §56.05) is involved, two parallel consequences, not one verdict.

  • CMIA: civil-liability exposure (private right of action, statutory damages)
  • §1280.15: licensed facilities only: 15-business-day CDPH + patient report
  • A facility gets both analyses at once; other CMIA-covered entities get civil exposure only

Civil Code §1798.82

California's general breach statute, applies whenever "personal information" (medical or otherwise) is involved, regardless of CMIA/HIPAA status.

  • Personal-info trigger → encryption safe harbor
  • If reportable: individuals within 30 days
  • More than 500 CA residents → AG notice; large/costly breaches → substitute notice
Combine every applicable outcome into one incident record. If HIPAA says reportable, use the Contact/Incident Information tab to draft the HHS OCR Breach Portal submission from the same facts.

Reporting deadlines at a glance

Source-linked decision table and review limits, September 5, 2026
DecisionRule and required distinctionSource
HIPAA scopeCovered entity or business associate; unsecured PHI and impermissible use/disclosure. Confirm exceptions and a documented four-factor determination, not a numerical score.HHS breach guidance
Discovery and recipientsUse the first known or reasonably discoverable day, not the end of an investigation. Individual notice: without unreasonable delay, within 60 calendar days. BA notice goes to the covered entity; shorter contracts may apply.45 CFR 164.404; HHS BA guidance
Different thresholdsHHS: 500 or more individuals, versus annual reporting for fewer than 500, due within 60 days after year-end. Media: more than 500 residents of one state/jurisdiction. Do not infer the state count from the total count.HHS reporting thresholds
California owner / maintainerConfirm computerized personal information, acquisition and resident/role scope. Owner/licensee: 30 calendar days after discovery or notification, subject to statutory delays. Maintainer: immediate owner/licensee notice. More than 500 CA residents: AG sample within 15 calendar days of resident notice.Civil Code 1798.82(a), (b), (f), (g)
Licensed California facilitySpecified licenses under 1204/1250/1725/1745; unlawful/unauthorized access, use or disclosure. CDPH and patient notices generally within 15 business days of detection. The statutory law-enforcement patient-notice delay is not a blanket CDPH reporting delay.HSC 1280.15
Facility exceptions / business daysReview the complete exclusions, first-business-day detection rule and listed holidays. No calendar-day conversion or due date is calculated. Official CDPH final-rule retrieval was unavailable in this pass; confirm current regulatory text before relying on an exception.CDPH final-rule publication; 22 CCR 79901 reproduction
CMIA liabilitySeparate civil analysis, not a notice clock. Section 56.36(e) requires all statutory conditions and concerns nominal damages; notice compliance alone does not establish the defense.Civil Code 56.36

This is a targeted rule review, not legal certification. Other-state references were not reverified in this batch. Confirm amendments, agency instructions and case-specific facts with qualified counsel.

Track each independent clock Do not substitute one framework's deadline for another. A data maintainer may owe immediate owner notice; a licensed California facility generally has 15 business days for CDPH/patient reporting. Business days exclude specified holidays, not just weekends. This tool displays rules, not calculated due dates.
FrameworkNotify whomDeadlineLarge-breach add-ons / notes
HSC §1280.15 CDPH and affected patients (licensed clinics, health facilities, home health agencies, hospices only) Within 15 business days after discovery (or reasonably-believed breach) independent clock Penalties up to $25,000 per patient (first occurrence); up to $17,500 per patient thereafter.
Civil Code §1798.82 Affected California residents Within 30 calendar days of discovery or notification (only statutory delays for law enforcement, scope or reasonable system integrity) More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents. Substitute notice if cost >$250,000, affected class >500,000, or contact info is lacking.
HIPAA Breach Rule CE: individuals and HHS by count; BA: covered entity Within 60 calendar days after discovery, without unreasonable delay More than 500 residents of one state/jurisdiction → prominent media outlets, same 60-day bound. <500 → annual log to OCR, due within 60 days of the end of the calendar year.
CMIA no notice deadline of its own n/a (civil-liability statute) Individual notice for CA residents runs through §1798.82's 30-day clock; the §56.36(e) nominal-damages defense requires all statutory conditions, not notice compliance alone.

Prepare an HHS OCR breach-reporting worksheet here. Nothing is submitted. Use "Copy worksheet" to transfer your draft into the real portal at https://ocrportal.hhs.gov; confirm its current fields, instructions, filing role and attestation before submission.

Report Type: what type of breach report are you filing?

Which describes your role in this filing?

Breach Information

Breach Information, Notice & Actions Taken, and Attestation Screens.

Breach Affecting: how many individuals are affected?

Type of Breach (select all that apply)

Location of Breach (select all that apply)

Type of PHI Involved · Clinical (select all that apply)

Type of PHI Involved · Demographic (select all that apply)

Type of PHI Involved · Financial (select all that apply)

Type of PHI Involved · Other

0 / 4,000

Safeguards in Place Prior to Breach (select all that apply)

Notice of Breach and Actions Taken

Was Substitute Notice Required?

Was Media Notice Required?

Actions Taken in Response to Breach (select all that apply)

0 / 4,000
Attestation (Informational Only)
Review the current HHS OCR portal's disclosure and attestation before filing. Information submitted to OCR may be subject to public disclosure under applicable law; HHS publishes a list of breaches affecting 500 or more individuals. This local worksheet does not submit a report or record a legal attestation. Confirm accuracy, authorized filing role and all required fields in the official portal.

Which HIPAA role does this assessment cover?

Does this involve an impermissible use or disclosure of unsecured PHI? Confirm HIPAA scope and HHS encryption/destruction guidance, including key security.

Federal floor under 45 CFR §§164.402–408. First check whether one of three regulatory exceptions takes this outside the definition of "breach" entirely. If none apply, the disclosure is presumed a breach unless a 4-factor risk assessment shows a low probability the PHI was compromised.

Reporting clock, if this ends up reportable Covered entities: individual notice without unreasonable delay, no later than 60 calendar days after discovery. HHS OCR uses that outer limit for 500 or more individuals. Business associates notify the covered entity without unreasonable delay, within 60 days, subject to shorter contracts. More than 500 residents of one state/jurisdiction adds prominent-media notice on the same 60-day bound; breaches of <500 go on the annual OCR log, due within 60 days of the end of the calendar year. 45 CFR §§164.404/406/408
1 Exceptions to the breach definition

Was the access unintentional, made in good faith by a workforce member/person acting under the covered entity's authority and within the scope of their authority, with no further impermissible use or disclosure?

Was this an inadvertent disclosure between two people both authorized to access PHI at the same covered entity/business associate (or organized health care arrangement), with no further impermissible use or disclosure?

Do you have a good-faith belief that the unauthorized recipient would not reasonably have been able to retain the PHI (e.g., misdirected item returned unopened, confirmed undelivered)?

If all four factors suggest low risk: has the responsible privacy official documented evidence supporting a low probability of compromise?

Answer the questions above to see a recommendation.

CMIA (Civil Code §56 et seq.) and Health & Safety Code §1280.15 are one medical-information framework with two separate consequences: §1280.15 explicitly borrows CMIA's definition of "medical information" (§56.05) and its breach-exceptions structure now mirrors HIPAA's. CMIA is civil-liability exposure (private right of action, statutory damages); §1280.15 is a regulatory reporting duty that applies only to licensed facilities. A facility gets both analyses from the same incident; other CMIA-covered entities get the civil-exposure analysis only.

Reporting clocks §1280.15 (licensed facilities): CDPH and affected patients within 15 business days of discovery, an independent reporting clock. CMIA itself sets no notice deadline. It is a civil-liability statute; individual notice for CA residents runs through Civil Code §1798.82 (30 calendar days), and the §56.36(e) defense requires every statutory condition and does not eliminate actual damages or fees.
1 Entity-type gate

Which best describes the reporting entity?

Answer the entity-type question above to see a recommendation.

Confirm the role and scope for this incident involving computerized personal information and California residents.

Was there unauthorized acquisition, or a reasonable belief of acquisition, compromising the computerized personal information? A good-faith employee/agent acquisition for business purposes with no further unauthorized use/disclosure is excluded.

California's general breach notification statute. Walk the flow below: does the incident involve "personal information" as the statute defines it → does the encryption safe harbor apply → what notice obligations follow.

Reporting clock, if notice is required Affected CA residents: within 30 calendar days of discovery or notification, subject to statutory delays for law enforcement, determining scope or restoring reasonable system integrity. More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents.
1 Does this involve "personal information" under §1798.82(h)? (select all that apply)

Name combined with an unencrypted data element, or a username/email combined with a password/security answer:

Answer the questions above to see a recommendation.

California and federal HIPAA are covered by full interactive modules above. The table below is a quick reference for other states' breach notification statutes, not a guided assessment.

Reference only All 49 states other than California are populated and verified as of July 9, 2026. These rows are a quick reference, not a guided assessment or legal advice. State statutes change often, so check the cited primary source (or your counsel) before relying on any row here for an actual incident.
StateIndividual-notice deadlineHarm / risk-of-harm thresholdAG-notification thresholdCRA noticeSubstitute noticeSource

This tool draws on publicly available primary regulatory sources (45 CFR §§164.400–414; California Civil Code §§56.05, 56.36, 1798.82; Health & Safety Code §1280.15; and the 2026 California Supreme Court decision in J.M. v. Illuminate Education, Inc.) and is provided for general compliance-learning purposes. It is not legal advice. Brandon Goulter is not an attorney, and using this tool creates no professional advisory relationship. Breach determinations are fact-specific and ultimately require documented judgment by a licensed privacy attorney, verify current requirements against primary sources before acting on an actual incident.