This tool runs entirely in your browser. Nothing you enter is transmitted to or stored on Goulter Compliance Advisory's server, and using this tool does not make Goulter Compliance Advisory a HIPAA business associate. Your answers, including anything typed on the Contact/Incident Information tab, are saved only in this browser (via localStorage) so you can resume later. Export or record anything sensitive before closing this tab or clearing your browser data.
Compliance Tool · Privacy & Breach Notification

Breach Notification Risk Assessment

Start with the Overview to see how an incident routes through three legally distinct frameworks, then work each applicable module for a recommendation with rationale and citations. The Contact/Incident Information tab drafts an HHS OCR Breach Portal submission from the same incident facts.

Your combined action plan

Answer questions in any module above to see your personalized combined action plan here.

Three legally distinct frameworks can apply to the same incident, often at the same time. Use this map to see how they relate, then open the module(s) that fit.

Incident Detected
Triage: who's involved, what data, where, and how it was exposed
Independent obligations HIPAA, CMIA/§1280.15, and Civil Code §1798.82 are triggered separately and can all apply to the same incident. A "not reportable" result under one does not exempt the incident from the others, work through every module that could apply.

HIPAA Breach Rule

Applies if the entity is a HIPAA covered entity or business associate.

  • 3 exceptions can take it out of "breach" entirely
  • Else a 4-factor analysis decides low-probability vs. reportable
  • If reportable: individuals + HHS OCR within 60 days

CMIA / HSC §1280.15

Applies if California medical information (Civil Code §56.05) is involved, two parallel consequences, not one verdict.

  • CMIA: civil-liability exposure (private right of action, statutory damages)
  • §1280.15: licensed facilities only: 15-business-day CDPH + patient report
  • A facility gets both analyses at once; other CMIA-covered entities get civil exposure only

Civil Code §1798.82

California's general breach statute, applies whenever "personal information" (medical or otherwise) is involved, regardless of CMIA/HIPAA status.

  • Personal-info trigger → encryption safe harbor
  • If reportable: individuals within 30 days
  • ≥500 CA residents → AG notice; large/costly breaches → substitute notice
Combine every applicable outcome into one incident record. If HIPAA says reportable, use the Contact/Incident Information tab to draft the HHS OCR Breach Portal submission from the same facts.

Reporting deadlines at a glance

Fastest clock wins When more than one framework applies to the same incident, plan the whole response around the shortest deadline, for a licensed California facility that is §1280.15's 15 business days.
FrameworkNotify whomDeadlineLarge-breach add-ons / notes
HSC §1280.15 CDPH and affected patients (licensed clinics, health facilities, home health agencies, hospices only) Within 15 business days after discovery (or reasonably-believed breach) fastest clock Penalties up to $25,000 per patient (first occurrence); up to $17,500 per patient thereafter.
Civil Code §1798.82 Affected California residents Within 30 calendar days of discovery (delay allowed for law enforcement or to determine scope) More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents. Substitute notice if cost >$250,000, affected class >500,000, or contact info is lacking.
HIPAA Breach Rule Affected individuals + HHS OCR Within 60 calendar days after discovery, without unreasonable delay ≥500 residents of one state/jurisdiction → prominent media outlets, same 60-day bound. <500 → annual log to OCR, due within 60 days of the end of the calendar year.
CMIA no notice deadline of its own n/a (civil-liability statute) Individual notice for CA residents runs through §1798.82's 30-day clock; complying with HIPAA notification is a §56.36(e) affirmative defense.

Draft your HHS OCR Breach Portal submission here, field-for-field with the portal's own "Breach Portal Required Information" form. Nothing is sent anywhere, fill it out, then use "Copy worksheet" to paste the text into the real portal at https://ocrportal.hhs.gov.

Contact: General & Contact Information Screens

Report Type: what type of breach report are you filing?

Which describes your role in this filing?

Breach Information

Breach Information, Notice & Actions Taken, and Attestation Screens.

Breach Affecting: how many individuals are affected?

Type of Breach (select all that apply)

Location of Breach (select all that apply)

Type of PHI Involved · Clinical (select all that apply)

Type of PHI Involved · Demographic (select all that apply)

Type of PHI Involved · Financial (select all that apply)

Type of PHI Involved · Other

0 / 4,000

Safeguards in Place Prior to Breach (select all that apply)

Notice of Breach and Actions Taken

Was Substitute Notice Required?

Was Media Notice Required?

Actions Taken in Response to Breach (select all that apply)

0 / 4,000
Attestation (Informational Only)
Under the Freedom of Information Act (5 U.S.C. §552) and HHS regulations at 45 C.F.R. Part 5, OCR may be required to release information provided in your breach notification. For breaches affecting more than 500 individuals, some of the information provided on this form will be made publicly available by posting on the HHS web site pursuant to §13402(e)(4) of the HITECH Act. OCR will also use this information, pursuant to §13402(i) of the HITECH Act, to provide an annual report to Congress regarding the number and nature of reported breaches and the actions taken to respond. OCR will make every effort, as permitted by law, to protect information that identifies individuals or that, if released, could constitute a clearly unwarranted invasion of personal privacy.

I attest, to the best of my knowledge, that the above information is accurate.

Federal floor under 45 CFR §§164.402–408. First check whether one of three regulatory exceptions takes this outside the definition of "breach" entirely. If none apply, the disclosure is presumed a breach unless a 4-factor risk assessment shows a low probability the PHI was compromised.

Reporting clock, if this ends up reportable Individuals and HHS OCR: no later than 60 calendar days after discovery. ≥500 residents of one state/jurisdiction adds prominent-media notice on the same 60-day bound; breaches of <500 go on the annual OCR log, due within 60 days of the end of the calendar year. 45 CFR §§164.404/406/408
1 Exceptions to the breach definition

Was the access unintentional, made in good faith by a workforce member/person acting under the covered entity's authority and within the scope of their authority, with no further impermissible use or disclosure?

Was this an inadvertent disclosure between two people both authorized to access PHI at the same covered entity/business associate (or organized health care arrangement), with no further impermissible use or disclosure?

Do you have a good-faith belief that the unauthorized recipient would not reasonably have been able to retain the PHI (e.g., misdirected item returned unopened, confirmed undelivered)?

Answer the questions above to see a recommendation.

CMIA (Civil Code §56 et seq.) and Health & Safety Code §1280.15 are one medical-information framework with two separate consequences: §1280.15 explicitly borrows CMIA's definition of "medical information" (§56.05) and its breach-exceptions structure now mirrors HIPAA's. CMIA is civil-liability exposure (private right of action, statutory damages); §1280.15 is a regulatory reporting duty that applies only to licensed facilities. A facility gets both analyses from the same incident; other CMIA-covered entities get the civil-exposure analysis only.

Reporting clocks §1280.15 (licensed facilities): CDPH and affected patients within 15 business days of discovery, the fastest clock in this tool. CMIA itself sets no notice deadline. It is a civil-liability statute; individual notice for CA residents runs through Civil Code §1798.82 (30 calendar days), and HIPAA-notice compliance is a §56.36(e) affirmative defense.
1 Entity-type gate

Which best describes the reporting entity?

Answer the entity-type question above to see a recommendation.

California's general breach notification statute. Walk the flow below: does the incident involve "personal information" as the statute defines it → does the encryption safe harbor apply → what notice obligations follow.

Reporting clock, if notice is required Affected CA residents: within 30 calendar days of discovery (delay permitted for law-enforcement needs or to determine scope). More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents.
1 Does this involve "personal information" under §1798.82(h)? (select all that apply)

Name combined with an unencrypted data element, or a username/email combined with a password/security answer:

Answer the questions above to see a recommendation.

California and federal HIPAA are covered by full interactive modules above. The table below is a quick reference for other states' breach notification statutes, not a guided assessment.

Reference only All 49 states other than California are populated and verified as of July 9, 2026. These rows are a quick reference, not a guided assessment or legal advice. State statutes change often, so check the cited primary source (or your counsel) before relying on any row here for an actual incident.
StateIndividual-notice deadlineHarm / risk-of-harm thresholdAG-notification thresholdCRA noticeSubstitute noticeSource

This tool draws on publicly available primary regulatory sources (45 CFR §§164.400–414; California Civil Code §§56.05, 56.36, 1798.82; Health & Safety Code §1280.15; and the 2026 California Supreme Court decision in J.M. v. Illuminate Education, Inc.) and is provided for general compliance-learning purposes. It is not legal advice. Brandon Goulter is not an attorney, and using this tool creates no professional advisory relationship. Breach determinations are fact-specific and ultimately require documented judgment by a licensed privacy attorney, verify current requirements against primary sources before acting on an actual incident.