Start with the Overview to see how an incident routes through three legally distinct frameworks, then work each applicable module for a recommendation with rationale and citations. The Contact/Incident Information tab drafts an HHS OCR Breach Portal submission from the same incident facts.
Three legally distinct frameworks can apply to the same incident, often at the same time. Use this map to see how they relate, then open the module(s) that fit.
Applies if the entity is a HIPAA covered entity or business associate.
Applies if California medical information (Civil Code §56.05) is involved, two parallel consequences, not one verdict.
California's general breach statute, applies whenever "personal information" (medical or otherwise) is involved, regardless of CMIA/HIPAA status.
| Framework | Notify whom | Deadline | Large-breach add-ons / notes |
|---|---|---|---|
| HSC §1280.15 | CDPH and affected patients (licensed clinics, health facilities, home health agencies, hospices only) | Within 15 business days after discovery (or reasonably-believed breach) fastest clock | Penalties up to $25,000 per patient (first occurrence); up to $17,500 per patient thereafter. |
| Civil Code §1798.82 | Affected California residents | Within 30 calendar days of discovery (delay allowed for law enforcement or to determine scope) | More than 500 CA residents → electronic sample notice to the CA Attorney General within 15 calendar days of notifying residents. Substitute notice if cost >$250,000, affected class >500,000, or contact info is lacking. |
| HIPAA Breach Rule | Affected individuals + HHS OCR | Within 60 calendar days after discovery, without unreasonable delay | ≥500 residents of one state/jurisdiction → prominent media outlets, same 60-day bound. <500 → annual log to OCR, due within 60 days of the end of the calendar year. |
| CMIA | no notice deadline of its own | n/a (civil-liability statute) | Individual notice for CA residents runs through §1798.82's 30-day clock; complying with HIPAA notification is a §56.36(e) affirmative defense. |
Draft your HHS OCR Breach Portal submission here, field-for-field with the portal's own "Breach Portal Required Information" form. Nothing is sent anywhere, fill it out, then use "Copy worksheet" to paste the text into the real portal at https://ocrportal.hhs.gov.
Report Type: what type of breach report are you filing?
Which describes your role in this filing?
Type of Covered Entity
Breach Information, Notice & Actions Taken, and Attestation Screens.
Breach Affecting: how many individuals are affected?
Type of Breach (select all that apply)
Location of Breach (select all that apply)
Type of PHI Involved · Clinical (select all that apply)
Type of PHI Involved · Demographic (select all that apply)
Type of PHI Involved · Financial (select all that apply)
Type of PHI Involved · Other
Safeguards in Place Prior to Breach (select all that apply)
Was Substitute Notice Required?
Was Media Notice Required?
Actions Taken in Response to Breach (select all that apply)
Federal floor under 45 CFR §§164.402–408. First check whether one of three regulatory exceptions takes this outside the definition of "breach" entirely. If none apply, the disclosure is presumed a breach unless a 4-factor risk assessment shows a low probability the PHI was compromised.
Was the access unintentional, made in good faith by a workforce member/person acting under the covered entity's authority and within the scope of their authority, with no further impermissible use or disclosure?
Was this an inadvertent disclosure between two people both authorized to access PHI at the same covered entity/business associate (or organized health care arrangement), with no further impermissible use or disclosure?
Do you have a good-faith belief that the unauthorized recipient would not reasonably have been able to retain the PHI (e.g., misdirected item returned unopened, confirmed undelivered)?
CMIA (Civil Code §56 et seq.) and Health & Safety Code §1280.15 are one medical-information framework with two separate consequences: §1280.15 explicitly borrows CMIA's definition of "medical information" (§56.05) and its breach-exceptions structure now mirrors HIPAA's. CMIA is civil-liability exposure (private right of action, statutory damages); §1280.15 is a regulatory reporting duty that applies only to licensed facilities. A facility gets both analyses from the same incident; other CMIA-covered entities get the civil-exposure analysis only.
Which best describes the reporting entity?
Internal misdirection: was this paper/email/fax inadvertently accessed within the same facility, with no further disclosure?
Good-faith belief the unauthorized recipient could not retain the medical information?
Was the access permitted or required by state or federal law?
Was the data encrypted, and lost/stolen without being actually accessed, used, or disclosed in an unlawful/unauthorized manner?
Does a HIPAA-style 4-factor analysis show low probability the medical information was compromised? (See the HIPAA tab for the full analysis.)
California's general breach notification statute. Walk the flow below: does the incident involve "personal information" as the statute defines it → does the encryption safe harbor apply → what notice obligations follow.
Name combined with an unencrypted data element, or a username/email combined with a password/security answer:
California and federal HIPAA are covered by full interactive modules above. The table below is a quick reference for other states' breach notification statutes, not a guided assessment.
| State | Individual-notice deadline | Harm / risk-of-harm threshold | AG-notification threshold | CRA notice | Substitute notice | Source |
|---|
This tool draws on publicly available primary regulatory sources (45 CFR §§164.400–414; California Civil Code §§56.05, 56.36, 1798.82; Health & Safety Code §1280.15; and the 2026 California Supreme Court decision in J.M. v. Illuminate Education, Inc.) and is provided for general compliance-learning purposes. It is not legal advice. Brandon Goulter is not an attorney, and using this tool creates no professional advisory relationship. Breach determinations are fact-specific and ultimately require documented judgment by a licensed privacy attorney, verify current requirements against primary sources before acting on an actual incident.