California Breach Notification Law for Healthcare: Requirements and Timeline to Notify Patients
Notification Timeline and Deadlines
Healthcare organizations that handle California residents’ data must coordinate three overlapping regimes: California’s general Data Breach Notification law, the Confidentiality of Medical Information Act (CMIA) and Health & Safety Code duties for licensed facilities, and HIPAA’s breach rules. The earliest applicable deadline controls.
Timelines at a glance
- California general notice to individuals: provide notice “in the most expedient time possible and without unreasonable delay,” considering law‑enforcement holds and efforts to determine scope and restore system integrity.
- Licensed facilities (clinics, health facilities, home health agencies, hospices) under California Health & Safety Code: notify the California Department of Public Health (CDPH) and the affected patient(s) no later than 15 business days after discovery of an unauthorized access, use, or disclosure of medical information.
- HIPAA covered entities/business associates: notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach of Protected Health Information.
- Attorney General Submission: when a single incident requires notifying more than 500 California residents, submit a sample of the consumer notice to the California Attorney General at the same time you notify residents.
Coordinating overlapping rules
When HIPAA allows up to 60 days but California requires faster action (for example, the 15‑business‑day rule for CDPH‑licensed facilities), you must make patient notification on the earlier state timeline. Keep written evidence of discovery date, internal triage steps, and the date notices were issued.
Law-enforcement delays
If a law‑enforcement agency determines that notice would impede an investigation, you may delay consumer notice until the agency advises that notice no longer compromises the investigation. Document the request and the date the hold is lifted.
Notification Content Requirements
California specifies clear Notification Letter Requirements so patients can act quickly. Use plain language and avoid dense legal jargon.
Core elements your notice must include
- Conspicuous title: “Notice of Data Breach.”
- What Happened: a concise description, with discovery date and breach date or date range.
- What Information Was Involved: identify the data types (for example, medical information, health insurance information, Social Security numbers, driver’s license numbers, financial account data, or online credentials).
- What We Are Doing: containment, investigation, and security improvements.
- What You Can Do: specific steps patients should take, including account monitoring and security actions tailored to the incident.
- For More Information: a toll‑free number or email, and hours of operation.
California-specific add‑ons
- If Social Security numbers or driver’s license/California ID numbers were involved, offer identity theft prevention and mitigation services at no cost for at least 12 months, and explain how to enroll.
- If financial account numbers were involved, state whether access codes, passwords, or security credentials were also exposed and what protective actions you are taking.
- If the incident exposed an online account username/email plus password or security question/answer, instruct affected individuals to change credentials immediately; do not send notice to the compromised email account you provide as a service.
- Include the date of the notice and your contact information; if Social Security numbers or driver’s license numbers were exposed, include the major credit reporting agencies’ contact details.
Permissible delivery methods and substitutes
- Written notice by U.S. mail, or email notice if the consumer has consented to electronic delivery.
- Substitute notice may be used if contact information is insufficient, notice costs exceed a statutory threshold, or more than 500,000 residents are affected. Substitute notice typically includes email (when available), a conspicuous website posting for at least 30 days, and statewide media notice.
Attorney General Reporting Obligations
For any single Medical Information Breach that triggers notice to more than 500 California residents, you must make an Attorney General Submission. File a sample copy of the consumer notice, along with your organization’s name and contact details, timing of the incident and discovery, and a general description of the breach and data types involved. Submit this contemporaneously with patient notifications; the Attorney General may post your submission on the public breach portal.
Personal Information Definition and Scope
California’s Data Breach Notification law protects “personal information” about a resident when combined with a name or unique identifier. In healthcare, this often overlaps with Protected Health Information, but the categories are not identical. You must evaluate both sets of rules.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Personal information that can trigger notice
- Social Security number; driver’s license or California ID number; passport or other government ID numbers.
- Financial account or payment card number in combination with any required access code, password, or security credential.
- Medical information (individually identifiable information regarding a person’s medical history, mental or physical condition, or treatment, created or maintained by a healthcare provider or plan).
- Health insurance information (policy or subscriber numbers, application or claims details).
- Biometric data used to authenticate identity (for example, fingerprint, retina, faceprint, or voiceprint templates).
- Online account credentials (username/email with password or security questions/answers).
Scope notes for healthcare
- CMIA applies to providers, health plans, and their contractors that create, maintain, or receive medical information. HIPAA applies to covered entities and business associates that handle PHI. Many organizations must comply with both.
- When multiple regimes apply, follow the rule that provides the most protection to consumers or imposes the shortest notification timeline.
Encrypted Data Exemptions
California recognizes Notification Exceptions when data is properly secured. If personal information was encrypted and the encryption keys or security credentials were not accessed or acquired, consumer notice under the state breach law is generally not required.
When the encryption safe harbor does not apply
- If an unauthorized party also acquired the encryption key, password, or other credential that would render the data readable, the exemption does not apply.
- For incidents involving online credentials, treat exposed usernames/emails plus passwords or security answers as notice‑triggering even if passwords were hashed, if the compromise could reasonably allow account access.
HIPAA interaction
- Under HIPAA, properly encrypted PHI (consistent with HHS guidance) is not considered “unsecured PHI,” so the event is not a reportable breach unless the encryption was ineffective or keys were compromised.
- Where HIPAA’s risk assessment shows a low probability of compromise, you may determine that notice is not required; document the assessment thoroughly.
California Health & Safety Code considerations
For CDPH‑licensed facilities, the duty is to report unlawful or unauthorized access, use, or disclosure of a patient’s medical information. Strong encryption can support a conclusion that no usable medical information was accessed, but you must evaluate the facts (for example, whether keys or credentials were exposed) and document your decision.
Breach Reporting to Healthcare Department
California Department of Public Health (CDPH)
- Who: clinics, health facilities, home health agencies, and hospices licensed by CDPH.
- When: report to CDPH no later than 15 business days after discovery of the incident; notify the affected patient(s) within the same 15‑business‑day window.
- What to submit: a description of what happened and when, the types of medical information involved, the number of patients, corrective actions taken, and a contact point for CDPH follow‑up.
HIPAA reporting to HHS Office for Civil Rights (OCR)
- 500 or more individuals: notify HHS OCR without unreasonable delay and no later than 60 calendar days after discovery; notify prominent media in the state or jurisdiction if the breach affects 500+ residents there.
- Fewer than 500 individuals: log the breach and report to HHS OCR no later than 60 days after the end of the calendar year.
Coordinate these submissions with your patient notices and any Attorney General Submission so the facts and dates align.
Penalties for Non-Compliance
Enforcement Penalties can be significant. California can impose administrative fines, and patients may bring civil claims; HIPAA also carries civil and criminal exposure.
- CDPH administrative penalties (Health & Safety Code): up to $25,000 per patient per violation, plus up to $17,500 for each subsequent violation, with a maximum of $250,000 per event, depending on severity and corrective actions.
- CMIA civil liability: patients may recover actual damages, nominal damages (at least $1,000), and attorneys’ fees; providers and plans may also face civil penalties for negligent or willful disclosures.
- HIPAA: tiered civil monetary penalties per violation, escalating for willful neglect; criminal penalties may apply for knowing wrongful disclosures.
- CCPA/CPRA: consumers may seek statutory damages (typically $100–$750 per consumer per incident) for certain data breaches resulting from a failure to implement reasonable security procedures.
Prompt containment, transparent Data Breach Notification, and documented remediation can mitigate penalties and regulatory scrutiny.
FAQs
What is the deadline for notifying patients of a healthcare data breach?
For California residents, provide notice “without unreasonable delay.” If you are a CDPH‑licensed facility, you must notify the patient and CDPH within 15 business days of discovery. HIPAA also requires notice to affected individuals without unreasonable delay and no later than 60 calendar days; follow the shortest applicable timeline.
What information must be included in the breach notification?
Use the standardized headings: What Happened, What Information Was Involved, What We Are Doing, What You Can Do, and For More Information. Include discovery and incident dates, the data types affected (for example, medical information, health insurance information, Social Security numbers), steps you are taking, specific protective actions for patients, and clear contact information. If SSNs or driver’s license numbers were exposed, offer at least 12 months of identity theft protection and include credit bureau contacts.
When must the Attorney General be notified about a breach?
When a single incident requires notifying more than 500 California residents, submit an Attorney General Submission at the same time you send patient notices. Provide a sample of the consumer letter and a concise incident description.
Are encrypted data breaches exempt from notification requirements?
Generally yes, if the personal information was encrypted and no keys or credentials were acquired, California’s safe harbor applies and notice is not required. The exemption disappears if keys were compromised or if exposed credentials could reasonably allow account access. Under HIPAA, properly encrypted PHI is not “unsecured PHI,” but you must still confirm that the encryption was effective and document your risk assessment.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.