California CMIA Breach Notice Content Requirements: What You Must Include Beyond HIPAA

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

California CMIA Breach Notice Content Requirements: What You Must Include Beyond HIPAA

Kevin Henry

Data Breaches

September 06, 2026

8 minutes read
Share this article
California CMIA Breach Notice Content Requirements: What You Must Include Beyond HIPAA

CMIA Breach Notification Timeline

Under California’s medical information breach compliance framework, clinics, health facilities, home health agencies, and hospices must notify both the California Department of Public Health (CDPH) and each affected patient no later than 15 business days after detecting a breach. California Health and Safety Code 1280.15 sets this accelerated timeline, and Title 22 CCR 79902 operationalizes it.

HIPAA allows up to 60 calendar days after discovery. That means California’s deadline is significantly faster—counted in business days, not calendar days—so you need an internal breach investigation protocol that can triage, validate, and draft notices quickly.

Law enforcement can delay patient and CDPH notifications if disclosure would impede an active investigation. Any delay must be documented, and extensions are time-limited, so track and calendar the end date the agency specifies.

Required Notice Content

Patient-facing content mandated by 22 CCR 79902(b)(1)

  • Brief description of what happened, including your facility name and address, the date of the breach, and the date of discovery (if known).
  • Description of the types of medical information involved (for example, name, diagnosis, health insurance information, medical record number, Social Security number).
  • Clear steps the individual should take to protect themselves.
  • What you are doing to investigate, apply data breach mitigation measures, and prevent future incidents.
  • Contact procedures for questions or more information (toll‑free number, email, website, or postal address), written in plain language.

California consumer notification standards that apply in addition to HIPAA

  • Title and format: The notice must be titled “Notice of Data Breach,” written in plain language, and use a minimum 10‑point font.
  • Core content: Include your name and contact information; the specific types of personal information impacted; the date/estimated date or date range of the breach; whether notice was delayed for law enforcement; and a general description of the incident.
  • Credit reporting details: If Social Security numbers or driver’s license/California ID numbers were exposed, include the toll‑free numbers and addresses of the major credit reporting agencies.
  • Identity theft protection: If your organization was the source of the breach and SSNs or government‑issued IDs were exposed, offer appropriate identity theft prevention and mitigation services at no cost for at least 12 months, with instructions to enroll.
  • Attorney General sample copy: If a single event requires notice to more than 500 California residents, submit a sample copy of the consumer notice to the California Attorney General within 15 calendar days of notifying residents.

Structured Notice Headings

California prescribes standardized section titles to keep notices clear and scannable. Present your consumer notice content under these headings in this order:

  • What Happened
  • What Information Was Involved
  • What We Are Doing
  • What You Can Do
  • For More Information

You may add an “Other Important Information” section if needed, but never omit the required headings. Use straightforward language; avoid legalese and internal jargon.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Differences Between CMIA and HIPAA

  • Timing: CMIA (via California Health and Safety Code 1280.15 and 22 CCR 79902) requires notice to patients and CDPH within 15 business days of detection; HIPAA allows up to 60 calendar days.
  • Who you must notify: CMIA adds the California Department of Public Health reporting requirements for licensed facilities; HIPAA requires notices to affected individuals, HHS (and media for incidents affecting 500+ in a state/jurisdiction). California’s consumer notification standards also require submitting a sample notice to the Attorney General when 500+ Californians are affected.
  • How the notice must look: California mandates the “Notice of Data Breach” title, prescribed headings, and readable formatting; HIPAA does not require this structure.
  • Documentation duties: California regulations require a documented risk assessment process and centralized records of non‑breach incidents retained for six years; HIPAA requires a risk assessment but does not prescribe California’s specific recordkeeping format.
  • Enforcement and penalties: CDPH may issue administrative penalties tailored to medical information breach compliance, on top of CMIA civil remedies. HIPAA penalties are enforced by HHS OCR under a different schedule and methodology.

Reporting Obligations to Public Health

When to report

Report a breach (or a breach reasonably believed to have occurred) to CDPH no later than 15 business days after detection. If some facts are still developing, file on time with what you know, then supplement as more information becomes available.

How to report

You may report by the methods CDPH specifies (for example, via its CalHEART portal, first‑class mail, telephone, facsimile, or email). Keep proof of submission and time‑stamps for your compliance file.

What to include (22 CCR 79902(a)(1))

  • Facility name and address.
  • Date and time the breach occurred and was detected.
  • Names of affected patients.
  • Description of the medical information breached, including the nature and extent of the data, types of individually identifiable information, and likelihood of re‑identification.
  • Events surrounding the breach, including whether information was actually acquired or viewed.
  • Names and contact information of the individual(s) who performed the breach, any witnesses, and any unauthorized recipients (to the extent known).
  • Date you notified (or will notify) the patient or representative.
  • Facility contact for follow‑up queries.
  • Corrective or data breach mitigation measures you have taken.
  • Any other reported instances involving a breach of that same patient’s information within the past six years.
  • A copy of the patient notice and any related patient communications.
  • Audit reports, witness statements, or other documents relied upon in determining that a breach occurred.

If you determine an incident is not a breach after a documented risk assessment, maintain a centralized record and the supporting materials for at least six years, as required by 22 CCR 79902.

Penalties for Non-Compliance

CDPH administrative penalties (California Health and Safety Code 1280.15; 22 CCR 79903–79904)

  • Up to $25,000 per patient whose medical information was unlawfully or without authorization accessed, used, or disclosed, plus up to $17,500 per subsequent occurrence involving the same patient, capped at $250,000 per reported event.
  • $100 per day for late reporting to CDPH or to patients following the 15‑business‑day deadline, subject to the overall statutory cap.
  • Regulations set a base penalty of $15,000 per violation, adjusted by factors such as facility history, scope, mitigation, and corrective action.

CMIA civil remedies (California Civil Code)

  • Private right of action with nominal damages of $1,000 and recovery of actual damages, plus injunctive relief.
  • Administrative or civil penalties for knowing or willful misuse of medical information for financial gain, up to $250,000 per violation, in addition to disgorgement of proceeds.
  • Penalties under California Health and Safety Code 1280.15 offset duplicative CMIA administrative fines for the same violation.

Conclusion

Beyond HIPAA’s 60‑day rule, California imposes faster timelines, prescriptive consumer notification standards, and detailed Department of Public Health reporting requirements. Build a breach investigation protocol that can verify facts within days, draft a compliant “Notice of Data Breach” using the required headings, and assemble the 22 CCR 79902 report package for CDPH. Doing so strengthens medical information breach compliance and materially reduces penalty exposure.

FAQs

What specific content must be included in a CMIA breach notice?

Your patient notice must plainly explain what happened (including your facility name/address, breach and discovery dates), what medical information was involved, steps the individual should take, what you are doing to investigate and mitigate, and how to contact you. California consumer notification standards also require the “Notice of Data Breach” title, minimum 10‑point font, core incident details, and credit‑bureau contacts if SSNs or driver’s license/ID numbers were exposed. If you were the source of a breach involving SSNs or government IDs, offer at least 12 months of identity‑theft protection at no cost.

How does CMIA notification timing differ from HIPAA?

CMIA (via California Health and Safety Code 1280.15 and 22 CCR 79902) requires notice to affected patients and CDPH within 15 business days of detecting a breach. HIPAA allows notice without unreasonable delay, but no later than 60 calendar days after discovery. California’s clock is faster and runs on business days, so you must act sooner.

What are the required headings in a CMIA breach notice?

Organize your consumer notice under these headings: What Happened; What Information Was Involved; What We Are Doing; What You Can Do; and For More Information. Use the title “Notice of Data Breach,” plain language, and a minimum 10‑point font. You may add “Other Important Information” if relevant, but never omit the required headings.

What penalties apply for failing to comply with CMIA breach reporting?

CDPH may assess up to $25,000 per patient and up to $17,500 per subsequent occurrence involving the same patient, with a $250,000 cap per reported event. Late notices can incur $100 per day until reported. Separately, CMIA provides a private right of action with $1,000 nominal damages and actual damages, and authorizes administrative or civil penalties up to $250,000 per violation for knowing or willful misuse for financial gain.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles