Skip to main content
CoreFolioHIPAA
California

California medical data breach notification: the 30-day clock, the Attorney-General filing, and how it works with HIPAA

California's breach law (Civil Code 1798.82) sets a 30-day notice clock for medical and health-insurance data, an Attorney-General filing over 500 residents, and a CDPH rule for licensed facilities — here's how it layers on HIPAA.

By CoreFolio

8-minute read

If patient data is breached in California, a practice faces a tighter clock than HIPAA alone imposes. California's data-breach statute, Civil Code § 1798.82, now requires notice to affected residents within 30 calendar days — shorter than HIPAA's 60-day outer limit — and a breach affecting more than 500 California residents adds a filing with the California Attorney General. Licensed clinics and health facilities carry a further reporting duty to the state health department. This article maps the California breach rules for medical data and how they sit on top of HIPAA's Breach Notification Rule.

Key takeaways

  • California requires breach notice to affected residents within 30 calendar days of discovery or notification (Civil Code § 1798.82, as amended effective 2025) — tighter than HIPAA's 60 days.1
  • The statute's "personal information" expressly includes medical information and health-insurance information.1
  • A breach affecting more than 500 California residents requires a sample copy of the notice to the California Attorney General within 15 calendar days of consumer notice.1
  • HIPAA compliance is a partial safe harbor: § 1798.82(e) deems the content of the notice satisfied, not the timing or the Attorney-General filing.1
  • Licensed clinics, health facilities, home health agencies, and hospices have a separate 15-business-day report to the California Department of Public Health (Health and Safety Code § 1280.15).2

Which California breach law reaches medical data

California's general breach-notification statute is Civil Code § 1798.82. It applies to any individual or business that conducts business in California and owns or licenses computerized data containing personal information. For a medical or dental practice, the key point is what "personal information" covers: the statute defines it to include "medical information" — information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional — and "health insurance information," each when tied to the individual's name.1 A breach of that unencrypted computerized data (or encrypted data whose key was also compromised) triggers the notice obligation.

The 30-day clock (as amended effective 2025)

The headline change practices need to internalize: California now caps breach-notice timing at 30 calendar days. Civil Code § 1798.82(a)(2)(A) provides that the disclosure "shall be made within 30 calendar days of discovery or notification of the data breach."1 Two delays are built in: § 1798.82(a)(2)(B) allows a delay "to accommodate the legitimate needs of law enforcement" or "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system."1

HIPAA's Breach Notification Rule sets a 60-day outer limit for notifying individuals.3 Against that, the practical rule for a California breach is simple: the 30-day state clock is the one to plan to for California residents. A practice whose incident-response procedure still references only HIPAA's 60 days is out of step with current California law.

HIPAA compliance is only a partial safe harbor

California does give HIPAA-covered entities a break — but a narrow one. Civil Code § 1798.82(e) provides that a covered entity under HIPAA "will be deemed to have complied with the notice requirements in subdivision (d) if it has complied completely with Section 13402(f)" of the HITECH Act.1 Subdivision (d) governs the content of the breach notice. So a HIPAA covered entity that follows the HITECH content rules does not have to duplicate California's notice-content formatting.

What the safe harbor does not cover:

  • the 30-day timing in subdivision (a);
  • the underlying obligation to notify California residents at all; or
  • the Attorney-General sample-copy filing for larger breaches.

In other words, "we followed HIPAA" answers what the notice must say, not when it must go out or who else must receive a copy.

The Attorney-General filing (more than 500 residents)

The step practices most often miss: when a single breach requires notifying "more than 500 California residents," the business must "electronically submit a single sample copy of that security breach notification," excluding personally identifiable information, to the California Attorney General "within 15 calendar days of notifying affected consumers."1 The Attorney General publishes those sample notices on a public database. HIPAA's own rule separately requires notifying the U.S. Department of Health and Human Services (HHS) and, for a breach affecting 500 or more residents of a state or jurisdiction, providing prominent media notice.4 These are parallel obligations — a large California breach can trigger a HHS report, media notice, and the California Attorney-General filing.

Licensed facilities: the CDPH 15-business-day report

A distinct duty applies to licensed health facilities. Health and Safety Code § 1280.15 requires "a clinic, health facility, home health agency, or hospice licensed pursuant to Section 1204, 1250, 1725, or 1745" to prevent, and to report, unlawful or unauthorized access to, use, or disclosure of patients' medical information — reporting to the California Department of Public Health and to the affected patient "no later than 15 business days" after the incident is detected.2

The scope is the catch. Section 1280.15 reaches entities licensed as facilities — hospitals, licensed surgical or community clinics, home health agencies, hospices — not a typical private physician office or dental practice, whose clinicians are licensed as individual professionals rather than as a "health facility." If your practice holds a facility license under one of those sections, this 15-business-day CDPH report is an additional, separate clock. If it does not, § 1798.82 is your operative California breach rule.

How the pieces fit together

For a California practice responding to a breach of patient data, the layers stack rather than replace one another:

  • HIPAA Breach Notification Rule — notify individuals within 60 days, notify HHS, and provide media notice for a breach affecting 500+ residents of a state or jurisdiction.34
  • Civil Code § 1798.82 — notify affected California residents within 30 days; file a sample copy with the California Attorney General if more than 500 California residents are notified. HIPAA content compliance satisfies the notice content only.1
  • Health and Safety Code § 1280.15 — if you are a licensed facility, report to CDPH and the affected patient within 15 business days.2

The tightest applicable clock governs the practice's response.

What this means for your HIPAA documentation

Two different HIPAA exercises get confused here, so it is worth separating them. The analysis a breach actually triggers is the four-factor risk assessment at 45 CFR § 164.402 — the one that decides whether an impermissible use or disclosure is a reportable breach at all — with the notification duties that follow at § 164.404 and § 164.408. That is a different exercise from the security risk analysis at § 164.308(a)(1)(ii)(A), which assesses risks to ePHI before anything goes wrong. What California changes is the timing and the recipients on the notification side. A California practice's breach procedure should:

  1. Default to 30 days, not 60, for notifying California residents, with the law-enforcement and scope-determination delays documented if used.
  2. Build in the Attorney-General filing as a checklist step for any breach affecting more than 500 California residents, due within 15 calendar days of consumer notice.
  3. Record your facility-license status so the § 1280.15 CDPH report is either on your checklist or documented as inapplicable.
  4. Treat HIPAA content compliance as the notice template, while tracking the California timing and recipients separately.
  5. Keep your documentation dated. A breach is when your incident-response documentation is read most closely; a current, dated file is the difference between an organized response and an improvised one.

Turning that into policies and procedures a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Civ. Code § 1798.82 (breach of the security of computerized personal information — the 30-calendar-day notice requirement at (a)(2)(A) and law-enforcement/scope delay at (a)(2)(B), both as amended effective 2025; "personal information" including medical information and health-insurance information; the HIPAA content safe harbor at (e); and the Attorney-General sample-copy filing within 15 calendar days when more than 500 California residents are notified for a single breach). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.82. 2 3 4 5 6 7 8 9 10

  2. Cal. Health & Safety Code § 1280.15 (a clinic, health facility, home health agency, or hospice licensed pursuant to Section 1204, 1250, 1725, or 1745 must report unlawful or unauthorized access, use, or disclosure of patients' medical information to the California Department of Public Health and to the affected patient no later than 15 business days after detection). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC&sectionNum=1280.15. 2 3

  3. 45 CFR § 164.404(b) (HIPAA Breach Notification Rule — individual notice "without unreasonable delay and in no case later than 60 calendar days" after discovery of a breach). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.404 2

  4. 45 CFR § 164.406 (HIPAA Breach Notification Rule — notice to prominent media outlets for a breach of the unsecured protected health information of more than 500 residents of a State or jurisdiction) and 45 CFR § 164.408 (notification to the Secretary of HHS). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.406 — and https://www.ecfr.gov/current/title-45/section-164.408 2