Topic guide

Data breaches

Incident response, the deadlines for notifying people and regulators, and how California's 30-day rule fits with HIPAA, CDPH and FTC requirements.

Last reviewed

In short

  • Since January 1, 2026, California businesses must notify affected residents within 30 calendar days of discovering or being notified of a breach. The only permitted delays are for law enforcement, or as necessary to determine the scope of the breach and restore the system (SB 446).
  • If more than 500 Californians are notified, send a sample notice to the Attorney General within 15 calendar days of notifying them.
  • Licensed clinics, health facilities, home health agencies and hospices have a shorter clock: 15 business days to report to CDPH and notify the patient.
  • When several regimes apply, meet the shortest deadline.

The timeline

The California clock starts on "discovery or notification of the data breach" (Civ. Code § 1798.82(a)(2)(A)).

  1. Discovery or notification

    Record the date. The 30-day California clock starts now. A vendor that maintains data for you must notify you "immediately following discovery" (§ 1798.82(b)).

  2. Contain, investigate, preserve

    Activate the incident-response plan, stop the intrusion, determine what was accessed or acquired, and preserve evidence. Involve counsel early so the investigation is structured with privilege in mind.

  3. Licensed health facilities: CDPH and patient

    Clinics, health facilities, home health agencies and hospices report unauthorized access, use or disclosure of medical information to CDPH and notify the patient (Health & Saf. Code § 1280.15(b)).

  4. Notify affected California residents

    Send the "Notice of Data Breach" with the required headings and content, unless a permitted delay applies (§ 1798.82(a)(2), (d)).

  5. Attorney General, if more than 500 residents

    Submit one sample copy, without personal information, through the AG's online form (§ 1798.82(f)).

  6. HIPAA and FTC outer limits

    HIPAA covered entities notify individuals "without unreasonable delay" and no later than 60 days after discovery, plus HHS when 500 or more are affected and the media when more than 500 residents of a state are affected (45 CFR §§ 164.404–164.408). Health apps outside HIPAA follow the FTC Health Breach Notification Rule's 60-day limit (16 CFR § 318.4).

Don't treat the scoping delay as an extension. The statute allows delay "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system," but sets no outer limit, and there is no guidance yet on how long that can run. Plan to notify within 30 days, and document any reason you can't.

Which rules apply to you

WhoRuleDeadline
Businesses that own or license computerized personal information of California residentsCiv. Code § 1798.8230 calendar days; AG sample within 15 days after, if over 500
Vendors that maintain data they don't ownCiv. Code § 1798.82(b)Notify the owner immediately
Licensed clinics, health facilities, home health agencies, hospicesHealth & Saf. Code § 1280.1515 business days to CDPH and the patient
HIPAA covered entities45 CFR §§ 164.400–164.41460 calendar days outer limit; HHS annually if under 500
HIPAA business associates45 CFR § 164.410To the covered entity within 60 days, or sooner under the BAA
Health apps and personal health records not covered by HIPAA16 CFR Part 318 (FTC)60 calendar days outer limit
State and local agenciesCiv. Code § 1798.29"Most expedient time possible and without unreasonable delay" (not changed by SB 446)

A HIPAA covered entity that fully complies with HITECH's notice-content rules is deemed to comply with California's content and format rules, but the rest of § 1798.82, including its timing and the AG filing, still applies (§ 1798.82(e)).

Health facilities: CDPH reporting

Under Health & Safety Code § 1280.15, a clinic, health facility, home health agency or hospice licensed under Health & Safety Code §§ 1204, 1250, 1725 or 1745 must prevent unlawful or unauthorized access to, use of, or disclosure of patients' medical information. When it happens, the facility must report to CDPH and notify the affected patient no later than 15 business days after it is detected.

  • This covers far more than hacking: a staff member looking at a record without a work reason can trigger it.
  • Penalties can reach $25,000 per patient, plus $100 per day for late reporting, subject to a $250,000 combined cap per reported event (§ 1280.15(a), (d)).
  • For skilled nursing facilities and other licensed providers, this clock usually runs out first.

Lawsuit exposure

If the breach resulted from a failure to maintain reasonable security, affected consumers can sue under the CCPA for $107 to $799 each per incident, or actual damages (Civ. Code § 1798.150). Consumers must give 30 days' notice before seeking statutory damages, and security improvements made after the breach don't count as a cure. See Security.

Incident response checklist

  • Keep a written incident-response plan, and test it.11 CCR § 7123(c)(17); 45 CFR § 164.308(a)(6)
  • Record the date of discovery or notification. The 30-day clock runs from it.Civ. Code § 1798.82(a)(2)(A)
  • If you hold data for another business, notify the owner immediately.Civ. Code § 1798.82(b)
  • Decide whether it's a "breach": unauthorized acquisition of computerized personal information as defined, considering whether the data was encrypted and whether the key was compromised.Civ. Code § 1798.82(a)(1), (g), (h)
  • Document any law-enforcement delay request and any scoping or restoration work that justifies a delay.Civ. Code § 1798.82(a)(2)(B), (c)
  • Draft the "Notice of Data Breach" with the required headings and content, in at least 10-point type.Civ. Code § 1798.82(d)
  • Where Social Security or government ID numbers were involved and you were the source, offer at least 12 months of free identity-theft protection.Civ. Code § 1798.82(d)(2)(G)
  • For more than 500 California residents, file the sample notice with the AG within 15 days of notifying them.Civ. Code § 1798.82(f)
  • Licensed health facilities: report to CDPH and notify patients within 15 business days.Health & Saf. Code § 1280.15(b)
  • HIPAA entities: notify individuals, HHS and, where required, the media within 60 days.45 CFR §§ 164.404–164.408
  • Keep copies of the notices, the analysis and the remediation. Audited businesses must include a sample notice in their next cybersecurity audit report.11 CCR § 7123(e)
  • Prepare for demand letters: 30-day notice-and-cure rules apply, but security upgrades after a breach are not a cure.Civ. Code § 1798.150(b)

Guides in this topic

Official sources