In short
- Since January 1, 2026, California businesses must notify affected residents within 30 calendar days of discovering or being notified of a breach. The only permitted delays are for law enforcement, or as necessary to determine the scope of the breach and restore the system (SB 446).
- If more than 500 Californians are notified, send a sample notice to the Attorney General within 15 calendar days of notifying them.
- Licensed clinics, health facilities, home health agencies and hospices have a shorter clock: 15 business days to report to CDPH and notify the patient.
- When several regimes apply, meet the shortest deadline.
The timeline
The California clock starts on "discovery or notification of the data breach" (Civ. Code § 1798.82(a)(2)(A)).
Discovery or notification
Record the date. The 30-day California clock starts now. A vendor that maintains data for you must notify you "immediately following discovery" (§ 1798.82(b)).
Contain, investigate, preserve
Activate the incident-response plan, stop the intrusion, determine what was accessed or acquired, and preserve evidence. Involve counsel early so the investigation is structured with privilege in mind.
Licensed health facilities: CDPH and patient
Clinics, health facilities, home health agencies and hospices report unauthorized access, use or disclosure of medical information to CDPH and notify the patient (Health & Saf. Code § 1280.15(b)).
Notify affected California residents
Send the "Notice of Data Breach" with the required headings and content, unless a permitted delay applies (§ 1798.82(a)(2), (d)).
Attorney General, if more than 500 residents
Submit one sample copy, without personal information, through the AG's online form (§ 1798.82(f)).
HIPAA and FTC outer limits
HIPAA covered entities notify individuals "without unreasonable delay" and no later than 60 days after discovery, plus HHS when 500 or more are affected and the media when more than 500 residents of a state are affected (45 CFR §§ 164.404–164.408). Health apps outside HIPAA follow the FTC Health Breach Notification Rule's 60-day limit (16 CFR § 318.4).
Don't treat the scoping delay as an extension. The statute allows delay "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system," but sets no outer limit, and there is no guidance yet on how long that can run. Plan to notify within 30 days, and document any reason you can't.
Which rules apply to you
| Who | Rule | Deadline |
|---|---|---|
| Businesses that own or license computerized personal information of California residents | Civ. Code § 1798.82 | 30 calendar days; AG sample within 15 days after, if over 500 |
| Vendors that maintain data they don't own | Civ. Code § 1798.82(b) | Notify the owner immediately |
| Licensed clinics, health facilities, home health agencies, hospices | Health & Saf. Code § 1280.15 | 15 business days to CDPH and the patient |
| HIPAA covered entities | 45 CFR §§ 164.400–164.414 | 60 calendar days outer limit; HHS annually if under 500 |
| HIPAA business associates | 45 CFR § 164.410 | To the covered entity within 60 days, or sooner under the BAA |
| Health apps and personal health records not covered by HIPAA | 16 CFR Part 318 (FTC) | 60 calendar days outer limit |
| State and local agencies | Civ. Code § 1798.29 | "Most expedient time possible and without unreasonable delay" (not changed by SB 446) |
A HIPAA covered entity that fully complies with HITECH's notice-content rules is deemed to comply with California's content and format rules, but the rest of § 1798.82, including its timing and the AG filing, still applies (§ 1798.82(e)).
Health facilities: CDPH reporting
Under Health & Safety Code § 1280.15, a clinic, health facility, home health agency or hospice licensed under Health & Safety Code §§ 1204, 1250, 1725 or 1745 must prevent unlawful or unauthorized access to, use of, or disclosure of patients' medical information. When it happens, the facility must report to CDPH and notify the affected patient no later than 15 business days after it is detected.
- This covers far more than hacking: a staff member looking at a record without a work reason can trigger it.
- Penalties can reach $25,000 per patient, plus $100 per day for late reporting, subject to a $250,000 combined cap per reported event (§ 1280.15(a), (d)).
- For skilled nursing facilities and other licensed providers, this clock usually runs out first.
Lawsuit exposure
If the breach resulted from a failure to maintain reasonable security, affected consumers can sue under the CCPA for $107 to $799 each per incident, or actual damages (Civ. Code § 1798.150). Consumers must give 30 days' notice before seeking statutory damages, and security improvements made after the breach don't count as a cure. See Security.
Incident response checklist
- Keep a written incident-response plan, and test it.11 CCR § 7123(c)(17); 45 CFR § 164.308(a)(6)
- Record the date of discovery or notification. The 30-day clock runs from it.Civ. Code § 1798.82(a)(2)(A)
- If you hold data for another business, notify the owner immediately.Civ. Code § 1798.82(b)
- Decide whether it's a "breach": unauthorized acquisition of computerized personal information as defined, considering whether the data was encrypted and whether the key was compromised.Civ. Code § 1798.82(a)(1), (g), (h)
- Document any law-enforcement delay request and any scoping or restoration work that justifies a delay.Civ. Code § 1798.82(a)(2)(B), (c)
- Draft the "Notice of Data Breach" with the required headings and content, in at least 10-point type.Civ. Code § 1798.82(d)
- Where Social Security or government ID numbers were involved and you were the source, offer at least 12 months of free identity-theft protection.Civ. Code § 1798.82(d)(2)(G)
- For more than 500 California residents, file the sample notice with the AG within 15 days of notifying them.Civ. Code § 1798.82(f)
- Licensed health facilities: report to CDPH and notify patients within 15 business days.Health & Saf. Code § 1280.15(b)
- HIPAA entities: notify individuals, HHS and, where required, the media within 60 days.45 CFR §§ 164.404–164.408
- Keep copies of the notices, the analysis and the remediation. Audited businesses must include a sample notice in their next cybersecurity audit report.11 CCR § 7123(e)
- Prepare for demand letters: 30-day notice-and-cure rules apply, but security upgrades after a breach are not a cure.Civ. Code § 1798.150(b)
Guides in this topic
- Law explainerCalifornia's breach notice law after SB 446: 30 days, and what the notice must sayCivil Code 1798.82 as amended by SB 446: the 30-calendar-day deadline, AG filing within 15 days, the encryption safe harbor, required headings, and substitute notice.
- Topic guideSecurity policies and controlsCalifornia's reasonable-security duty (Civ. Code 1798.81.5), CCPA breach lawsuits, the AG's CIS Controls benchmark, the HIPAA Security Rule, and CalPrivacy cybersecurity audit deadlines.
Official sources
- Civil Code § 1798.82 (as amended by SB 446, Stats. 2025, ch. 319)
- Data security breach reporting and list of reported breaches (California Attorney General)
- Health and Safety Code § 1280.15
- HIPAA Breach Notification Rule, 45 CFR §§ 164.400–164.414 (eCFR)
- FTC Health Breach Notification Rule, 16 CFR Part 318 (eCFR)