Contact Us
IT Total Care

Blog

Home health aide in blue scrubs brushing a seated client's hair during a home visit, the care setting behind how to report a medical information breach to CDPH.

How to Report a Medical Information Breach to CDPH in 15 Business Days

This guide explains why reporting a medical information breach to CDPH matters for a California licensed agency, how to work through the filing step by step on your own, and how IT Total Care builds the detection and evidence the filing depends on, so the fifteen days are spent writing a report rather than reconstructing what happened.

1. Why Does Reporting a Medical Information Breach to CDPH Matter for California Agencies?

Reporting a medical information breach to CDPH matters because California imposes a separate, shorter, and independently enforceable obligation on licensed home health agencies and hospices. It is not a state version of the federal rule. It carries its own trigger, its own deadline, its own required content, and its own penalties.

The gap between what an agency has time for and what the state allows is wide. IBM’s Cost of a Data Breach Report 2026 put the mean time to identify and contain a breach at 247 days, a figure that describes all industries rather than home-based care specifically. California gives a licensed agency 15 business days from detection. The state is not waiting for a completed investigation. It is asking for a report.

What Does Section 1280.15 Actually Require of a Licensed Agency?

California Health and Safety Code section 1280.15, implemented by Title 22 sections 79900 through 79905 effective July 1, 2021, sets five things a licensed agency has to get right. Each one is a place a filing commonly goes wrong.

  • Who the statute reaches. Clinics, health facilities, home health agencies, and hospices licensed under Health and Safety Code sections 1204, 1250, 1725, or 1745. A California Home Care Organization is licensed by the Department of Social Services under a different chapter and is not among the licensee types this section enumerates.
  • A broader trigger than the federal rule. The obligation attaches to unlawful or unauthorized access to, or use or disclosure of, a patient’s medical information, which is a wider category than unsecured protected health information.
  • An obligation that runs independently of HIPAA. A determination that no federal notice is required does not end the analysis. The state question has to be worked separately, on its own facts.
  • Fifteen business days from detection. Roughly 21 calendar days, to CDPH and to the affected patient, both inside the same window. Detection starts it, not confirmation.
  • Penalty exposure on two separate axes. The breach itself is one exposure. The failure to report on time is a second, and it accrues daily until the report is made.

Two adjacent questions sit outside this guide. How the federal clock works, and how it interacts with this one, is covered in HIPAA breach notification for home health agencies. Whether a properly encrypted device is reportable at all is a separate question again.

2. How to Report a Medical Information Breach to CDPH in Five Steps

Reporting a medical information breach to CDPH takes five steps: record the detection date and count in business days, determine whether the incident is reportable, file the report with CDPH, notify the affected patient inside the same window, and track the filing while managing any law enforcement delay. Each step has to be documented while it happens.

Step 1: Record the Detection Date and Count in Business Days

Record the date and the time of detection before doing anything else, because every deadline in this process runs from that one entry. Under Title 22 section 79901, a breach is detected on the first business day it is known, or by exercising reasonable diligence would have been known, to any workforce member or agent other than the person who caused it. Detection starts the clock. Confirmation does not.

Then count the days correctly, because this is where agencies quietly lose a week. Fifteen business days is roughly 21 calendar days, and the regulation excludes Saturdays, Sundays, and nine named holidays: New Year’s Day, Martin Luther King Jr. Day, Presidents’ Day, Memorial Day, Independence Day, Labor Day, Veterans’ Day, Thanksgiving Day, and Christmas Day. Write the resulting due date on a calendar the same day it is calculated, and write the federal date beside it.

Step 2: Determine Whether the Incident Is Reportable

Decide reportability against the state definition, not the federal one. The trigger is unlawful or unauthorized access to, or use or disclosure of, a patient’s medical information. Because that category is wider than unsecured PHI, an incident can be outside the federal rule and squarely inside this one, which is why the two analyses have to be run separately.

The 2021 regulations expanded the exceptions to align more closely with HIPAA, so not every misdirected fax or email is now reportable. The original narrow exception survives alongside them: internal paper records, electronic mail, or facsimile transmissions inadvertently misdirected within the same facility or health care system in the course of coordinating care or delivering services do not constitute unauthorized access.

If the agency concludes an incident is not a breach, that conclusion creates its own obligation. Title 22 section 79902 requires a centralized record of each non-breach incident, together with every material the assessment relied on, available for CDPH inspection at all times and retained for at least six years. A decision not to report is a record, not the absence of one.

Step 3: File the Report With CDPH

File the report within 15 business days of detection. It goes to CDPH by email, telephone, facsimile, first-class mail, or through the department’s website, and the substance has to be provided in writing and signed by a representative of the agency. The filing is where most agencies discover they do not have what the state wants.

Title 22 section 79902 sets a considerably longer content list for the CDPH report than for the patient notice, and the two are often confused. The report requires:

  • The name and address of the facility where the breach occurred
  • The date and time each breach occurred, and the date and time each was detected
  • The names of the affected patients
  • A description of the medical information involved, including the types of individually identifiable information and the likelihood of re-identification
  • A description of the events surrounding the breach
  • Names and contact information for whoever performed the breach, any witnesses, and any unauthorized person who used or received the information, to the extent known
  • The date the patient was notified, was attempted to be notified, or will be notified
  • Contact information for an agency representative CDPH can reach for more detail
  • A description of any corrective or mitigating action the agency has taken
  • Any other reported event involving that patient’s medical information in the previous six years
  • A copy of the notification sent to the patient, and anything else provided to them about the breach
  • Any audit reports, witness statements, or other documents the agency relied on in determining a breach occurred

Step 4: Notify the Affected Patient Inside the Same Window

Notify the patient within the same 15 business days, because the patient notice is a separate obligation carrying its own separate penalty. An agency that files with CDPH on time and forgets the patient has met one obligation and breached another, and the daily exposure on the second one keeps running.

The patient notice has its own five required elements, and the regulation requires all of them in plain language rather than in the language a policy document would use:

  • A brief description of what happened, including the agency name and address, the date of the breach, and the date it was discovered
  • A description of the types of medical information involved, such as name, date of birth, diagnosis, or account number
  • The steps the patient should take to protect themselves from potential harm
  • A brief description of what the agency is doing to investigate the breach, mitigate harm, and prevent further breaches
  • Contact procedures, including a toll-free number, an email address, a website, or a postal address

Send it in writing by first-class mail to the last known address. Email is available only where the patient previously agreed in writing to electronic notice and has not withdrawn that agreement, which in practice means almost never. The notice may go out in more than one mailing as information becomes available.

Step 5: Track the Filing and Manage Any Law Enforcement Delay

Treat the filing as unfinished until CDPH has everything. A breach is not deemed reported unless the agency has provided, or made a good faith effort to provide, every required item, which means an incomplete submission leaves the clock running and the daily penalty accruing behind it. Track the date sent and the date accepted as two different dates.

Do not hold the filing while waiting for complete information. Submit what is known, and supply the remaining items as they become available, which the regulation expressly contemplates. Unreasonable delay in supplementing is itself penalized, and CDPH weighs the size of the affected population, the quality of the initial report, and who caused the incident when it decides whether a delay was reasonable.

Law enforcement can delay the patient notice, though not the CDPH report. A written statement supports a delay of up to 60 days from the request, with a further extension of up to 60 days available on a written declaration. An oral statement caps the delay at 30 calendar days unless a conforming written statement arrives inside that period, and the agency has to document the oral statement, including who made it and when. A delayed report is due within 15 business days after the designated end of the delay.

What Are the Penalties for a Late or Incomplete Filing?

Penalties attach on two axes, and the second one is the one an agency fully controls. The breach itself carries one exposure. The failure to report carries another that accrues every day until the report is made, and CDPH assesses the CDPH filing and the patient notice separately.

  • Up to $25,000 per patient whose medical information was accessed, used, or disclosed without authorization
  • Up to $17,500 per subsequent occurrence relating to a reported event
  • $100 for each day the breach is not reported to CDPH, and $100 for each day it is not reported to the patient, running after the initial 15-day period
  • A regulatory base penalty of $15,000 for an initial violation, adjusted up or down by as much as $10,000 against a three-year compliance history, the agency’s own detection and corrective action, and factors outside its control
  • Seventy percent of the initial violation’s final penalty for a subsequent occurrence, capped at the statutory $17,500
  • A combined cap of $250,000 per reported event, with CDPH retaining discretion to reduce a final penalty it considers unduly burdensome or excessive

Why Is Documentation Itself Part of the Penalty Exposure?

One evidentiary rule deserves particular attention. For enforcement purposes, CDPH presumes the agency did not notify the patient if the notification was not documented, and the agency can rebut that presumption only by a preponderance of the evidence. An undocumented notice and a notice that never happened look identical from the outside, which makes the filing record part of the compliance itself rather than a byproduct of it.

Limitations: Reporting a medical information breach to CDPH is less a technical problem than a timing and documentation problem, which is exactly why agencies handling it internally struggle. The detection date is the first casualty, because nobody writes it down while everyone is still deciding whether the incident is serious. The federal calendar gets managed attentively and the state one surfaces on day 40, three weeks after it expired. The filing goes in without the section 79902 items and is not deemed reported, so the agency believes it complied while the daily penalty keeps accruing. None of this requires anyone to be careless. It requires only that the process was not written down before it was needed.

3. Where Does IT Total Care Fit Into How to Report a Medical Information Breach to CDPH?

IT Total Care does not make the breach determination and does not file with CDPH. Both are the agency’s legal obligations and neither transfers to a vendor. What we build is the detection record, the technical evidence, and the documentation the filing rests on, so the fifteen business days go into producing a report rather than into reconstructing what happened.

That distinction matters more in home-based care than in an office business, because the evidence is scattered across personal phones, field laptops, and platforms the agency does not host. We have built this kind of operational discipline for growing SF Bay Area agencies, including the work behind how Bridge Home Health and Hospice scaled from 25 to more than 250 employees.

Our process includes the following, grouped the way an incident actually unfolds.

What Establishes the Detection Date?

  • Timestamped detection records. Monitoring that produces a system-generated detection record rather than a recollection, alerting that surfaces an incident on the day it happens rather than on the Monday after, and both clocks started from the same recorded date so the state and federal calendars run in parallel.
  • A durable incident log. A record the agency can still produce later showing what was detected, when, and by whom, which is the evidence an enforcement review asks for first.

What Produces the Evidence a Determination Needs?

  • Evidence the determination rests on. Audit logs from Axxess, WellSky, or the agency’s own platform showing whether patient information was actually accessed or only exposed, and scope reconstruction to the patient level rather than an estimate of how many records were involved.
  • Provable device records. Per-device encryption status, remote wipe completion, and account and session state retrievable from Intune, JumpCloud, Apple Business Manager, or Entra ID, so mitigation is evidence rather than intention.
  • Findings written for the filing. Technical findings recorded in a form that drops into the patient notice and the CDPH report without translation, so the agency is not paying someone to rewrite an engineer’s notes during week two.

What Keeps Both Clocks Visible?

  • A rehearsed incident response runbook. A procedure that names the 15-business-day state deadline and the 60-calendar-day federal deadline side by side, with the earlier one driving the schedule, and that gets rehearsed rather than written, because an agency reading it for the first time during a ransomware weekend will miss dates.
  • A named responsible party for each filing. The CDPH report and the patient notice are separate obligations with separate daily exposure, so each one gets an owner who confirms it happened rather than assuming somebody did it.
  • Vendor notification obligations tracked. A vendor that discovers an incident inside your environment owes you notice that starts your own clock, which is something your business associate agreement should already require.

“Most of the agencies we work with hear about the 15 business days from us rather than from CDPH. This allows us to build a plan based on the timeline they are actually required to follow, not the 60 day timeline most agencies have heard of.”

Brendan Duebner, President of IT Total Care

Ready to Make CDPH Reporting a Documented Process Instead of a Scramble?

IT Total Care works with home health and hospice agencies across the San Francisco Bay Area on the detection, evidence, and documentation a CDPH filing depends on. Our home-based care IT support covers monitoring and alerting, incident logging, device and encryption records, and scope reconstruction to the patient level. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.

Leave a Comment

Your email address will not be published. Required fields are marked *