Contact Us
IT Total Care

Blog

Caregiver wearing a photo identification badge resting a hand on a seated older woman holding a cane, the client records behind California's 30-day breach notification

How to Meet California’s 30-Day Breach Notification Deadline

At 4:40 on a Friday afternoon, an office coordinator at a home care agency in the East Bay opens the shared drive to pull the weekend’s care plans and finds every file renamed. She calls the owner, who calls the person who set up the network four years ago, and by the time anyone uses the word breach it is Monday. Nobody wrote down when she first noticed. That missing line is the problem, because California’s breach notification clock started on Friday and the agency can no longer prove when.

Learning how to meet California’s 30-day breach notification deadline is less about knowing the statute than about having a sequence you can run under pressure. This guide covers why the deadline matters for agencies holding client information, how to work through it internally step by step, and how IT Total Care handles the detection and evidence side of it for Bay Area agencies. For the wider picture of what law reaches an agency in the first place, see our overview of cybersecurity for home care agencies.

1. Why Does California’s 30-Day Breach Notification Deadline Matter for Home Care Agencies?

California’s 30-day breach notification deadline matters because it is short, it is fixed, and it starts before anyone understands what happened. SB 446 took effect January 1, 2026 and replaced a flexible reasonableness standard with a hard count of calendar days. An agency that discovers an incident on day one is expected to have notified affected California residents by day thirty.

The gap between that deadline and how long incidents actually take to understand is the whole difficulty. IBM’s Cost of a Data Breach Report 2026, released July 29, 2026, put the average time to identify and contain a breach at 247 days across all industries. That figure describes organizations far larger than a forty-caregiver agency, and it is not a home care number, but it explains why a thirty-day notification window is a planning problem rather than a paperwork problem.

What Does the Statute Actually Require?

Five features of the statute decide how a home care agency has to prepare:

  • Who the law reaches: Civil Code section 1798.82 applies to any individual or business that conducts business in California and owns, licenses, or maintains computerized data containing personal information about California residents. There is no small-business exemption and no industry carve-out, and it reaches out-of-state companies doing business here.
  • The deadline itself: Notice must go to affected California residents within 30 calendar days of discovery or notification of the breach. Calendar days, not business days, and the count runs from the earlier of the two triggers.
  • What counts as triggering data: Medical information is a triggering data element when combined with a client’s name. Care plans, shift notes, and diagnosis references living in ClearCare or WellSky Personal Care meet the statutory definition, which means a breach of the scheduling platform is a notifiable breach.
  • The second clock: A breach affecting more than 500 California residents adds a sample notice to the Attorney General within 15 calendar days of notifying those individuals. That clock starts at consumer notice rather than at discovery, which is the detail most often misread.
  • The narrow delay: Delay is permitted only for the legitimate needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Internal deliberation about whether to notify is not a qualifying reason.

2. How Can an Agency Meet California’s 30-Day Breach Notification Deadline on Its Own?

An agency can run this internally in five steps: record the discovery date and name the trigger, confirm the statutory threshold was actually met, scope the exposure and count California residents, draft the notice against the statutory format, and then send, file, and document any delay. The steps are not complicated. Running them in order, under pressure, with a real deadline behind them is the part that takes preparation.

Step 1: Record the Discovery Date and Name the Trigger

Write down the date and time the moment anything is noticed, before anyone begins investigating. The 30-day count runs from discovery or notification of the breach, and nothing downstream is defensible without that recorded date. Then name which trigger applies, because an agency that discovered the incident itself and an agency that was told by a vendor are on the same deadline but hold very different evidence of when it started.

  • Record the date, the time, who noticed, and what they saw, in a system that carries its own timestamp rather than in a document somebody can edit two weeks later.
  • If a vendor or partner notified you, keep their notice. It is the external evidence of when your clock began, and it is the strongest document you will have.
  • If you hold personal information you do not own, section 1798.82(b) requires you to notify the owner or licensee of the information immediately on discovery. That is a separate and faster obligation than the 30-day consumer deadline.
  • Count in calendar days. A ransomware event discovered at 4:40 on a Friday afternoon leaves 30 calendar days, and the weekend counts against you.

Step 2: Confirm the Statutory Threshold Was Actually Met

Notification is required when unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Acquisition is the threshold. An incident that disrupted systems without anyone taking data may not require notice at all, and an incident where you cannot rule acquisition out generally does, because the statute asks what you reasonably believe rather than what you can prove.

  • Encrypted information sits outside the trigger unless the encryption key or security credential was also acquired and you have a reasonable belief it could render the information readable or usable.
  • Good faith acquisition of personal information by an employee or agent, for the agency’s own purposes, is not a breach of the security of the system, provided the information is not used or further disclosed without authorization.
  • Do not wait for certainty. The standard is reasonable belief, and waiting for forensic confirmation is how agencies spend three of their thirty days.

Step 3: Scope the Exposure and Count California Residents

Identify which specific data elements were exposed and count how many California residents were affected. These two facts decide everything about the notice: the elements determine what the notice must contain and whether an identity theft offer attaches, and the resident count determines whether the Attorney General filing applies. Scoping vaguely at this step produces a notice that is wrong in both directions.

  • List the exposed elements individually rather than as a category: name, address, medical information, health insurance information, Social Security number, government-issued identification number, or account number with its access code.
  • Count California residents specifically. The 500 threshold is about residency, not about total client count or total records.
  • Work from a current inventory of systems and devices rather than from memory. Agencies without one spend days rebuilding it while the clock runs, which is why a maintained device inventory pays for itself exactly once.
  • Where one platform serves several service lines, scope by data set rather than by department, because the statute follows the information and not your org chart.

Step 4: Draft the Notice Against the Statutory Format

Build the notice while the investigation continues rather than after it concludes. The statute prescribes the title, the headings, and the minimum type size, and it prints a model security breach notification form whose use is deemed to be in compliance. Drafting from scratch adds risk and days for no benefit.

  • Title it “Notice of Data Breach” and present the information under the statutory headings in order: What Happened? What Information Was Involved? What We Are Doing, What You Can Do, and For More Information. The model form printed in the statute adds an Other Important Information heading that the headings provision does not list, so pick one and follow it consistently.
  • Write in plain language, at no smaller than 10-point type, with the title and headings clearly and conspicuously displayed.
  • Include your agency’s name and contact information, the types of personal information involved, the date or date range of the breach where determinable, and the date of the notice itself.
  • State whether notification was delayed as a result of a law enforcement investigation, where that is possible to determine at the time.
  • Offer 12 months of identity theft prevention and mitigation services only where your agency was the source of the breach and the exposure included a Social Security number or a government-issued identification number such as a driver’s license, California ID, passport, or military ID. A breach of client names and care plan content triggers notification without triggering that offer.
  • Where the breach involves online account credentials and no other personal information, the statute allows a different form of notice directing people to change that password and any other account using the same credentials. Do not deliver that notice to the breached email address itself.

Step 5: Send, File, and Document Any Delay

Send by written or electronic notice, then start the second clock deliberately rather than discovering it later. The Attorney General filing runs from the date consumer notices go out, not from discovery, so the moment notices are sent is the moment that date should go on a calendar with a named owner against it.

  • Substitute notice is available only on the statutory thresholds: notice costs exceeding $250,000, an affected class exceeding 500,000 people, or insufficient contact information. Most agencies will never reach any of the three, so plan on written or electronic notice.
  • For more than 500 California residents, submit a single sample copy of the notice, stripped of personally identifiable information, to the Attorney General electronically within 15 calendar days of notifying consumers.
  • Diary that date the moment consumer notices go out, and give it an owner by name rather than by role.
  • If you used a delay, document the basis at the time rather than reconstructing it later. The law enforcement delay requires a law enforcement agency to determine that notice would impede a criminal investigation. The scope and integrity delay is yours to invoke, but only on facts you can show.

What Makes This Hard to Run Internally?

Limitations: The procedure above is not technically difficult, and that is precisely why agencies underestimate it. It runs once every several years, under pressure, using people who are already busy delivering care. What we see fail is never the knowledge. It is that nobody recorded the discovery date, so a deadline that was actually met cannot be evidenced. It is the Attorney General filing missed because everyone assumed both clocks ran from discovery. And it is twelve months of identity theft services offered reflexively on a breach that never required them, which is a real and avoidable cost paid for a misreading of the statute. Those are rehearsal failures rather than understanding failures, and rehearsal is the item that never gets scheduled.

3. How Does IT Total Care Help Agencies Meet California’s 30-Day Breach Notification Deadline?

IT Total Care supplies the parts of this that have to exist before an incident: the monitoring that produces a defensible discovery timestamp, the reconstruction that tells you what was actually exposed, and the evidence that supports whichever position you take. The determinations stay with the agency, because the breach determination and the notification decision are legal calls an IT provider cannot make on your behalf. What we can do is make sure those calls rest on facts rather than recollection.

What Does Breach Readiness Support Include?

Our breach readiness process includes:

  • Defensible discovery timestamps: Monitoring that records when an indicator first appeared and when it was first seen, so the start of your 30-day clock is a log entry rather than somebody’s memory of a Friday afternoon.
  • Encryption evidence: Documentation of whether the affected data was encrypted at the time and whether keys or credentials were also taken, since the statutory trigger turns on unencrypted personal information.
  • Rehearsed response: Breach response exercised against both the 30-day consumer deadline and the 15-day Attorney General window, rather than written once and filed where nobody has read it.

“Breaches are everyone’s nightmare for a number of reasons. What determines if the nightmare is brief or drawn out is whether or not a rehearsed plan is in place. I would only trust California providers who are intimately familiar with home care, home health, and home hospice to build this plan.”

Brendan Duebner, President, IT Total Care

Ready to Make Your 30-Day Clock Defensible?

IT Total Care works with home care, home health, and home hospice agencies throughout the San Francisco Bay Area, from Santa Clara County to the East Bay, building the monitoring and documentation that a notification deadline actually rests on. Our breach detection and notification readiness for home-based care agencies covers discovery timestamping, scope reconstruction, encryption evidence, and response rehearsal. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.

Leave a Comment

Your email address will not be published. Required fields are marked *