Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

California Breach Notification Compliance

Civil Code §1798.82 & Health & Safety Code §1280.15 — California’s Stricter Breach Notification Requirements

lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned

WHAT IS CALIFORNIA BREACH NOTIFICATION LAW?

California’s breach notification standard is stricter, faster, and broader than federal law.

California was the first state in the nation to enact a data breach notification law, and its requirements remain among the most demanding in the United States. For Sacramento businesses in healthcare, legal, and financial services, California’s breach notification framework imposes timelines, content requirements, and notification recipients that go beyond — and in some cases conflict with — the federal standards they already track under HIPAA, GLBA, and FTC rules.

Two primary California statutes govern breach notification obligations: Civil Code §1798.82, which applies to any business that owns or licenses personal information of California residents, and Health & Safety Code §1280.15, which applies specifically to licensed healthcare facilities and imposes an even tighter notification timeline to state regulators. Understanding which law applies — and when — is a threshold compliance obligation for every LBT client.

First

state breach notification law in the US

"Most expedient time possible"

notification standard

15

business days for healthcare to notify CDPH

500+

records triggers media notification requirement

WHO MUST COMPLY

Broader than most businesses realize.

Civil Code §1798.82 applies to any business — regardless of size, industry, or location — that owns, licenses, or maintains computerized personal information about California residents. The law does not require the business to be headquartered in California. If you hold personal information about a California resident, you are subject to the notification obligation when that data is breached.

Statute

Who It Covers & When It Applies

Civil Code §1798.82

Any business owning or licensing computerized personal information of California residents. Applies to healthcare, legal, financial, and all other industries. Triggered by unauthorized acquisition of unencrypted personal information.

Health & Safety Code §1280.15

Licensed healthcare facilities, clinics, home health agencies, and their contractors. Triggered by unlawful or unauthorized access to, or use or disclosure of, patient medical information. Imposes 15-business-day notification to CDPH.

Civil Code §1798.29

State agencies that own or license computerized personal information — same notification obligations as §1798.82.

CPRA (Civil Code §1798.150)

Adds a private right of action for breaches of unencrypted, unredacted personal information resulting from failure to implement reasonable security. Statutory damages $100–$750 per consumer per incident.

WHAT COUNTS AS A BREACH

The California definition is broader than HIPAA’s ‘breach’ standard.

California Civil Code §1798.82 defines a breach as the unauthorized acquisition of computerized personal information that compromises the security, confidentiality, or integrity of the data. Unlike HIPAA’s breach definition — which requires a risk assessment to determine whether a presumption of breach applies — California’s standard is triggered more directly by unauthorized access, without the same harm threshold analysis.

Personal Information Categories That Trigger Notification

Social Security number

Driver’s license or California identification card number

Financial account number combined with any required security code or password

Medical information — any individually identifiable health information

Health insurance information

Username or email address with password or security question (for online accounts)

Genetic data

Biometric data used for authentication

Tax identification number, passport number, or military identification

Encrypted Data Provides a Safe Harbor — With a Catch

California’s breach notification law provides a safe harbor for encrypted data — notification is not required if the personal information was encrypted and the encryption key was not also acquired. This makes encryption not just a best practice but a direct legal liability mitigation strategy. An LBT-managed environment with properly implemented encryption reduces notification obligations, litigation exposure, and CPPA enforcement risk simultaneously.

NOTIFICATION REQUIREMENTS

What California requires — and how it differs from federal standards.

Requirement

California Standard vs. Federal Comparison

Notification timeline

California: ‘in the most expedient time possible and without unreasonable delay.’ No fixed deadline. In practice, regulators and courts have treated delays beyond 30–45 days as presumptively unreasonable. HIPAA: 60 days from discovery.

Healthcare-specific timeline

Health & Safety Code §1280.15: 15 business days to notify CDPH after detecting unauthorized access to medical information. Significantly faster than HIPAA’s 60-day federal window.

Who must be notified

California: affected individuals; California AG (if 500+ California residents affected); media in the affected area (if 500+ residents in a single county). HIPAA: individuals, HHS, and local media (500+ in a state). GLBA: FTC (500+ affected customers) within 30 days.

Content of notice

California mandates specific content: description of what happened, types of information involved, what the business is doing, what affected individuals can do, contact information, toll-free numbers for major reporting agencies. More prescriptive than HIPAA’s notice requirements.

Notice format

California requires ‘plain language’ written notice. Model form provided by the AG’s office. Electronic notice permitted only if consistent with E-SIGN Act requirements.

Substitute notice

If cost exceeds $250,000, more than 500,000 affected, or insufficient contact information: conspicuous website posting plus statewide media. Threshold lower than HIPAA’s substitute notice provisions.

PENALTIES

Civil, criminal, and private litigation exposure.

CALIFORNIA AG CIVIL PENALTY PER VIOLATION

$2,500 per unintentional $7,500 per intentional violation

The CPPA and California AG can assess penalties per violation — and each affected individual’s record can constitute a separate violation. A breach affecting 1,000 California residents with intentional or reckless conduct carries potential AG exposure of $7.5 million, independent of private litigation.

Enforcement Path

Exposure

California AG enforcement

Civil penalties up to $2,500 (unintentional) or $7,500 (intentional) per violation; injunctive relief; public enforcement action that damages reputation

CPPA enforcement (CPRA §1798.150)

Private right of action: $100–$750 statutory damages per consumer per incident, or actual damages if greater. Class action exposure.

CDPH administrative penalties (healthcare)

Up to $25,000 per patient for unauthorized access to medical information under Health & Safety Code §1280.15

Malpractice / negligence

Delayed or inadequate breach notification supports negligence per se claims; California courts treat notification failures as evidence of unreasonable conduct

Cyber insurance coverage conditions

Many policies require notification within a specified window; failure to meet California’s ‘expedient time’ standard may constitute a breach of policy conditions affecting coverage

HOW LBT BUILDS BREACH NOTIFICATION READINESS

Calibrated to California’s timeline — not the federal default.

Most MSPs build incident response programs around HIPAA’s 60-day federal clock. LBT’s incident response program is calibrated to California’s stricter standards — ensuring clients can meet the CDPH’s 15-business-day requirement and the AG’s ‘most expedient time possible’ standard under Civil Code §1798.82.

✓ California-Calibrated Incident Response Plan

A written incident response plan with detection, containment, assessment, and notification workflows timed to California’s requirements — not the more permissive federal HIPAA or GLBA windows.

✓ 15-Business-Day CDPH Notification Capability

For healthcare clients, LBT’s incident response procedures support delivery of the required CDPH notification within 15 business days of breach discovery — the most demanding timeline in the California stack.

✓ Encryption as Safe Harbor

Full implementation of data encryption at rest and in transit across all managed systems — activating California’s encrypted-data safe harbor and eliminating notification obligations for properly encrypted records even when systems are accessed without authorization.

✓ Breach Scope Assessment & Notification Drafting Support

Rapid forensic assessment of breach scope to determine which California residents are affected, which statutes apply, and what notifications are required — with support drafting AG-compliant plain-language consumer notices.

✓ Media Notification Readiness

For incidents affecting 500+ California residents in a county, preparation of required media notification content and distribution coordination — a requirement many businesses only discover in the middle of an incident.

✓ CPRA Private Right of Action Defense

Documented security program demonstrating ‘reasonable security’ — the CPRA’s private right of action requires plaintiffs to show the breach resulted from failure to implement reasonable security measures. LBT’s program produces that documentation as a byproduct of normal operations.

Is Your Business Breach Notification Ready?

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

BOOK YOUR FREE BREACH NOTIFICATION READINESS ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California

© 2026 LBT Technology Group, LLC · California Breach Notification Law · Sacramento, CA · Confidential

This document is for informational purposes only and does not constitute legal advice.

California Incident Response

California Breach Notification Compliance

Prepare for California’s broader triggers, faster healthcare deadline, prescribed notices, and layered enforcement.

15 daysHealthcare deadline

Business days to notify CDPH

500+AG and media triggers

Depending on affected residents

FirstState notification law

Broad California standard

Why this matters

California’s breach notification standard is stricter, faster, and broader than federal law.

California was the first state in the nation to enact a data breach notification law, and its requirements remain among the most demanding in the United States. For Sacramento businesses in healthcare, legal, and financial services, California’s breach notification framework imposes timelines, content requirements, and notification recipients that go beyond — and in some cases conflict with — the federal standards they already track under HIPAA, GLBA, and FTC rules.

Two primary California statutes govern breach notification obligations: Civil Code §1798.82, which applies to any business that owns or licenses personal information of California residents, and Health & Safety Code §1280.15, which applies specifically to licensed healthcare facilities and imposes an even tighter notification timeline to state regulators. Understanding which law applies — and when — is a threshold compliance obligation for every LBT client.

Who must comply

Broader than most businesses realize.

Civil Code §1798.82 applies to any business — regardless of size, industry, or location — that owns, licenses, or maintains computerized personal information about California residents. The law does not require the business to be headquartered in California. If you hold personal information about a California resident, you are subject to the notification obligation when that data is breached.

Response area 1

Trigger & Statutes

Identify the law, organization, data, and acquisition or access event that controls the response.

Civil Code §1798.82

Any business owning or licensing computerized personal information of California residents. Applies to healthcare, legal, financial, and all other industries. Triggered by unauthorized acquisition of unencrypted personal information.

Health & Safety Code §1280.15

Licensed healthcare facilities, clinics, home health agencies, and their contractors. Triggered by unlawful or unauthorized access to, or use or disclosure of, patient medical information. Imposes 15-business-day notification to CDPH.

Civil Code §1798.29

State agencies that own or license computerized personal information — same notification obligations as §1798.82.

CPRA (Civil Code §1798.150)

Adds a private right of action for breaches of unencrypted, unredacted personal information resulting from failure to implement reasonable security. Statutory damages $100–$750 per consumer per incident.

What counts as a breach

The California definition is broader than HIPAA’s ‘breach’ standard.

01Social Security number
02Driver’s license or California identification card number
03Financial account number combined with any required security code or password
04Medical information — any individually identifiable health information
05Health insurance information
06Username or email address with password or security question (for online accounts)
07Genetic data
08Biometric data used for authentication
09Tax identification number, passport number, or military identification

Penalties and exposure

Civil, criminal, and private litigation exposure.

$2,500 per unintentional $7,500 per intentional violation

The CPPA and California AG can assess penalties per violation — and each affected individual’s record can constitute a separate violation. A breach affecting 1,000 California residents with intentional or reckless conduct carries potential AG exposure of $7.5 million, independent of private litigation.

01California AG enforcement

Civil penalties up to $2,500 (unintentional) or $7,500 (intentional) per violation; injunctive relief; public enforcement action that damages reputation

02CPPA enforcement (CPRA §1798.150)

Private right of action: $100–$750 statutory damages per consumer per incident, or actual damages if greater. Class action exposure.

03CDPH administrative penalties (healthcare)

Up to $25,000 per patient for unauthorized access to medical information under Health & Safety Code §1280.15

04Malpractice / negligence

Delayed or inadequate breach notification supports negligence per se claims; California courts treat notification failures as evidence of unreasonable conduct

05Cyber insurance coverage conditions

Many policies require notification within a specified window; failure to meet California’s ‘expedient time’ standard may constitute a breach of policy conditions affecting coverage

California-calibrated readiness

Calibrated to California’s timeline — not the federal default.

Most MSPs build incident response programs around HIPAA’s 60-day federal clock. LBT’s incident response program is calibrated to California’s stricter standards — ensuring clients can meet the CDPH’s 15-business-day requirement and the AG’s ‘most expedient time possible’ standard under Civil Code §1798.82.

01
California-Calibrated Incident Response Plan

A written incident response plan with detection, containment, assessment, and notification workflows timed to California’s requirements — not the more permissive federal HIPAA or GLBA windows.

02
15-Business-Day CDPH Notification Capability

For healthcare clients, LBT’s incident response procedures support delivery of the required CDPH notification within 15 business days of breach discovery — the most demanding timeline in the California stack.

03
Encryption as Safe Harbor

Full implementation of data encryption at rest and in transit across all managed systems — activating California’s encrypted-data safe harbor and eliminating notification obligations for properly encrypted records even when systems are accessed without authorization.

04
Breach Scope Assessment & Notification Drafting Support

Rapid forensic assessment of breach scope to determine which California residents are affected, which statutes apply, and what notifications are required — with support drafting AG-compliant plain-language consumer notices.

05
Media Notification Readiness

For incidents affecting 500+ California residents in a county, preparation of required media notification content and distribution coordination — a requirement many businesses only discover in the middle of an incident.

06
CPRA Private Right of Action Defense

Documented security program demonstrating ‘reasonable security’ — the CPRA’s private right of action requires plaintiffs to show the breach resulted from failure to implement reasonable security measures. LBT’s program produces that documentation as a byproduct of normal operations.

Next step

Prepare the response before California’s notification clocks begin.

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

This document is for informational purposes only and does not constitute legal advice.