California’s breach notification rules just became more demanding for healthcare organizations. This post looks at SB 446 through the lens of real breach trends and hands-on compliance experience. It’s meant to help leaders see what’s changed and why it matters now.
Table of contents
Why Healthcare Data Breaches Continue to Escalate
We recently wrote about healthcare data breaches, noting the rapid increase in incidents and the exponential growth in the number of individuals whose protected health information was exposed. Just to remind everyone about a few findings in the analysis:
- The majority of Hacking/IT Incidents involved email or network servers. Both of these categories increased by about 50% between 2023 and 2024.
- Hacking/IT incidents at healthcare providers affected 55 million and 48 million people in 2023 and 2024, respectively. Hacking/IT incidents accounted for the overwhelming majority (99% and 95%) of reported healthcare data breaches in both years.
- Healthcare data breaches were reported by 468 providers in 2023 and 538 in 2024.
So there is little dispute about the seriousness of the problem. Now the State of California has stepped into the breach (so to speak) with Senate Bill 446. This is a new law on customer notification requirements following a security breach of personal information maintained by a business or individual doing business in California.
A Summary of Senate Bill 446 Requirements
The first paragraph of the new law lays out the fundamental duty of businesses and individuals (an entity or entities) who conduct business in California: a breach in the security of unencrypted personal information data of a California resident must be disclosed if there is reason to believe an unauthorized person has acquired the data.
Disclosure of a breach must occur within 30 days of discovery or notification of the breach, unless law enforcement requests a delay. Notification may be in writing, electronically, or by a substitute notice.
There is a specific format the business or individual must utilize when notifying affected individuals. A HIPAA Covered Entity is deemed to comply with AB446 as long as it complies with the content of notifications required by the HITECH Act breach notification regulations. The California Attorney General must receive a sample copy of a breach notification notice within 15 days of notifying affected consumers if the breach affects more than 500 California residents.
Of course, there are several other provisions about notifying consumers, data ownership or leasing, encryption keys, and reasonable belief, but that is the gist of the law.
Definitions in SB 446
The law includes several definitions to clarify to whom it applies and what the terms used in law include.
- “Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or business. It does not include the acquisition of information by agents or employees of the business or an individual, provided they are acting in good faith, and the data is not used or further unauthorized disclosed.
- Personal Information means an individual’s first name (or initial) plus last name and one or more of the following unencrypted data elements:
- Social security number.
- Driver’s license number, tax ID number, or one of several other identification numbers, e.g., passport number.
- Account number, debit or credit card number, plus a security code, access code, or password that would permit access to an individual’s financial account(s).
- Medical Information (including medical history, mental or physical condition, medical treatment or diagnosis by a health care professional).
- Health Insurance Information (identification number, application information, claims history or appeals records)
- Unique biometric data.
- Automated license plate recognition system data.
- Genetic data.
- An individual’s user name or email address, in combination with a password or security question and answer that would permit access to an online account.
Note that the definition of medical information in California SB446 is not synonymous with the definition of Protected Health Information (PHI) in the HIPAA regulations. PHI also includes information related to the past, present, or future payment for the provision of health care to the individual. So there may be situations where notifying affected individuals may be required under HIPAA, but not under SB446.
California Breach Notification Requirements
SB446 specifies the elements of a 30-day breach notification to affected California residents. The law requires that the text be no smaller than 10-point type. These elements include information displayed under specific headings; some sub-elements are optional.
- The notice must be written in plain language with a title of “Notice of Data Breach”. It must include the name and contact information of the business or individual reporting the security breach, and the date of the notice.
- What Happened?
- A general description of the breach incident, or at least what is known as of the date of notifying affected individuals.
- The date (or estimated date or date range) the breach occurred.
- What Information was Involved?
- What types of personal information were, or are reasonably believed to be, the subject of a breach.
- What Are We Doing?
- Whether the notification was delayed as a result of a law enforcement investigation, if that information is possible to determine at the time the notice is provided.
- What the business or individual is doing to protect individuals whose information has been breached (optional).
- What Can You Do?
- If an individual or business is the source of the breach, the notice requirements include offering to provide identity theft prevention and mitigation services for breaches involving social security numbers, driver’s license numbers, or other identifying numbers.
- Advice on steps individuals can take to protect themselves (optional)
- For breaches of biometric data, advice on how to notify other entities that rely on biometric data for authentication that the biometric data may have been compromised (optional)
- For More Information:
The law contains a format for a table of the elements, which, if used, would be deemed to be in compliance with the law.
Notification Methods Under AB446
Notification procedures under AB446 include three options.
- Written notice. The law is not specific about the method of delivery, e.g., by US Mail, in person, etc.
- Electronic notice. Electronically submitting the notice to affected consumers requires consumer consent in accordance with 15 US Code Section 7001. Many businesses or individuals compiling personal information on customers in data systems may not have obtained such consent in advance of a data breach.
- Substitute notice requirements. A business or individual may utilize a substitute notice if they can demonstrate (a) the cost of the notice would exceed $250,000, or (b) the affected California residents to be notified exceeds 500,000 persons, or (c) the entity does not have sufficient contact information. Substitute notice terms. If a substitute notice is used, there are 3 methods allowed: email (if the entity has email addresses), posting on the entity’s website home page, or notification using major statewide media.
Other Special Breach Notification Requirements
There are three other special security breach notification provisions.
- When a breach only involves the use of an email address and password to access an online account, the notification can be provided by email advising the individual to change their password and security question answers.
- When a breach only involves the use of login credentials to an email address furnished by the entity, notification should be provided by another notification method, unless it is delivered to the individual when they are online from the IP address the entity knows the individual customarily uses to access the account.
- If a business or individual maintains its own notification procedures as part of an information security policy, and the procedures are otherwise consistent with the timing requirements of SB446, an entity may follow its own procedures and be in compliance with the law.
What Should HIPAA Covered Entities Do Now?
Certainly, California Covered Entities serving California residents should be reviewing their breach notification policies and incorporating the provisions of SB 446 into the policies. A few differences to review:
One of the biggest takeaways is to recognize that California law expects prompt notification of breaches even when information about a company breach is incomplete. Many Covered Entities delay notifying individuals about breaches while they investigate the incident. Those delayed notifications may be viewed very dimly by the California Attorney General in the future.
Our experience as HIPAA Privacy Officers both inside and outside of California makes us well-positioned to help California Covered Entities review and revise their breach notification procedures. Let us know how we can help!
