AI-Powered Incident & Breach Response Purpose-Built for Healthcare

Know what to do. Know when it’s due.

BreachClock helps healthcare teams assess potential breaches, coordinate response tasks, and track notification obligations and deadlines—all in one documented matter.

Built for security, privacy, compliance, and legal teams.

BreachClock · Overview

Scroll to see more

Overview

Active matters, upcoming deadlines, and work that still needs a decision.

New matter
Active matters

6

Non-closed matters

Open tasks

3

Current open tasks, all dates

Overdue obligations

1

Unsatisfied accepted clocks past due

Needs review

2

Draft or under review

Task progress
7 days30 days90 days

Denominator: 6 tasks on non-closed matters created or completed in the last 30 days. Each task is counted once.

Completions by day — discrete counts, not a fitted trend. 2 completion days.

  • 2026-09-021
  • 2026-09-181
Notification pipeline

Approved is not sent. Canceled records are omitted. 1 overdue unsent.

Overdue unsent 1

Upcoming deadlines

Action list of unsatisfied accepted clocks, oldest due date first. Proposed dates are listed separately and are not accepted. Times in America/New York.

ObligationDueStatus

Notify California Attorney General (overdue accepted)

MC-00006

Demonstration

Sep 10, 2026, 11:59 PM

America/New York

Overdue

Notify covered entity / customer (due in 7 days)

MC-00005

Demonstration

Sep 23, 2026, 11:59 PM

America/New York

Accepted

Notify affected individuals (due in 8–30 days)

MC-00006

Demonstration

Oct 3, 2026, 11:59 PM

America/New York

Accepted

Awaiting deadline review

Proposed clocks only. Dates are not accepted deadlines.

Notify California Attorney General (demonstration)

MC-00001

Demonstration

Oct 4, 2026, 11:59 PM

America/New York

Proposed

Notify HHS Secretary (demonstration)

MC-00001

Demonstration

Nov 18, 2026, 11:59 PM

America/New York

Proposed

Rule library

Researched versions stay tests-complete until a human records an overlay. Federal HIPAA is separate from the 51-jurisdiction count.

Jurisdictions researched / 51

51 / 51

Implemented rules / 51

51 / 51

Tests complete / 51

51 / 51

Internally reviewed / 51

0 / 51

Counsel approved for operational matching / 51

0 / 51

Federal HIPAA

Counsel approved

Counsel. Not counted in the 51.

Rules approved for operational matching
  • HIPAA-IND-2013 — Individual notice to affected individuals

Workspace

Self-serve signup, Stripe billing, invite-only members, authenticator MFA, and in-app support.

Billing

Essentials trial

Stripe checkout and customer portal

Members

Invite-only

Work-email invites, no shared temp passwords

Security

Authenticator MFA

Optional org-wide requirement

Support

Tickets open

FAQs and documentation in-app

Built for the clocks that start after discovery.

Covered entityBusiness associateVendorPotential PHI incidentHHS notification clockState AG noticeIndividual noticeBAA / contract deadline

From incident facts to a reviewable deadline register.

A potential breach is more than a ticket. It is a set of clocks, owners, and decisions. BreachClock keeps those in one matter.

Capture

Record incident metadata — discovery time, role, data types, encryption, estimated impact, and states — without collecting patient names or raw PHI.

Propose

A deterministic rule engine evaluates structured facts against versioned demonstration rules and proposes notification obligations with due dates.

Decide

Privacy officers accept, override, or add manual obligations. Tasks, rationales, and an append-only timeline keep the response trail intact.

Turn structured facts into clocks your team can review.

BreachClock does not ask a model to invent legal deadlines. It evaluates typed facts against approved rule versions and shows the work.

01

Matter facts

Discovery date, timezone, organization role, encryption status, estimated affected count, and jurisdictions.

02

Proposed obligations

Rule version, input snapshot, explanation, calculation date, and a proposed due date in calendar or business days.

03

Accepted or overridden

An authorized user accepts the calculated clock or overrides it with a required reason. Prior calculations stay in history.

The engine proposes. Your team decides.

BreachClock is decision support. It tracks proposed clocks and recorded judgments. It does not replace counsel or make a final legal determination.

  1. 1

    Engine proposes

    Approved demonstration rules match facts and produce a proposed obligation with a calculated due date.

  2. 2

    Officer reviews

    Nothing is treated as the working deadline until a privacy officer or organization admin accepts or overrides it.

  3. 3

    Trail is preserved

    Recalculation, acceptance, override reasons, tasks, and decisions stay on an append-only timeline and print report.

Incident metadata is sensitive. BreachClock treats it that way.

Access controls, tenant isolation, and server-side authorization are part of the product — not a later overlay. Hiding a button is not authorization.

Enter incident metadata only. Do not enter patient names, medical record numbers, or other raw PHI. BreachClock is not a HIPAA compliance certification.

  • Tenant-isolated organization data
  • Row-level security on matter records
  • Role-based permissions on the server
  • No service-role key in the browser
  • Incident metadata only — not patient records
  • No raw PHI fields in the data model
  • Validated mutations on the server
  • Append-only activity timeline
  • Sensitive request bodies are not logged
  • Hosted on Vercel with tenant-isolated Supabase data

Read the Trust Center for current controls, planned work, and how to request restricted materials.

Stop tracking breach clocks in a spreadsheet.

Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.

Self-serve trial. No local seed account required.

Cookies

We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.