Capture
Record incident metadata — discovery time, role, data types, encryption, estimated impact, and states — without collecting patient names or raw PHI.
AI-Powered Incident & Breach Response Purpose-Built for Healthcare
BreachClock helps healthcare teams assess potential breaches, coordinate response tasks, and track notification obligations and deadlines—all in one documented matter.
Built for security, privacy, compliance, and legal teams.
BreachClock · Overview
Scroll to see more
Active matters, upcoming deadlines, and work that still needs a decision.
6
Non-closed matters
3
Current open tasks, all dates
1
Unsatisfied accepted clocks past due
2
Draft or under review
Derived stages for non-closed matters. Each matter is counted once. Not a completion percentage.
Dates shown in America/New York.
Overdue first, oldest due date first. Then future accepted dates.
Proposed clocks only. These dates are not accepted.
Linked notice recorded sent. Stored obligation status is still accepted or overridden.
Approved is not sent. Canceled records are omitted. 1 overdue unsent.
Overdue unsent 1
Action list of unsatisfied accepted clocks, oldest due date first. Proposed dates are listed separately and are not accepted. Times in America/New York.
| Obligation | Due | Status |
|---|---|---|
Notify California Attorney General (overdue accepted) MC-00006 Demonstration | Sep 10, 2026, 11:59 PM America/New York | Overdue |
Notify covered entity / customer (due in 7 days) MC-00005 Demonstration | Sep 23, 2026, 11:59 PM America/New York | Accepted |
Notify affected individuals (due in 8–30 days) MC-00006 Demonstration | Oct 3, 2026, 11:59 PM America/New York | Accepted |
Awaiting deadline reviewProposed clocks only. Dates are not accepted deadlines. | ||
Notify California Attorney General (demonstration) MC-00001 Demonstration | Oct 4, 2026, 11:59 PM America/New York | Proposed |
Notify HHS Secretary (demonstration) MC-00001 Demonstration | Nov 18, 2026, 11:59 PM America/New York | Proposed |
Researched versions stay tests-complete until a human records an overlay. Federal HIPAA is separate from the 51-jurisdiction count.
51 / 51
51 / 51
51 / 51
0 / 51
0 / 51
Counsel approved
Counsel. Not counted in the 51.
Self-serve signup, Stripe billing, invite-only members, authenticator MFA, and in-app support.
Essentials trial
Stripe checkout and customer portal
Invite-only
Work-email invites, no shared temp passwords
Authenticator MFA
Optional org-wide requirement
Tickets open
FAQs and documentation in-app
A potential breach is more than a ticket. It is a set of clocks, owners, and decisions. BreachClock keeps those in one matter.
Record incident metadata — discovery time, role, data types, encryption, estimated impact, and states — without collecting patient names or raw PHI.
A deterministic rule engine evaluates structured facts against versioned demonstration rules and proposes notification obligations with due dates.
Privacy officers accept, override, or add manual obligations. Tasks, rationales, and an append-only timeline keep the response trail intact.
BreachClock does not ask a model to invent legal deadlines. It evaluates typed facts against approved rule versions and shows the work.
01
Discovery date, timezone, organization role, encryption status, estimated affected count, and jurisdictions.
02
Rule version, input snapshot, explanation, calculation date, and a proposed due date in calendar or business days.
03
An authorized user accepts the calculated clock or overrides it with a required reason. Prior calculations stay in history.
BreachClock is decision support. It tracks proposed clocks and recorded judgments. It does not replace counsel or make a final legal determination.
Engine proposes
Approved demonstration rules match facts and produce a proposed obligation with a calculated due date.
Officer reviews
Nothing is treated as the working deadline until a privacy officer or organization admin accepts or overrides it.
Trail is preserved
Recalculation, acceptance, override reasons, tasks, and decisions stay on an append-only timeline and print report.
Access controls, tenant isolation, and server-side authorization are part of the product — not a later overlay. Hiding a button is not authorization.
Enter incident metadata only. Do not enter patient names, medical record numbers, or other raw PHI. BreachClock is not a HIPAA compliance certification.
Read the Trust Center for current controls, planned work, and how to request restricted materials.
Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.
Self-serve trial. No local seed account required.
Cookies
We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.