On December 29, 2025, an Oakland dental practice filed a breach notice with the California Attorney General, who published it under the heading "Misconfigured system exposing sensitive data." The notice states that the practice uses HIPAA-compliant and secure platforms.
That last detail is worth pausing on, because in California it answers a narrower question than most practice owners assume.
Dental IT support in San Francisco and Oakland carries a state-specific exposure that most practice owners have never had explained to them. Every compliance conversation in dentistry runs through HIPAA, and California’s breach-notification statute does give covered entities a limited safe harbor. But California regulates patient records under a second statute that HIPAA does not switch off, that contains no safe harbor of any kind, and that lets patients sue the practice directly without proving they were harmed.
Medix Dental IT has spent more than 20 years working exclusively in dental, supporting single-doctor offices through multi-location dental groups. That focus is why we read the California statutes the way a defense attorney would rather than the way a compliance checklist does.
California Regulates Your Records Twice, and Only One of Them Has a Safe Harbor
Most practice owners know California Civil Code § 1798.82, the breach-notification statute, by its effects rather than its number. As amended by SB 446, effective January 1, 2026, it requires notice within 30 calendar days of discovery. That deadline is new, and summaries written before 2026 stating that California has no fixed deadline are now out of date.
That statute does contain a HIPAA accommodation, and it is narrower than it looks. Under § 1798.82(e), a covered entity that complied with the federal notice rules is deemed to have complied with subdivision (d), which governs what the notice letter says and how it is formatted. The same sentence then adds that "nothing in this subdivision shall be construed to exempt a covered entity from any other provision of this section."
Here is the part that changes the analysis. A dentist is licensed under Division 2 of the Business and Professions Code, which makes a dental practice a "provider of health care" as defined in Civil Code § 56.05. That places the practice directly under the Confidentiality of Medical Information Act, California’s own medical-records law.
The CMIA contains no HIPAA safe harbor. Not a conditional one, not a scoped one. The breach statute has one at § 1798.82(e). The reasonable-security statute has one at § 1798.81.5(e). The California Consumer Privacy Act has one at § 1798.145(c). The CMIA has none, and it has been running in parallel the entire time.
That is the practical difference for a California practice as we read it, though how it applies to your situation is a question for your attorney rather than for us. As the statute is written, § 56.36(b)(1) provides that a patient whose records were negligently released may recover $1,000 in nominal damages without proving any actual damage, and § 56.36(c)(1) provides for a fine or civil penalty of up to $2,500 per violation for negligent disclosure. Both are written as private and administrative remedies rather than as something a regulator must first initiate.
The State Already Wrote the Checklist You Will Be Graded Against
There is a defense, and it is unusually specific. Section 56.36(e)(2) gives a covered entity an affirmative defense that removes those nominal damages. It is not a general reasonableness standard, and it is not something an attorney can assemble after the fact.
The defense has nine elements, labeled (A) through (I), and the statute requires all of them to be established. Several concern the incident itself and are outside anyone’s control once it happens. Element (C) requires that the release was solely to another covered entity or business associate, so the defense is unavailable in an ordinary exposure to the public or to an attacker. Element (D) requires that it was not an incident of medical identity theft.
Element (E) is the one that belongs to your IT program. It requires that the practice took appropriate preventive actions consistent with its obligations, "including, but not limited to," all of the following:
- (i) Developing and implementing security policies and procedures.
- (ii) Designating a security official who is responsible for developing and implementing those policies and procedures, including educating and training the workforce.
- (iii) Encrypting the information or records, and protecting against the release or use of the encryption key and passwords, or transmitting the records in a manner designed to provide equal or greater protections.
Read that as an operations document rather than a legal one. A written policy set. A named person accountable for it and for training the team. Encryption that covers the keys and passwords, not only the drive. Those are three infrastructure decisions, and the statute asks whether you made them before the incident. Elements (F) and (H) then ask what you did after, requiring documented corrective action and reasonable steps to prevent a similar release.
Nothing on that list can be produced retroactively. A practice that adopts a policy set the week after a release has not satisfied element (E), because element (E) asks about the posture that existed at the time. The state has already published the criteria, and each one is either a document you have or a document you do not.
The Oakland filing is a useful illustration precisely because it describes a small, ordinary mistake, self-reported and corrected quickly. According to that notice, a year-end reminder about using insurance benefits went out with an attachment containing a list of active patients, exposing names, dates of birth, phone numbers, and email addresses, with no Social Security numbers, financial information, insurance IDs, or clinical records.
The point is not what that office did. It is that § 56.36(e)(2) would ask any practice in that position for dated answers: whether a security official had been designated, what the written policies said, and whether either can be evidenced. We are an IT company and not a law firm, so we will not tell you how such an analysis comes out. But those answers tend to be determined years earlier, by decisions that looked at the time like ordinary IT housekeeping. A cybersecurity assessment is worth running for one reason above all: it tells you in writing, and in advance, which of those nine answers you can currently support.
California also makes this visible. The Attorney General publishes submitted breach notices, including the letters themselves, which is how the December filing above can still be read today.
What Bay Area Practices Actually Get From Us
California is an unusual market. Only 11.45% of California dentists are affiliated with a dental support organization, well below the national rate of 16.07%, according to the ADA Health Policy Institute. The San Francisco-Oakland-Fremont metro holds 3,029 dental offices according to Census County Business Patterns, and most are independently owned. There is no corporate compliance department standing behind element (E). The owner is, usually while also seeing patients.
- Enterprise-grade cybersecurity. Managed detection and response, identity governance, and tenant-level monitoring in Microsoft 365 or Google Workspace. Microsoft Research found multifactor authentication reduces the risk of account compromise by 99.22% across the population it studied, and in California that control also sits inside element (E)(iii). Boring is cheaper than chaos.
- Encryption and key management that satisfies a written standard, covering records at rest and in transit, with the keys and passwords protected separately, because § 56.36(e)(2)(E)(iii) treats those as part of the same requirement.
- Backup and disaster recovery built for a region that plans around earthquakes and public safety power shutoffs, and tested on a schedule. See our approach to dental data backup and recovery.
- Dental software expertise across Dentrix, Eaglesoft, and Open Dental, including Open Dental in the cloud.
- Documentation your defense would actually rest on: a named security official, a current policy set, training records, and dated evidence of corrective action.
- IT KPI reporting on uptime, multifactor adoption, endpoint compliance, and backup health, so the posture is visible before anyone needs to prove it.
We support practices across San Francisco, Oakland, Berkeley, Fremont, Hayward, Daly City, San Mateo, Redwood City, Walnut Creek, Concord, Richmond, Alameda, San Rafael, and Half Moon Bay.
If you want the fuller picture of how we structure this for growing groups, the DSO tech playbook covers it. Otherwise, contact us and we will tell you plainly where your current documentation stands.
San Francisco and Oakland Dental IT Support FAQs
What areas around San Francisco and Oakland does Medix Dental IT support?
We support practices throughout the San Francisco-Oakland-Fremont metro, covering Alameda, Contra Costa, San Francisco, San Mateo, and Marin counties: San Francisco, Oakland, Berkeley, Fremont, Hayward, Daly City, San Mateo, Redwood City, Walnut Creek, Concord, Richmond, Alameda, San Rafael, and Half Moon Bay. San Jose sits in a separate metropolitan area, and we support practices there as well.
We follow HIPAA. Is that enough in California?
Not by itself, as we read the statutes. HIPAA compliance earns a limited accommodation under California’s breach-notification law: § 1798.82(e) deems you compliant with the rules governing what your notice letter says, and that same sentence preserves every other obligation in the section. Separately, the Confidentiality of Medical Information Act applies to your practice on its own terms and contains no HIPAA safe harbor at all. Whether that changes anything in your particular situation is a question for your attorney.
Can a patient sue our practice directly over a data breach in California?
As the statute is written, Civil Code § 56.36(b) allows an individual to bring an action for negligent release of confidential medical information, and § 56.36(b)(1) provides for $1,000 in nominal damages without the patient having to show actual damages. As we read it, that is a different kind of exposure from a regulatory penalty, because it is not written to depend on an agency deciding to act, though whether it applies to any given incident is a question for your attorney. Note separately that the California Consumer Privacy Act’s private right of action generally does not reach patient records, because § 1798.145(c)(1)(B) excludes a provider of health care governed by the CMIA, though only "to the extent" it maintains that information as medical or protected health information.
What does the CMIA affirmative defense actually require from our IT setup?
Section 56.36(e)(2) lists nine elements, (A) through (I), all of which must be established. Element (E) is the infrastructure one: developing and implementing security policies and procedures, designating a security official responsible for those policies and for training the workforce, and encrypting records while protecting the encryption keys and passwords. Elements (F) and (H) add documented corrective action and steps to prevent a similar release. None of it can be assembled after an incident, which is why we treat it as ordinary operational work rather than legal work.
How quickly do we have to notify patients after a breach in California?
Under § 1798.82(a)(2)(A), disclosure must be made within 30 calendar days of discovery or notification, subject to a delay for law enforcement or to determine the scope of the breach and restore system integrity. That 30-day deadline took effect January 1, 2026 under SB 446, so older guidance stating that California has no fixed deadline is out of date. If more than 500 California residents are affected, § 1798.82(f) also requires submitting a sample copy of the notice to the Attorney General within 15 days of notifying consumers.
What dental software does your San Francisco and Oakland team support?
We work across the systems Bay Area practices actually run, including Dentrix, Eaglesoft, and Open Dental, plus the imaging and practice-management integrations attached to them. For practices moving off a server in a closet, we deploy Open Dental in a hosted environment with encryption and key handling documented, which in California matters for reasons beyond uptime.
Posted in Service Areas