NEXUSBY CYBERCHAIN TECHNOLOGIES
DEMONSTRATION ENVIRONMENTLAKEVIEW GENERAL HOSPITALSYNTHETIC DATA ONLYNOT FOR PHIFictional hospital · real Nexus governance logic
Prospect path · California

Nexus for a California health system

California layers CMIA, the Attorney General breach-notice regime, and CDPH facility reporting on top of HIPAA. This path walks what a California CIO, CISO, privacy officer, or compliance lead sees in Nexus: the California breach picture (real records), the regulatory stack (reference, not legal advice), the readiness controls each obligation touches, which AI may touch medical information, and the receipt that proves it.

3California records
18,247,267Affected (published counts)
2Tracking disclosures
WHAT IS REAL AND WHAT IS SYNTHETIC ON THIS PATHThe California breach records and regulatory references are real and sourced (verified 2026-09-10). The assessment, models, decisions, and receipts are the synthetic Lakeview demonstration; Lakeview is an Ontario hospital, so its computed applicability is Canadian — California control mappings below are editorial.

1 · California breach trend · FACT

Computed from the California records in the Nexus store — a curated set, not the full Attorney General list.

OrganizationAffectedData (jurisdiction term)TypeDisclosedSource
Kaiser Foundation Health PlanHealth plan / insurer13,400,000PHIprotected health information (HIPAA) · medical information (CMIA)Unauthorized access / disclosure2024-04HHS OCR breach portal (Kaiser Foundation Health Plan, Inc.)registry listed · 2026-09-10
Blue Shield of CaliforniaHealth plan / insurer4,700,000PHIprotected health information (HIPAA) · medical information (CMIA)Unauthorized access / disclosure2025-04-09HIPAA Journal — Blue Shield of California impermissible disclosure to Google Ads (secondary)source verified · 2026-09-10
Scripps HealthHealth system147,267PII + PHIprotected health information (HIPAA) · medical information (CMIA / H&S § 1280.15)Ransomware2021-06HIPAA Journal — Scripps Health ransomware attack notifications (secondary)source verified · 2026-09-10

Open the California executive view with filters →

2 · Nexus analysis · INFERENCE

NEXUS ANALYSIS · INFERENCE

2 of 3 California records are disclosures through analytics or advertising tags — no attacker, no perimeter failure. Under CMIA the advertising or analytics vendor is a contractor holding medical information; under HIPAA it is a business-associate question; under § 1798.82 it is a notice to residents and the Attorney General. Ransomware records (1) add the CDPH 15-business-day clock for licensed facilities. The common thread is not the attack — it is knowing which systems and vendors hold medical information before anything happens.

3 · The California stack · reference

Confidentiality of Medical Information Act (CMIA)

California Civil Code § 56 et seq.

Term: medical information

State medical-privacy statute that applies to providers, health plans, contractors, and businesses organized to maintain medical information — broader than HIPAA's covered-entity model.

Source ↗verified 2026-09-10

California breach-notification law with Attorney General sample notice

California Civil Code § 1798.82 (and § 1798.29 for agencies)

Term: personal information (includes medical information and health insurance information)

Requires notice to affected California residents and, when more than 500 residents are affected, submission of a sample notice to the Attorney General, who publishes the breach list.

Source ↗verified 2026-09-10

Health facility breach reporting to CDPH

California Health & Safety Code § 1280.15

Term: medical information (unlawful or unauthorized access, use, or disclosure)

Licensed clinics, health facilities, home health agencies, and hospices must report unlawful or unauthorized access to, or use or disclosure of, a patient's medical information to CDPH and the affected patient within 15 business days of detection; CDPH may assess administrative penalties.

Source ↗verified 2026-09-10

California Consumer Privacy Act as amended by the CPRA

California Civil Code § 1798.100 et seq.

Term: personal information; sensitive personal information

Consumer privacy law with exemptions for medical information governed by CMIA and protected health information governed by HIPAA — but which still reaches non-exempt data such as website, marketing, and workforce information held by covered businesses.

Source ↗verified 2026-09-10

HIPAA Privacy, Security, and Breach Notification Rules (federal)

45 CFR Parts 160 and 164

Term: protected health information (PHI)

Applies alongside the California instruments; a California breach of PHI affecting 500+ individuals is reported to HHS OCR and listed on the federal breach portal.

Source ↗verified 2026-09-10

4 · Readiness controls each obligation touches · editorial mapping

Each obligation maps to controls in the Nexus healthcare question bank. Open a control to see how it is asked, scored, and evidenced in the synthetic assessment.

ObligationGovernance domainsControlsRecommended action
Two notification clocks: CDPH 15 business days (licensed facilities) and HIPAA 60 days; AG sample notice above 500 residents.Incident response · Incident notification · Breach assessmentSEC-03 · securityPRIV-03 · privacyPut the CDPH clock, the AG filing threshold, and the HHS clock into one incident runbook with named owners; rehearse it with a tabletop that includes an AI or vendor-originated incident.
Tracking technologies on member and patient web properties disclose medical information without an attacker (Kaiser 2024, Blue Shield of California 2025).Web and app governance · Consent · Third-party data accessPRIV-01 · privacyPRIV-02 · privacyVEN-03 · vendor_lifecycleInventory analytics and advertising tags on patient-facing properties, confirm what each transmits, and treat each vendor as a CMIA contractor with terms to match.
CMIA reaches contractors and technology vendors holding medical information; HIPAA requires business-associate agreements.Vendor risk management · Third-party AI and data access · Data residencyVEN-01 · vendor_lifecycleVEN-02 · vendor_lifecycleDATA-01 · privacyList every vendor and AI tool processing medical information, confirm the agreement in place, and record where the data is hosted and by which sub-processors.
§ 1280.15 counts unauthorized access by workforce members — snooping is reportable.Access controls · Audit logging · Workforce trainingSEC-04 · securityCLIN-04 · clinicalGOV-05 · governanceVerify role-based access and audit logging on the record system, and that staff training names snooping as a reportable breach.

11 distinct controls referenced.

5 · Which AI may touch medical information · synthetic, real evaluator

The same rule a California organization needs under CMIA and HIPAA: PHI and medical information go only to models running inside infrastructure you control. The evaluator says so deterministically.

  • Sovereign clinical modelALLOWELIGIBLE_OK
  • ?
    Sovereign general modelREVIEW REQUIREDWORKLOAD_NOT_APPROVED · EVALUATION_UNAVAILABLE
  • External cloud assistantBLOCKPHI_REQUIRES_SOVEREIGN_EXECUTION · CLASSIFICATION_NOT_ALLOWED
  • Research red-team modelBLOCKHIGH_RISK_RESEARCH_ONLY · PUBLIC_DATA_ONLY · CAPABILITY_NOT_SUPPORTED

Full eligibility matrix →

6 · The receipt an auditor accepts · synthetic

A clinician asked an external cloud model to summarize a chart. Blocked, reason-coded, redirected to a sovereign model, sealed in a verified chain. Open receipt DEMO-RCPT-0001

COVERAGE AND LIMITS
  • California records come from HHS OCR listings and organization notices; the California Attorney General breach list (oag.ca.gov) is cited as a registry but is not yet ingested automatically, so California coverage is incomplete.
  • CDPH § 1280.15 reports are not published as a searchable registry; CDPH enforcement actions are not yet integrated.
  • Nexus's readiness engine was built for Canadian healthcare; the California control mappings here are editorial, not computed applicability.

Nexus does not determine compliance with any of these instruments. It is designed to support the controls they expect and to produce evidence that those controls operated.

California organization? Start with a 30-minute review.

A confidential conversation about where medical information flows in your organization today, which AI tools have arrived, and what a governed, private deployment would look like under CMIA and HIPAA.

Every record on this page is synthetic and belongs to a fictional hospital. Nothing here is a customer, a patient, or a production measurement. The scoring, eligibility, and audit logic are the real Nexus engines running over the synthetic inputs.