About

About BreachClock

BreachClock is a product of DownStream Health Technologies, Inc. It is a healthcare privacy and breach-response workspace that helps teams assess a potential incident, coordinate the work that follows, and track notification obligations and deadlines in one documented matter.

After discovery, the hard part is rarely writing another spreadsheet column. It is knowing which clocks may apply, which of those clocks a person has accepted, what still needs a decision, and whether a contemplated notice was actually recorded as sent.

BreachClock brings that response lifecycle into one structured system of record.

It tracks decisions and deadlines. It does not make a final legal determination, and it is not a HIPAA compliance certification.

Our goal is simple

Know what to do. Know when it’s due.

Vision

To create a world where a healthcare organization can see, from discovery through closure, what it may need to do — and when a person decided it was due.

We envision privacy, security, compliance, and counsel sharing one matter instead of reconstructing the story from email, shared drives, and conflicting clocks.

BreachClock is building toward a future where a potential incident is not a folder of files, but a living record of facts, review, accepted deadlines, and recorded notices.

Mission

Our mission is to turn incident metadata into a reviewable response record: proposed clocks, human decisions, and notices that are never confused with a send.

BreachClock helps organizations:

  • open a documented matter from incident metadata — not patient records
  • assess whether a potential incident may require notification, with a human still accountable
  • see proposed clocks from versioned rules, then accept or override them
  • coordinate investigation tasks without inventing statutory deadlines from a playbook
  • draft, approve, and record notices without sending them from the product
  • close a matter with a timeline that shows who decided what, and when

We aim to make breach-response accountability easier to understand, easier to coordinate, and easier to document — without asking the product to file a notice or declare reportability.

Principles

Traceability over black-box answers.

Every proposed clock should show the rule version, the facts used, and the calculation. An AI brief should show its sources. A send record should show that it was recorded, not transmitted.

AI assists. Humans remain accountable.

An assessment brief can organize facts and unanswered questions. It is not a breach determination and is never auto-approved.

No false certainty.

A proposed deadline is not an accepted commitment. An approved notice is not a sent notice. BreachClock should say so.

Incident metadata only.

The product is built for discovery time, jurisdictions, encryption status, and estimated counts — not patient names, medical record numbers, or lists of affected individuals.

Accepted clocks do not move themselves.

Recalculation may propose a new date. A human-accepted deadline stays until an authorized user reviews or overrides it.

Security and privacy by design.

Tenant isolation, role checks on the server, and an append-only activity timeline are part of the product — not a later overlay.

Response work is operational, not only legal.

Privacy, security, compliance, and counsel share the same matter. Tasks, assessments, and notices should live together without collapsing into a single “percent complete.”

Conservative by default.

When BreachClock cannot treat a clock as accepted, a notice as sent, or a brief as a decision, it should not imply otherwise.

What We Believe

The clocks that matter after a potential healthcare incident are easy to miss and hard to unwind.

A federal notice window, a state attorney-general clock, and a customer BAA term can all start from the same discovery time — and none of them should move because a spreadsheet was copied.

Those obligations become real the moment the organization has facts a person is willing to stand behind.

Yet many teams still reconstruct the answer when a regulator, customer, or board asks what was due and what was done.

BreachClock exists to close that gap.

Our Approach

BreachClock organizes the response around a connected model:

  1. Matter
  2. Assessment
  3. Decision
  4. Obligation
  5. Notification
  6. Closure

That lets teams move beyond a shared inbox and toward a matter they can review, accept, and close with a record.

The result is a clearer answer to questions a privacy program has to be able to ask:

  • What happened, and when did we discover it?
  • Which notification clocks may apply?
  • Which of those clocks has a person accepted?
  • What still needs a decision?
  • Which contemplated notices are drafted, approved, or recorded as sent?

That is the problem BreachClock is built to solve.

Stop tracking breach clocks in a spreadsheet.

Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.

Self-serve trial. No local seed account required.

Cookies

We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.