Traceability over black-box answers.
Every proposed clock should show the rule version, the facts used, and the calculation. An AI brief should show its sources. A send record should show that it was recorded, not transmitted.
About
BreachClock is a product of DownStream Health Technologies, Inc. It is a healthcare privacy and breach-response workspace that helps teams assess a potential incident, coordinate the work that follows, and track notification obligations and deadlines in one documented matter.
After discovery, the hard part is rarely writing another spreadsheet column. It is knowing which clocks may apply, which of those clocks a person has accepted, what still needs a decision, and whether a contemplated notice was actually recorded as sent.
BreachClock brings that response lifecycle into one structured system of record.
It tracks decisions and deadlines. It does not make a final legal determination, and it is not a HIPAA compliance certification.
Our goal is simple
Know what to do. Know when it’s due.
To create a world where a healthcare organization can see, from discovery through closure, what it may need to do — and when a person decided it was due.
We envision privacy, security, compliance, and counsel sharing one matter instead of reconstructing the story from email, shared drives, and conflicting clocks.
BreachClock is building toward a future where a potential incident is not a folder of files, but a living record of facts, review, accepted deadlines, and recorded notices.
Our mission is to turn incident metadata into a reviewable response record: proposed clocks, human decisions, and notices that are never confused with a send.
BreachClock helps organizations:
We aim to make breach-response accountability easier to understand, easier to coordinate, and easier to document — without asking the product to file a notice or declare reportability.
Every proposed clock should show the rule version, the facts used, and the calculation. An AI brief should show its sources. A send record should show that it was recorded, not transmitted.
An assessment brief can organize facts and unanswered questions. It is not a breach determination and is never auto-approved.
A proposed deadline is not an accepted commitment. An approved notice is not a sent notice. BreachClock should say so.
The product is built for discovery time, jurisdictions, encryption status, and estimated counts — not patient names, medical record numbers, or lists of affected individuals.
Recalculation may propose a new date. A human-accepted deadline stays until an authorized user reviews or overrides it.
Tenant isolation, role checks on the server, and an append-only activity timeline are part of the product — not a later overlay.
Privacy, security, compliance, and counsel share the same matter. Tasks, assessments, and notices should live together without collapsing into a single “percent complete.”
When BreachClock cannot treat a clock as accepted, a notice as sent, or a brief as a decision, it should not imply otherwise.
The clocks that matter after a potential healthcare incident are easy to miss and hard to unwind.
A federal notice window, a state attorney-general clock, and a customer BAA term can all start from the same discovery time — and none of them should move because a spreadsheet was copied.
Those obligations become real the moment the organization has facts a person is willing to stand behind.
Yet many teams still reconstruct the answer when a regulator, customer, or board asks what was due and what was done.
BreachClock exists to close that gap.
BreachClock organizes the response around a connected model:
That lets teams move beyond a shared inbox and toward a matter they can review, accept, and close with a record.
The result is a clearer answer to questions a privacy program has to be able to ask:
That is the problem BreachClock is built to solve.
Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.
Self-serve trial. No local seed account required.
Cookies
We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.