Privacy operations should enable a defensible response.
The work after discovery should make the organization more prepared and more honest — not faster at declaring reportability it has not reviewed.
About

Casey Morganelli
Founder and CEO, BreachClock
BreachClock was founded by Casey Morganelli, a cybersecurity and information security executive with more than 15 years of experience leading security, risk, compliance, and governance programs across complex organizations.
Throughout his career, Casey has worked at the intersection of cybersecurity, privacy, regulation, and executive decision-making. His experience includes enterprise security strategy, incident response, governance, third-party risk, and programs aligned to healthcare and privacy requirements.
He has led security organizations, advised senior executives, and built programs aligned to frameworks and requirements including HIPAA, HITRUST, SOC 2, ISO 27001, GDPR, and other security and privacy standards.
Casey holds a PhD in Information and Cyber Security and maintains industry certifications including CISSP, CISM, CIPP/US, and CIPM.
The idea behind BreachClock came from a recurring problem Casey saw in healthcare privacy operations:
Organizations spend enormous effort investigating a potential incident, but the clocks, drafts, and decisions that follow often live in separate tools — and a proposed date can be treated as if someone had already accepted it.
BreachClock was created to make those clocks visible, reviewable, and documented.
Casey’s vision for BreachClock is to change what happens after discovery.
Rather than allowing a potential incident to become a folder of files, BreachClock turns it into a living matter: facts, assessment, decision, accepted deadlines, and recorded notices.
The goal is to give organizations a continuous understanding of:
That vision is reflected in BreachClock’s core model:
Casey approaches privacy operations from a practitioner’s perspective.
The objective is not to create more process for its own sake. It is to give organizations better information so they can make better decisions — and keep a record of those decisions.
That philosophy shapes BreachClock in several ways:
The work after discovery should make the organization more prepared and more honest — not faster at declaring reportability it has not reviewed.
HIPAA, state notice laws, and customer terms are inherently complex. Good software should make the clocks easier to navigate while preserving the facts, versions, and approvals underneath.
A brief can organize unknowns. It should not silently become the breach decision.
Organizations should be able to show who accepted a deadline, who approved a notice, and that “mark sent” recorded an action performed outside the product.
Facts live with security, clocks with privacy, drafts with counsel, and confirmation numbers in a portal. BreachClock was built to connect those pieces without storing raw PHI.
Casey’s mission is to build BreachClock into a workspace organizations can trust to answer a deceptively simple question:
What must we do, and when did we decide it was due?
By making assessment, deadlines, and notification records easier to review, BreachClock aims to help healthcare teams reduce missed clocks and turn breach response from a reconstructed story into a continuous operational record.
Know what to do. Know when it’s due.
Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.
Self-serve trial. No local seed account required.
Cookies
We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.