About

About the Founder

Casey Morganelli, founder of BreachClock

Casey Morganelli

Founder and CEO, BreachClock

BreachClock was founded by Casey Morganelli, a cybersecurity and information security executive with more than 15 years of experience leading security, risk, compliance, and governance programs across complex organizations.

Throughout his career, Casey has worked at the intersection of cybersecurity, privacy, regulation, and executive decision-making. His experience includes enterprise security strategy, incident response, governance, third-party risk, and programs aligned to healthcare and privacy requirements.

He has led security organizations, advised senior executives, and built programs aligned to frameworks and requirements including HIPAA, HITRUST, SOC 2, ISO 27001, GDPR, and other security and privacy standards.

Casey holds a PhD in Information and Cyber Security and maintains industry certifications including CISSP, CISM, CIPP/US, and CIPM.

Why BreachClock

The idea behind BreachClock came from a recurring problem Casey saw in healthcare privacy operations:

Organizations spend enormous effort investigating a potential incident, but the clocks, drafts, and decisions that follow often live in separate tools — and a proposed date can be treated as if someone had already accepted it.

  • A federal clock may live in one spreadsheet.
  • A state notice window may live in another.
  • A customer BAA term may be known to only the lawyer who negotiated it.
  • An AI draft may be treated as a determination because it is formatted like one.
  • And when someone later asks what was due and what was sent, teams often reconstruct the answer from email.

BreachClock was created to make those clocks visible, reviewable, and documented.

Founder’s Vision

Casey’s vision for BreachClock is to change what happens after discovery.

Rather than allowing a potential incident to become a folder of files, BreachClock turns it into a living matter: facts, assessment, decision, accepted deadlines, and recorded notices.

The goal is to give organizations a continuous understanding of:

  • when the organization discovered the incident
  • which clocks a rule version proposed
  • which of those clocks a person accepted
  • what an assessment brief still cannot answer
  • whether a decision has been approved
  • which notices are drafted, approved, or recorded as sent
  • what remains open before closure

That vision is reflected in BreachClock’s core model:

  1. Matter
  2. Assessment
  3. Decision
  4. Obligation
  5. Notification
  6. Closure

Philosophy

Casey approaches privacy operations from a practitioner’s perspective.

The objective is not to create more process for its own sake. It is to give organizations better information so they can make better decisions — and keep a record of those decisions.

That philosophy shapes BreachClock in several ways:

Privacy operations should enable a defensible response.

The work after discovery should make the organization more prepared and more honest — not faster at declaring reportability it has not reviewed.

Complexity should be reduced, not hidden.

HIPAA, state notice laws, and customer terms are inherently complex. Good software should make the clocks easier to navigate while preserving the facts, versions, and approvals underneath.

AI should support judgment, not replace it.

A brief can organize unknowns. It should not silently become the breach decision.

Trust requires a record.

Organizations should be able to show who accepted a deadline, who approved a notice, and that “mark sent” recorded an action performed outside the product.

The most important risks sit between inboxes.

Facts live with security, clocks with privacy, drafts with counsel, and confirmation numbers in a portal. BreachClock was built to connect those pieces without storing raw PHI.

Founder’s Mission

Casey’s mission is to build BreachClock into a workspace organizations can trust to answer a deceptively simple question:

What must we do, and when did we decide it was due?

By making assessment, deadlines, and notification records easier to review, BreachClock aims to help healthcare teams reduce missed clocks and turn breach response from a reconstructed story into a continuous operational record.

Know what to do. Know when it’s due.

Stop tracking breach clocks in a spreadsheet.

Start a trial workspace, create a matter, and see proposed deadlines your team can accept or override.

Self-serve trial. No local seed account required.

Cookies

We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.