Fee petition mechanics · Updated August 2026
California Confidentiality of Medical Information Act (CMIA) Civ. Code § 56.36(g) attorney fee petition mechanics: California Medical Board patient complaint case number date as primary Welch anchor
California Confidentiality of Medical Information Act (CMIA) Civ. Code § 56.36(g) attorney fee petition mechanics — solos representing patients whose confidential medical information was disclosed without authorization by a licensed physician, physician-owned medical group, hospital, health plan, employer, pharmaceutical company, or other California-regulated entity, who must document the Hensley lodestar from the CALIFORNIA MEDICAL BOARD (CMB) PATIENT COMPLAINT CASE NUMBER DATE as the primary Welch temporal anchor — which is THE ONLY primary Welch anchor in the fee-petition-mechanics series recorded in the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATABASE at mbc.ca.gov, not the Tyler Odyssey Court CMS, not a state labor or environmental regulatory database, not a local government building and safety code enforcement system, and not a federal institutional database; when a patient files a formal complaint with the California Medical Board about a licensed physician or physician-owned medical group for unauthorized disclosure of confidential medical information in violation of the CMIA, the Board assigns a complaint case number on the date of receipt and sends a written case receipt acknowledgment to the complainant — this CMB case number date, recorded in the Board's enforcement case management system, is the earliest government-institution-assigned date in CMIA wrongful disclosure cases against licensed physicians and medical groups, and it precedes the Tyler Odyssey civil CMIA complaint by four to eighteen months during which the CMB's parallel administrative investigation runs concurrently with civil case preparation; CMIA §§ 56–56.37 is the California Legislature's answer to a deliberate gap in federal law: the Health Insurance Portability and Accountability Act of 1996 [HIPAA] established the federal framework for protecting individually identifiable health information, but Congress intentionally built HIPAA with no private right of action — enforcement is vested exclusively in the U.S. Department of Health and Human Services Office for Civil Rights [HHS-OCR], which investigates complaints and imposes civil monetary penalties against covered entities, but individual patients cannot sue in federal court to recover damages for a HIPAA violation; the CMIA fills this federal enforcement void for California patients by providing a civil damages pathway — Civ. Code § 56.36(b)(1) provides $1,000 statutory damages per negligent violation; § 56.36(b)(2) provides $25,000 per knowing and willful violation; and § 56.36(c) provides punitive damages where the defendant's conduct constitutes oppression, fraud, or malice — together with a mandatory attorney fee entitlement under § 56.36(g): "The prevailing plaintiff in any action brought pursuant to subdivision (b) or pursuant to Section 56.35 shall be entitled to recover reasonable attorney's fees and costs from the defendant"; because HIPAA has no private right and therefore generates no concurrent federal fee-shifting claim, CMIA § 56.36(g) cases are PURE KETCHUM — no Dague split, no Hensley task-level segregation between California and federal work, the entire lodestar from the CMB patient complaint case number date through the Tyler Odyssey CMIA civil complaint judgment is pure Ketchum eligible for the full contingency multiplier under Ketchum v. Moses (2001) 24 Cal.4th 1122 and PLCM Group Inc. v. Drexler (2000) 22 Cal.4th 1084; the CMIA covers a broader class of defendants than HIPAA — while HIPAA's Privacy Rule applies to "covered entities" [healthcare providers that transmit health information electronically, health plans, and healthcare clearinghouses] and their "business associates," the CMIA applies to healthcare providers, health plans, contractors, employers who receive medical information about employees or job applicants, pharmaceutical companies that receive patient health data, and any other person or entity that receives, obtains, maintains, or uses medical information as defined in Civ. Code § 56.05(j); a California employer who learns of an employee's HIV status from a workplace wellness program and discloses it to coworkers violates the CMIA but may not be a HIPAA covered entity; a pharmaceutical company that uses patient prescription data for marketing in violation of § 56.10 violates the CMIA even if no HIPAA-covered entity transmitted the information directly; PRIMARY ANCHOR: CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATE at mbc.ca.gov — the CMB receives patient complaints about licensed physicians under Bus. & Prof. Code § 2220 and assigns each complaint a case number on the date of receipt; for CMIA wrongful disclosure complaints against physicians or physician-owned medical groups, the CMB case number receipt date is the first institutional record created by a government agency in the enforcement chain; the CMB's Enforcement program investigates each complaint and may refer the matter to a Medical Quality Hearing Panel [MQHP] or the Attorney General for formal accusation proceedings under Bus. & Prof. Code § 2234(e) [unprofessional conduct] if the evidence supports a finding that the unauthorized disclosure constituted a CMIA violation; the CMB investigation creates institutional records — interview scheduling dates, expert reviewer engagement dates, subpoena issuance dates, and informal conference dates — that are assigned by the CMB on its own investigative timeline, entirely outside the plaintiff attorney's scheduling control; SECONDARY ANCHOR: CALIFORNIA ATTORNEY GENERAL DATA BREACH NOTIFICATION DATABASE at oag.ca.gov/privacy/databreach — THE ONLY secondary anchor in the fee-petition-mechanics series in the CALIFORNIA AG DATA BREACH NOTIFICATION DATABASE; under Civ. Code § 1798.82, any entity that experiences a breach of security affecting unencrypted personal information of more than 500 California residents must notify the Attorney General of California in the most expedient time possible; for institutional healthcare breaches affecting 500 or more patients [hospital EHR system compromises, health plan vendor data theft, medical group credential breaches], the defendant entity submits a notification to the AG's database, which is publicly accessible at oag.ca.gov/privacy/databreach and records the entity name, date of breach, date of AG notification submission, and number of Californians affected; the AG breach notification receipt date is the earliest publicly confirmed institutional record of the unauthorized disclosure event in large-scale CMIA breach cases — it is created by the defendant entity's mandatory compliance filing, is recorded in a state government database, and is entirely outside the plaintiff attorney's scheduling control; THREE UNIQUE DISTINCTIONS that make the CMB patient complaint case number date and the CMIA § 56.36(g) Hensley lodestar structurally unlike every other anchor and fee-shifting framework in the fee-petition-mechanics series: (1) THE ONLY page where HIPAA EXPLICITLY FORECLOSES A PRIVATE RIGHT OF ACTION creating a California-exclusive CMIA civil recovery pathway — because there is no concurrent federal claim with attorney fee-shifting, the entire lodestar is pure Ketchum without any Hensley task-level segregation between California and federal work, and without any Dague constraint on positive multiplier availability; no other page in the fee-petition-mechanics series has this specific structural feature where federal law's deliberate foreclosure of individual enforcement creates a California-exclusive pure Ketchum pathway; pages with concurrent federal claims [FEHA + Title VII, CFRA + FMLA, § 203 + FLSA] require Hensley segregation on the federal hours; CMIA requires none; (2) THE ONLY primary Welch anchor in the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATABASE at mbc.ca.gov — no other page in the fee-petition-mechanics series uses the Medical Board's enforcement case management database as the primary institutional anchor; the CMB complaint date precedes Tyler Odyssey by four to eighteen months, creating a substantial pre-litigation billing period anchored in a CMB government record; (3) THE ONLY secondary anchor in the CALIFORNIA AG DATA BREACH NOTIFICATION DATABASE at oag.ca.gov/privacy/databreach — no other page in the fee-petition-mechanics series uses the Attorney General's breach notification database as a secondary institutional anchor; the AG database is publicly searchable and confirms the breach date, the notification date, and the scale of the unauthorized disclosure; KETCHUM ANALYSIS: PURE KETCHUM with no Dague constraint — no federal statute provides individual patients with a civil damages and mandatory attorney fees claim for unauthorized medical information disclosure; Ketchum v. Moses (2001) 24 Cal.4th 1122; PLCM Group Inc. v. Drexler (2000) 22 Cal.4th 1084; Hensley v. Eckerhart (1983) 461 U.S. 424 lodestar from CMB patient complaint case number date; Missouri v. Jenkins (1989) 491 U.S. 274 fees-on-fees; three billing gaps driven by the CMB patient complaint case number date and HIPAA-void analysis and preservation demand and expert consultation advisory calls (5 × 2 × 63 min × 55% = 5.78 hrs = $1,734–$2,890/yr), Tyler Odyssey CMIA civil complaint and EHR audit log analysis and disclosure scope assessment and negligent-vs-knowing-willful distinction and settlement negotiation advisory calls (6 × 2 × 65 min × 55% = 7.15 hrs = $2,145–$3,575/yr), and fee petition and pure Ketchum multiplier and dual-track lodestar reconstruction and fees-on-fees advisory calls (5 × 2 × 45 min × 55% = 4.13 hrs = $1,239–$2,065/yr). For a solo California attorney who regularly represents patients in CMIA § 56.36(g) wrongful medical information disclosure actions, the annual billing gap from CMIA advisory call underlogging is $5,118–$8,530.
TL;DR
ClaimHour captures every California Medical Board patient complaint case number date and HIPAA-void analysis and preservation demand to defendant healthcare entity and expert consultation on CMIA standard of care and fee demand letter advisory call that begins the Hensley lodestar in the CMB's enforcement database before Tyler Odyssey Court CMS ever records the § 56.36(g) CMIA case, every Tyler Odyssey CMIA civil complaint and EHR audit log analysis and disclosure scope assessment and negligent-vs-knowing-willful distinction and California AG breach notification database verification and settlement negotiation advisory call, and every fee petition and pure Ketchum multiplier and dual-track lodestar reconstruction [CMB administrative track + Tyler Odyssey civil track] and Missouri v. Jenkins fees-on-fees advisory call — passively, no timer, no audio, no call contents. $29–$59/mo. No PMS required.
First billing gap: California Medical Board patient complaint case number date — the unique government-database anchor that begins the Hensley lodestar before Tyler Odyssey sees the CMIA case, driven by HIPAA's deliberate foreclosure of a private right
The CALIFORNIA MEDICAL BOARD (CMB) PATIENT COMPLAINT CASE NUMBER DATE — the date recorded in the CMB's enforcement case management database when the Board receives a patient's formal complaint about a licensed physician or physician-owned medical group for unauthorized disclosure of confidential medical information in violation of the Confidentiality of Medical Information Act — is THE ONLY primary Welch temporal anchor in the fee-petition-mechanics series recorded in the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATABASE at mbc.ca.gov. In every other page in the fee-petition-mechanics series, the primary institutional anchor is: a state labor regulatory database [EDD UI Online for § 203 waiting time penalty; DLSE wage claim portal for § 98.2 de novo trial]; a state civil rights database [CRD CARES system for FEHA employment discrimination]; a local building and safety code enforcement database [LADBS LADBSCASE in Los Angeles for Civ. Code § 1942.4]; a specialized environmental or consumer protection database [OEHHA Prop 65 Clearinghouse for § 25249.7; LWDA PAGA Online Notice System for Lab. Code § 2699]; or the Tyler Odyssey Court CMS itself [for most other pages in the series]. The California Medical Board patient complaint case number date is unique because: (a) it is assigned by a state professional licensing enforcement agency — the CMB — acting on its own investigative mandate under Bus. & Prof. Code § 2220 et seq., not at the plaintiff attorney's request and not contingent on the plaintiff attorney's decision to file a civil complaint; (b) the CMB assigns the case number on the date of receipt and sends a written acknowledgment letter to the complainant — creating a paper and electronic institutional record in the CMB case management database entirely without any action by the plaintiff attorney beyond the patient's filing of the initial complaint form; and (c) the CMB complaint date typically precedes the Tyler Odyssey civil CMIA complaint by four to eighteen months, during which the CMB investigates the complaint through its Enforcement program while the plaintiff attorney simultaneously prepares the civil case — creating the longest and richest pre-Tyler-Odyssey billing period in the fee-petition-mechanics series.
THE HIPAA STRUCTURAL FOUNDATION FOR THE FIRST BILLING GAP: The California Medical Board patient complaint case number date creates the first billing gap in CMIA cases because of the relationship between HIPAA's no-private-right structure and CMIA's mandatory civil enforcement mechanism. When a California patient discovers that a licensed physician disclosed their confidential medical information without authorization — whether to the patient's employer, to a family member, to another provider without proper authorization, to a media outlet, through negligent EHR security practices that permitted third-party access, or to a pharmaceutical company marketing database — the patient faces an immediate choice: file an administrative complaint with HHS-OCR for HIPAA enforcement, file a complaint with the California Medical Board for professional misconduct investigation, or file a CMIA civil action in the California superior court. The critical structural feature is that HIPAA enforcement and CMIA civil enforcement can and do run concurrently — and neither precludes the other. HHS-OCR's investigation of a HIPAA complaint generates no attorney fees for the patient's attorney; the CMB's investigation of the § 2234(e) professional misconduct complaint generates no civil damages or attorney fees for the patient. Only the CMIA § 56.36(g) civil action generates mandatory attorney fees for the prevailing plaintiff attorney. The first billing gap arises because the plaintiff attorney begins substantive work on the CMIA civil case from the date of the CMB complaint filing — analyzing the § 56.10 exception structure, drafting preservation demands to the defendant healthcare entity, engaging expert consultants on the CMIA standard of care, and preparing fee demand letters — before the Tyler Odyssey civil complaint is filed, and before any court creates an institutional record of the matter. This pre-Tyler-Odyssey work is billable under the § 56.36(g) lodestar [it is "reasonable and necessary" to the prosecution of the CMIA claim] but is almost entirely reconstructed rather than contemporaneously logged, because it occurs before any formal case number exists in any court management system.
THE CMB COMPLAINT ECOSYSTEM AND ITS EFFECT ON THE FIRST BILLING GAP: The California Medical Board receives approximately 8,000 to 10,000 formal complaints annually under its jurisdiction over approximately 145,000 licensed physicians. CMIA-related complaints are processed by the CMB's Enforcement program, which operates under the Division of Medical Quality. When the CMB receives a patient complaint about unauthorized medical information disclosure: (a) the Board's intake unit assigns a complaint case number on the date of receipt — this date is the primary Welch anchor; (b) the intake unit sends the complainant a written acknowledgment within 30 days confirming receipt and providing the case number and assigned investigator contact information; (c) the CMB's Medical Consultants [licensed physicians who review complaints for clinical context] evaluate whether the disclosed information was confidential medical information under the CMIA and whether the disclosure fell within one of the § 56.10 exceptions; (d) a CMB field investigator may contact the complainant [the patient] to obtain additional information — this CMB-initiated contact creates an institutional calendar event that the plaintiff attorney must prepare the client for, generating additional first billing gap hours; (e) if the complaint has merit, the CMB Enforcement program may issue a citation and fine under Bus. & Prof. Code § 125.9 [for administrative violations not warranting full accusation proceedings] or refer the matter to the California AG's Office for formal accusation under § 2234 [for more serious violations]; the citation issuance date and the AG referral date are additional institutional anchors in the CMB investigation chain, all predating the Tyler Odyssey civil CMIA complaint. Advisory calls that generate the first billing gap in CMIA cases include: (1) CMIA § 56.10 EXCEPTION ANALYSIS — Civ. Code § 56.10 enumerates the circumstances under which medical information may be disclosed without authorization, including: disclosure to providers treating the patient [§ 56.10(b)(2)]; disclosure to insurers for claims processing [§ 56.10(b)(3)]; disclosure in judicial or administrative proceedings where the patient is a party [§ 56.10(b)(7)]; disclosure to the patient's employer when the patient's medical condition creates a direct threat in the workplace [§ 56.10(c)(8) under specified conditions]; each of the § 56.10 exceptions must be analyzed against the specific facts of the disclosure; advisory calls about whether the defendant's disclosure falls within any § 56.10 exception — and how to counter the defendant's anticipated exception defense — generate substantial first billing gap hours before the Tyler Odyssey complaint is filed; (2) PRESERVATION DEMAND DRAFTING AND DELIVERY — the attorney must send preservation demands to the defendant healthcare entity for all electronic records documenting the disclosure: EHR audit logs showing who accessed the patient's electronic health record and when; email and messaging system audit trails; fax transmission logs; disclosure authorization tracking systems; contract records with third parties who received the information; any breach notification communications sent to HHS-OCR or the California AG; preservation demands are sent before the Tyler Odyssey complaint and generate advisory calls about scope, timing, litigation hold confirmation, and follow-up when preservation demands are disputed or inadequately acknowledged; (3) EXPERT CONSULTATION ON CMIA STANDARD OF CARE — CMIA wrongful disclosure cases frequently require expert consultation before the complaint is filed to assess whether the disclosure was unauthorized [was it within a § 56.10 exception?], whether it was negligent [did the defendant fail to implement reasonable safeguards?], or whether it was knowing and willful [did the defendant intentionally disclose despite knowledge of the CMIA prohibition?]; pre-complaint expert consultation generates first billing gap hours that are almost entirely reconstructed because expert communications before a formal engagement letter often occur by phone [the single most underlogged billing event in solo practice]; (4) FEE DEMAND LETTER STRATEGY — many CMIA § 56.36(g) cases resolve pre-complaint through a formal demand letter asserting the CMIA violation, the applicable statutory damages floor [§ 56.36(b)(1): $1,000 for negligent violations; § 56.36(b)(2): $25,000 for knowing/willful violations], and the mandatory attorney fee entitlement under § 56.36(g); preparing and sending the fee demand letter, evaluating the defendant's response, and deciding whether to file suit generates advisory calls that occur entirely in the pre-Tyler-Odyssey window anchored by the CMB complaint date. At 55% untracked: 5 clients × 2 calls × 63 min × 55% = 346.5 min / 60 = 5.78 hours = $1,734–$2,890/year at $300–$500/hr.
The California Medical Board patient complaint case number date has a structural feature that distinguishes it from every other primary Welch anchor in the fee-petition-mechanics series: it is the earliest institutional record in a concurrent dual-track enforcement system — the CMB administrative track and the Tyler Odyssey civil track — arising from a single wrongful disclosure event. In most other pages in the series, the primary anchor is a single-track institutional event: the EDD UI claim for § 203 creates only the labor enforcement track; the LADBS code enforcement citation for § 1942.4 creates only the local housing enforcement track. In CMIA cases, the CMB complaint creates the first of two parallel tracks, both of which generate attorney fee-billable work under § 56.36(g): the CMB administrative track [complaint receipt, intake review, expert medical consultation, field investigation, citation/referral] and the Tyler Odyssey civil CMIA track [complaint, responsive pleadings, discovery, motion practice, trial/settlement, fee petition]. The CMB track billing hours — drafting the CMB complaint, coordinating the client's preparation for CMB investigator interviews, reviewing CMB inquiry letters for factual accuracy, analyzing CMB expert reviewer reports for use in the civil case — are all billable under the § 56.36(g) lodestar because they are reasonably and necessarily incurred in connection with the prosecution of the CMIA § 56.36(b) civil claim. Ketchum v. Moses (2001) 24 Cal.4th 1122. PLCM Group Inc. v. Drexler (2000) 22 Cal.4th 1084. Hensley v. Eckerhart (1983) 461 U.S. 424. Missouri v. Jenkins (1989) 491 U.S. 274.
Second billing gap: Tyler Odyssey CMIA civil complaint date, EHR audit log analysis, disclosure scope assessment, negligent-versus-knowing-willful distinction, and California AG breach notification database verification
The period between the California Medical Board patient complaint case number date [when the CMIA § 56.36(g) lodestar begins] and the Tyler Odyssey civil CMIA complaint date [when the court gets involved] is where the second billing gap accumulates through EHR audit log analysis, disclosure scope assessment, CMIA § 56.10 exception mapping, negligent-versus-knowing-willful damages distinction advisory calls, California AG breach notification database verification, and settlement negotiation — work that is almost entirely reconstructed rather than contemporaneously logged because each individual advisory call about the scope of the disclosure or the applicable damages tier seems too granular to bill separately, and because the plaintiff attorney in a CMIA case is managing a parallel CMB administrative track and a civil track simultaneously, with calls about each track blurring together in the attorney's memory. The second billing gap in CMIA § 56.36(g) cases is structurally distinct from other pages in the fee-petition-mechanics series because: (a) the EHR audit log is simultaneously the primary evidence of the CMIA violation and the primary source of the damages analysis — the same audit log that shows who accessed the patient's record without authorization also shows whether the access was incidental [potentially negligent] or systematic and repeated [potentially knowing and willful]; (b) the § 56.36(b) damages tier structure [$1,000 for negligent violations vs. $25,000 for knowing/willful violations] creates a high-stakes damages characterization advisory call that typically occurs multiple times during the second billing gap as new evidence emerges from discovery; and (c) the California AG breach notification database verification [for institutional breaches of 500+ patients] creates a unique second billing gap advisory call that does not appear in any other fee-petition-mechanics page.
EHR AUDIT LOG ANALYSIS AND ITS ROLE IN THE SECOND BILLING GAP: Electronic health record audit logs are the foundational evidence in CMIA § 56.36(b) wrongful disclosure cases against healthcare providers. Under the HIPAA Security Rule [45 C.F.R. § 164.312(b)], covered entities and business associates must implement technical mechanisms to record and examine activity in information systems that contain electronic protected health information — audit controls. California CMIA defendants who are HIPAA-covered entities are therefore required to maintain EHR audit logs, and these logs are discoverable in CMIA civil litigation. The EHR audit log for a patient's record shows: (a) every user account that accessed the patient's record, with the username, the workstation ID, the date and time of access, and the access type [view, edit, print, download, export, share]; (b) any external disclosures made through the EHR system's disclosure management module [including disclosed-to recipient identification, disclosure date, and authorization reference]; (c) any break-the-glass access events where a user bypassed normal access controls to access a record they were not normally authorized to view; (d) any remote or VPN access events that accessed the patient's record from outside the facility network; and (e) any unusual batch export or mass download events that may indicate an insider data theft or external ransomware exfiltration. Advisory calls about the EHR audit log generate the largest category of second billing gap hours in CMIA cases: (1) AUDIT LOG SCOPE AND COMPLETENESS ADVISORY — after the Tyler Odyssey complaint is filed and discovery begins, the plaintiff attorney requests all audit log entries for the patient's EHR record for a specified lookback period; initial audit log productions are frequently incomplete [logs are sometimes over-written after 90 or 180 days if not specifically preserved; defendant may produce only subset of log types]; advisory calls about whether the audit log production is complete, how to challenge incomplete productions, and what additional discovery is needed to reconstruct the full access history generate significant second billing gap hours; (2) UNAUTHORIZED ACCESS IDENTIFICATION ADVISORY — the audit log shows which user accounts accessed the patient's record; the attorney must analyze whether each access event was authorized [was the accessing user a member of the patient's treatment team? was there a valid reason for the access documented in the record?] or unauthorized [did the accessing user have no treatment relationship, no administrative need, and no disclosed authorization from the patient?]; this analysis requires cross-referencing the audit log with the patient's treatment records, appointment history, and the defendant entity's own access control documentation; advisory calls about which access events are potentially unauthorized generate second billing gap hours that are almost entirely unlogged because each access event analysis call is short [10–20 minutes] and seems like research rather than a distinctly billable advisory event; (3) CALIFORNIA AG BREACH NOTIFICATION DATABASE VERIFICATION — for institutional breaches [hospital EHR system compromises, health plan vendor breaches, medical group credential theft] that affect 500 or more California patients, the AG's breach notification database at oag.ca.gov/privacy/databreach is a critical secondary source of information; the attorney accesses the AG database to verify: the breach date as reported by the defendant entity; whether the entity notified the AG in a timely manner [Civ. Code § 1798.82 requires notification "in the most expedient time possible and without unreasonable delay"]; the number of Californians the entity reported as affected [relevant to damages scope in any class or representative action]; and whether the entity's AG notification description of the breach type matches the facts uncovered in civil discovery; advisory calls about the AG database findings, discrepancies between the AG notification and the civil discovery production, and how to use the AG notification as an admission by the defendant entity generate second billing gap hours that are unique to CMIA institutional breach cases.
THE NEGLIGENT-VERSUS-KNOWING-AND-WILLFUL DISTINCTION AND ITS HIGH-STAKES SECOND BILLING GAP EFFECT: The Civ. Code § 56.36(b) damages structure creates a binary choice with enormous financial consequences: (1) § 56.36(b)(1): if a healthcare provider or other regulated entity negligently discloses or provides access to medical information without authorization in violation of the CMIA, the provider shall be subject to a civil penalty not to exceed $1,000 for each violation; (2) § 56.36(b)(2): if a healthcare provider or other regulated entity knowingly and willfully discloses or provides access to medical information without authorization in violation of the CMIA, the provider shall be subject to a civil penalty not to exceed $25,000 for each violation; (3) § 56.36(c): a defendant whose knowing and willful conduct rises to the level of oppression, fraud, or malice is additionally subject to punitive damages. The difference between a negligent violation [$1,000/violation] and a knowing/willful violation [$25,000/violation] is 25× — a fact pattern involving 50 unauthorized accesses to a patient's HIV status in a small medical group's EHR is worth $50,000 under a negligent theory and $1,250,000 under a knowing/willful theory. Advisory calls about the negligent-versus-knowing-and-willful characterization of the evidence occur throughout the second billing gap as new evidence emerges: (a) INITIAL CHARACTERIZATION ADVISORY — at the time of the Tyler Odyssey complaint, the attorney must make an initial characterization decision based on the evidence gathered from the CMB complaint period; advisory calls about whether the initial pleading should allege negligent violation, knowing/willful violation, or both [in the alternative] generate second billing gap hours shortly after the Tyler Odyssey complaint date; (b) EVIDENCE-DRIVEN RECHARACTERIZATION ADVISORY — as discovery proceeds and EHR audit logs, email communications, and witness depositions are obtained, evidence may emerge that upgrades a case initially characterized as negligent into a knowing/willful case [e.g., an email from the disclosing physician to the unauthorized recipient explicitly requesting that the recipient share the disclosed information further, showing that the disclosure was intentional]; advisory calls about whether to amend the complaint to assert the higher damages tier and how to frame the knowing/willful argument generate second billing gap hours that occur multiple times as the evidentiary record develops; (c) SETTLEMENT VALUATION ADVISORY — settlement negotiations in CMIA § 56.36(g) cases require the attorney to advise the client on a settlement range that accounts for: the number of violations and the applicable per-violation penalty under the appropriate tier; the probability of success at trial on the knowing/willful theory; the attorney fee exposure to the defendant under § 56.36(g) if the plaintiff prevails [defendants are acutely aware that a § 56.36(g) fee award may substantially exceed the underlying damages in cases with multiple violations]; and any punitive damages exposure under § 56.36(c); advisory calls about settlement valuation — which depend on the knowing/willful characterization analysis — generate second billing gap hours that are almost entirely unlogged because settlement strategy discussions feel like "case planning" rather than discrete billable advisory events. At 55% untracked: 6 clients × 2 calls × 65 min × 55% = 429 min / 60 = 7.15 hours = $2,145–$3,575/year at $300–$500/hr.
CMIA DEFENDANT CLASS BREADTH AND ITS EFFECT ON SECOND BILLING GAP ADVISORY CALLS: The CMIA § 56.10 prohibition applies to a defendant class that is substantially broader than the HIPAA-covered entity framework, and the breadth of the defendant class creates a rich variety of second billing gap advisory scenarios: (a) EMPLOYER-DEFENDANT CASES — Civ. Code § 56.20 specifically prohibits employers from disclosing medical information about their employees or applicants for employment without authorization; an employer who receives a physician's letter about an employee's medical restrictions and shares it with the employee's supervisor or coworkers without the employee's authorization violates § 56.20; the primary Welch anchor in an employer-defendant CMIA case is typically the Tyler Odyssey complaint date [no CMB complaint is filed because the employer is not a licensed physician subject to CMB jurisdiction], and the secondary anchor is the California AG data breach notification database if the breach affects 500+ employees; advisory calls about whether the employer's disclosure falls within the § 56.10(c)(8) "direct threat to the workplace" exception generate complex second billing gap hours because the exception requires analysis of both the specific medical condition disclosed and the employee's job duties; (b) PHARMACEUTICAL COMPANY CASES — Civ. Code § 56.10(c)(7) permits disclosure to pharmaceutical companies for pharmaceutical research under specified conditions; unauthorized use of patient prescription data for marketing purposes or disclosure beyond the research authorization conditions violates the CMIA; advisory calls about whether the defendant pharmaceutical company's use of patient prescription data falls within or outside the § 56.10(c)(7) research authorization generate second billing gap hours that require specialized analysis of the research authorization contract and the actual use of the data; (c) CONTRACTOR/BUSINESS ASSOCIATE CASES — healthcare contractors who receive patient medical information under a service agreement with a HIPAA-covered entity are subject to both HIPAA's business associate requirements and the CMIA's contractor obligations under Civ. Code § 56.10; advisory calls about the interplay between the contractor's HIPAA business associate agreement [BAA] breach and the direct CMIA § 56.36 civil damages exposure generate second billing gap hours that require analysis of both the BAA terms and the specific CMIA provisions applicable to contractors. Ketchum v. Moses (2001) 24 Cal.4th 1122. PLCM Group Inc. v. Drexler (2000) 22 Cal.4th 1084. Hensley v. Eckerhart (1983) 461 U.S. 424. Missouri v. Jenkins (1989) 491 U.S. 274.
Third billing gap: Tyler Odyssey CMIA judgment date, Civ. Code § 56.36(g) mandatory fee award, pure Ketchum multiplier, and dual-track lodestar reconstruction
The TYLER ODYSSEY CIVIL CMIA JUDGMENT OR SETTLEMENT DATE — the date the California superior court enters judgment or the parties execute a settlement agreement in the CMIA § 56.36(b) action — is the third institutional anchor in the CMIA § 56.36(g) Hensley lodestar chain and generates the third billing gap through advisory calls about the mandatory fee award structure, the pure Ketchum multiplier calculation, the dual-track [CMB + Tyler Odyssey] lodestar reconstruction, and fees-on-fees for the § 56.36(g) fee petition preparation itself. Because Civ. Code § 56.36(g) uses a MANDATORY "shall be entitled to recover" standard — the prevailing plaintiff "shall be entitled to recover reasonable attorney's fees and costs from the defendant" — the § 56.36(g) fee petition mechanics are structurally distinct from the discretionary "may award" standards of some statutes in the series: the threshold question of whether the court will award fees at all is eliminated by the statute's mandatory language; the entire debate at the fee petition stage is about the lodestar amount, the dual-track structure of the lodestar, the PLCM Group prevailing market rate, and whether a Ketchum contingency multiplier applies. The § 56.36(g) fee petition differs structurally from most other fee petition pages in the series because the lodestar encompasses two parallel billing tracks [the CMB administrative track and the Tyler Odyssey civil track] from a single wrongful disclosure event — and the plaintiff attorney must document and justify both tracks as part of the § 56.36(g) mandatory fee claim.
THE DUAL-TRACK LODESTAR RECONSTRUCTION AND ITS THIRD BILLING GAP EFFECT: Reconstructing the § 56.36(g) lodestar from the CMB patient complaint case number date requires the plaintiff attorney to document work on two parallel tracks: (1) CMB ADMINISTRATIVE TRACK BILLING PERIOD [CMB complaint case number date → Tyler Odyssey CMIA civil complaint date]: this period covers the pre-litigation work performed in connection with the CMB administrative investigation — drafting the CMB complaint; coordinating the client's interview preparation for CMB investigator contacts; reviewing CMB inquiry letters to confirm factual accuracy without converting the responses into attorney work product; analyzing the CMB's expert medical reviewer reports for use in the civil case; and preparing any submissions to the CMB's Enforcement program that bear on the factual record relevant to the civil CMIA claim; billing advisory calls about which CMB-track hours are properly included in the § 56.36(g) lodestar generate the most difficult third billing gap reconstruction hours, because the plaintiff attorney must demonstrate that each CMB-track hour was reasonably and necessarily incurred in connection with the prosecution of the CMIA § 56.36(b) civil claim — a standard that is satisfied when the attorney can show that the CMB-track work [e.g., the CMB complaint's factual narrative] was directly relevant to establishing the elements of the civil CMIA claim; (2) TYLER ODYSSEY CIVIL CMIA TRACK BILLING PERIOD [Tyler Odyssey complaint date → judgment/settlement]: this period covers the standard civil litigation work — complaint drafting, service, responsive pleading, written discovery, EHR audit log analysis, expert depositions, motion practice, trial preparation, and trial or settlement — all of which are straightforward Hensley-documented hours; no Hensley segregation between California and federal hours is required [because there is no concurrent federal claim with attorney fee-shifting]; the entire Tyler Odyssey civil track is pure Ketchum. The dual-track reconstruction challenge creates distinctive third billing gap advisory calls: (a) CMB-TRACK INCLUSION ANALYSIS — the defendant will typically object to CMB-track hours on the grounds that they are "administrative" hours not recoverable in a civil fee petition; the plaintiff attorney must prepare a defense of each CMB-track category demonstrating that the work was reasonably necessary to the civil CMIA prosecution [case law on the recoverability of concurrent administrative track hours in California mandatory fee statutes supports inclusion when the administrative record was reasonably necessary to establish the civil claim elements]; (b) LODESTAR SUMMARY PREPARATION — documenting the dual-track lodestar from the CMB complaint date through the Tyler Odyssey judgment requires preparation of a detailed billing record summary that identifies each billing event by track, date, time units, and description; for the CMB-track period [which often lacks formal matter numbers and contemporaneous billing records because no court case was open], reconstruction from emails, calendar entries, phone logs, and CMB correspondence is required; advisory calls about the reconstruction methodology and the level of documentation required generate significant third billing gap hours that are themselves unlogged because they occur in the fee petition preparation phase.
THE PURE KETCHUM MULTIPLIER IN CMIA § 56.36(g) FEE PETITIONS: CMIA § 56.36(g) is PURE KETCHUM — the entire lodestar from the CMB patient complaint case number date through the Tyler Odyssey civil CMIA judgment is pure Ketchum eligible for the full contingency multiplier without any Dague constraint. The Ketchum multiplier analysis for CMIA § 56.36(g) fee petitions includes: (i) IDENTIFYING THE COMPLETE DUAL-TRACK LODESTAR from the CMB patient complaint case number date through the Tyler Odyssey civil CMIA complaint judgment — including all pre-complaint CMB-track hours [HIPAA-void analysis, § 56.10 exception analysis, preservation demand drafting, expert consultation, fee demand letter preparation], all Tyler Odyssey civil-track hours [complaint, discovery, EHR audit log analysis, expert depositions, motion practice, trial/settlement], and all fee petition preparation hours [Missouri v. Jenkins fees-on-fees]; (ii) APPLYING THE KETCHUM FACTORS — CONTINGENCY RISK: at the time the attorney accepted the CMIA case on contingency, the contingency risk included [a] whether the defendant could successfully establish a § 56.10 exception to the CMIA prohibition; [b] whether the evidence would support a knowing/willful rather than merely negligent characterization of the disclosure [the 25× damages difference]; [c] whether the EHR audit log and other electronic evidence would be preserved and discoverable; [d] whether the defendant entity would have insurance coverage for CMIA civil liability [many general liability policies exclude data breach claims] or would seek bankruptcy protection; NOVELTY AND DIFFICULTY: EHR audit log forensic analysis, CMIA § 56.10 exception mapping across multiple defendant types [physician, employer, pharmaceutical company, contractor], the interaction between HIPAA's no-private-right structure and CMIA's California-exclusive enforcement pathway, and the dual-track [CMB + Tyler Odyssey] lodestar documentation all contribute to novelty and difficulty; RESULTS OBTAINED: the combination of statutory damages [§ 56.36(b)(1) $1,000/negligent or § 56.36(b)(2) $25,000/knowing-willful per violation], emotional distress damages, punitive damages in cases of oppression/fraud/malice under § 56.36(c), and mandatory attorney fees under § 56.36(g) produces a multi-component recovery; PRECLUSION OF OTHER EMPLOYMENT: EHR audit log forensic analysis with expert coordination, CMB administrative track interface, and CMIA expert depositions preclude significant other intake; (iii) PLCM GROUP PREVAILING MARKET RATE for plaintiff-side medical information privacy practice in California: the prevailing market rate must account for the specialized knowledge required — CMIA §§ 56–56.37 provisions and their HIPAA analogs; EHR system audit log analysis [Epic EHR audit log exports, Cerner PowerChart audit reports, MEDITECH audit trail documentation, eClinicalWorks system activity logs]; CMIA § 56.10 exception structure; the CMB enforcement process under Bus. & Prof. Code § 2220 et seq.; California AG data breach notification compliance under Civ. Code § 1798.82; the negligent-versus-knowing-and-willful evidence threshold under § 56.36(b); and dual-track [CMB + Tyler Odyssey] lodestar documentation under Hensley and Ketchum; (iv) MISSOURI V. JENKINS (1989) 491 U.S. 274 FEES-ON-FEES: time spent preparing the § 56.36(g) fee petition — documenting the dual-track lodestar from the CMB patient complaint case number date through the Tyler Odyssey CMIA judgment; reconstructing CMB-track billing from email, calendar, and correspondence records for the pre-complaint period; defending the CMB-track hours against defendant's objections; analyzing the Ketchum multiplier factors [contingency risk on § 56.10 exception defense and on knowing/willful theory]; and drafting the fee declaration and supporting exhibits — is itself recoverable as part of the § 56.36(g) mandatory fee award under Missouri v. Jenkins.
DISTINCT FROM HIPAA: The most important structural distinction in CMIA § 56.36(g) fee petition mechanics — the feature that makes every hour of attorney work in a CMIA case pure Ketchum — is HIPAA's foreclosure of a private right of action. A California patient whose CMIA-covered medical information was wrongfully disclosed has two enforcement pathways: (1) a HHS-OCR HIPAA complaint [if the defendant is a HIPAA covered entity or business associate] — this generates no attorney fees, no civil damages to the patient, and no private enforcement record in Tyler Odyssey; and (2) a CMIA § 56.36(b) civil action — this generates mandatory attorney fees under § 56.36(g), statutory damages per violation, and potentially punitive damages. Because there is no concurrent federal civil claim with attorney fee-shifting, there is no Dague split: the plaintiff attorney never needs to segregate California CMIA hours from federal hours for multiplier eligibility purposes [because no federal hours exist]; the entire lodestar is Ketchum-multiplier-eligible from the first day of work through the fee petition. DISTINCT FROM CIV. CODE § 1798.150 CCPA/CPRA DATA BREACH PRIVATE RIGHT: Civ. Code § 1798.150 gives California consumers a private right of action against businesses subject to the CCPA that experience a breach of unencrypted or nonredacted personal information due to the business's failure to implement reasonable security procedures. KEY DIFFERENCES from CMIA § 56.36(g): (a) § 1798.150 applies to "personal information" broadly defined [name + SSN, financial account numbers, login credentials, medical information, and several other categories]; CMIA applies specifically to "medical information" as defined in Civ. Code § 56.05(j) [individually identifiable information about a patient's medical history, diagnosis, treatment, or prognosis]; (b) § 1798.150 provides statutory damages of $100–$750 per consumer per incident [or actual damages if greater]; CMIA § 56.36(b)(1) provides up to $1,000 per negligent violation; § 56.36(b)(2) provides up to $25,000 per knowing/willful violation; (c) § 1798.150 applies to "businesses" subject to the CCPA [defined by revenue, data volume, and other thresholds]; CMIA applies to healthcare providers, health plans, contractors, employers, pharmaceutical companies, and other specified entities regardless of CCPA coverage; (d) § 1798.150 does not contain a "shall be entitled to recover" attorney fee standard of the kind in § 56.36(g); (e) a CMIA medical information breach by a CCPA-subject business may trigger both § 1798.150 and CMIA § 56.36(b) simultaneously — requiring analysis of which claim's damages and fee-shifting provisions are more favorable and whether both can be pursued in the same action. DISTINCT FROM HEALTH & SAFETY CODE § 1430(b) NURSING HOME RESIDENTS' RIGHTS: § 1430(b) covers all rights established by federal or state law for nursing home residents broadly — the right to dignity, the right to privacy, the right to access personal records, and many others; a nursing home's wrongful disclosure of a patient's medical information to third parties may violate both the patient's CMIA § 56.36 rights [for the specific medical information disclosure] and the patient's § 1430(b) rights [for the broader privacy violation in the SNF setting]; the § 1430(b) primary Welch anchor [CDPH SNF Survey and Certification database] is different from the CMIA primary anchor [CMB patient complaint case number date]; the § 1430(b) defendant class is specifically licensed SNFs and ICFs, while CMIA's defendant class is broader. At 55% untracked: 5 clients × 2 calls × 45 min × 55% = 247.5 min / 60 = 4.13 hours = $1,239–$2,065/year at $300–$500/hr.
How ClaimHour fits California CMIA Civ. Code § 56.36(g) medical information privacy practice
California solo attorneys representing patients whose confidential medical information was wrongfully disclosed by licensed physicians, physician-owned medical groups, hospitals, health plans, employers, pharmaceutical companies, or other California-regulated entities — generating a § 56.36(g) mandatory fee award from the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATE as the primary Welch temporal anchor (CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATE = primary Welch anchor; THE ONLY primary Welch anchor in the fee-petition-mechanics series recorded in the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATABASE at mbc.ca.gov — not Tyler Odyssey Court CMS, not a state labor or environmental regulatory database, not a local government building code enforcement system, and not a federal institutional database; the CMB assigns the complaint case number on the date of receipt and records it in the CMB enforcement case management database entirely outside the plaintiff attorney's scheduling control; the CMB complaint date precedes Tyler Odyssey by four to eighteen months and creates the pre-litigation billing period for HIPAA-void analysis, § 56.10 exception analysis, preservation demand drafting, expert consultation, and fee demand letter preparation; CALIFORNIA ATTORNEY GENERAL DATA BREACH NOTIFICATION DATABASE at oag.ca.gov/privacy/databreach = secondary institutional anchor for institutional healthcare breaches affecting 500+ Californians under Civ. Code § 1798.82 — THE ONLY secondary anchor in the fee-petition-mechanics series in the CALIFORNIA AG DATA BREACH NOTIFICATION DATABASE; THREE UNIQUE DISTINCTIONS: (1) THE ONLY page where HIPAA EXPLICITLY FORECLOSES A PRIVATE RIGHT OF ACTION creating a California-exclusive CMIA civil recovery pathway with no concurrent federal claim and therefore no Dague constraint — the entire lodestar is pure Ketchum from the CMB complaint date through the Tyler Odyssey judgment; (2) THE ONLY primary Welch anchor in the CALIFORNIA MEDICAL BOARD PATIENT COMPLAINT CASE NUMBER DATABASE at mbc.ca.gov; (3) THE ONLY secondary anchor in the CALIFORNIA AG DATA BREACH NOTIFICATION DATABASE at oag.ca.gov/privacy/databreach; MANDATORY 'shall be entitled to recover' attorney fee standard under Civ. Code § 56.36(g) — the prevailing plaintiff 'shall be entitled to recover reasonable attorney's fees and costs from the defendant'; no threshold good faith finding, no willfulness finding, no bilateral fee risk required for fee entitlement; PURE KETCHUM — HIPAA has no private right of action; HITECH has no private right of action; no federal statute gives individual patients a civil damages and mandatory attorney fees claim for medical information disclosure; the entire lodestar from CMB patient complaint case number date through Tyler Odyssey CMIA civil judgment is pure Ketchum eligible for full contingency multiplier; KETCHUM MULTIPLIER FACTORS: contingency risk [§ 56.10 exception defense at case inception; knowing/willful versus negligent characterization risk; EHR audit log preservation uncertainty; defendant entity insurance coverage for CMIA liability]; novelty and difficulty [EHR audit log forensic analysis across multiple EHR platforms [Epic, Cerner, MEDITECH, eClinicalWorks]; CMIA § 56.10 exception mapping; HIPAA/CMIA overlap analysis; dual-track [CMB + Tyler Odyssey] lodestar documentation]; results obtained [statutory damages per violation under § 56.36(b)(1) [up to $1,000 negligent] or § 56.36(b)(2) [up to $25,000 knowing/willful], plus emotional distress damages, plus punitive damages under § 56.36(c) for oppression/fraud/malice]; preclusion of other employment [EHR audit log forensic analysis; CMB administrative track coordination; expert deposition preparation]; PLCM Group prevailing market rate for plaintiff-side medical information privacy practice in California [specialized knowledge: CMIA §§ 56–56.37; EHR audit log analysis; CMB enforcement process; HIPAA/CMIA defendant class mapping; AG breach notification database; § 56.36(b) damages tier structure]; DISTINCT from HIPAA [no private right; HHS-OCR administrative enforcement only; no civil damages to patient; no attorney fee claim]; DISTINCT from Civ. Code § 1798.150 CCPA/CPRA data breach [broader personal information; $100–$750 statutory damages per incident; CCPA-subject businesses; different anchor]; DISTINCT from Health & Safety Code § 1430(b) nursing home residents' rights [SNF/ICF defendant class; all patient rights not specifically medical information; CDPH SNF survey database anchor]; DISTINCT from Pen. Code § 637.2 CIPA [electronic communication interception not medical information disclosure; different wrongful act; different anchor]; DISTINCT from Bus. & Prof. Code § 2234 physician misconduct [CMB administrative license discipline only; no civil damages; no patient attorney fee claim]; Ketchum v. Moses 24 Cal.4th 1122 (2001); PLCM Group Inc. v. Drexler 22 Cal.4th 1084 (2000); Hensley v. Eckerhart 461 U.S. 424 (1983) lodestar from CMB patient complaint case number date; Missouri v. Jenkins 491 U.S. 274 (1989) fees-on-fees; three billing gaps: 5.78 hrs = $1,734–$2,890/yr; 7.15 hrs = $2,145–$3,575/yr; 4.13 hrs = $1,239–$2,065/yr; total 17.06 hrs = $5,118–$8,530/yr), CMB patient complaint case number date and HIPAA-void analysis and § 56.10 exception analysis and preservation demand and expert consultation and fee demand letter advisory calls in the pre-Tyler-Odyssey CMB-track billing window after the CMB assigns the complaint case number, and Tyler Odyssey CMIA civil complaint date and EHR audit log analysis and disclosure scope assessment and negligent-versus-knowing-willful distinction and California AG breach notification database verification and settlement negotiation advisory calls, and fee petition and pure Ketchum multiplier and dual-track lodestar reconstruction [CMB track + Tyler Odyssey track] and Missouri v. Jenkins fees-on-fees advisory calls at the § 56.36(g) enforcement stage — and if your CMIA medical information privacy attorney fee petition lodestar must satisfy the Hensley contemporaneous-record standard from the California Medical Board patient complaint case number date through the entire pre-complaint CMB-track billing period and the Tyler Odyssey CMIA civil complaint and EHR audit log discovery and disclosure scope assessment and negligent-versus-knowing-willful damages tier analysis and settlement negotiation and mandatory fee award and pure Ketchum multiplier and dual-track lodestar reconstruction, ClaimHour was built for that gap.
See also
- California Health & Safety Code § 1430(b) nursing home residents' rights attorney fee petition mechanics
- California CIPA Pen. Code § 637.2 invasion of privacy attorney fee petition mechanics
- California Civ. Code § 1799.3 video privacy protection attorney fee petition mechanics
- California CCP § 1021.5 private attorney general attorney fee petition mechanics
- California CalECPA Pen. Code § 1546 electronic communications privacy attorney fee petition mechanics
- All fee petition mechanics posts