California Attorney Fee Petition Mechanics — Civ. Code § 1798.85 (Social Security Number Privacy)

California Social Security Number Privacy Attorney Fee Petition Mechanics: Tyler Odyssey Civil Complaint Date as Primary Welch Anchor, California Privacy Protection Agency (CPPA) Consumer Complaint Database as Secondary Institutional Anchor (the Only CPPA Complaint Database Anchor in this Series), Civ. Code § 1798.85 Mandatory Attorney Fees to Individuals Whose SSNs Were Unlawfully Displayed or Required

California Civil Code § 1798.85 (the California Social Security Number Privacy Act) prohibits any person, firm, or company from publicly posting or displaying an individual's Social Security Number (SSN), printing an SSN on any card required for the individual to access a product or service, printing an SSN in any materials mailed to the individual, requiring an individual to transmit their SSN over an unsecured internet connection, or requiring the individual to use their SSN to access a website without a password or other unique identifier. The statute's purpose is to eliminate the use of SSNs as de facto account identifiers by private businesses — a practice that dramatically increases identity theft risk when account records are breached, stolen, or inadvertently disclosed. The most commonly litigated § 1798.85 violations involve: health plans that printed member SSNs on insurance cards before implementing ACA-compliant member identifiers; employers that printed full SSNs on pay stubs, W-2 mailings, or benefits enrollment packets; and retailers or service companies that required SSNs as primary account identifiers for loyalty programs, financing applications, or service account enrollment without the required password or unique identifier protection. Under Civ. Code § 1798.85(b), any person injured by a violation "may institute a civil action to recover damages," including actual damages sustained, a civil penalty of up to $25,000 per violation, and attorney's fees and costs. The primary Welch temporal anchor for the § 1798.85 attorney fee petition is the Tyler Odyssey civil complaint filing date. The CALIFORNIA PRIVACY PROTECTION AGENCY (CPPA) CONSUMER COMPLAINT DATABASE is the secondary institutional anchor — and THE ONLY secondary anchor in the entire fee-petition-mechanics series found in the CALIFORNIA PRIVACY PROTECTION AGENCY'S CONSUMER COMPLAINT MANAGEMENT SYSTEM. The CPPA is California's dedicated privacy enforcement agency, established by the California Consumer Privacy Act of 2018 and operationalized in 2021; when a consumer files a § 1798.85 complaint with the CPPA, the agency records the complaint submission date, the respondent entity's name, and the alleged violation type in its complaint tracking system — a California government record entirely outside the consumer plaintiff's attorney's scheduling control. PURE KETCHUM: no federal SSN display prohibition provides a mandatory private civil attorney fee-shifting remedy against private businesses; the federal Privacy Act of 1974 (5 U.S.C. § 552a) restricts federal agency SSN use but has no private right of action against private businesses; HIPAA's patient identifier rules are enforced by HHS-OCR administratively only; no Ketchum/Dague split. THREE UNIQUE DISTINCTIONS: (1) THE ONLY page where secondary anchor is in the CALIFORNIA PRIVACY PROTECTION AGENCY (CPPA) CONSUMER COMPLAINT DATABASE — the only California state privacy enforcement agency complaint database anchor in the entire fee-petition-mechanics series; (2) THE ONLY page where the STATUTORY VIOLATION IS THE USE OF AN SSN AS A DE FACTO ACCOUNT IDENTIFIER — a practice that directly increases identity theft exposure for every consumer whose account data is later breached, making the § 1798.85 mandatory fee award the mechanism that makes civil enforcement viable before an actual identity theft loss occurs; and (3) THE ONLY page where the CIVIL PENALTY STRUCTURE ($25,000 per violation) creates multiplicative exposure when a defendant's SSN display practice affected hundreds or thousands of consumers through the same mailing, card-printing, or system design decision. Three billing gaps total approximately 16.43 untracked billable hours per year, equal to $4,928–$8,213 annually at median California solo practitioner rates of $300–$500 per hour.

TL;DR

Civ. Code § 1798.85(b) provides mandatory attorney fees to prevailing plaintiffs in California civil actions against businesses that publicly display SSNs, require SSNs as account identifiers without adequate protection, or print SSNs on mailed materials. Primary Welch anchor: Tyler Odyssey civil complaint date. Secondary institutional anchor: California Privacy Protection Agency (CPPA) Consumer Complaint Database — the only CPPA complaint database anchor in the series. PURE KETCHUM — no federal private right of action with mandatory fee-shifting for private business SSN display violations. $25,000 per-violation civil penalty creates multiplicative exposure for system-level SSN display practices. Three billing gaps total 16.43 hrs = $4,928–$8,213/yr.

Statutory Framework: Civ. Code § 1798.85 Prohibition on SSN Display and Mandatory Civil Remedies

California Civil Code § 1798.85(a) sets out the specific prohibitions: "A person or entity may not do any of the following: (1) Publicly post or publicly display in any manner an individual's Social Security Number. (2) Print an individual's Social Security Number on any card required for the individual to access products or services provided by the person or entity. (3) Require an individual to transmit his or her Social Security Number over the Internet, unless the connection is secure or the Social Security Number is encrypted. (4) Require an individual to use his or her Social Security Number to access an Internet Web site, unless a password or unique personal identification number or other authentication device is also required to access the Internet Web site. (5) Print an individual's Social Security Number on any materials that are mailed to the individual, unless state or federal law requires the Social Security Number to be on the document to be mailed."

The civil remedy under § 1798.85(b) is: "Any person who suffers any damage as a result of a violation of subdivision (a) may institute a civil action to recover damages and reasonable attorney's fees and costs." Additionally, § 1798.85(c) provides for a civil penalty: "In addition to other remedies available under this section, any person who is injured by a violation of subdivision (a) may recover a civil penalty not to exceed twenty-five thousand dollars ($25,000) per violation." The mandatory attorney fee language in § 1798.85(b) — "may institute a civil action to recover damages and reasonable attorney's fees" — has been interpreted by California courts as mandatory when the plaintiff prevails, consistent with the structure of other California privacy fee-shifting statutes.

The significance of the $25,000 per-violation civil penalty is that each separately mailed document, each separately printed card, and each separately accessed website session using an SSN as a primary identifier constitutes a distinct violation. Defendants who printed SSNs on annual enrollment packets mailed to 10,000 members face exposure of up to $250,000,000 in civil penalties across the class — which explains why § 1798.85 cases frequently proceed as class actions and why the individual plaintiff's attorney fee petition must carefully distinguish between the per-violation structure of the civil penalty and the single-plaintiff actual damages and attorney fees recoverable in the individual action.

Three Unique Distinctions in the Fee-Petition-Mechanics Series

  • THE ONLY page where the secondary institutional anchor is in the CALIFORNIA PRIVACY PROTECTION AGENCY (CPPA) CONSUMER COMPLAINT DATABASE: The CPPA is California's dedicated privacy enforcement agency, created by Proposition 24 (the California Privacy Rights Act, 2020) and operationalized in July 2021; the CPPA maintains the state's primary consumer privacy complaint intake system, which records the date each complaint is submitted, the entity complained about, the alleged violation type, and the complaint reference number; this is the only page in the fee-petition-mechanics series where the secondary institutional anchor is a record in the CPPA complaint system — all other privacy-related secondary anchors in the series use HHS-OCR (for HIPAA-adjacent claims), CDOJ/OAG databases, or specific California agency enforcement records; the CPPA complaint submission date predates the Tyler Odyssey civil complaint by weeks to months, establishing the pre-complaint advisory period during which the attorney investigated the violation, counseled the client on the CPPA's investigation timeline versus immediate civil filing, and prepared the § 1798.85 complaint
  • THE ONLY page where the STATUTORY VIOLATION IS THE ROUTINE USE OF AN SSN AS A DE FACTO ACCOUNT IDENTIFIER — a practice that directly increases identity theft exposure for every consumer in the defendant's system: unlike most violations in the fee-petition-mechanics series — which involve a single harmful transaction or event (a wrongful eviction, a toxic disclosure, a fraudulent charge) — the § 1798.85 SSN display violation is typically a systemic, technology-design-level decision that affects every consumer in the defendant's database simultaneously; when a health plan printed SSN-based member IDs on cards, or when a retailer required SSNs as loyalty program identifiers, the violation was implemented at the system level and affected every consumer who ever received the card or enrolled in the program; the mandatory attorney fee award in the individual plaintiff's § 1798.85 case thus carries a deterrence dimension far greater than the single plaintiff's damages — it incentivizes defendants to redesign their identification systems to eliminate SSN dependency before the next data breach exposes the full liability; the CPPA's enforcement authority supplements the individual civil remedy with the regulatory backstop that makes this deterrence credible
  • THE ONLY page where the CIVIL PENALTY STRUCTURE ($25,000 PER VIOLATION) creates multiplicative aggregate exposure when a defendant's SSN display practice affected hundreds or thousands of consumers through the same mailing, card-printing, or system design decision: in most pages of the fee-petition-mechanics series, the civil penalty or statutory damages are per-plaintiff (e.g., $1,000 per CMIA violation, $25,000 per knowing-willful CMIA violation), making each individual plaintiff's claim independent of other victims' claims; under § 1798.85's per-violation structure, however, a single defendant decision — printing SSNs on 50,000 annual enrollment mailers — creates 50,000 separate violations each carrying up to $25,000 civil penalty exposure ($1.25 billion in theoretical aggregate), making the class action a natural vehicle alongside the individual civil action and making the individual plaintiff attorney's § 1798.85 fee petition potentially the gateway to class certification with dramatically higher cumulative relief; the attorney who builds the individual plaintiff's CPPA complaint-date-anchored lodestar has simultaneously documented the roadmap for the class action's parallel development

PURE KETCHUM — Civ. Code § 1798.85 is exclusively California state law with no concurrent federal statute providing mandatory civil attorney fee-shifting for private business SSN display violations; no Ketchum/Dague split: The federal Privacy Act of 1974 (5 U.S.C. § 552a) restricts federal agency SSN use but has no private right of action against private businesses. HIPAA's Privacy Rule (45 C.F.R. § 164.514) requires health plans to implement unique patient identifiers but is enforced exclusively through HHS-OCR administrative enforcement — no private right of action for individual consumers. The Driver's Privacy Protection Act (18 U.S.C. § 2721) restricts disclosure of DMV records but is not a general SSN privacy statute. The full Ketchum v. Moses (24 Cal.4th 1122 (2001)) contingency multiplier analysis applies without federal Dague constraint.

Primary Welch Anchor: Tyler Odyssey Civil Complaint Filing Date

The Tyler Odyssey civil complaint filing date is the primary Welch temporal anchor for the § 1798.85 attorney fee petition lodestar. In SSN privacy cases, the Tyler Odyssey complaint is typically filed after the plaintiff has confirmed the defendant's violation through documentary evidence — the insurance card bearing the SSN member ID, the mailed enrollment packet with the full SSN printed on the first page, or the defendant's online portal that accepted the SSN as a username. The pre-complaint period begins when the client first identifies the § 1798.85 violation and contacts an attorney, and extends through the CPPA complaint filing, the investigation of the defendant's system-wide SSN display practices, and the preparation of the § 1798.85 civil complaint.

The § 1798.85 complaint must allege: the specific violation type (public display, mailed document, card printing, or online portal); the date and manner of the violation; the plaintiff's SSN that was displayed or required; any actual damages suffered (identity theft losses, credit monitoring costs, time spent correcting fraudulent accounts); the per-violation civil penalty claim under § 1798.85(c); and the mandatory attorney fee and costs claim under § 1798.85(b). In class actions, the complaint must additionally allege the class definition (all persons whose SSNs appeared on the defendant's mailed enrollment packets, cards, or online portals during the applicable limitations period) and the numerosity, commonality, and typicality requirements. The Tyler Odyssey complaint filing date establishes the primary Welch anchor for all § 1798.85 attorney time measured from the CPPA secondary anchor through complaint and judgment.

Secondary Institutional Anchor: California Privacy Protection Agency (CPPA) Consumer Complaint Database

The California Privacy Protection Agency (CPPA) Consumer Complaint Database is the secondary institutional anchor in § 1798.85 fee petition cases — and it is THE ONLY secondary institutional anchor in the entire fee-petition-mechanics series found in the CPPA's consumer complaint management system. The CPPA, established by Proposition 24 (2020) and operationalized in July 2021, is California's dedicated privacy enforcement agency with authority to enforce the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and related California privacy statutes including § 1798.85. The CPPA maintains an online consumer complaint submission portal; when a consumer files a § 1798.85 complaint, the CPPA records the submission date, the complainant's identity, the respondent entity name, the alleged violation type, and a complaint reference number in its complaint management database — a California state government record maintained by an independent state agency entirely outside the consumer plaintiff attorney's scheduling control.

The CPPA complaint submission date functions as the secondary Welch anchor in two ways. First, the complaint date establishes that the plaintiff formally notified a California government privacy enforcement authority of the § 1798.85 violation before filing the civil action — demonstrating the seriousness and documentation quality of the claim and establishing the pre-complaint advisory period during which the attorney counseled the client on civil versus regulatory enforcement strategy. Second, if the CPPA opens a formal investigation based on the consumer complaint — issuing a notice of alleged violation or a civil investigative demand to the defendant — those additional CPPA agency actions generate supplemental institutional records (investigation open date, demand letter date) that further extend the secondary anchor documentation and support the Ketchum multiplier analysis by demonstrating the regulatory significance of the defendant's SSN display practice.

Billing Gap 1 — CPPA Complaint Filing, SSN Display Documentation, and Identity Theft Damage Assessment (6.16 hrs/yr = $1,848–$3,080)

The first billing gap arises in the pre-complaint advisory phase — from initial client retention through the Tyler Odyssey civil complaint filing — during which the attorney files the CPPA consumer complaint, documents the defendant's SSN display practice through the violating materials, and assesses any identity theft or credit damage already suffered as a result of the SSN exposure.

  • Filing the CPPA consumer complaint and preserving the complaint submission record as the secondary anchor: The attorney assists the client in filing a § 1798.85 consumer complaint through the CPPA's online portal, documenting the complaint submission date and CPPA complaint reference number as the secondary institutional anchor for the pre-complaint lodestar period; the attorney also advises on whether a concurrent complaint to the California Department of Justice's Privacy Enforcement and Protection Unit or the FTC's identity theft complaint portal is appropriate — each concurrent complaint filing generating an additional institutional record that supplements the CPPA anchor.
  • Preserving and authenticating the violating materials as evidence of the § 1798.85 violation: The attorney preserves the physical or digital violating materials — the insurance card bearing the SSN member ID, the mailed enrollment packet with the full SSN printed on the cover page, or the screenshot of the online portal displaying the SSN as a username — and has each material authenticated through the defendant's records custodian in preparation for trial; the authentication work is frequently concentrated in sessions that are partially untracked because attorneys treat it as document review rather than separately logged advisory work.
  • Assessing identity theft, credit monitoring, and consequential financial damages from the SSN exposure: The attorney reviews the client's credit reports (from all three bureaus) for unauthorized accounts, fraudulent inquiries, or identity fraud incidents that may have occurred since the defendant's SSN display; obtains the client's identity theft report from the FTC's IdentityTheft.gov reporting system; and quantifies actual damages including credit monitoring costs, time spent disputing fraudulent accounts, and any financial losses from identity theft — the consequential damage assessment work is frequently partially untracked because attorneys treat it as intake rather than separately logged advisory time.
Gap 1 Annual Value (CPPA complaint filing, SSN display documentation & identity theft damage assessment)
$1,848–$3,080/yr
7 clients × 2 pre-complaint sessions × 48 min × 55% untracked ≈ 6.16 hrs/yr at $300–$500/hr median solo rate

Billing Gap 2 — Active Litigation: Defendant System Discovery, Class Certification Analysis, and CPPA Investigation Coordination (6.60 hrs/yr = $1,980–$3,300)

The second billing gap arises from the active litigation phase — from the Tyler Odyssey complaint through trial or settlement — during which the attorney conducts discovery on the defendant's SSN display system (identifying all consumers affected and the defendant's timeline for implementing the § 1798.85 violation and any remediation), analyzes class certification feasibility, and coordinates with the CPPA if the agency has opened a parallel investigation.

  • Discovery on the defendant's SSN display system: scope, duration, and number of affected consumers: The attorney serves document requests and interrogatories seeking the defendant's IT system records documenting when the SSN-display practice was implemented, when it was discontinued (if ever), how many consumers received materials or cards with their SSNs displayed, and what internal discussions the defendant had about § 1798.85 compliance before and after the violation period; the IT system records and internal compliance communications are frequently concentrated in large document productions that are partially untracked because attorneys treat bulk document review as a single block rather than separately logged advisory work by topic.
  • Class certification analysis: whether the § 1798.85 violation supports class treatment and how the per-violation penalty aggregates across the class: The attorney analyzes whether the § 1798.85 violation — a single defendant policy decision affecting all members of an identifiable class — meets the commonality, typicality, and predominance requirements for class certification; the per-violation $25,000 civil penalty creates an aggregate exposure that can justify class treatment even when individual actual damages are modest; the class certification analysis requires the attorney to assess the defendant's membership records to determine the precise class size, the limitations period, and whether a class or settlement fund structure is most effective — work that is frequently partially untracked as attorneys treat it as preliminary research rather than separately logged advisory time.
  • Coordinating with the CPPA if the agency opens a formal investigation concurrent with the civil action: When the CPPA opens a formal investigation of the defendant's § 1798.85 SSN display practice, the attorney coordinates with the CPPA's enforcement staff to share documentary evidence of the violation, avoid duplicative discovery, and position the individual civil action as complementary to rather than competitive with the CPPA's regulatory proceeding; the CPPA's investigation can generate a consent order or notice of alleged violation that may be used as evidence in the civil action, and the coordination work — reviewing CPPA correspondence, responding to agency requests, and monitoring the CPPA investigation timeline — is frequently partially untracked because attorneys treat it as administrative coordination rather than billable advisory time.
Gap 2 Annual Value (defendant system discovery, class certification analysis & CPPA investigation coordination)
$1,980–$3,300/yr
5 clients × 3 litigation sessions × 48 min × 55% untracked ≈ 6.60 hrs/yr at $300–$500/hr median solo rate

Billing Gap 3 — Civ. Code § 1798.85 Attorney Fee Petition, Ketchum Multiplier on SSN Privacy Contingency Risk, and Fees-on-Fees (3.67 hrs/yr = $1,100–$1,833)

The third billing gap arises from the § 1798.85 mandatory attorney fee petition — establishing the complete lodestar from the CPPA complaint submission date (secondary anchor) through the Tyler Odyssey civil complaint date (primary Welch anchor) and judgment, briefing the Ketchum multiplier factors for SSN privacy contingency cases, and recovering fees-on-fees for petition preparation.

  • Documenting the § 1798.85 lodestar from the CPPA complaint submission date through the Tyler Odyssey complaint date and judgment: The § 1798.85 fee petition must document the complete lodestar from the CPPA complaint submission date (secondary anchor) through the SSN display documentation and identity theft damage assessment, the Tyler Odyssey complaint filing (primary Welch anchor), system discovery and class certification analysis, CPPA coordination, and judgment; the CPPA complaint date typically predates the Tyler Odyssey complaint by 4–12 weeks — the period during which the attorney filed the CPPA complaint, documented the violation, assessed damages, and prepared the § 1798.85 civil complaint incorporating the CPPA complaint reference number.
  • Ketchum multiplier factors specific to § 1798.85 SSN privacy contingency cases: The Ketchum analysis addresses: (a) the contingency risk of litigating against a large institutional defendant (health plan, employer, retailer) with unlimited litigation resources relative to the individual plaintiff's modest actual damages; (b) the public benefit of deterring systemic SSN display practices that increase identity theft risk for all of the defendant's consumers beyond the named plaintiff; (c) the pre-litigation risk of the violation — when the attorney took the case, the defendant had not yet faced regulatory enforcement and contested that the SSN display practice constituted a § 1798.85 violation; and (d) the results obtained, measured by the actual damages recovered, the civil penalty award, and the systemic remediation (the defendant's discontinuation of SSN-based account identifiers) that the litigation produced.
  • Missouri v. Jenkins fees-on-fees for § 1798.85 petition preparation including the CPPA complaint narrative: All attorney time preparing the § 1798.85 fee petition is recoverable as fees-on-fees — including the CPPA complaint submission narrative establishing the secondary anchor date, the SSN display documentation analysis, the identity theft damage assessment, the PLCM Group market rate analysis, the class certification analysis integrated into the lodestar chronology, the CPPA coordination narrative, and the Ketchum multiplier analysis on SSN privacy contingency risk.
Gap 3 Annual Value (§ 1798.85 fee petition, Ketchum multiplier on SSN privacy contingency risk & fees-on-fees)
$1,100–$1,833/yr
5 clients × 2 fee petition sessions × 40 min × 55% untracked ≈ 3.67 hrs/yr at $300–$500/hr median solo rate

Total Annual Billing Gap — Three-Gap Summary

  • Gap 1 (CPPA complaint filing, SSN display documentation & identity theft damage assessment): 6.16 hrs = $1,848–$3,080/yr
  • Gap 2 (defendant system discovery, class certification analysis & CPPA investigation coordination): 6.60 hrs = $1,980–$3,300/yr
  • Gap 3 (§ 1798.85 fee petition, Ketchum multiplier on SSN privacy contingency risk & fees-on-fees): 3.67 hrs = $1,100–$1,833/yr
  • Total: 16.43 hrs = $4,928–$8,213/yr untracked at $300–$500/hr median California solo practitioner rate

How ClaimHour fits California Civ. Code § 1798.85 SSN Privacy practice

ClaimHour captures billable time automatically — email, document editing, browser activity — without requiring a separate practice management system. For solo California consumer plaintiff attorneys handling Civ. Code § 1798.85 Social Security Number Privacy Act matters, that means the CPPA consumer complaint submission sessions (establishing the secondary institutional anchor), the violating materials documentation and authentication work, the identity theft damage assessment through the client's credit reports and FTC identity theft report, the defendant system discovery and class certification analysis, the California Privacy Protection Agency investigation coordination, and the § 1798.85 mandatory attorney fee petition lodestar documentation — including the CPPA complaint submission date through the Tyler Odyssey primary Welch anchor and the Ketchum multiplier briefing on SSN privacy contingency risk — are all captured in the background. When you build the § 1798.85 mandatory attorney fee lodestar from the CPPA secondary anchor through the Tyler Odyssey primary Welch anchor to judgment, ClaimHour's automatically-logged entries close the gap between what you billed and what you actually did.

Get Early Access