# California Law and Ethics practice questions: Patient information

Five original California Law and Ethics practice questions on patient information, each answered on this page with a rationale and a source.

Last updated: 2026-09-29.

## Question 1

On February 9, 2026, a practice discovers that a phishing attack exposed the unencrypted personal information of 720 California residents. Law enforcement does not request any delay. Which notification plan satisfies California law?

- A. Notify affected patients without unreasonable delay and in no case later than 60 days after discovery.
- B. Notify affected patients within 45 days and post a substitute notice on the practice website.
- C. Notify affected patients within 30 calendar days, and send the Attorney General a sample copy of the notice.
- D. Notify the Dental Board within 7 days and let the Board coordinate the patient notifications.

**Answer C:** Notify affected patients within 30 calendar days, and send the Attorney General a sample copy of the notice.

SB 446 amended Civil Code §1798.82 effective 1/1/2026 — patient notice no later than 30 calendar days after discovery, plus a sample notice to the Attorney General within 15 calendar days of notifying individuals when more than 500 California residents are affected.

**Common trap:** option A is the federal HIPAA clock (60 days) — California's stricter 30-day rule controls; option D confuses breach notice with the Board's separate 7-day adverse-event report.

Source: [SB 446 amending California Civil Code §1798.82 — 30-calendar-day breach-notice deadline effective 1/1/2026; 15-day AG sample notice for breaches…](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB446)

## Question 2

Dr. Patel is closing his practice. His files include the chart of a 52-year-old Medi-Cal (Denti-Cal) beneficiary last treated in March 2024; no audit is pending and the provider contract has ended. What is the minimum retention period for that chart?

- A. At least 10 years from the date of service, audit completion, or contract end, whichever is later.
- B. 7 years from the last date of service under HSC §123145, which applies to every dentist.
- C. 5 years from the date the Denti-Cal provider contract ended, per the plan terms.
- D. 3 years from the last visit, matching the Cal/OSHA training-record retention rule.

**Answer A:** At least 10 years from the date of service, audit completion, or contract end, whichever is later.

WIC §14124.1 requires Medi-Cal (Denti-Cal) provider records to be retained at least 10 years, using the applicable later trigger among service, audit completion, or contract end. HSC §123145's seven-year rule applies only when a provider licensed under HSC §§1205, 1253, 1575, or 1726 ceases operation; the Dental Board has said no general law sets one retention period for every dentist.

**Common trap:** do not convert a limited facility-closure statute into a universal private-dental-office rule.

Source: [California Welfare & Institutions Code §14124.1 — 10-year minimum record retention for Medi-Cal (Denti-Cal) providers](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=WIC&sectionNum=14124.1)

## Question 3

On February 1, 2026, a California dental practice discovers that an unauthorized third party has hacked into its unencrypted local server, compromising the personal information of 650 California residents. Law enforcement does not request a delay for a criminal investigation. Under California law, what is the latest date the practice must notify the affected patients?

- A. February 16, 2026 (within 15 calendar days of discovery).
- B. March 3, 2026 (within 30 calendar days of discovery).
- C. April 2, 2026 (within 60 calendar days of discovery).
- D. There is no fixed date; notice is due "without unreasonable delay."

**Answer B:** March 3, 2026 (within 30 calendar days of discovery).

Effective January 1, 2026, California Senate Bill 446 strictly requires entities to notify affected California residents of a data breach no later than 30 calendar days following discovery. This supersedes the federal HIPAA baseline.

**Common trap:** Choosing 60 days (the federal HIPAA standard), 15 days (which is the timeline for submitting a sample notification to the California Attorney General when a breach impacts more than 500 residents), or the old "without unreasonable delay" phrasing that SB 446 eliminated.

Source: [SB 446 and Civ. Code section 1798.82 California breach-notice update to a 30-calendar-day deadline effective 1/1/2026](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB446)

## Question 4

A patient arrives at a dental office highly agitated. They are currently in collections for a delinquent $3,500 account balance regarding prior implant therapy. The patient presents a legally valid authorization demanding a full copy of their entire clinical record and all radiographs to take to a new provider. The office manager wishes to withhold the records until a payment plan is signed. What is the most appropriate action?

- A. Withhold the records until the payment plan is signed, because the unpaid debt arises from the same course of treatment.
- B. Release only a narrative summary of the chart until the balance is resolved.
- C. Transmit the copies within 15 days, provided the patient pays a reasonable cost-based copying fee, regardless of the prior unpaid balance.
- D. Require the patient to pay the full $3,500 balance plus copying costs before any records are released.

**Answer C:** Transmit the copies within 15 days, provided the patient pays a reasonable cost-based copying fee, regardless of the prior unpaid balance.

California law explicitly bans the "hostage rule." A health care provider is strictly prohibited from withholding patient records because of an unpaid bill for health care services.

**Common trap:** Believing the provider can hold radiographs or physical charts as leverage because the debt is directly related to the provided services, or assuming the dentist's ownership of the physical chart overrides the patient's right of access.

Source: [HSC section 123110 patient inspection, copies, form/format, fees (including the §123110(j) per-page caps under SB 815), and unpaid-balance rule](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC&sectionNum=123110)

## Question 5

A pediatric dental clinic licensed under HSC §1205 permanently ceases operation. Patient X is an unemancipated, private-pay (non-Medi-Cal) minor who was last treated there at age 14 and is now 16. Under HSC §123145, what is the earliest age at which this clinic may dispose of Patient X's record?

- A. 18 years old.
- B. 19 years old.
- C. 21 years old.
- D. 24 years old.

**Answer C:** 21 years old.

When a provider licensed under one of the four HSC provisions listed in §123145 ceases operation, an unemancipated minor's record must be kept at least 1 year after age 18 and never less than 7 years after discharge. Seven years after the age-14 discharge is age 21, which is longer than age 19.

**Common trap:** Applying §123145 to every private dental practice. The provider's HSC §1205 license and cessation of operations are essential facts; the Dental Board has stated that no general law sets one retention period for all dentists. Medi-Cal records follow a separate program rule.

Source: [HSC section 123145 — retention when a provider licensed under HSC §§1205, 1253, 1575, or 1726 ceases operation; not a universal private-dental-office…](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC&sectionNum=123145)

## Next step

[Take the free 15-question practice test](https://dentovio.com/free-practice-test)

Official reference: [Dental Board of California — Law and Ethics Examination](https://www.dbc.ca.gov/applicants/law_and_ethics_exam.shtml). Original exam-style questions written for study, never recalled exam content. Independent educational preparation, not legal advice, and not affiliated with or endorsed by the Dental Board of California. Confirm current requirements with the Board.
