{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:calctapp-a164552-2025-11-26",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:calctapp-a164552-2025-11-26)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-08",
    "fingerprint": "ewai:se:068e13",
    "proof": "sha256:52e15a96ac14340edc5b1b01eded61336387928d1d780ff156be6e5b166ed84b",
    "jurisdiction": "se",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "case_kit",
  "object_id": "case_kit:us:calctapp-a164552-2025-11-26",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/case_kit",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:calctapp-a164552-2025-11-26",
  "source": "NovaCopilot",
  "item": {
    "coverage": {
      "complete": 6,
      "total": 8,
      "label": "6 of 8 components ready",
      "components": {
        "citation_graph": false,
        "precedent": false,
        "outcome": true,
        "provision_link": true,
        "obligation": true,
        "sanction": true,
        "risk": true,
        "conflict": true
      },
      "reasons": {
        "citation_graph": "no_citations_in_text",
        "precedent": "fulltext_not_stored"
      }
    },
    "case_id": "us:calctapp-a164552-2025-11-26",
    "acts": [
      "hipaa",
      "hipaa-security"
    ],
    "components": [
      {
        "type": "citation_graph",
        "status": "gap",
        "ids": [
          "citation_graph:us:calctapp-a164552-2025-11-26"
        ],
        "sha256": "b193233f1dbe6d891f0e083b7f1d9c25ca9e86e8acc91361d6b1247bf97df165"
      },
      {
        "type": "precedent",
        "status": "gap",
        "ids": [],
        "sha256": null
      },
      {
        "type": "outcome",
        "status": "ready",
        "ids": [
          "outcome:us:hipaa"
        ],
        "sha256": "4bfabededc150bd1d206b19ae12344f5437bb9b9450c3d955413d3c93f1fe72f"
      },
      {
        "type": "provision_link",
        "status": "ready",
        "ids": [
          "provision_link:us:hipaa"
        ],
        "sha256": "fa5dcd486d657a7e7108229a64eebd01fd51c92fd46078217ce2e271fa77ad69"
      },
      {
        "type": "obligation",
        "status": "ready",
        "ids": [
          "obligation:us:hipaa-art-164-308-covered-entity",
          "obligation:us:hipaa-art-164-404-covered-entity",
          "obligation:us:hipaa-art-164-406-covered-entity",
          "obligation:us:hipaa-art-164-408-covered-entity",
          "obligation:us:hipaa-art-164-410-business-associate"
        ],
        "sha256": "4846ac7c2e48fa032c0d6b6b69fdbe75a09bbd6f15226a4d05b930ea5ad2e615"
      },
      {
        "type": "sanction",
        "status": "ready",
        "ids": [
          "sanction:us:hipaa-art-1320d-5"
        ],
        "sha256": "cb8ca3c35f6af0b9fc0674178dec680b532425cc9614be13dd02c28c0c91d7de"
      },
      {
        "type": "risk",
        "status": "ready",
        "ids": [
          "risk_chain:us:hipaa"
        ],
        "sha256": "156382122344ed3c6113b99286c83a1ff5b1b167f13d1605d029542fb4fb76c5"
      },
      {
        "type": "conflict",
        "status": "ready",
        "ids": [
          "conflict:us:calctapp-a164552-2025-11-26"
        ],
        "sha256": "565ef9f605a6ea210307da1e4a26df8c424d33a6c07897e0b246d3ae11efb2d5"
      }
    ],
    "parts": [
      {
        "type": "citation_graph",
        "status": "gap",
        "summary": null,
        "reason": "no_citations_in_text",
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:calctapp-a164552-2025-11-26"
        ]
      },
      {
        "type": "precedent",
        "status": "gap",
        "summary": null,
        "reason": "fulltext_not_stored",
        "urls": []
      },
      {
        "type": "outcome",
        "status": "ready",
        "summary": "Sample of 18 judgments under hipaa.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
          "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa"
        ]
      },
      {
        "type": "provision_link",
        "status": "ready",
        "summary": "Provision relations for hipaa.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:hipaa"
        ]
      },
      {
        "type": "obligation",
        "status": "ready",
        "summary": "5 obligations triggered by the applied provisions.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-308-covered-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-404-covered-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-406-covered-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-408-covered-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-410-business-associate"
        ]
      },
      {
        "type": "sanction",
        "status": "ready",
        "summary": "1 sanctions linked to those obligations.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/sanction/us:hipaa-art-1320d-5"
        ]
      },
      {
        "type": "risk",
        "status": "ready",
        "summary": "Risk level medium.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa"
        ]
      },
      {
        "type": "conflict",
        "status": "ready",
        "summary": "Later or earlier judgments that depart from, limit or distinguish this case; empty means none found.",
        "reason": null,
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/conflict/us:calctapp-a164552-2025-11-26"
        ]
      }
    ],
    "gaps": [
      "citation_graph:no_citations_in_text",
      "precedent:fulltext_not_stored"
    ],
    "method": "Each component is loaded from its existing deterministic object. Coverage counts ready components; gaps carry fixed reason codes. No model writes anything.",
    "links": {
      "case": "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:calctapp-a164552-2025-11-26",
      "relations": "https://legal.exploreworldai.com/api/public/v1/relations?id=us%3Acalctapp-a164552-2025-11-26",
      "changes": "https://legal.exploreworldai.com/api/public/v1/case-kits/changes"
    },
    "hash": "5a0773f76dd7144f4e50b05f0bb801c2f51b322aa3f987a5070b69f8c207702f",
    "extended": {
      "coverage": {
        "complete": 2,
        "total": 4,
        "label": "2 of 4 extended components ready",
        "all_components": {
          "complete": 8,
          "of": 12
        }
      },
      "parts": [
        {
          "type": "outcome_pattern",
          "status": "gap",
          "summary": null,
          "reason": "insufficient_cases",
          "urls": [],
          "sha256": null
        },
        {
          "type": "timeline",
          "status": "gap",
          "summary": null,
          "reason": "not_in_register",
          "urls": [],
          "sha256": null
        },
        {
          "type": "role_duties",
          "status": "ready",
          "summary": "2 roles, 5 duties.",
          "reason": null,
          "urls": [],
          "sha256": "98d8da5355a3195ca69a71bd1f0c3ae64f89707d52a685c939d89f0f4d7c9c1e"
        },
        {
          "type": "compliance_checklist",
          "status": "ready",
          "summary": "5 checks across 2 roles.",
          "reason": null,
          "urls": [],
          "sha256": "1add2bd94d648e0235027f536ada38741616cfcbaffa426d056b71a447b89d51"
        }
      ],
      "role_duties": [
        {
          "role": "business-associate",
          "obligations": [
            {
              "id": "obligation:us:hipaa-art-164-410-business-associate",
              "act": "hipaa",
              "article": "164.410",
              "must_do": "Notify the covered entity following discovery of a breach of unsecured protected health information.",
              "deadline": "60 days",
              "url": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-410-business-associate"
            }
          ]
        },
        {
          "role": "covered-entity",
          "obligations": [
            {
              "id": "obligation:us:hipaa-art-164-404-covered-entity",
              "act": "hipaa",
              "article": "164.404",
              "must_do": "Notify each affected individual of a breach of unsecured protected health information without unreasonable delay.",
              "deadline": "60 days",
              "url": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-404-covered-entity"
            },
            {
              "id": "obligation:us:hipaa-art-164-406-covered-entity",
              "act": "hipaa",
              "article": "164.406",
              "must_do": "Notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction.",
              "deadline": "60 days",
              "url": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-406-covered-entity"
            },
            {
              "id": "obligation:us:hipaa-art-164-408-covered-entity",
              "act": "hipaa",
              "article": "164.408",
              "must_do": "Notify the Secretary of HHS of breaches of unsecured protected health information.",
              "deadline": "60 days",
              "url": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-408-covered-entity"
            },
            {
              "id": "obligation:us:hipaa-art-164-308-covered-entity",
              "act": "hipaa",
              "article": "164.308",
              "must_do": "Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information.",
              "deadline": null,
              "url": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-308-covered-entity"
            }
          ]
        }
      ],
      "compliance_checklist": [
        {
          "role": "business-associate",
          "steps": [
            {
              "step": 1,
              "check": "Notify the covered entity following discovery of a breach of unsecured protected health information.",
              "provision": "hipaa 164.410",
              "deadline": "60 days",
              "exceptions": 0,
              "if_not": [
                "sanction:us:hipaa-art-1320d-5"
              ],
              "done": false
            }
          ]
        },
        {
          "role": "covered-entity",
          "steps": [
            {
              "step": 1,
              "check": "Notify each affected individual of a breach of unsecured protected health information without unreasonable delay.",
              "provision": "hipaa 164.404",
              "deadline": "60 days",
              "exceptions": 0,
              "if_not": [
                "sanction:us:hipaa-art-1320d-5"
              ],
              "done": false
            },
            {
              "step": 2,
              "check": "Notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction.",
              "provision": "hipaa 164.406",
              "deadline": "60 days",
              "exceptions": 0,
              "if_not": [
                "sanction:us:hipaa-art-1320d-5"
              ],
              "done": false
            },
            {
              "step": 3,
              "check": "Notify the Secretary of HHS of breaches of unsecured protected health information.",
              "provision": "hipaa 164.408",
              "deadline": "60 days",
              "exceptions": 0,
              "if_not": [
                "sanction:us:hipaa-art-1320d-5"
              ],
              "done": false
            },
            {
              "step": 4,
              "check": "Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information.",
              "provision": "hipaa 164.308",
              "deadline": null,
              "exceptions": 0,
              "if_not": [
                "sanction:us:hipaa-art-1320d-5"
              ],
              "done": false
            }
          ]
        }
      ],
      "answers": [
        {
          "question": "What applies?",
          "answer_from": [
            "provision_link",
            "obligation"
          ],
          "urls": [
            "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:hipaa",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-308-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-404-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-406-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-408-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-410-business-associate"
          ],
          "answerable": true
        },
        {
          "question": "Which obligations exist?",
          "answer_from": [
            "obligation",
            "role_duties"
          ],
          "urls": [
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-308-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-404-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-406-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-408-covered-entity",
            "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-410-business-associate"
          ],
          "answerable": true
        },
        {
          "question": "Which sanctions can be triggered?",
          "answer_from": [
            "sanction"
          ],
          "urls": [
            "https://legal.exploreworldai.com/api/public/v1/obj/sanction/us:hipaa-art-1320d-5"
          ],
          "answerable": true
        },
        {
          "question": "What is the risk?",
          "answer_from": [
            "risk"
          ],
          "urls": [
            "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa"
          ],
          "answerable": true
        },
        {
          "question": "Which precedent supports this?",
          "answer_from": [
            "precedent",
            "citation_graph"
          ],
          "urls": [],
          "answerable": false
        },
        {
          "question": "How do courts usually rule?",
          "answer_from": [
            "outcome",
            "outcome_pattern",
            "conflict"
          ],
          "urls": [
            "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
            "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa",
            "https://legal.exploreworldai.com/api/public/v1/obj/conflict/us:calctapp-a164552-2025-11-26"
          ],
          "answerable": true
        },
        {
          "question": "What must a given role do to comply?",
          "answer_from": [
            "role_duties",
            "compliance_checklist",
            "timeline"
          ],
          "urls": [],
          "answerable": false
        }
      ],
      "note": "Additive fields outside hash. Core components and hash are unchanged."
    }
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:calctapp-a164552-2025-11-26",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:calctapp-a164552-2025-11-26",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:calctapp-a164552-2025-11-26"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:calctapp-a164552-2025-11-26?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "us:calctapp-a164552-2025-11-26"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=us",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:52e15a96ac14340edc5b1b01eded61336387928d1d780ff156be6e5b166ed84b",
  "version": "legal-2026-10-08",
  "expires": "2026-10-09T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-08+legal-2026-10-08+2026-10-08T18:37:18",
    "content_hash": "sha256:52e15a96ac14340edc5b1b01eded61336387928d1d780ff156be6e5b166ed84b",
    "revalidate_after": "2026-10-08T19:54:13.353Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:calctapp-a164552-2025-11-26",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}