Get Security Assessment

HIPAA Compliance in California: CCPA, CMIA & State Requirements

California healthcare organizations must comply with federal HIPAA regulations plus multiple state privacy laws that provide stronger protections. This guide explains how California's CCPA, CMIA, and related statutes extend beyond HIPAA requirements.

Quick Answer

California imposes three major privacy frameworks on healthcare data: HIPAA (federal), CCPA/CPRA (consumer privacy rights), and CMIA (medical record confidentiality). California law often requires stricter standards—for example, CMIA gives patients broader rights to access and amend records than HIPAA, and the CCPA applies to any health information of California residents regardless of covered entity status. Healthcare organizations must meet the highest standard in all three frameworks.

How California Law Extends Beyond HIPAA

While HIPAA sets the federal baseline for healthcare privacy, California state law creates additional compliance obligations:

1. California Consumer Privacy Act (CCPA) & CPRA

The CCPA applies to "for-profit entities" that collect California residents' personal information and exceed specified thresholds. The CPRA (effective 2023) broadened protections:

2. Confidentiality of Medical Information Act (CMIA)

California's CMIA (Health & Safety Code §56) provides healthcare-specific protections that exceed HIPAA:

3. California Health & Safety Code Requirements

Additional state statutes impose specific requirements:

Key California State Statutes & References

Health & Safety Code §56 et seq. (CMIA)
The primary state law governing medical information confidentiality. Requires informed written consent for disclosure, restricts use and redisclosure, and grants patients rights to access and amend records.
Health & Safety Code §120975-120995 (Genetic Privacy)
Specific requirements for genetic testing, results, and records. Requires written authorization for genetic testing and restricts disclosure of genetic information.
Health & Safety Code §1595 et seq. (HIV Confidentiality)
Establishes strict confidentiality protections for HIV-related information. Requires specific written authorization for any disclosure of HIV status.
California Consumer Privacy Act (CCPA) - Civil Code §1798.100 et seq.
Grants California consumers rights to know, delete, and opt-out regarding their personal information, with limited exemptions for HIPAA covered entities.
California Privacy Rights Act (CPRA) - Civil Code §1798.140 et seq.
Effective 2023, strengthens CCPA with enhanced consumer rights, additional sensitive data protections, and new regulatory authority for California Attorney General.
California Data Breach Notification Law - Civil Code §1798.82
Requires notification of breaches of unencrypted personal information to affected individuals without unreasonable delay. More stringent timing than HIPAA.

California Attorney General Enforcement

The California Attorney General maintains aggressive enforcement of healthcare privacy laws:

Notable enforcement actions: The California AG has pursued healthcare organizations for CCPA violations, inadequate data security, and delayed breach notifications, resulting in multi-million dollar settlements.

Comparison: HIPAA vs. California State Requirements

Area HIPAA California Law (CMIA/CCPA/CPRA) More Stringent
Access to Records 60 days to provide access 30 days (CMIA); immediate right to access California
Amend Records Can deny amendment; requires dispute resolution Patient right to amend (CMIA); stricter approval standards California
Authorization Required Permissive; includes routine use authorizations Specific written authorization; no blanket forms allowed California
Breach Notification Within 60 days Without unreasonable delay (interpreted as days) California
Scope of Health Data PHI as defined in HIPAA Includes genetic, HIV, mental health, substance abuse information California
Data Security Standards Risk analysis-based reasonable safeguards Reasonable security; state interprets strictly; no single standard Similar (California interpreted strictly)
Sale of Data Generally allowed with authorization CCPA restricts; CPRA prohibits sensitive health data sale California
Consumer Deletion Right No absolute deletion right CPRA grants deletion right (exceptions for medical necessity) California

California-Specific Breach Notification Requirements

California's breach notification law (Civil Code §1798.82) imposes requirements beyond HIPAA:

Notification Timeline

Content Requirements

Breach notices must include:

Notification Methods

Exemptions

California allows no notification if breach involves only encrypted or secured data (with specific encryption standards).

Frequently Asked Questions

Are non-covered HIPAA entities still subject to California healthcare privacy laws? +

Yes. California's CMIA applies to any provider, plan, or clearinghouse handling California resident medical information, even if not covered by HIPAA. Additionally, CCPA/CPRA applies to "for-profit entities"—which can include telehealth startups, health apps, and other non-traditional providers. If your organization processes health information of California residents, you must comply with state law regardless of HIPAA coverage status.

What does "sensitive personal information" include under California CPRA for healthcare? +

Under CPRA, "sensitive personal information" in healthcare contexts includes: genetic data, biometric data, health information (diagnosis, treatment, genetic tests), precise geolocation data, and social security numbers. Unlike HIPAA's narrower PHI definition, CPRA's approach sweeps in broader categories of health-related data. The practical implication: organizations cannot sell or use this data for profiling without explicit opt-in consent under CPRA, even if HIPAA permits it.

Can we use blanket authorization forms for disclosures of health information under California law? +

No. California CMIA (Health & Safety Code §56.11) explicitly prohibits blanket authorizations. Each authorization must be specific, written in plain language, and identify the exact information to be disclosed and the recipient. This is significantly stricter than HIPAA, which permits more general authorization language. Violating this requirement can result in patient lawsuits with statutory damages.

What penalties apply for California healthcare privacy violations? +

Penalties vary by statute: CMIA violations allow private lawsuits with statutory damages; CPRA violations carry civil penalties of $2,500-$7,500 per violation enforced by the California AG; data breach notification violations can result in AG enforcement and restitution. Additionally, HIPAA violations in California may be enforced by the state AG. Penalties have increased significantly in recent years, with healthcare organizations facing settlements in the millions for systematic violations.

Is Your Organization Compliant With California Requirements?

California's overlapping privacy frameworks create complex compliance obligations. Get a professional security assessment to identify gaps in your HIPAA, CMIA, and CCPA compliance.

Get Your Security Assessment