California adds heightened disclosure rules and steep penalties for HIV test results, and — for health plans — specific-authorization rules for genetic test results, on top of HIPAA. What each requires, and which one reaches a practitioner-owned practice.
California's breach law (Civil Code 1798.82) sets a 30-day notice clock for medical and health-insurance data, an Attorney-General filing over 500 residents, and a CDPH rule for licensed facilities — here's how it layers on HIPAA.
How California's Confidentiality of Medical Information Act and related laws layer on top of HIPAA — stricter authorizations, patient lawsuits, breach notice, and sensitive-data rules.
California adds the psychotherapist-patient privilege (Evidence Code 1014), LPS-system confidentiality (Welfare & Institutions Code 5328), and a codified duty to protect (Civil Code 43.92) on top of HIPAA — here's how they fit together.
In California, minors can consent on their own to certain care — mental health, pregnancy, STIs, drug and alcohol treatment. That controls who signs authorizations and whether a parent can access the record.
California's CMIA requires the systems that hold a practice's records — EHR/EMR vendors and certain apps — to segregate reproductive and gender-affirming data, limit access, and block out-of-state disclosure. Civil Code 56.101(c), added by AB 352, expressly excludes providers.
Substance use disorder records in California carry two layers stricter than HIPAA — 42 CFR Part 2 and Health & Safety Code 11845.5. How they interact and which controls.
California's CMIA (Civil Code 56.11) sets stricter rules than HIPAA for a valid medical-information authorization — 14-point type, a standalone signature, a one-year expiration, and nine required elements. Here's the checklist.
California's CMIA reaches beyond doctors and plans. Businesses that hold medical information, and certain reproductive or sexual-health apps, are deemed providers under Civil Code 56.06 — even when they sit outside a HIPAA business-associate relationship.
The California Data Exchange Framework creates data-sharing duties for many practices. Who must participate, and how HIPAA, CMIA, and 42 CFR Part 2 interact.