HIV and genetic testing in California: the consent and disclosure rules that layer on HIPAA
California adds heightened disclosure rules and steep penalties for HIV test results, and specific-authorization rules for genetic test results, on top of HIPAA. What each requires.
By CoreFolio
11-minute read
California singles out two categories of sensitive health information for handling that goes beyond the federal Health Insurance Portability and Accountability Act (HIPAA): HIV and genetic information. For HIV, California requires informed consent to test and wraps test results in a heightened disclosure rule backed by civil and criminal penalties (Health and Safety Code §§ 120980, 120990). For genetic data, a specific written authorization is required to disclose genetic test results held by a provider or plan (Civil Code § 56.17), and the California Genetic Information Privacy Act (CalGINA) governs direct-to-consumer testing companies. Neither replaces HIPAA; both add a step on top of it.
These rules reach ordinary practices, not just specialists. A primary-care office that orders an HIV screen, or a clinic that collects a cheek swab for a pharmacogenetic test, is inside them. This article explains what each rule requires, where it is genuinely stricter than HIPAA, and how the pieces fit together.
Key takeaways
- Before an HIV test, a California provider must inform the patient it is planned, give information, note that treatment options exist, and advise the right to decline; consent may be oral or written but must be documented (Health and Safety Code § 120990).1
- California restricts disclosure of HIV test results to a written authorization or a statutory exception, with civil penalties of up to $2,500 for negligent disclosure and $5,000 to $10,000 for willful or malicious disclosure (§ 120980).2
- HIV and AIDS public health records held by state or local public health agencies are separately confidential under the AIDS Public Health Records Confidentiality Act (§ 121025).3
- Genetic test results in a person's medical records require a specific written authorization to disclose, with its own conditions and penalties (Civil Code § 56.17).4
- CalGINA (Civil Code §§ 56.18–56.186) governs direct-to-consumer genetic testing companies and largely exempts genetic information a provider handles as medical information under the CMIA or HIPAA.5
HIV: informed consent to test, and the notice-and-decline step
California does not require a separate, signed HIV-specific consent form. Assembly Bill 682 repealed that requirement in 2007 because a dedicated written consent had become a barrier to routine screening.1 What the law requires now is informed consent plus a specific pre-test notice. Under Health and Safety Code § 120990, before ordering an HIV test a medical care provider must inform the patient the test is planned, provide information about the test, inform the patient that treatment options exist for someone who tests positive, and advise the patient of the right to decline; if the patient declines, the provider notes that in the record (§ 120990(a)).1 That pre-test notice-and-decline step is the ordering provider's duty. A separate requirement governs the consent to actually run the test: no one may administer an HIV test without the patient's informed consent, which "may be provided orally or in writing," and the person administering the test — who may or may not be the ordering provider — must document that consent in the client's medical record (§ 120990(c)). The section does not apply to a clinical laboratory (§ 120990(i)). A patient who independently requests an HIV test need not be given the pre-test information.1
So a California practice can meet the requirement through a documented general consent — but it has to actually give the notice, honor a decline, and record that consent was obtained.
HIV: the heightened disclosure rule and its penalties
Where California is clearly stricter than HIPAA on HIV is disclosure of the result. Health and Safety Code § 120980 makes an unauthorized disclosure of HIV test results, in a manner that identifies the person tested, a penalty-bearing act. A person who negligently discloses such results, except pursuant to a written authorization or a specific statutory exception, is subject to "a civil penalty in an amount not to exceed two thousand five hundred dollars ($2,500) plus court costs," paid to the subject of the test.2 A person who willfully or maliciously discloses them is subject to "a civil penalty in an amount not less than five thousand dollars ($5,000) and not more than ten thousand dollars ($10,000) plus court costs," and a disclosure that results in economic, bodily, or psychological harm can be a misdemeanor.2 The subject may also recover actual damages.
Two points make this precise. First, the penalty attaches to the identifying disclosure of a test result without authorization — it is a specific, named exposure on top of HIPAA's general enforcement. Second, unlike the CMIA's patient private right of action under Civil Code § 56.36, these are statutory penalties tied to HIV test results specifically. For a practice, the operational rule is simple: treat HIV results as requiring a valid written authorization before any identifying disclosure that a statutory exception does not cover.
HIV and AIDS public health records (§ 121025)
California layers a separate confidentiality statute on the public health side. The AIDS Public Health Records Confidentiality Act, Health and Safety Code § 121025, provides that public health records relating to HIV or AIDS that contain personally identifying information and were "developed or acquired by a state or local public health agency, or an agent of that agency, are confidential and shall not be disclosed," except as otherwise provided by law for public health purposes or pursuant to a written authorization by the subject of the record.3 These records are also generally protected from being disclosed, discovered, or compelled to be produced in a legal proceeding.3
This statute is aimed at public health agencies and their agents, not at every clinical provider. A private practice's own HIV test records are governed by the CMIA and § 120980, while § 121025 protects the surveillance and reporting records held on the public health side. Knowing which set a given record sits in is the practical question.
Genetic test results held by a provider or plan (§ 56.17)
Genetic information gets its own California rule inside the CMIA. Civil Code § 56.17 applies to the disclosure of genetic test results contained in a patient's or enrollee's medical records and requires a written authorization meeting specific conditions before those results are disclosed to a third party in an identifying manner.4 The authorization conditions track the CMIA authorization standard — dated and signed, specifying the information, the disclosing party, and the recipients — and the statute requires a separate written authorization for each disclosure of the test results.4
The section is backed by its own penalties: a person who negligently discloses genetic test results without a qualifying authorization is subject to a civil penalty up to $1,000, and a willful disclosure to a penalty of $1,000 to $5,000, plus court costs paid to the subject.4 For a practice, the rule is that genetic test results are not disclosed on a general medical authorization — they need authorization written to the genetic-results standard.
CalGINA and direct-to-consumer testing (§ 56.18)
California also regulates the consumer-testing market. The California Genetic Information Privacy Act (CalGINA), Civil Code §§ 56.18–56.186, applies to direct-to-consumer (DTC) genetic testing companies — businesses that sell consumer-initiated genetic testing products or services and analyze the resulting genetic data.5 CalGINA requires a company to obtain the consumer's express consent — an affirmative authorization in response to a clear, prominent notice, which cannot be inferred from inaction or obtained through "dark patterns" — for the collection, use, and disclosure of genetic data, with separate consent for defined activities such as transfer to third parties and marketing.5
Crucially, CalGINA largely exempts medical information already governed by the CMIA and protected health information governed by HIPAA, and providers and covered entities to the extent they handle genetic information the same way they handle medical information.5 So a typical clinical practice is governed by the CMIA and § 56.17 for genetic test results, not by CalGINA — but a vendor a practice uses, or a consumer-facing testing product a patient brings in, may fall squarely inside CalGINA.
The federal genetic-privacy backdrop
Two federal rules sit alongside California's. HIPAA itself bars a health plan from using or disclosing genetic information for underwriting purposes (45 CFR § 164.502(a)(5)(i)), and the federal Genetic Information Nondiscrimination Act (GINA) restricts the use of genetic information in health insurance and employment.6 California's specific-authorization rule for genetic test results is additive to these — it governs the disclosure step for records a provider holds.
How these layer with HIPAA
HIPAA's preemption framework preserves the California rules. A state provision that relates to the privacy of individually identifiable health information and is more stringent than the federal standard is not preempted, under 45 CFR § 160.203.7 The HIV disclosure rule and its penalties, and the genetic-results authorization rule, are more protective than HIPAA's general requirements, so they control where they reach. The HIV notice-and-decline step is an added procedural requirement rather than a narrower disclosure gate, but it is a real obligation a HIPAA-only workflow will miss.
The reconciling principle is the same one that governs the rest of California's overlay: comply with HIPAA and with the stricter California step. Following the California rule never violates HIPAA, because HIPAA permits — but does not compel — the disclosures at issue.
What this means for your forms and procedures
These rules land on your forms and procedures — where they meet HIPAA's authorization requirements at 45 CFR § 164.508 and the policies and procedures § 164.530(i) requires a practice to maintain. A practice that orders HIV tests or handles genetic test results should reflect:
- an HIV informed-consent-and-decline step in the testing workflow, captured in the general consent or a dedicated notice, and documented (§ 120990);
- disclosure controls for HIV results that require a valid written authorization before any identifying disclosure a statutory exception does not cover (§ 120980);
- a genetic-results authorization that meets Civil Code § 56.17 before genetic test results are disclosed; and
- staff training so intake and testing staff apply the sensitive-category steps consistently.
A documentation set that treats HIPAA as the only applicable law is incomplete for a California practice that touches either category.
What California practices should do this month
- Build the HIV notice step into intake. Confirm your general consent or intake process gives the § 120990 pre-test information, records the opportunity to decline, and documents that consent was obtained.
- Set HIV disclosure rules. Require a valid written authorization before any identifying disclosure of HIV test results that a statutory exception does not cover, and train staff on the § 120980 penalties.
- Use a genetic-results authorization. For genetic test results, adopt an authorization that meets Civil Code § 56.17 and do not release results on a general medical authorization.
- Check your vendors and consumer products. Flag whether any testing vendor or consumer-facing product falls under CalGINA, and confirm the CMIA governs the results your practice holds.
- Write it into your procedures. Record the HIV and genetic obligations in the written policies and procedures that govern consent and disclosure.
These steps prepare the ground. Turning them into forms and procedures a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.
Sources
Footnotes
-
Cal. Health & Safety Code § 120990 (consent for an HIV test — pre-test information and the right to decline; informed consent may be oral or written but must be documented in the medical record; exception where the patient independently requests the test; the prior separate written-consent requirement was repealed by AB 682 in 2007). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=120990. ↩ ↩2 ↩3 ↩4
-
Cal. Health & Safety Code § 120980 (unauthorized disclosure of HIV test results in an identifying manner — negligent disclosure civil penalty not to exceed $2,500; willful or malicious disclosure not less than $5,000 and not more than $10,000, plus court costs paid to the subject; misdemeanor where the disclosure results in economic, bodily, or psychological harm; actual damages recoverable). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=120980. ↩ ↩2 ↩3
-
Cal. Health & Safety Code § 121025 (AIDS Public Health Records Confidentiality Act — HIV/AIDS public health records with personally identifying information developed or acquired by a state or local public health agency are confidential and not disclosed except for public health purposes provided by law or on written authorization by the subject; not disclosable, discoverable, or compelled to be produced in a proceeding). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=121025. ↩ ↩2 ↩3
-
Cal. Civ. Code § 56.17 (disclosure of genetic test results contained in a patient's or enrollee's medical records — written authorization required, with a separate authorization for each disclosure; negligent disclosure civil penalty up to $1,000, willful disclosure $1,000 to $5,000, plus court costs paid to the subject). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.17. ↩ ↩2 ↩3 ↩4
-
California Genetic Information Privacy Act (CalGINA), Cal. Civ. Code §§ 56.18–56.186 (added by SB 41) — direct-to-consumer genetic testing companies must obtain a consumer's express consent for the collection, use, and disclosure of genetic data, with separate consent for defined activities; the chapter exempts medical information governed by the CMIA and protected health information governed by HIPAA, and providers and covered entities to the extent they handle genetic information as medical information or protected health information. California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.18. ↩ ↩2 ↩3 ↩4
-
45 CFR § 164.502(a)(5)(i) (HIPAA — prohibition on health plans using or disclosing genetic information for underwriting purposes, implementing the Genetic Information Nondiscrimination Act). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.502 ↩
-
45 CFR § 160.203 (preemption of contrary State law; the "more stringent" exception for state privacy provisions). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-160.203 ↩