HIV and genetic testing in California: the consent and disclosure rules that layer on HIPAA
California adds heightened disclosure rules and steep penalties for HIV test results, and — for health plans — specific-authorization rules for genetic test results, on top of HIPAA. What each requires, and which one reaches a practitioner-owned practice.
By CoreFolio
12-minute read
California singles out two categories of sensitive health information for handling that goes beyond the federal Health Insurance Portability and Accountability Act (HIPAA): HIV and genetic information. For HIV, California requires informed consent to test and wraps test results in a heightened disclosure rule backed by civil and criminal penalties (Health and Safety Code §§ 120980, 120990). For genetic data, a specific written authorization is required to disclose genetic test results held by a health care service plan (Civil Code § 56.17), and the California Genetic Information Privacy Act (CalGINA) governs direct-to-consumer testing companies. Neither replaces HIPAA; both add a step on top of it.
The HIV rule reaches ordinary practices, not just specialists — a primary-care office that orders an HIV screen is inside it. The genetic-authorization rule in § 56.17 is narrower: it is written for health plans, so a treating practice that orders a pharmacogenetic test releases those results under the CMIA's general authorization (Civil Code § 56.11), not under a separate genetic form. This article explains what each rule requires, where it is genuinely stricter than HIPAA, and how the pieces fit together.
Key takeaways
- Before an HIV test, a California provider must inform the patient it is planned, give information, note that treatment options exist, and advise the right to decline; consent may be oral or written but must be documented (Health and Safety Code § 120990).1
- California restricts disclosure of HIV test results to a written authorization or a statutory exception, with civil penalties of up to $2,500 for negligent disclosure and $5,000 to $10,000 for willful or malicious disclosure (§ 120980).2
- HIV and AIDS public health records held by state or local public health agencies are separately confidential under the AIDS Public Health Records Confidentiality Act (§ 121025).3
- Genetic test results held by a health care service plan require a specific written authorization to disclose, with their own conditions and penalties (Civil Code § 56.17). A practitioner-owned practice is not inside § 56.17 — it releases genetic test results in a patient's record under the CMIA's general authorization (Civil Code § 56.11).4
- CalGINA (Civil Code §§ 56.18–56.186) governs direct-to-consumer genetic testing companies and largely exempts genetic information a provider handles as medical information under the CMIA or HIPAA.5
HIV: informed consent to test, and the notice-and-decline step
California does not require a separate, signed HIV-specific consent form. Assembly Bill 682 repealed that requirement in 2007 because a dedicated written consent had become a barrier to routine screening.1 What the law requires now is informed consent plus a specific pre-test notice. Under Health and Safety Code § 120990, before ordering an HIV test a medical care provider must inform the patient the test is planned, provide information about the test, inform the patient that treatment options exist for someone who tests positive, and advise the patient of the right to decline; if the patient declines, the provider notes that in the record (§ 120990(a)).1 That pre-test notice-and-decline step is the ordering provider's duty. A separate requirement governs the consent to actually run the test: no one may administer an HIV test without the patient's informed consent, which "may be provided orally or in writing," and the person administering the test — who may or may not be the ordering provider — must document that consent in the client's medical record (§ 120990(c)). The section does not apply to a clinical laboratory (§ 120990(i)). A patient who independently requests an HIV test need not be given the pre-test information.1
So a California practice can meet the requirement through a documented general consent — but it has to actually give the notice, honor a decline, and record that consent was obtained.
HIV: the heightened disclosure rule and its penalties
Where California is clearly stricter than HIPAA on HIV is disclosure of the result. Health and Safety Code § 120980 makes an unauthorized disclosure of HIV test results, in a manner that identifies the person tested, a penalty-bearing act. A person who negligently discloses such results, except pursuant to a written authorization or a specific statutory exception, is subject to "a civil penalty in an amount not to exceed two thousand five hundred dollars ($2,500) plus court costs," paid to the subject of the test.2 A person who willfully or maliciously discloses them is subject to "a civil penalty in an amount not less than five thousand dollars ($5,000) and not more than ten thousand dollars ($10,000) plus court costs," and a disclosure that results in economic, bodily, or psychological harm can be a misdemeanor.2 The subject may also recover actual damages.
Two points make this precise. First, the penalty attaches to the identifying disclosure of a test result without authorization — it is a specific, named exposure on top of HIPAA's general enforcement. Second, unlike the CMIA's patient private right of action under Civil Code § 56.36, these are statutory penalties tied to HIV test results specifically. For a practice, the operational rule is simple: treat HIV results as requiring a valid written authorization before any identifying disclosure that a statutory exception does not cover.
HIV and AIDS public health records (§ 121025)
California layers a separate confidentiality statute on the public health side. The AIDS Public Health Records Confidentiality Act, Health and Safety Code § 121025, provides that public health records relating to HIV or AIDS that contain personally identifying information and were "developed or acquired by a state or local public health agency, or an agent of that agency, are confidential and shall not be disclosed," except as otherwise provided by law for public health purposes or pursuant to a written authorization by the subject of the record.3 These records are also generally protected from being disclosed, discovered, or compelled to be produced in a legal proceeding.3
This statute is aimed at public health agencies and their agents, not at every clinical provider. A private practice's own HIV test records are governed by the CMIA and § 120980, while § 121025 protects the surveillance and reporting records held on the public health side. Knowing which set a given record sits in is the practical question.
Genetic test results: a health-plan rule (§ 56.17), and what a practice uses
Genetic information gets its own California rule inside the CMIA — but read the scope line first. Civil Code § 56.17 sits in a chapter titled "Disclosure of Genetic Test Results by a Health Care Service Plan," and subdivision (a) says the section applies to the disclosure of genetic test results by a health care service plan contained in an applicant's or enrollee's medical records.4 For a plan inside that section, disclosure needs a written authorization meeting specific conditions — dated and signed, in 14-point type, specifying the information, the disclosing party, and the recipients — and a separate written authorization is required for each disclosure.4 The section carries its own penalties: up to $1,000 for a negligent disclosure and $1,000 to $5,000 for a willful one, plus court costs.4
A practitioner-owned practice is not inside § 56.17. California imposes no separate provider genetic-authorization form. When a practice discloses genetic test results in a patient's record, those results are confidential medical information released under the CMIA's general authorization (Civil Code § 56.11) — the same instrument the practice uses for other medical information. Practically: use one CMIA-compliant authorization, and do not assume you owe patients a distinct "genetic" form the way a health plan does.
CalGINA and direct-to-consumer testing (§ 56.18)
California also regulates the consumer-testing market. The California Genetic Information Privacy Act (CalGINA), Civil Code §§ 56.18–56.186, applies to direct-to-consumer (DTC) genetic testing companies — businesses that sell consumer-initiated genetic testing products or services and analyze the resulting genetic data.5 CalGINA requires a company to obtain the consumer's express consent — an affirmative authorization in response to a clear, prominent notice, which cannot be inferred from inaction or obtained through "dark patterns" — for the collection, use, and disclosure of genetic data, with separate consent for defined activities such as transfer to third parties and marketing.5
Crucially, CalGINA largely exempts medical information already governed by the CMIA and protected health information governed by HIPAA, and providers and covered entities to the extent they handle genetic information the same way they handle medical information.5 So a typical clinical practice is governed by the CMIA — its general authorization under § 56.11 — for genetic test results, not by CalGINA and not by the plan-specific rule in § 56.17. A vendor a practice uses, or a consumer-facing testing product a patient brings in, may fall squarely inside CalGINA.
The federal genetic-privacy backdrop
Two federal rules sit alongside California's. HIPAA itself bars a health plan from using or disclosing genetic information for underwriting purposes (45 CFR § 164.502(a)(5)(i)), and the federal Genetic Information Nondiscrimination Act (GINA) restricts the use of genetic information in health insurance and employment.6 California's specific-authorization rule for genetic test results is additive to these — it governs the disclosure step for records a provider holds.
How these layer with HIPAA
HIPAA's preemption framework preserves the California rules. A state provision that relates to the privacy of individually identifiable health information and is more stringent than the federal standard is not preempted, under 45 CFR § 160.203.7 The HIV disclosure rule and its penalties, and the genetic-results authorization rule, are more protective than HIPAA's general requirements, so they control where they reach. The HIV notice-and-decline step is an added procedural requirement rather than a narrower disclosure gate, but it is a real obligation a HIPAA-only workflow will miss.
The reconciling principle is the same one that governs the rest of California's overlay: comply with HIPAA and with the stricter California step. Following the California rule never violates HIPAA, because HIPAA permits — but does not compel — the disclosures at issue.
What this means for your forms and procedures
These rules land on your forms and procedures — where they meet HIPAA's authorization requirements at 45 CFR § 164.508 and the policies and procedures § 164.530(i) requires a practice to maintain. A practice that orders HIV tests or handles genetic test results should reflect:
- an HIV informed-consent-and-decline step in the testing workflow, captured in the general consent or a dedicated notice, and documented (§ 120990);
- disclosure controls for HIV results that require a valid written authorization before any identifying disclosure a statutory exception does not cover (§ 120980);
- genetic test results released on your CMIA general authorization (Civil Code § 56.11) — the plan-specific § 56.17 form does not apply to a treating practice; and
- staff training so intake and testing staff apply the sensitive-category steps consistently.
A documentation set that treats HIPAA as the only applicable law is incomplete for a California practice that touches either category.
What California practices should do this month
- Build the HIV notice step into intake. Confirm your general consent or intake process gives the § 120990 pre-test information, records the opportunity to decline, and documents that consent was obtained.
- Set HIV disclosure rules. Require a valid written authorization before any identifying disclosure of HIV test results that a statutory exception does not cover, and train staff on the § 120980 penalties.
- Release genetic test results on your CMIA general authorization. For a practitioner-owned practice, genetic test results are medical information disclosed under Civil Code § 56.11 — the § 56.17 conditions bind health care service plans, not treating practices, so you do not need a separate genetic form.
- Check your vendors and consumer products. Flag whether any testing vendor or consumer-facing product falls under CalGINA, and confirm the CMIA governs the results your practice holds.
- Write it into your procedures. Record the HIV and genetic obligations in the written policies and procedures that govern consent and disclosure.
These steps prepare the ground. Turning them into forms and procedures a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.
Sources
Footnotes
-
Cal. Health & Safety Code § 120990 (consent for an HIV test — pre-test information and the right to decline; informed consent may be oral or written but must be documented in the medical record; exception where the patient independently requests the test; the prior separate written-consent requirement was repealed by AB 682 in 2007). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=120990. ↩ ↩2 ↩3 ↩4
-
Cal. Health & Safety Code § 120980 (unauthorized disclosure of HIV test results in an identifying manner — negligent disclosure civil penalty not to exceed $2,500; willful or malicious disclosure not less than $5,000 and not more than $10,000, plus court costs paid to the subject; misdemeanor where the disclosure results in economic, bodily, or psychological harm; actual damages recoverable). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=120980. ↩ ↩2 ↩3
-
Cal. Health & Safety Code § 121025 (AIDS Public Health Records Confidentiality Act — HIV/AIDS public health records with personally identifying information developed or acquired by a state or local public health agency are confidential and not disclosed except for public health purposes provided by law or on written authorization by the subject; not disclosable, discoverable, or compelled to be produced in a proceeding). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=121025. ↩ ↩2 ↩3
-
Cal. Civ. Code § 56.17 — Chapter 2.5, "Disclosure of Genetic Test Results by a Health Care Service Plan." Subdivision (a): the section applies to disclosure of genetic test results by a health care service plan contained in an applicant's or enrollee's medical records. For a plan, written authorization is required (14-point type, dated and signed, specifying the information, disclosing party, and recipients), with a separate authorization for each disclosure; negligent disclosure civil penalty up to $1,000, willful $1,000 to $5,000, plus court costs. The section does not impose a provider-specific genetic-authorization form; a treating practice releases genetic test results under the CMIA general authorization (Cal. Civ. Code § 56.11). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.17. ↩ ↩2 ↩3 ↩4
-
California Genetic Information Privacy Act (CalGINA), Cal. Civ. Code §§ 56.18–56.186 (added by SB 41) — direct-to-consumer genetic testing companies must obtain a consumer's express consent for the collection, use, and disclosure of genetic data, with separate consent for defined activities; the chapter exempts medical information governed by the CMIA and protected health information governed by HIPAA, and providers and covered entities to the extent they handle genetic information as medical information or protected health information. California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.18. ↩ ↩2 ↩3 ↩4
-
45 CFR § 164.502(a)(5)(i) (HIPAA — prohibition on health plans using or disclosing genetic information for underwriting purposes, implementing the Genetic Information Nondiscrimination Act). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.502 ↩
-
45 CFR § 160.203 (preemption of contrary State law; the "more stringent" exception for state privacy provisions). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-160.203 ↩