Skip to main content
CoreFolioHIPAA
California

Medi-Cal and managed-care member data: the privacy layers a California provider inherits

Serving Medi-Cal patients adds confidentiality duties beyond HIPAA — Welfare & Institutions Code 14100.2, the Medi-Cal records rule, and DHCS managed-care contract terms. What each requires.

By CoreFolio

9-minute read

A California practice that serves Medi-Cal patients answers to more than the federal Health Insurance Portability and Accountability Act (HIPAA). Medi-Cal — California's Medicaid program, administered by the Department of Health Care Services (DHCS) — carries its own confidentiality statute, its own records regulation, and a managed-care contract structure that pushes privacy and security terms down from DHCS to health plans and then to the providers in their networks. Each layer sits on top of HIPAA, and where a layer is stricter, it is the one you follow.

This article maps the layers a Medi-Cal provider or managed-care subcontractor inherits: Welfare and Institutions Code § 14100.2, the DHCS records rule at 22 CCR § 51009, and the plan-contract terms that make HIPAA compliance a contractual as well as a legal duty. It is written for the practice trying to understand what it signed when it joined a Medi-Cal plan's network.

Key takeaways

  • Welfare and Institutions Code § 14100.2 makes Medi-Cal applicant and recipient information confidential and usable only for purposes directly connected with administering the Medi-Cal program; knowing unauthorized release or possession is a misdemeanor.1
  • The safeguarded information expressly includes names, addresses, medical services, social and economic circumstances, and medical data including diagnosis and history (§ 14100.2(b)).1
  • 22 CCR § 51009 bars releasing an individual Medi-Cal beneficiary's medical records without the written consent of the beneficiary or personal representative, while allowing program-administration exchanges and de-identified summary data.2
  • Medi-Cal Managed Care Plans are HIPAA covered entities, and the DHCS contract requires them to comply with the HIPAA Privacy and Security Rules and flow those duties down to network providers and subcontractors.3
  • Serving Medi-Cal patients does not replace HIPAA — it adds the state confidentiality statute, the records rule, and your plan-contract terms on top of the federal floor (45 CFR § 160.203).4

Layer one: the Medi-Cal confidentiality statute (§ 14100.2)

The foundational rule is Welfare and Institutions Code § 14100.2. Under subdivision (a), all types of information — written or oral — concerning a person, made or kept by a public officer or agency in connection with administering Medi-Cal (and the related managed-care and specialty chapters) for which the state receives federal Title XIX funds, is confidential and "shall not be open to examination other than for purposes directly connected with the administration of the Medi-Cal program."1

Subdivision (b) spells out what that safeguarded information includes: names and addresses, medical services provided, social and economic conditions or circumstances, agency evaluations of personal information, and medical data, including diagnosis and past history of disease or disability.1 And the statute has teeth — a person who knowingly releases or possesses that confidential information without authorization is guilty of a misdemeanor.1

The statute is written primarily to public officers and agencies, but its reach matters to providers because it defines the confidentiality regime the whole program operates under, and its "purposes directly connected with administration" standard is the lens DHCS applies to the data flowing through its plans and providers.

Layer two: the Medi-Cal records regulation (22 CCR § 51009)

DHCS's implementing regulation is more direct about a provider's records. Title 22 of the California Code of Regulations, § 51009, provides that all individual medical records of Medi-Cal beneficiaries acquired by providers, the department, other state or local agencies, or contracting administrative-service organizations are confidential and shall not be released without the written consent of the beneficiary or the beneficiary's personal representative.2

The rule is not absolute. It expressly permits release of de-identified statistical or summary data, and it permits the exchange of information among providers, fiscal intermediaries, and official state or local agencies as needed to administer the program and to effect recovery under the enumerated Welfare and Institutions Code sections.2 So the treatment, payment, and program- administration exchanges that HIPAA and Medi-Cal contemplate are not blocked — but a release to an outside third party outside those channels normally requires the beneficiary's written consent.

For a practice, the operating rule is: a Medi-Cal beneficiary's records get the same authorization discipline as any sensitive record, and program-administration data flows stay inside the channels the rule and your plan contract define.

Layer three: the DHCS managed-care contract

Most Medi-Cal members are enrolled in managed care — they receive services through a Medi-Cal Managed Care Plan that contracts with DHCS. That plan is a health plan and therefore a HIPAA covered entity. DHCS's boilerplate managed-care contract requires the plan to comply with the HIPAA Privacy and Security Rules and with program-specific privacy and information-security requirements, and to bind its network providers and subcontractors to equivalent obligations.3

This is how the contract layer reaches a provider. When a practice joins a Medi-Cal plan's network, its provider agreement — or a business associate or subcontract agreement where the practice performs functions on the plan's behalf — passes down the plan's DHCS-derived duties: HIPAA Security Rule safeguards, privacy limits on member data, and prompt reporting of security incidents and breaches to the plan (and, through the plan, to DHCS). The exact deadlines and notice formats are set by your specific contract, so the practical step is to read the privacy and information-security exhibit of the agreement you signed and map its reporting clock into your incident-response plan.

The CalAIM initiative adds a further data-sharing layer for coordinating care and connecting members leaving jail with services; Assembly Bill 133 amended the Welfare and Institutions Code to let designated Medi-Cal partners share member information for those purposes consistent with federal law, though individual authorization is still required in many cases.5 If your practice participates in CalAIM Community Supports or Enhanced Care Management, its data-sharing authorizations are part of the picture too.

How the layers reconcile with HIPAA

The reconciling rule is HIPAA's own preemption framework. Under 45 CFR § 160.203, a state law that relates to the privacy of individually identifiable health information and is more stringent than the federal standard is not preempted.4 Section 14100.2 and 22 CCR § 51009 are more protective than HIPAA's general permissions for this population, so they control where they reach. The plan contract's terms are not preemption questions at all — they are duties you agreed to by contract, enforceable on their own terms in addition to the law.

None of this conflicts with HIPAA, because HIPAA's disclosure permissions are ceilings, not mandates. Applying the Medi-Cal confidentiality rule, obtaining written consent before an out-of-channel release of beneficiary records, and meeting your contract's reporting deadlines all satisfy HIPAA while meeting the stricter California and contractual requirements.

What this means for your HIPAA documentation

Serving Medi-Cal patients adds obligations on two different fronts. The confidentiality and consent-to-release rules land on the written policies and procedures HIPAA requires a practice to maintain under 45 CFR § 164.530(i), while your plan contract's information-security and incident-reporting terms land on your safeguards and the security incident procedures HIPAA requires under § 164.308(a)(6). A Medi-Cal provider or managed-care subcontractor should reflect:

  • the § 14100.2 confidentiality duty over Medi-Cal applicant and recipient information, and the misdemeanor exposure for knowing unauthorized release;
  • the 22 CCR § 51009 consent-to-release rule for individual beneficiary records, with program-administration exchanges handled inside the permitted channels;
  • the privacy, security, and breach-reporting terms in your DHCS-derived plan contract, including any deadline to notify the plan or DHCS of a security incident, mapped into your incident-response plan; and
  • any CalAIM data-sharing authorizations if your practice participates in those programs.

A documentation set that treats HIPAA as the only applicable law is incomplete for a Medi-Cal practice — it will miss the confidentiality statute and, more practically, the contract obligations the practice actually signed.

What California Medi-Cal practices should do this month

  1. Read your plan contract's privacy exhibit. Find the privacy, information-security, and breach or incident-reporting terms in each Medi-Cal managed-care agreement you signed, and note every deadline.
  2. Map the reporting clock. Add the plan's security-incident and breach notice deadlines to your incident-response plan so a real event does not blow a contractual timeline.
  3. Set your beneficiary-records release rule. Require written consent before releasing an individual Medi-Cal beneficiary's records outside the permitted program-administration channels (22 CCR § 51009).
  4. Train staff on Medi-Cal confidentiality. Make sure front-desk and billing staff know that Medi-Cal applicant and recipient information is confidential under § 14100.2 and usable only for program-connected purposes.
  5. Record it in your documentation. Capture the statute, the records rule, and your contract terms in the policies and procedures that govern release and incident response.

These steps prepare the ground. Turning them into policies and procedures that honor your contract deadlines, in a form a regulator or plan auditor would find defensible, is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Welf. & Inst. Code § 14100.2 (confidentiality of Medi-Cal applicant and recipient information — subd. (a) confidential, usable only for purposes directly connected with administration of the Medi-Cal program; subd. (b) safeguarded information includes names, addresses, medical services, social and economic circumstances, and medical data including diagnosis and history; knowing unauthorized release or possession is a misdemeanor). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=WIC&sectionNum=14100.2. 2 3 4 5

  2. Cal. Code Regs. tit. 22, § 51009 (confidential nature of Medi-Cal records — individual beneficiary medical records shall not be released without the written consent of the beneficiary or personal representative; permits de-identified statistical or summary data and program-administration exchange among providers, fiscal intermediaries, and official agencies). Legal Information Institute: https://www.law.cornell.edu/regulations/california/22-CCR-51009 2 3

  3. California Department of Health Care Services (DHCS), Medi-Cal Managed Care contract boilerplate and Medi-Cal managed care overview — plans are HIPAA covered entities required to comply with the HIPAA Privacy and Security Rules and to bind network providers and subcontractors to equivalent privacy and security obligations. DHCS: https://www.dhcs.ca.gov/individuals/Pages/MMCDHealthPlanDir.aspx 2

  4. 45 CFR § 160.203 (preemption of contrary State law; the "more stringent" exception for state privacy provisions). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-160.203 2

  5. California CalAIM initiative and Assembly Bill 133 (amending Welf. & Inst. Code § 14184.102 to permit designated Medi-Cal partners to share member information to implement CalAIM consistent with federal law; individual authorization still required in many cases). DHCS CalAIM: https://www.dhcs.ca.gov/CalAIM/Pages/calaim.aspx