California medical privacy laws that layer with HIPAA: what practices need to know about the CMIA
How California's Confidentiality of Medical Information Act and related laws layer on top of HIPAA — stricter authorizations, patient lawsuits, breach notice, and sensitive-data rules.
By CoreFolio
10-minute read
California practices answer to two layers of medical-privacy law at once: the federal Health Insurance Portability and Accountability Act (HIPAA) and California's own Confidentiality of Medical Information Act (CMIA), Civil Code §§ 56–56.37. The CMIA predates HIPAA and is stricter in several places — it reaches more businesses, requires a more detailed patient authorization, lets patients sue directly, and adds special rules for reproductive, gender-affirming, and mental-health data. Where California law is more protective than HIPAA, the California rule is the one you follow.
This article maps how the two layers fit together for a California medical, dental, or behavioral health practice, and points to the specific California rules that most often create gaps against a HIPAA-only program. The rules are knowable; getting your documentation to reflect the right ones takes care.
Key takeaways
- California's CMIA (Civil Code §§ 56–56.37) is a standalone medical-privacy statute that layers on top of HIPAA, not a copy of it.
- Unlike HIPAA, the CMIA gives patients a private right of action — Civil Code § 56.36 allows $1,000 in nominal damages per violation without proof of actual harm.1
- California's patient authorization must meet formatting rules HIPAA does not impose, including 14-point type and a one-year expiration (Civil Code § 56.11).2
- California's breach-notice clock runs to 30 calendar days — tighter than HIPAA's 60 — and a breach affecting more than 500 residents adds a 15-day filing with the California Attorney General (Civil Code § 1798.82).3
- For data security, a genuine HIPAA Security Rule program generally carries California's reasonable-security duty; the California deltas concentrate in authorization, breach filing, patient remedies, and sensitive-data rules.
How California law layers on top of HIPAA
HIPAA does not preempt a state law that is more stringent — that is, a state law giving an individual greater privacy protection or greater rights. The general preemption rule and its privacy exception are set out at 45 CFR § 160.203.4
"A standard, requirement, or implementation specification adopted under this subchapter that is contrary to a provision of State law preempts the provision of State law."
That rule then carves out an exception where the state provision relates to the privacy of individually identifiable health information and is more stringent than the federal standard. This is "floor preemption": HIPAA is the floor, and the stricter state rule controls. California is the state where that principle does the most work, because it has a comprehensive medical-privacy statute of its own.
The CMIA: California's medical-privacy statute
The Confidentiality of Medical Information Act, Civil Code §§ 56–56.37, governs how medical information is handled in California. Three features make it stricter than HIPAA for a typical practice.
It reaches more than HIPAA's "covered entities." Beyond providers and plans, the CMIA reaches contractors and businesses that handle medical information — and, after recent amendments, certain digital services that collect reproductive or sexual-health information. A vendor a HIPAA analysis might treat as outside the covered-entity or business-associate frame can still be a "provider of health care" under the CMIA.
Its authorization is more prescriptive. When a provider needs a patient's authorization to disclose medical information, the CMIA sets formatting rules HIPAA does not. Under Civil Code § 56.11, a valid authorization must be "handwritten or … in a typeface no smaller than 14-point type," must be "clearly separate from any other language present on the same page" and executed by a signature that serves no other purpose, and must state an expiration date or event that limits it to "one year or less" unless the signer requests a longer period.2 These are concrete, checkable requirements a general HIPAA authorization form usually does not satisfy.
It lets patients sue. This is the difference California practices feel most. HIPAA has no private right of action — only the Office for Civil Rights (OCR) and state attorneys general enforce it. The CMIA does the opposite. Under Civil Code § 56.36, an individual may bring a civil action against a person or entity that negligently released their confidential medical information, and may recover "nominal damages of one thousand dollars ($1,000)" per violation without having to prove actual harm, plus any actual damages sustained.1 A negligent release of medical information is a private lawsuit in California, not only a regulatory matter.
Breach notification: the Attorney-General filing (Civil Code § 1798.82)
California's data-breach statute, Civil Code § 1798.82, requires a business that owns or licenses computerized personal information — which the statute defines to include medical information and health-insurance information — to notify affected California residents of a breach. As amended effective 2025, the disclosure "shall be made within 30 calendar days of discovery or notification of the data breach," subject to a delay for the legitimate needs of law enforcement or to determine the scope of the breach and restore the system's integrity.3 That 30-day outer limit is tighter than HIPAA's 60-day deadline for notifying individuals.5
The provision practices most often miss is the Attorney-General filing. When a single breach requires notifying more than 500 California residents, the business must "electronically submit a single sample copy of that security breach notification" to the California Attorney General "within 15 calendar days of notifying affected consumers."3 Following HIPAA's own breach process does not remove this separate California step — the state posts those sample notices publicly.
Sensitive services: reproductive, gender-affirming, and behavioral-health data
Recent CMIA amendments (AB 254 and AB 352) added rules for "medical information on the provision of sensitive services" — care related to reproductive and sexual health, gender-affirming care, mental or behavioral health, sexually transmitted infections, and substance use. Civil Code § 56.101 now requires businesses that electronically store or maintain that information to build capabilities to segregate it, to limit access, and to prevent its disclosure or transfer to persons and entities outside California in defined circumstances.6 Notably, these sensitive-services rules do not carry a HIPAA exemption, so they apply to HIPAA-covered practices as well.
For mental-health records specifically, California layers additional confidentiality on top of HIPAA. Records obtained in the course of providing services under the Lanterman-Petris-Short Act are confidential under Welfare and Institutions Code § 5328, disclosable only in enumerated situations.7 Whether a given private therapy practice's confidentiality obligation flows through § 5328, through the CMIA, or through the Evidence Code psychotherapist-patient privilege depends on the practice's setting, and California's duty-to-warn rule adds its own contour. That intersection is detailed in the behavioral-health article in this series.
Data security: your HIPAA program likely carries the state floor
California imposes a general duty to use reasonable security procedures to protect personal information (Civil Code § 1798.81.5). For a practice, that duty is largely a floor a genuine HIPAA Security Rule program already meets. The California deltas that go beyond HIPAA are not in the technical safeguards — they are in authorization content, the breach Attorney-General filing, the patient private right of action, and the sensitive-services rules above. Where a gap exists against the HIPAA Security Rule, the same gap generally exists against California's security duty.
A note on the CCPA and the Data Exchange Framework
Two other California regimes come up often. The California Consumer Privacy Act (CCPA/CPRA) largely exempts medical information already governed by the CMIA and HIPAA, so it mostly reaches a practice's non-clinical data. The California Data Exchange Framework (DxF) creates data-sharing duties for many practices and interacts with CMIA consent rules in ways worth understanding on their own; the DxF is covered in a separate article in this series.
What this means for your HIPAA documentation
California's additions land in three different places. The authorization, consent, and sensitive-services rules belong in the written policies, procedures, and forms HIPAA requires a practice to maintain under 45 CFR § 164.530(i). The breach timelines belong with the security incident procedures HIPAA separately requires under § 164.308(a)(6). And the heightened litigation exposure is a genuine input to the security risk analysis at § 164.308(a)(1)(ii)(A), because it raises what a breach of ePHI actually costs a California practice. Your documentation should reflect:
- the CMIA authorization format (§ 56.11);
- the patient private right of action (§ 56.36) as a real risk your safeguards are managing, not only an OCR concern;
- the § 1798.82 breach timeline — a 30-calendar-day notice clock for California residents plus the Attorney-General filing for a breach affecting more than 500 of them;
- the sensitive-services rules (§ 56.101) if you hold reproductive, gender-affirming, mental-health, or substance-use information — whose § 56.101(c) capability duties sit with the system holding the records rather than with the practice; and
- the mental-health confidentiality rules where your patient population makes them relevant.
A documentation set that treats HIPAA as the only applicable law is incomplete for a California practice, because it will not surface the state-specific rules and recipients a California regulator — or a plaintiff's attorney — would expect a practice to have accounted for.
What California practices should do this month
You do not need a law firm for the first, organizational steps. You do need to be precise about which rules apply to you.
- Check your authorization form against § 56.11. Confirm it uses at least 14-point type, is a separate document with its own signature, and states an expiration of one year or less. A generic HIPAA authorization often misses these.
- Tighten your breach clock and add the Attorney-General step. Make sure your incident-response plan notifies affected California residents within § 1798.82's 30-calendar-day window (tighter than HIPAA's 60 days) and flags the sample-copy filing to the California Attorney General for any breach affecting more than 500 California residents, within 15 calendar days of consumer notice.
- Flag your sensitive-services data. If you hold reproductive, gender-affirming, mental-health, or substance-use information, confirm the system that holds those records provides the § 56.101(c) segregation and out-of-state disclosure controls.
- Treat medical privacy as legal risk. Because § 56.36 lets patients sue for $1,000 per violation without proving harm, the business case for a documented, current risk analysis in California is stronger than the federal penalty risk alone.
- Bring the California facts into your documentation. When you next update it, record the CMIA authorization, breach-filing, sensitive-services, and any behavioral-health rules in the policies and procedures they belong to — not as an afterthought.
These steps prepare the ground. Turning them into policies, procedures, and forms a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.
Sources
Footnotes
-
Cal. Civ. Code § 56.36 (remedies for violation of the CMIA — a private right of action; nominal damages of one thousand dollars ($1,000) recoverable without proof of actual damages, plus actual damages). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.36. ↩ ↩2
-
Cal. Civ. Code § 56.11 (conditions for a valid authorization to disclose medical information — handwritten or 14-point type; clearly separate with a dedicated signature; expiration limited to one year or less). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.11. ↩ ↩2
-
Cal. Civ. Code § 1798.82 (breach of security of computerized personal information — notice to affected residents within 30 calendar days of discovery or notification, as amended effective 2025; sample copy to the Attorney General within 15 calendar days when more than 500 California residents are notified for a single breach). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82. ↩ ↩2 ↩3
-
45 CFR § 160.203 (preemption of contrary State law; the "more stringent" privacy exception). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-160.203 ↩
-
45 CFR § 164.404(b) (HIPAA Breach Notification Rule — individual notice "without unreasonable delay and in no case later than 60 calendar days" after discovery of a breach). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.404 ↩
-
Cal. Civ. Code § 56.101 (duties for businesses that electronically store or maintain medical information on the provision of sensitive services — segregation, access limits, and out-of-state disclosure restrictions; subdivision (c) added by AB 352, and subdivision (c)(4) provides that those requirements do not apply to a provider of health care). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=56.101. ↩
-
Cal. Welf. & Inst. Code § 5328 (confidentiality of information and records obtained in the course of providing services under the Lanterman-Petris-Short Act; enumerated disclosure exceptions). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=WIC§ionNum=5328. ↩