Skip to main content
CoreFolioHIPAA
California

Reproductive and gender-affirming health data in California: what the CMIA requires (AB 352)

California's CMIA requires the systems that hold a practice's records — EHR/EMR vendors and certain apps — to segregate reproductive and gender-affirming data, limit access, and block out-of-state disclosure. Civil Code 56.101(c), added by AB 352, expressly excludes providers.

By CoreFolio

7-minute read

California treats reproductive and gender-affirming health data as a category that needs its own handling — not just general medical-privacy protection. Under the Confidentiality of Medical Information Act (CMIA), amended by AB 352 and AB 254, the software vendors and apps that hold a practice's records must be able to segregate information about gender-affirming care, abortion, and contraception, limit who can access it, and prevent it from being disclosed or transferred outside California. The statute puts those capability duties on the record-holding business, not on the practice — § 56.101(c)(4) provides that they “shall not apply to a provider of health care.” For a practice, that makes this a vendor-diligence and documentation question. This article explains those requirements, who they reach, and how they sit alongside HIPAA.

Key takeaways

  • Civil Code § 56.101(c) (added by AB 352) required covered systems to build sensitive-services data capabilities by July 1, 2024.1
  • Those capabilities: limit access, prevent out-of-state disclosure or transfer, segregate gender-affirming care, abortion, and contraception data, and automatically disable access to the segregated information.1
  • "Sensitive services" is broadly defined in Civil Code § 56.05(s) to cover mental/behavioral health, reproductive and sexual health, STIs, substance use, gender-affirming care, and intimate-partner violence.2
  • The § 56.101(c) capability duties fall on the businesses and apps that hold the data — EHR/EMR vendors (§ 56.06) and certain reproductive or sexual-health digital services deemed providers by AB 254 — and § 56.101(c)(4) states they do not apply to a provider of health care.3
  • What a practice owes under this section is § 56.101(a): handling medical information confidentially as it creates, maintains, stores, and disposes of it. The segregation engineering is its vendor's to build and the practice's to verify.1
  • These are California statutory requirements that apply regardless of the status of any federal reproductive-privacy rule.

What counts as "sensitive services"

Civil Code § 56.05(s) defines "sensitive services" as "all health care services related to mental or behavioral health, sexual and reproductive health, sexually transmitted infections, substance use disorder, gender-affirming care, and intimate partner violence," and it includes the services a minor can consent to on their own under the Family Code.2 That is a wide net — most primary care, OB-GYN, behavioral health, and many general practices touch at least one of these categories.

What AB 352 requires (§ 56.101(c))

AB 352 added specific engineering and policy duties to the CMIA. Civil Code § 56.101(c) provides that a business (as described in § 56.06) that electronically stores or maintains medical information on the provision of sensitive services — including on an electronic health record or electronic medical record system — on behalf of a provider had to "develop capabilities, policies, and procedures, on or before July 1, 2024," to enable all of the following (§ 56.101(c)):

  • Limit user access privileges to systems containing information related to gender-affirming care, abortion and abortion-related services, and contraception, to only those authorized to access it.
  • Prevent the disclosure, access, or transfer of that information to persons and entities outside California, except as the CMIA otherwise permits.
  • Segregate that information from the rest of the patient's record.
  • Automatically disable access to the segregated information when appropriate.

Separately, § 56.101(b) requires an electronic health record or electronic medical record system to protect the integrity of medical information and to automatically record and preserve any change or deletion — logging the identity of the person, the date and time, and the change made.1

Unlike subdivision (c), subdivision (b) carries no provider carve-out. A practice that operates its own record system should treat those integrity and audit-logging requirements as its own.

Who has to comply

The § 56.101(c) obligations sit with the record-holding system, not with the practice. Section 56.101 reaches a business described in § 56.06 — one that maintains medical information to make it available to individuals or providers — which squarely includes EHR and EMR vendors that hold a practice's records.3 And AB 254 extended the CMIA's reach to certain reproductive or sexual-health digital services: an app offered to consumers to manage their information, or for diagnosis or treatment, is "deemed to be a provider of health care subject to the requirements of this part."3

Subdivision (c)(4) is explicit that these requirements “shall not apply to a provider of health care.”

For a practice, the practical consequence is a vendor-diligence question: does our EHR (and any sensitive-services app we rely on) actually provide the § 56.101 segregation, access-limiting, and out-of-state-disclosure controls? If a practice cannot answer that, it has a documentation gap.

The out-of-state disclosure restriction

The requirement to prevent disclosure or transfer of gender-affirming care, abortion, and contraception data to persons and entities outside California is the CMIA's contribution to California's broader policy of shielding this care from other states' investigations. It is a data-handling capability the covered system must actually have — not just a policy statement — and it interacts with California's other shield provisions. How it plays out in a specific cross-border request is a legal question for counsel.

How this sits with HIPAA

HIPAA remains the federal floor for protected health information. Federal reproductive-health privacy rulemaking, however, has been the subject of litigation and change, so a California practice should not assume a federal rule fills these gaps. The § 56.101 capabilities are set by California statute and apply on their own terms. Where your HIPAA Security Rule program already limits access and logs changes, you are part of the way there; the California-specific additions are the segregation of sensitive-services data and the out-of-state disclosure controls — capabilities you procure and verify from your vendor rather than build yourself, since § 56.101(c)(4) does not place them on providers.

What this means for your practice

The controls at issue here are access limits, segregation, and change logging — the same territory as the HIPAA Security Rule's access-control, audit-control, and integrity standards at 45 CFR § 164.312(a)(1), (b), and (c)(1). That puts them alongside your security risk analysis under § 164.308(a)(1)(ii)(A), which is where you record the systems holding ePHI and the gaps in them. A practice that handles sensitive-services data should:

  1. Inventory where sensitive-services data lives — which systems hold reproductive, gender-affirming, behavioral-health, or substance-use records.
  2. Ask your EHR/EMR vendor about § 56.101. Confirm, in writing, whether the system supports access limits, segregation, out-of-state disclosure controls, and change logging.
  3. Check your apps. If you use a reproductive or sexual-health digital service, treat it as in-scope under AB 254 and diligence it accordingly.
  4. Document the controls in your risk analysis. Record the capabilities you verified and any gaps as findings to remediate.

Turning that into a dated risk analysis and vendor documentation a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Civ. Code § 56.101 (confidentiality in handling medical information, with negligent handling subject to the § 56.36 remedies; the § 56.101(b) electronic-record integrity and change-logging requirements; and the § 56.101(c) duty, by July 1, 2024, to limit access to, prevent out-of-state disclosure of, segregate, and automatically disable access to gender-affirming care, abortion and abortion-related services, and contraception information; added/amended by AB 352). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.101. 2 3 4

  2. Cal. Civ. Code § 56.05(s) (definition of "sensitive services" — mental or behavioral health, sexual and reproductive health, sexually transmitted infections, substance use disorder, gender-affirming care, and intimate partner violence). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.05. 2

  3. Cal. Civ. Code § 56.06 (businesses treated as providers of health care under the CMIA — a business organized to maintain medical information for individuals or providers, and, per subdivision (e), a business offering a reproductive or sexual health digital service, "deemed to be a provider of health care subject to the requirements of this part"; added by AB 254). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.06. 2 3