Skip to main content
CoreFolioHIPAA
California

Can patients sue for a medical privacy violation in California? The CMIA private right of action

Unlike HIPAA, California's CMIA lets patients sue directly for a negligent release of medical information — $1,000 per violation without proving harm (Civil Code 56.36), plus a penalty ladder up to $250,000.

By CoreFolio

5-minute read

Yes — in California, a patient can sue your practice directly for mishandling their medical information. That is the single biggest difference between California's Confidentiality of Medical Information Act (CMIA) and HIPAA. HIPAA has no private right of action; only the government enforces it. The CMIA, at Civil Code § 56.36, lets an individual bring a civil action for a negligent release of their confidential medical information and recover $1,000 per violation without proving any harm. This article explains that remedy, the penalty ladder behind it, and why it makes documented safeguards a legal defense.

Key takeaways

  • California's CMIA gives patients a private right of action for a negligent release of medical information (Civil Code § 56.36(b)).1
  • A patient can recover $1,000 in nominal damages per violation without proving actual harm, plus any actual damages.1
  • Separate penalties climb from $2,500 (negligent) to $25,000 (knowing and willful) to $250,000 (knowing use for financial gain).1
  • HIPAA has no private right of action — it is enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, not by patients.
  • The practical effect: in California, a privacy lapse is potential civil litigation, which raises the value of a current, documented risk analysis.

HIPAA vs. the CMIA on who can sue

Under HIPAA, enforcement runs through the government. HHS, through its Office for Civil Rights (OCR), investigates complaints and imposes penalties; state attorneys general have a limited enforcement role. A patient who believes their privacy was violated under HIPAA can file a complaint with OCR, but they cannot personally sue the practice under HIPAA itself.

California is different. The CMIA gives the patient their own cause of action. That means a California practice faces two distinct channels of exposure for the same lapse: a government enforcement track and a private-lawsuit track.

The private right of action (§ 56.36(b))

Civil Code § 56.36(b) provides that, "in addition to any other remedies available at law, an individual may bring an action against a person or entity who has negligently released confidential information or records" in violation of the CMIA, for either or both of:

  • Nominal damages of $1,000. The statute is explicit that "it is not necessary that the plaintiff suffered or was threatened with actual damages" to recover this amount.1
  • Actual damages, if any, sustained by the patient.1

The $1,000-without-proof-of-harm floor is what makes CMIA claims attractive to plaintiffs and what turns a single mishandled record into a viable lawsuit. It also scales: because the amount is "per violation," an incident affecting many patients can aggregate quickly.

The penalty ladder (§ 56.36(c))

Beyond the patient's own recovery, § 56.36(c) authorizes administrative fines and civil penalties, escalating with culpability:

  • Negligent disclosure — up to $2,500 per violation.
  • Knowing and willful obtaining, disclosure, or use by a person or entity other than a licensed health care professional — up to $25,000 per violation. For a licensed professional, the ladder runs $2,500 / $10,000 / $25,000 across first, second, and third-or-later violations.
  • Knowing or willful use for financial gain — up to $250,000 per violation, plus disgorgement of proceeds.

These penalties apply "irrespective of the amount of damages suffered by the patient," so they are not contingent on a patient being harmed.1

What a "negligent release" looks like

The everyday incidents that create CMIA exposure are the same ones a HIPAA risk analysis is built to prevent:

  • a fax or email of records sent to the wrong recipient;
  • records left visible or accessible to people without a need to see them;
  • a lost or stolen laptop, phone, or drive holding unencrypted records;
  • an employee accessing a patient's chart out of curiosity or for personal reasons; or
  • a vendor or contractor mishandling data the practice entrusted to it.

Each is a failure of an administrative, physical, or technical safeguard — which is exactly why the defense against CMIA liability and the work of HIPAA compliance are the same work.

Why documentation is your defense

A negligent-release claim turns on whether the practice acted reasonably. The practice's evidence that it did — a dated risk analysis, documented safeguards, workforce training records, and an incident-response procedure that was actually followed — is what distinguishes a defensible position from an indefensible one. In California, that documentation is not just a regulatory expectation; it is litigation evidence.

A California practice should:

  1. Treat privacy lapses as litigation risk. Because § 56.36 guarantees $1,000 per violation without proof of harm, the business case for current documentation is stronger than the federal penalty risk alone.
  2. Keep the risk analysis dated and current. Its value is highest exactly when an incident is being scrutinized after the fact.
  3. Document safeguards and training, not just intentions. Evidence that a control existed and was followed is what "reasonable" looks like in a courtroom.
  4. Tighten vendor oversight. A contractor's negligent release can become the practice's problem; business-associate diligence is part of the defense.

Turning that into a dated risk analysis, safeguards records, and an incident-response procedure a regulator — or a court — would find defensible is the work itself. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Civ. Code § 56.36 (violations of the CMIA — (a) misdemeanor where a violation causes economic loss or personal injury; (b) private right of action for a negligent release, with (b)(1) nominal damages of one thousand dollars ($1,000) recoverable without proof of actual damages and (b)(2) actual damages; (c) administrative fines and civil penalties of up to $2,500 for negligent disclosure, up to $25,000 for a knowing and willful violation, and up to $250,000 for a knowing or willful use for financial gain, plus disgorgement). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.36. 2 3 4 5 6