Skip to main content
CoreFolioHIPAA
California

CMIA authorization requirements: how a California medical release differs from a HIPAA authorization

California's CMIA (Civil Code 56.11) sets stricter rules than HIPAA for a valid medical-information authorization — 14-point type, a standalone signature, a one-year expiration, and nine required elements. Here's the checklist.

By CoreFolio

6-minute read

In California, the form a practice uses to release a patient's records has to clear a higher bar than HIPAA sets. The Confidentiality of Medical Information Act (CMIA) spells out, in Civil Code § 56.11, nine specific conditions a medical-information authorization must meet to be valid — including that it be in at least 14-point type, stand clearly apart from any other language with its own signature, and expire within one year. A generic HIPAA release frequently misses one or more of these. This article is the checklist, and how it differs from the federal authorization standard.

Key takeaways

  • A valid CMIA authorization must satisfy nine conditions in Civil Code § 56.11(b).1
  • It must be handwritten or in a typeface no smaller than 14-point type and clearly separate from other language, executed by a signature that "serves no other purpose."1
  • It must state an expiration date or event that limits it to one year or less (with clinical-trial and research exceptions).1
  • HIPAA's authorization standard (45 CFR § 164.508) overlaps but does not impose the 14-point type, standalone-signature, or one-year-default rules.2
  • You only need a § 56.11 authorization when the disclosure is not one that Civil Code § 56.10 already permits without one.3

When a CMIA authorization is required

The CMIA's default is confidentiality: a provider "shall not disclose medical information" about a patient without authorization, except as the statute allows. Civil Code § 56.10 sets out the exceptions. Some disclosures are compelled — for example, by a court order (§ 56.10(b)). Others are permitted without authorization — most importantly, disclosures to other providers of health care, health care service plans, or contractors for the patient's treatment and related health-care purposes (§ 56.10(c)).3

When a disclosure falls outside what § 56.10 permits — for instance, sending records to an employer, an attorney, a life insurer, or a marketing partner at the patient's request — the provider must first obtain a valid authorization under § 56.11.

The nine conditions of a valid authorization (§ 56.11(b))

To be valid, a CMIA authorization must:

  1. Be handwritten or in a typeface no smaller than 14-point type.1
  2. Be clearly separate from any other language present on the same page and executed by a signature "that serves no other purpose than to execute the authorization."1
  3. Be signed and dated (electronically or by hand) by the patient, or an authorized signer such as the patient's legal representative — with a minor able to sign only in the narrow case described below.1
  4. State the specific uses and limitations on the types of medical information to be disclosed.1
  5. State the name or functions of the provider (or plan, pharmaceutical company, or contractor) that may disclose the information.1
  6. State the name or functions of the persons or entities authorized to receive the information.1
  7. State the specific uses and limitations on the use of the information by those recipients.1
  8. State an expiration date or event that limits the authorization to one year or less, unless the signer requests a longer specific date or the authorization relates to an approved clinical trial or medical research study.1
  9. Advise the signer of the right to receive a copy of the authorization.1

How this differs from a HIPAA authorization

HIPAA has its own authorization standard at 45 CFR § 164.508, which requires core elements — a description of the information, who may disclose and receive it, the purpose, an expiration date or event, the signature, and required statements about revocation and redisclosure.2 The two standards overlap in substance, but the CMIA layers on formatting rules HIPAA does not:

  • Type size. HIPAA has no minimum type size; the CMIA requires 14-point type (or handwriting).1
  • Standalone document. HIPAA allows a compound authorization in some circumstances; the CMIA requires the authorization to be clearly separate, with a signature that does nothing but execute it.1
  • Expiration default. HIPAA lets the authorization run to a stated date or event without a fixed cap; the CMIA defaults to one year or less unless the signer asks for longer.1

Because a California disclosure usually has to satisfy both laws, practices generally use a single authorization form engineered to meet the stricter CMIA conditions — which, by construction, also carries the HIPAA elements.

Minors: who signs

Authorization for a minor's records is a frequent trip-up. Under Civil Code § 56.11(b)(3)(A), a minor may sign an authorization only for the release of medical information a provider obtained "in the course of furnishing services to which the minor could lawfully have consented" on their own under the Family Code (Part 4, commencing with Section 6900).1 For services a minor could consent to alone — certain reproductive, mental-health, or substance-use care — the minor controls the authorization. For everything else, the parent or legal representative signs. Getting this wrong is both a CMIA problem and a consent problem, and it is covered in depth in the minor-consent article in this series.

What this means for your forms and procedures

California's conditions sit on top of HIPAA's own authorization requirements at 45 CFR § 164.508, and the written policies and procedures the Privacy Rule requires a practice to maintain and retain under 45 CFR § 164.530(i) and (j). A California practice should:

  1. Audit your release form against the nine conditions. Confirm 14-point type, a standalone signature block, the one-year expiration language, and the copy-rights advisory.
  2. Use one form that satisfies both laws. Build the CMIA conditions in and the HIPAA elements come along; the reverse is not true.
  3. Map minor-consent scenarios. Note which services in your practice a minor can consent to alone, so your staff knows who signs.
  4. Record the form in your documentation. A defensible California file shows the authorization form actually in use, not a generic template.

Turning that into policies, procedures, and forms a regulator would find defensible is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through each step and produces that documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Civ. Code § 56.11 (conditions for a valid authorization to disclose medical information — (b)(1) handwritten or 14-point type; (b)(2) clearly separate with a dedicated signature; (b)(3) signed and dated, including the minor-signature limit at (b)(3)(A); (b)(4)–(b)(7) required content on information, disclosing party, recipient, and permitted uses; (b)(8) expiration of one year or less; (b)(9) advisory of the right to a copy). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.11. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16

  2. 45 CFR § 164.508 (HIPAA standard for uses and disclosures for which an authorization is required — core elements and required statements). Electronic Code of Federal Regulations: https://www.ecfr.gov/current/title-45/section-164.508 2

  3. Cal. Civ. Code § 56.10 (a provider shall not disclose medical information without authorization, except as compelled under subdivision (b) or permitted under subdivision (c), including disclosure to other providers, plans, or contractors for health-care purposes). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.10. 2