Skip to main content
CoreFolioHIPAA
California

Does the CMIA apply to my health app or tech vendor? California medical privacy beyond providers

California's CMIA reaches beyond doctors and plans. Businesses that hold medical information, and certain reproductive or sexual-health apps, are deemed providers under Civil Code 56.06 — even when they sit outside a HIPAA business-associate relationship.

By CoreFolio

6-minute read

If you build or sell health software, the question "does California's medical privacy law apply to us?" does not turn on whether you are a doctor or a health plan. California's Confidentiality of Medical Information Act (CMIA) reaches certain businesses that hold medical information, and — after AB 254 — certain reproductive or sexual-health apps, by deeming them "providers of health care" under Civil Code § 56.06. Crucially, a company can be outside a HIPAA business-associate relationship and still be bound by the CMIA. This article explains who is caught, what attaches, and why HIPAA status is not the whole answer.

Key takeaways

  • Civil Code § 56.06 deems certain businesses that maintain medical information to be providers of health care subject to the CMIA.1
  • AB 254 extended that to reproductive or sexual-health digital services (apps) offered to consumers.1
  • A vendor can be outside a HIPAA business-associate relationship and still be a deemed provider under the CMIA — the two frameworks are separate.
  • Covered businesses owe real duties: confidentiality in handling data (§ 56.101) and, for sensitive-services data, segregation and access controls.2
  • Deemed-provider status is limited to the CMIA — § 56.06 says it does not make the business a provider "for purposes of any law other than this part."1

Who the CMIA reaches beyond clinicians and plans

The CMIA's core confidentiality duty runs to every "provider of health care, health care service plan, pharmaceutical company, or contractor" that handles medical information.2 But Civil Code § 56.06 extends the definition of "provider of health care" to reach businesses that would not otherwise think of themselves as providers:

  • Data-maintaining businesses. A business "organized for the purpose of maintaining medical information in order to make the information available to an individual or to a provider of health care" — for example, a records repository or a platform holding patient data — is deemed a provider subject to the CMIA.1
  • Reproductive or sexual-health digital services (AB 254). A business "that offers a reproductive or sexual health digital service to a consumer for the purpose of allowing the individual to manage the individual's information, or for the diagnosis, treatment, or management of a medical condition," is "deemed to be a provider of health care subject to the requirements of this part."1

A period-tracking or fertility app, a mental-health or telehealth platform aimed at California consumers, or a business holding patient records for practices can each land inside this definition.

HIPAA business-associate status is a separate question

A common misread: "we signed no business-associate agreement, so no health privacy law applies to us." HIPAA and the CMIA are separate regimes. HIPAA's business-associate framework applies when a vendor handles protected health information on behalf of a HIPAA covered entity. A consumer-facing app that deals directly with individuals often has no HIPAA covered-entity behind it — and so may sit outside HIPAA's business-associate rules entirely — yet still be a deemed provider under CMIA § 56.06, with California obligations and liability. The absence of a business-associate agreement does not answer the California question.

What obligations attach

Once a business is a deemed provider, the CMIA's substantive rules apply. Two are central:

  • Confidentiality in handling data (§ 56.101). The business must handle medical information in a manner that preserves confidentiality; negligent handling is subject to the § 56.36 remedies and penalties.2
  • Sensitive-services capabilities. If the business electronically stores or maintains sensitive-services medical information (reproductive, gender- affirming, behavioral-health, and related categories), § 56.101(c) requires it to build capabilities to limit access, prevent out-of-state disclosure, segregate that data, and automatically disable access to it.2

And the liability is real: a negligent release exposes the business to the § 56.36 private right of action — $1,000 per violation without proof of harm — plus the administrative and civil penalty ladder.3

The limit worth knowing

Section 56.06 draws an explicit boundary: being deemed a provider is "for purposes of this part" — the CMIA — only. The statute states it "shall not be construed to make a business specified in this subdivision a provider of health care for purposes of any law other than this part."1 So the deemed-provider status governs CMIA obligations; it does not, on its own, pull the business into other provider-specific licensing or liability regimes. It is a targeted rule, not a wholesale reclassification.

What this means if you build health software

If you sell or operate health software touching California consumers or practices:

  1. Assess CMIA status independently of HIPAA. Ask whether § 56.06 deems you a provider, regardless of any business-associate analysis.
  2. Map your sensitive-services data. If you hold reproductive, gender-affirming, or behavioral-health information, treat the § 56.101(c) segregation and out-of-state controls as requirements.
  3. Budget for the private right of action. The § 56.36 $1,000-per- violation exposure makes a documented safeguards program a business necessity, not a nicety.
  4. Get your contracts right. Where you serve HIPAA covered entities, business-associate agreements still apply on the HIPAA side; the CMIA analysis sits alongside them.

A practice evaluating a vendor should ask the mirror-image question: does this vendor meet its CMIA obligations for the data we hand it? Either way, the answer belongs in documentation. Turning that into a defensible, dated record is the work itself — specific, citation-heavy, and easy to get wrong from a blank page. CoreFolio HIPAA walks through the practice side of that analysis and produces the documentation with the structure already in place.

Sources

Footnotes

  1. Cal. Civ. Code § 56.06 (businesses deemed providers of health care under the CMIA — subdivision (a), a business organized to maintain medical information to make it available to individuals or providers; and subdivision (e), added by AB 254, a business offering a reproductive or sexual health digital service, which "shall be deemed to be a provider of health care subject to the requirements of this part" — subject to the express limit that "this section shall not be construed to make a business specified in this subdivision a provider of health care for purposes of any law other than this part"). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.06. 2 3 4 5 6

  2. Cal. Civ. Code § 56.101 (duty to handle medical information so as to preserve confidentiality, with negligent handling subject to § 56.36; and the § 56.101(c) sensitive-services capabilities — limit access, prevent out-of-state disclosure, segregate, and automatically disable access — for a business described in § 56.06). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.101. 2 3 4

  3. Cal. Civ. Code § 56.36 (CMIA remedies and penalties — the private right of action with nominal damages of $1,000 per violation without proof of harm, plus administrative fines and civil penalties). California Legislative Information: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.36.