In short
- Transferring personal information as part of a merger, acquisition or bankruptcy is not a CCPA "sale," but the buyer must honor the promises made at collection or give prior notice of materially inconsistent changes.
- HIPAA permits a covered entity's records to move in a sale or merger, and for related due diligence, without patient authorization.
- Physicians must keep records at least seven years after the last date of service, including when a practice closes or changes hands.
- If you sell data about people you don't have a direct relationship with, you may be a data broker that must register and process deletion requests through California's DROP system.
Sharing data in the ordinary course
Most sharing is either a disclosure to a vendor for a business purpose, or a "sale" or "sharing" to a third party. The difference depends largely on the contract (see Vendor contracts). Selling or sharing triggers opt-out rights, notice duties and, since 2026, a risk assessment (11 CCR § 7150(b)(1)).
When sharing makes you a data broker
A "data broker" is "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship" (Civ. Code § 1798.99.80). Selling data about your own customers doesn't fit this definition; selling data about people you've never dealt with may.
- Data brokers must register with CalPrivacy by January 31 each year after a year in which they meet the definition. Failing to register costs $200 a day (§ 1798.99.82).
- CalPrivacy's Delete Request and Opt-out Platform (DROP) opened to consumers on January 1, 2026. Since August 1, 2026, registered brokers must check DROP at least every 45 days and process the deletion requests (§ 1798.99.86). CalPrivacy reported more than 500,000 Californians had signed up by late August 2026.
Selling or buying a business
Under the CCPA
A transfer of personal information "as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of the business" is not a sale, provided the information is used or shared consistently with the CCPA. If the buyer materially changes how it uses or shares a consumer's information in a way materially inconsistent with the promises made at collection, it must give the consumer prior notice of the new or changed practice (Civ. Code § 1798.140(ad)(2)(C)). A parallel rule applies to "sharing" (§ 1798.140(ah)(2)).
Under HIPAA
"Health care operations," for which no patient authorization is needed, include "the sale, transfer, merger, or consolidation of all or part of the covered entity with another covered entity, or an entity that following such activity will become a covered entity and due diligence related to such activity" (45 CFR § 164.501). The same transaction is also an exception to HIPAA's prohibition on selling protected health information (§ 164.502(a)(5)(ii)). Limit due-diligence disclosures to what is needed.
Closing or transferring a medical practice
- Physicians must keep adequate and accurate records for at least seven years after the last date of service to a patient; failing to do so is unprofessional conduct (Bus. & Prof. Code § 2266, effective January 1, 2024).
- Licensed facilities that close must preserve records for at least seven years after discharge, and for minors at least one year after they turn 18 and not less than seven years in any case (Health & Saf. Code § 123145).
- The Medical Board of California's practice information advises telling patients where their records will be stored and how they can get them.
- Dispose of medical information in a way that preserves its confidentiality (Civ. Code § 56.101).
Bankruptcy sales of customer data
If a debtor's privacy policy at the time of filing prohibits transferring personally identifiable information to unaffiliated persons, the trustee may sell it only if the sale is consistent with the policy, or if the court approves the sale after a consumer privacy ombudsman is appointed and after notice and a hearing (11 U.S.C. § 363(b)(1); § 332).
Switching vendors or systems
- HIPAA: a business associate agreement must require the vendor, at termination, to return or destroy all protected health information if feasible and keep no copies; if that isn't feasible, the protections continue (45 CFR § 164.504(e)(2)(ii)(J)).
- CCPA: the regulations don't list return-or-delete at termination as a required term, but your notice at collection must state how long you keep each category of information (11 CCR § 7012(e)). Contract for return and deletion, with proof.
- Portability: consumers are entitled to access responses in a structured, commonly used, machine-readable format they can transmit to another entity (Civ. Code § 1798.130(a)). Build exports that work.
Checklist
- In diligence, map the target's privacy promises and whether its vendor contracts are compliant.Civ. Code § 1798.140(ad)(2)(C)
- After closing, give prior notice before any materially inconsistent new use of acquired data.Civ. Code § 1798.140(ad)(2)(C)
- In healthcare deals, rely on the health-care-operations pathway and limit diligence disclosures.45 CFR §§ 164.501, 164.502(a)(5)(ii)
- When closing or selling a practice, name a records custodian, tell patients where records will be, and keep them at least seven years.Bus. & Prof. Code § 2266; Health & Saf. Code § 123145
- At vendor exit, obtain return or destruction of data, with written certification.45 CFR § 164.504(e)(2)(ii)(J)
- Before selling data about people you don't deal with directly, assess data broker status.Civ. Code §§ 1798.99.80, 1798.99.82, 1798.99.86
- In bankruptcy, check the privacy policy in effect at filing before planning a data sale.11 U.S.C. § 363(b)(1)
Related guides
- Topic guideVendor and service-provider contractsRequired privacy terms in vendor contracts: CCPA service provider, contractor and third-party terms (11 CCR 7051, 7053), reasonable-security clauses, and HIPAA business associate agreements.
- Topic guideHealth information confidentialityHIPAA and the California CMIA for healthcare and senior-care providers: coverage, patient access deadlines, authorizations, CDPH breach reporting, SNF and RCFE resident privacy, and 2025-2026 changes.
Official sources
- Civil Code § 1798.140; §§ 1798.99.80–1798.99.89 (data brokers)
- DROP (CalPrivacy)
- 45 CFR §§ 164.501, 164.502, 164.504 (eCFR)
- Business and Professions Code § 2266; Health and Safety Code § 123145
- 11 U.S.C. §§ 332, 363 (U.S. Code)