In short
- Most California providers are subject to both HIPAA and the CMIA. Where California gives patients more protection, follow California.
- California's patient-access deadlines are much shorter than HIPAA's: 5 working days to inspect and 15 days for copies.
- Licensed clinics, health facilities (including skilled nursing), home health agencies and hospices must report unauthorized access, use or disclosure, including staff "snooping," to CDPH and the patient within 15 business days.
- Patients can sue under the CMIA for $1,000 in nominal damages without proving actual harm.
Which laws apply to you
| Law | Covers | Source |
|---|---|---|
| HIPAA | Health plans, clearinghouses, and health care providers that transmit health information electronically in a standard transaction (such as electronic billing), plus their business associates. | 45 CFR § 160.103 |
| CMIA | Licensed health care professionals and licensed clinics and health facilities, health plans, and "contractors" (medical groups, IPAs, PBMs), whether or not they bill electronically. Also businesses that maintain medical information or offer software, apps, mental health or reproductive health digital services. | Civ. Code §§ 56.05, 56.06, 56.10 |
| CMIA employer rules | Every employer that receives employee medical information, including providers as employers. | Civ. Code § 56.20 |
| Health & Safety Code § 1280.15 | Clinics, health facilities (including skilled nursing), home health agencies and hospices licensed under §§ 1204, 1250, 1725 or 1745. | H&S Code § 1280.15 |
| CCPA | Patient information governed by HIPAA or the CMIA is exempt, but a provider's other data (website analytics, marketing lists, employees and applicants) is not. | Civ. Code § 1798.145(c) |
For how HIPAA and the CMIA differ, see CMIA vs. HIPAA: what California adds.
Patient access to records
| Rule | Inspect | Copies |
|---|---|---|
| California (H&S Code § 123110) | Within 5 working days of the request, during business hours | Within 15 days, in the form and format requested if readily producible |
| Skilled nursing residents (42 CFR § 483.10(g)(2)) | Within 24 hours, excluding weekends and holidays | Within 2 working days of the request |
| HIPAA (45 CFR § 164.524(b)(2)) | Act within 30 days, with one 30-day extension if the patient is told why in writing | |
HIPAA's 30 days is the federal outer limit, not the California deadline. HHS proposed shortening HIPAA's deadline to 15 days in 2021; as of this review that change has not been finalized. OCR has brought 55 enforcement actions under its right-of-access initiative, the most recent against Azul Vision, a California eye-care provider, in August 2026 ($50,000, after a patient waited two years for records).
Disclosures and authorizations
Under the CMIA, a provider may not disclose medical information without the patient's authorization unless a disclosure is required or permitted by statute (Civ. Code § 56.10). A valid CMIA authorization must (Civ. Code § 56.11):
- be handwritten by the signer or in type no smaller than 14-point;
- be clearly separate from other language, with a signature serving no other purpose;
- state the specific uses and limits on the types of information to be disclosed, who may disclose and receive it, and the recipient's permitted uses;
- state an expiration date or event, generally no more than one year out unless the patient asks for longer;
- tell the signer of the right to a copy, and a copy must be provided.
Testimonials and "success stories" need an authorization. In 2025 OCR settled with Cadia Healthcare, a skilled nursing and rehabilitation operator, for $182,000 after it posted patient stories and photos online without HIPAA authorizations.
Breach and "snooping" reporting
A licensed clinic, health facility, home health agency or hospice must report unlawful or unauthorized access to, use or disclosure of a patient's medical information to CDPH and the patient within 15 business days after it is detected (H&S Code § 1280.15(b)). "Unauthorized" includes viewing a record without a direct need for diagnosis, treatment or another lawful use, so a staff member browsing a neighbor's chart counts. Penalties reach $25,000 per patient, plus $100 a day for late reports, capped at $250,000 per reported event.
HIPAA's Breach Notification Rule runs separately: patients within 60 days of discovery, HHS contemporaneously for 500 or more, and the media when more than 500 residents of a state are affected (45 CFR §§ 164.404–164.408). See Data breaches.
Senior care: skilled nursing and assisted living
Skilled nursing facilities
Federal requirements for Medicare and Medicaid nursing facilities give residents a right to personal privacy and to confidentiality of their personal and medical records, covering accommodations, treatment, written and phone communications, personal care, visits and meetings (42 CFR § 483.10(h)). Medical records must be kept confidential and safeguarded against loss or unauthorized use, and retained for the period state law requires (42 CFR § 483.70(h)). Skilled nursing facilities are also "health facilities" subject to § 1280.15's 15-business-day reporting.
Residential care facilities for the elderly (assisted living)
Residents have the right to a reasonable level of personal privacy, including in medical treatment, communications, phone calls and internet use, and to confidential treatment of their records and personal information (H&S Code § 1569.269(a)(2)–(3)). CDSS regulations make resident records confidential and allow release only with the resident's or representative's written consent, except as the law provides (22 CCR § 87506).
Assisted living facilities are licensed by CDSS, not CDPH, and are not among the facilities covered by § 1280.15. Whether HIPAA or the CMIA applies to a particular facility depends on facts such as whether it bills electronically and which licensed professionals provide care there. It's worth confirming for each facility.
Reproductive health, sensitive services and immigration status
- Federal: in June 2025, a federal court in Texas vacated most of HHS's 2024 HIPAA reproductive-health privacy rule (Purl v. HHS, N.D. Tex. No. 2:24-cv-00228). HHS says the Notice of Privacy Practices changes not vacated remain in effect, with compliance required by February 16, 2026 (HHS).
- California: providers may not release abortion-related information in response to out-of-state subpoenas or requests based on laws that interfere with California's reproductive privacy protections (Civ. Code § 56.108), or knowingly share identifying abortion information with out-of-state persons through an EHR or health information exchange, subject to exceptions (§ 56.110). Providers working diligently and in good faith toward compliance have a safe harbor until January 31, 2027.
- EHR vendors, not providers, carry the duty to segregate and limit access to sensitive-services information such as abortion, contraception and gender-affirming care (Civ. Code § 56.101(c)). Confirm your vendor has done it.
- Immigration status: since September 20, 2025 (SB 81), a patient's immigration status and place of birth are medical information, and disclosure for immigration enforcement is barred without authorization or a legal basis. The Attorney General issued a bulletin for providers in October 2025.
- Substance use disorder records: the 2024 update to 42 CFR Part 2 required compliance by February 16, 2026 (89 Fed. Reg. 12472).
Websites, apps and tracking
Patient-facing websites and portals are a growing source of risk. Tracking pixels on health pages can involve the CMIA, the CCPA (for non-patient data) and California's wiretapping statute. A Court of Appeal decision filed in July 2026 and ordered published in August, Doe v. Adventist Health System/West, partly revived class certification in a case over tracking tools on hospital websites and a patient portal. See Products and technology.
Checklist for providers
- Confirm which laws apply: HIPAA (electronic billing), CMIA (licensed provider or facility), § 1280.15 (licensed clinic, facility, home health or hospice).45 CFR § 160.103; Civ. Code § 56.05; H&S Code § 1280.15
- Meet California's access deadlines: 5 working days to inspect, 15 days for copies (24 hours and 2 working days in skilled nursing).H&S Code § 123110; 42 CFR § 483.10(g)
- Review your Notice of Privacy Practices for the changes due February 16, 2026, removing the vacated reproductive-health paragraphs.45 CFR § 164.520; HHS guidance
- Set up a 15-business-day workflow for CDPH and patient notices, and document every patient notice.H&S Code § 1280.15(b), (d)
- Audit EHR access logs to detect snooping.H&S Code § 1280.15; Civ. Code § 56.101(b)
- Use CMIA-compliant authorization forms (14-point type, separate signature, one-year expiration), including for testimonials and photos.Civ. Code § 56.11
- Confirm your EHR vendor segregates sensitive-services information, and set a process for out-of-state requests.Civ. Code §§ 56.101(c), 56.108, 56.110
- Route immigration-enforcement requests to management or counsel, and honor only California or federal court orders.Civ. Code § 56.10 (SB 81)
- Keep a current Security Rule risk analysis. Don't wait for the proposed rule.45 CFR § 164.308(a)(1)(ii)(A)–(B)
- Sign business associate agreements with every vendor that touches protected health information.45 CFR § 164.504(e)
- Keep employee medical files separate, under written confidentiality procedures.Civ. Code § 56.20
- Treat website and marketing data as CCPA data if you meet the thresholds.Civ. Code § 1798.145(c)
Guides in this topic
- ComparisonCMIA vs. HIPAA: what California addsA side-by-side comparison of HIPAA and California's Confidentiality of Medical Information Act: coverage, lawsuits, fines, authorizations, access deadlines, breach reporting and reproductive health.
- Topic guideData breachesCalifornia data breach response: the 30-day notice deadline under SB 446, Attorney General filings, CDPH 15-business-day reports, HIPAA and FTC timelines, and an incident response checklist.