Health information · Comparison

CMIA vs. HIPAA: what California adds

HIPAA sets a federal floor. California's Confidentiality of Medical Information Act reaches more businesses, sets stricter forms and deadlines, and lets patients sue.

Last reviewed

Most California providers are subject to both laws. HIPAA generally doesn't displace state laws that are more protective of patients, so the practical rule is to meet whichever requirement is stricter.

Side by side

TopicHIPAACMIA and California law
Who's coveredHealth plans, clearinghouses, providers that bill electronically, and their business associates (45 CFR § 160.103)All licensed providers and facilities regardless of billing, plus contractors, employers (§ 56.20), and health software, apps and digital services deemed providers (§ 56.06)
Patient lawsuitsNo private right of action$1,000 nominal damages without proof of harm, plus actual damages (§ 56.36(b)); compensatory and limited punitive damages and fees for economic loss or injury (§ 56.35)
Government penaltiesTiered civil money penalties; annual caps for identical violations of up to $2,190,294, with lower caps for less culpable tiers (45 CFR § 102.3)Up to $2,500 per negligent violation, and up to $25,000 or $250,000 for knowing, willful or profit-driven violations (§ 56.36(c)); CDPH penalties up to $25,000 per patient (H&S § 1280.15)
Authorization formCore elements (45 CFR § 164.508)Adds 14-point type, a separate signature, a one-year default expiration, and a copy to the patient (§ 56.11)
Access to records30 days, plus one 30-day extension5 working days to inspect; 15 days for copies (H&S § 123110)
Breach reporting60-day outer limit; HHS and media notice at set thresholdsLicensed facilities: CDPH and patient within 15 business days (H&S § 1280.15); businesses generally: 30 days (Civ. Code § 1798.82)
Reproductive health2024 protections mostly vacated (Purl v. HHS, N.D. Tex. 2025)Limits on out-of-state subpoenas and sharing (§§ 56.108, 56.110); EHR segregation duties for vendors (§ 56.101(c))
Immigration statusNo special ruleTreated as medical information; no disclosure for immigration enforcement without authorization or a legal basis (SB 81, 2025; § 56.10)
EmployersEmployment records aren't protected health informationEmployers must protect employee medical information and generally need an authorization to use or disclose it (§ 56.20)

California reaches further

HIPAA applies to a provider only if it conducts certain transactions electronically. The CMIA applies to licensed providers regardless of how they bill. It also treats as providers several kinds of businesses HIPAA doesn't reach: businesses organized to maintain medical information, companies offering software or hardware (including mobile apps) designed to maintain medical information, and businesses offering mental health or reproductive or sexual health digital services (Civ. Code § 56.06). For a consumer health app, that can be the difference between no health-privacy statute and a statute with a private right of action.

Lawsuits change the risk

HIPAA is enforced only by government. The CMIA lets a patient recover $1,000 in nominal damages for a negligent release without proving any harm (Civ. Code § 56.36(b)). Multiplied across a patient population, that is why CMIA claims appear in data-breach and website-tracking class actions. The statute includes a limited defense for HIPAA-regulated entities that meet specified conditions after a breach (§ 56.36(e)).

What to do about it

  • Use one authorization form that meets both laws. In practice that means the CMIA form, which is stricter.Civ. Code § 56.11; 45 CFR § 164.508
  • Calendar access requests to California's 5-working-day and 15-day deadlines.H&S Code § 123110
  • Run breach analysis under the CMIA and § 1280.15 as well as HIPAA; the California clocks usually run out first.H&S Code § 1280.15; Civ. Code § 1798.82
  • If you build or use health apps, check whether § 56.06 makes the business a "provider" under the CMIA.Civ. Code § 56.06

Official sources