Most California providers are subject to both laws. HIPAA generally doesn't displace state laws that are more protective of patients, so the practical rule is to meet whichever requirement is stricter.
Side by side
| Topic | HIPAA | CMIA and California law |
|---|---|---|
| Who's covered | Health plans, clearinghouses, providers that bill electronically, and their business associates (45 CFR § 160.103) | All licensed providers and facilities regardless of billing, plus contractors, employers (§ 56.20), and health software, apps and digital services deemed providers (§ 56.06) |
| Patient lawsuits | No private right of action | $1,000 nominal damages without proof of harm, plus actual damages (§ 56.36(b)); compensatory and limited punitive damages and fees for economic loss or injury (§ 56.35) |
| Government penalties | Tiered civil money penalties; annual caps for identical violations of up to $2,190,294, with lower caps for less culpable tiers (45 CFR § 102.3) | Up to $2,500 per negligent violation, and up to $25,000 or $250,000 for knowing, willful or profit-driven violations (§ 56.36(c)); CDPH penalties up to $25,000 per patient (H&S § 1280.15) |
| Authorization form | Core elements (45 CFR § 164.508) | Adds 14-point type, a separate signature, a one-year default expiration, and a copy to the patient (§ 56.11) |
| Access to records | 30 days, plus one 30-day extension | 5 working days to inspect; 15 days for copies (H&S § 123110) |
| Breach reporting | 60-day outer limit; HHS and media notice at set thresholds | Licensed facilities: CDPH and patient within 15 business days (H&S § 1280.15); businesses generally: 30 days (Civ. Code § 1798.82) |
| Reproductive health | 2024 protections mostly vacated (Purl v. HHS, N.D. Tex. 2025) | Limits on out-of-state subpoenas and sharing (§§ 56.108, 56.110); EHR segregation duties for vendors (§ 56.101(c)) |
| Immigration status | No special rule | Treated as medical information; no disclosure for immigration enforcement without authorization or a legal basis (SB 81, 2025; § 56.10) |
| Employers | Employment records aren't protected health information | Employers must protect employee medical information and generally need an authorization to use or disclose it (§ 56.20) |
California reaches further
HIPAA applies to a provider only if it conducts certain transactions electronically. The CMIA applies to licensed providers regardless of how they bill. It also treats as providers several kinds of businesses HIPAA doesn't reach: businesses organized to maintain medical information, companies offering software or hardware (including mobile apps) designed to maintain medical information, and businesses offering mental health or reproductive or sexual health digital services (Civ. Code § 56.06). For a consumer health app, that can be the difference between no health-privacy statute and a statute with a private right of action.
Lawsuits change the risk
HIPAA is enforced only by government. The CMIA lets a patient recover $1,000 in nominal damages for a negligent release without proving any harm (Civ. Code § 56.36(b)). Multiplied across a patient population, that is why CMIA claims appear in data-breach and website-tracking class actions. The statute includes a limited defense for HIPAA-regulated entities that meet specified conditions after a breach (§ 56.36(e)).
What to do about it
- Use one authorization form that meets both laws. In practice that means the CMIA form, which is stricter.Civ. Code § 56.11; 45 CFR § 164.508
- Calendar access requests to California's 5-working-day and 15-day deadlines.H&S Code § 123110
- Run breach analysis under the CMIA and § 1280.15 as well as HIPAA; the California clocks usually run out first.H&S Code § 1280.15; Civ. Code § 1798.82
- If you build or use health apps, check whether § 56.06 makes the business a "provider" under the CMIA.Civ. Code § 56.06
Official sources
- Civil Code §§ 56–56.37 (California Legislative Information)
- 45 CFR Parts 160 and 164 (eCFR)
- Reproductive health care and HIPAA (HHS)
- Topic guideHealth information confidentialityHIPAA and the California CMIA for healthcare and senior-care providers: coverage, patient access deadlines, authorizations, CDPH breach reporting, SNF and RCFE resident privacy, and 2025-2026 changes.
- Topic guideData breachesCalifornia data breach response: the 30-day notice deadline under SB 446, Attorney General filings, CDPH 15-business-day reports, HIPAA and FTC timelines, and an incident response checklist.