Guide

HIPAA Compliance in California

How HIPAA interacts with California's CMIA, the CCPA/CPRA medical-data carve-outs, and state breach notification rules — in plain terms.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

California layers three bodies of law on top of HIPAA — the CMIA, the CCPA/CPRA with its medical-data carve-outs, and state breach notification statutes — and each one adds obligations that federal compliance alone does not satisfy.

Why California is different

HIPAA is a floor, not a ceiling. Section 160.203 of the federal rules preempts state law only where the state law is contrary to HIPAA and less protective of privacy. California law is frequently more protective, which means it survives preemption and applies alongside the federal rules. If you handle medical information about California residents — as a provider, a health plan, a digital health company, or a vendor to any of them — you are running two compliance programmes whether you have noticed or not.

The practical consequences cluster in three areas: the Confidentiality of Medical Information Act (CMIA), the consumer privacy regime under the CCPA as amended by the CPRA, and the state’s breach notification requirements. Each is worth understanding on its own terms.

The CMIA: California’s medical privacy statute

The CMIA, at California Civil Code section 56 and following, predates HIPAA and in several respects goes further. It applies to providers of health care, health plans, and contractors, and — following amendments aimed at the app economy — to businesses that offer software or hardware to consumers for the purpose of maintaining medical information, including many mobile health apps and wearable platforms. A consumer health app that sits outside HIPAA because no covered entity is involved can still sit squarely inside the CMIA.

Three differences from HIPAA matter most in practice.

First, the private right of action. HIPAA has none — individuals cannot sue under it, and enforcement runs through OCR and state attorneys general. The CMIA lets individuals sue directly, with nominal damages of $1,000 available without proof of actual harm, plus actual damages where they exist. A single mishandled record can become a lawsuit; a mishandled database can become a class action. This changes the risk calculus considerably: under HIPAA, a small breach might draw no regulatory attention at all, while under the CMIA it can still generate litigation.

Second, authorisation standards. The CMIA’s requirements for valid authorisation to disclose medical information are prescriptive about form and content, and disclosures that HIPAA would permit under its treatment, payment, and operations umbrella are not always permitted the same way under the CMIA. Marketing-adjacent uses deserve particular care.

Third, scope. Because the CMIA reaches businesses that maintain medical information for consumers regardless of covered-entity status, digital health companies should not assume that being outside HIPAA means being outside regulation. It often means the opposite: CMIA obligations without the familiar HIPAA framework to organise them.

CCPA/CPRA and the medical-data carve-outs

The CCPA, as amended by the CPRA, is California’s general consumer privacy law. It grants residents rights of access, deletion, correction, and opt-out, and it applies to for-profit businesses meeting certain revenue or data-volume thresholds.

Healthcare organisations often assume they are exempt. The truth is narrower. The statute exempts two categories: PHI collected by a HIPAA covered entity or business associate, and medical information governed by the CMIA. There is also a provider-level exemption for patient information that a CMIA-regulated provider maintains in the same manner as medical information. What the exemptions do not cover is everything else your organisation holds: website visitor data, marketing and advertising lists, data from wellness products that never touches a covered-entity relationship, and — subject to the statute’s employment provisions — workforce data.

The working method is a data inventory with a column for legal regime. For each data category, record whether it is PHI under HIPAA, medical information under the CMIA, personal information under CCPA/CPRA, or some combination. Most digital health companies discover they hold all three, in different systems, with different obligations attached. That inventory is also the foundation of the risk analysis HIPAA already requires, so the work compounds rather than duplicates.

California breach notification

California runs two breach notification regimes relevant to health data, and they are stricter than HIPAA’s in different ways.

The general statute, Civil Code section 1798.82, requires notification to affected residents in the most expedient time possible and without unreasonable delay. Medical information and health insurance information are expressly within the definition of personal information that triggers notice. Where a breach affects more than 500 California residents, a sample copy of the notice goes to the Attorney General, who publishes breach notices on a public website — meaning California breaches carry built-in publicity. The statute also prescribes the content and format of the notice itself, down to required headings.

The second regime is the one that surprises people. Health and Safety Code section 1280.15 requires clinics, health facilities, and hospices licensed by the state to report unauthorised access to or disclosure of patient medical information to both the affected patient and the California Department of Public Health within 15 business days. That is dramatically shorter than HIPAA’s 60-day individual-notification window, and the state has imposed administrative penalties for late reporting. If you operate a licensed facility in California, your incident response plan needs a 15-business-day clock in it, not a 60-day one.

Notifying under HIPAA does not excuse notifying under California law. The obligations run in parallel, and the tightest deadline governs your operational plan.

Running one programme that satisfies both

The efficient approach is not two programmes but one programme with California-specific extensions. Concretely:

  • Build your policies to HIPAA’s structure, then annotate the California deltas: CMIA authorisation standards, the 15-business-day facility notification clock, CCPA/CPRA rights handling for non-exempt data.
  • Extend your data inventory to classify every data category by regime, and keep it current as products change.
  • Put California timelines into your incident response runbook explicitly, so nobody is researching state law during a live incident.
  • Cover CMIA and state-law obligations in vendor contracts alongside the business associate agreement, especially for vendors handling consumer health data outside HIPAA’s scope.
  • Train your workforce on the private right of action — the knowledge that individuals can sue directly tends to sharpen attention in a way abstract federal penalties do not.

Document all of it. California enforcement, like federal enforcement, turns on what you can show, not what you meant.

Where SuperHIPAA fits

The platform tracks your policies, evidence, and vendor register against HIPAA’s requirements, and our team helps you layer the state-specific obligations on top — so the California deltas live in the same system as everything else instead of in someone’s head.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report showing where your HIPAA foundation stands, which is the base every California obligation builds on. If you are further along than you thought, we will tell you that too.

Questions

Does HIPAA compliance cover me for California law?

Not automatically. HIPAA sets a federal floor; California's CMIA and breach notification statutes add obligations on top, including a private right of action under CMIA and shorter notification timelines for licensed health facilities. You need to satisfy both.

What is the CMIA?

The Confidentiality of Medical Information Act, California Civil Code section 56 and following. It restricts how providers, health plans, contractors, and certain app developers use and disclose medical information about California residents, and it lets individuals sue directly — something HIPAA does not allow.

Does the CCPA/CPRA apply to healthcare organisations?

Partly. PHI held by a HIPAA covered entity or business associate is exempt, as is medical information governed by the CMIA. But data outside those categories — website analytics, marketing lists, employee data in some respects — can still fall under CCPA/CPRA if your organisation meets its thresholds.

Can patients sue under California law for a privacy violation?

Yes. Unlike HIPAA, the CMIA includes a private right of action, with nominal damages of $1,000 available without proving actual harm, plus actual damages where they exist. This is a major practical difference from federal enforcement.

What are California's breach notification deadlines?

General businesses must notify affected residents without unreasonable delay under Civil Code 1798.82, and notify the Attorney General when a breach affects more than 500 Californians. Licensed clinics and health facilities face a much tighter clock — 15 business days to notify patients and the state under Health and Safety Code 1280.15.

Is there a HIPAA certification that satisfies California regulators?

No. HHS operates no HIPAA certification programme and no state accepts one, because none exists. What regulators and customers accept is documented compliance and, where useful, an independent third-party assessment.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo