California layers three bodies of law on top of HIPAA — the CMIA, the CCPA/CPRA with its medical-data carve-outs, and state breach notification statutes — and each one adds obligations that federal compliance alone does not satisfy.
Why California is different
HIPAA is a floor, not a ceiling. Section 160.203 of the federal rules preempts state law only where the state law is contrary to HIPAA and less protective of privacy. California law is frequently more protective, which means it survives preemption and applies alongside the federal rules. If you handle medical information about California residents — as a provider, a health plan, a digital health company, or a vendor to any of them — you are running two compliance programmes whether you have noticed or not.
The practical consequences cluster in three areas: the Confidentiality of Medical Information Act (CMIA), the consumer privacy regime under the CCPA as amended by the CPRA, and the state’s breach notification requirements. Each is worth understanding on its own terms.
The CMIA: California’s medical privacy statute
The CMIA, at California Civil Code section 56 and following, predates HIPAA and in several respects goes further. It applies to providers of health care, health plans, and contractors, and — following amendments aimed at the app economy — to businesses that offer software or hardware to consumers for the purpose of maintaining medical information, including many mobile health apps and wearable platforms. A consumer health app that sits outside HIPAA because no covered entity is involved can still sit squarely inside the CMIA.
Three differences from HIPAA matter most in practice.
First, the private right of action. HIPAA has none — individuals cannot sue under it, and enforcement runs through OCR and state attorneys general. The CMIA lets individuals sue directly, with nominal damages of $1,000 available without proof of actual harm, plus actual damages where they exist. A single mishandled record can become a lawsuit; a mishandled database can become a class action. This changes the risk calculus considerably: under HIPAA, a small breach might draw no regulatory attention at all, while under the CMIA it can still generate litigation.
Second, authorisation standards. The CMIA’s requirements for valid authorisation to disclose medical information are prescriptive about form and content, and disclosures that HIPAA would permit under its treatment, payment, and operations umbrella are not always permitted the same way under the CMIA. Marketing-adjacent uses deserve particular care.
Third, scope. Because the CMIA reaches businesses that maintain medical information for consumers regardless of covered-entity status, digital health companies should not assume that being outside HIPAA means being outside regulation. It often means the opposite: CMIA obligations without the familiar HIPAA framework to organise them.
CCPA/CPRA and the medical-data carve-outs
The CCPA, as amended by the CPRA, is California’s general consumer privacy law. It grants residents rights of access, deletion, correction, and opt-out, and it applies to for-profit businesses meeting certain revenue or data-volume thresholds.
Healthcare organisations often assume they are exempt. The truth is narrower. The statute exempts two categories: PHI collected by a HIPAA covered entity or business associate, and medical information governed by the CMIA. There is also a provider-level exemption for patient information that a CMIA-regulated provider maintains in the same manner as medical information. What the exemptions do not cover is everything else your organisation holds: website visitor data, marketing and advertising lists, data from wellness products that never touches a covered-entity relationship, and — subject to the statute’s employment provisions — workforce data.
The working method is a data inventory with a column for legal regime. For each data category, record whether it is PHI under HIPAA, medical information under the CMIA, personal information under CCPA/CPRA, or some combination. Most digital health companies discover they hold all three, in different systems, with different obligations attached. That inventory is also the foundation of the risk analysis HIPAA already requires, so the work compounds rather than duplicates.
California breach notification
California runs two breach notification regimes relevant to health data, and they are stricter than HIPAA’s in different ways.
The general statute, Civil Code section 1798.82, requires notification to affected residents in the most expedient time possible and without unreasonable delay. Medical information and health insurance information are expressly within the definition of personal information that triggers notice. Where a breach affects more than 500 California residents, a sample copy of the notice goes to the Attorney General, who publishes breach notices on a public website — meaning California breaches carry built-in publicity. The statute also prescribes the content and format of the notice itself, down to required headings.
The second regime is the one that surprises people. Health and Safety Code section 1280.15 requires clinics, health facilities, and hospices licensed by the state to report unauthorised access to or disclosure of patient medical information to both the affected patient and the California Department of Public Health within 15 business days. That is dramatically shorter than HIPAA’s 60-day individual-notification window, and the state has imposed administrative penalties for late reporting. If you operate a licensed facility in California, your incident response plan needs a 15-business-day clock in it, not a 60-day one.
Notifying under HIPAA does not excuse notifying under California law. The obligations run in parallel, and the tightest deadline governs your operational plan.
Running one programme that satisfies both
The efficient approach is not two programmes but one programme with California-specific extensions. Concretely:
- Build your policies to HIPAA’s structure, then annotate the California deltas: CMIA authorisation standards, the 15-business-day facility notification clock, CCPA/CPRA rights handling for non-exempt data.
- Extend your data inventory to classify every data category by regime, and keep it current as products change.
- Put California timelines into your incident response runbook explicitly, so nobody is researching state law during a live incident.
- Cover CMIA and state-law obligations in vendor contracts alongside the business associate agreement, especially for vendors handling consumer health data outside HIPAA’s scope.
- Train your workforce on the private right of action — the knowledge that individuals can sue directly tends to sharpen attention in a way abstract federal penalties do not.
Document all of it. California enforcement, like federal enforcement, turns on what you can show, not what you meant.
Where SuperHIPAA fits
The platform tracks your policies, evidence, and vendor register against HIPAA’s requirements, and our team helps you layer the state-specific obligations on top — so the California deltas live in the same system as everything else instead of in someone’s head.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report showing where your HIPAA foundation stands, which is the base every California obligation builds on. If you are further along than you thought, we will tell you that too.