CMIA

Cal. Civ. Code §§ 56–56.37

Confidentiality of Medical Information Act

In force since January 1, 1982

Who it applies to

  • Health-care providers, health-care service plans, pharmaceutical companies and contractors handling medical information
  • Businesses offering software or hardware, including mobile applications, that maintain medical information

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Without unreasonable delay, per Cal. Civ. Code § 1798.82
To the regulator
Licensed clinics and facilities report to the California Department of Public Health within 15 business days
What triggers it
Unlawful or unauthorised access to, or use or disclosure of, medical information

Penalties

Headline
Administrative fines up to $250,000 per violation for the most serious breaches
Private right of action
Yes — individuals can sue directly
Notes
Nominal damages of $1,000 are available without proof of actual damage, which makes the CMIA a materially different litigation risk from HIPAA — HIPAA has no private right of action at all.

Amendment history

  1. January 1, 2024

    AB 254 and AB 352 — reproductive and gender-affirming care

    Extended CMIA protection to reproductive and sexual health application data and restricted disclosure of gender-affirming and abortion-related records.

Sources

Timeline

todayCMIA in forceJanuary 1, 1982AB 254 and AB 352 — reproductive and gender-affirming careJanuary 1, 2024