CMIA
Cal. Civ. Code §§ 56–56.37Confidentiality of Medical Information Act
In force since January 1, 1982
Who it applies to
- Health-care providers, health-care service plans, pharmaceutical companies and contractors handling medical information
- Businesses offering software or hardware, including mobile applications, that maintain medical information
Consumer rights
- Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.
Obligations
- Consent model
- Opt-in
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Without unreasonable delay, per Cal. Civ. Code § 1798.82
- To the regulator
- Licensed clinics and facilities report to the California Department of Public Health within 15 business days
- What triggers it
- Unlawful or unauthorised access to, or use or disclosure of, medical information
Penalties
- Headline
- Administrative fines up to $250,000 per violation for the most serious breaches
- Private right of action
- Yes — individuals can sue directly
- Notes
- Nominal damages of $1,000 are available without proof of actual damage, which makes the CMIA a materially different litigation risk from HIPAA — HIPAA has no private right of action at all.
Amendment history
January 1, 2024
AB 254 and AB 352 — reproductive and gender-affirming care
Extended CMIA protection to reproductive and sexual health application data and restricted disclosure of gender-affirming and abortion-related records.