California CMIA: Coverage, Authorization, and Penalties

The California Confidentiality of Medical Information Act, codified at Civil Code Section 56 and following, controls how healthcare providers, health plans, their contractors, pharmaceutical companies, and health-app developers may collect, use, and disclose identifiable patient data in California. It generally forbids sharing that information without the patient’s written authorization, sets strict formatting rules for what an authorization must contain, and backs the whole scheme with civil damages, administrative fines up to $250,000 per violation, and misdemeanor exposure. The law predates HIPAA by more than fifteen years and, in several areas, imposes stricter obligations than the federal rule.

Who the Law Covers

The CMIA reaches four groups of entities that handle medical information in California:1California Legislative Information. California Code CIV 56.05 – Definitions

  • Providers of health care — anyone licensed or certified under California’s Business and Professions Code, and clinics or hospitals licensed under the Health and Safety Code.
  • Health care service plans regulated under the Knox-Keene Act, essentially managed-care organizations like HMOs.
  • Contractors, including medical groups, independent practice associations, pharmaceutical benefits managers, and medical service organizations that handle patient data on behalf of a provider or plan.
  • Pharmaceutical companies that manufacture, sell, or distribute prescription drugs.

The data itself must qualify as “medical information”: individually identifiable records, electronic or physical, about a patient’s medical history, mental or physical condition, or treatment. Individually identifiable means the record carries enough personal detail — a name, address, email, phone number, or Social Security number — to link it to a specific person. Data that has been fully stripped of identifiers so no one could trace it back to a patient falls outside the statute, which matters for research institutions and analytics firms working with aggregated health data.

Health Apps and Wearables

The reach into consumer technology surprises people. California’s Attorney General has stated that the CMIA applies to businesses offering mobile apps or wearable devices designed to store medical information, even when those companies have no obligations under HIPAA.2State of California – Department of Justice – Office of the Attorney General. Attorney General Bonta Emphasizes Health Apps Legal Obligation to Protect Reproductive Health Information Fertility trackers, period-tracking apps, and pregnancy-related connected products are subject to the same disclosure restrictions as a hospital. If you use one of these apps in California, the information stored inside gets statutory protection.

How the CMIA Compares to HIPAA

HIPAA applies to “covered entities” — health plans, healthcare clearinghouses, and providers who transmit health information electronically. The CMIA covers a broader group. It reaches all healthcare providers operating in California, including small practices and individual practitioners who might not qualify as HIPAA-covered entities, plus pharmaceutical companies and health-app developers that HIPAA does not touch.

When both laws apply to the same organization, it must follow whichever rule is more protective of the patient. Because the CMIA is often stricter, California entities frequently find that the state law controls. Compliance with HIPAA alone is not enough in California.

When Disclosure Is Allowed Without Patient Consent

The default rule is that no covered entity may disclose a patient’s medical information without first getting the patient’s written authorization.3California Legislative Information. California Civil Code 56.10 – Disclosure of Medical Information The statute carves out two categories of exceptions: disclosures that are required and disclosures that are permitted.

Required Disclosures

Covered entities must release medical information, regardless of the patient’s wishes, in response to:

  • Court orders from a California or federal court.
  • Investigative subpoenas from boards, commissions, or administrative agencies acting within their authority.
  • Subpoenas or discovery notices issued in court or administrative proceedings.
  • Search warrants lawfully issued to a government law enforcement agency.
  • Coroner requests during a death investigation, including suspected abuse, poisoning, or public health concerns.
  • Other California laws that require disclosure, such as mandatory reporting of child abuse, elder abuse, or gunshot wounds.4California Legislative Information. California Code CIV 56.10 – Disclosure of Medical Information by Providers

Permitted Disclosures

Covered entities may share information — but do not have to — for the following purposes:

  • Treatment. Sharing data with other providers, plans, or professionals who are diagnosing or treating the patient.
  • Payment. Sharing data with insurers, employers, or others responsible for paying for care, limited to what is necessary to process payment.
  • Employment-related services. When a provider delivered care at the employer’s written request and expense, the provider may tell the employer about functional limitations affecting the employee’s work or leave eligibility, but not the underlying diagnosis.3California Legislative Information. California Civil Code 56.10 – Disclosure of Medical Information

Outside these exceptions, covered entities cannot intentionally sell medical information, use it for marketing, or repurpose it for anything unrelated to the patient’s healthcare.

What a Valid Authorization Looks Like

Where no exception applies, the entity needs written authorization from the patient before releasing records. The formatting requirements are stricter than a typical release form.5California Legislative Information. California Code CIV 56.11 – Authorization Requirements

The authorization must be handwritten by the signer or printed in type no smaller than 14 points. It must be clearly separated from any other language on the page, and the signature cannot serve two purposes at once. Signing to authorize a disclosure and to consent to treatment on the same line would be invalid.

The document itself must include all of the following:

  • The specific types of medical information to be disclosed, and any limitations
  • The name or function of the entity authorized to release the information
  • The name or function of the person or entity authorized to receive it
  • The permitted uses of the information by the recipient
  • An expiration date after which the authorization is no longer valid
  • A notice advising the signer of the right to receive a copy of the authorization

Generally the patient signs. A legal representative may sign for a minor or a patient who lacks capacity. An authorization missing any required element is invalid, and a disclosure made in reliance on a defective authorization counts as an unauthorized disclosure, exposing the entity to the full penalty range below.

Penalties for Violating the CMIA

A single unauthorized disclosure can trigger criminal liability, civil damages payable to the patient, and administrative fines simultaneously. Amounts scale with how deliberately the violation occurred.

Criminal Exposure

Any CMIA violation that results in economic loss or personal injury to a patient is punishable as a misdemeanor.6California Legislative Information. California Code CIV 56.36 – Penalties and Remedies The statute does not require proof of intent. A negligent disclosure that causes financial harm or injury can support prosecution.

Civil Damages to the Patient

A patient whose medical information was negligently released may sue for nominal damages of $1,000 per violation without having to prove actual harm. If the patient did suffer harm, such as identity theft, job loss, or emotional distress, they can recover actual damages in addition to or instead of the nominal award. The statute also allows recovery of reasonable attorney’s fees and costs, so pursuing a claim does not have to come out of the patient’s pocket.

Administrative and Civil Penalties

On top of what the patient recovers, per-violation fines apply, and they vary by the violator’s status and state of mind:

  • Negligent disclosure: up to $2,500 per violation, regardless of whether the patient suffered actual damages.
  • Knowing and willful violation by a non-licensed entity: up to $25,000 per violation.
  • Knowing and willful violation by a licensed health care professional: up to $2,500 for a first offense, $10,000 for a second, and $25,000 for a third or subsequent offense.
  • Violation for financial gain by a non-licensed entity: up to $250,000 per violation, plus disgorgement of any profits.
  • Violation for financial gain by a licensed professional: up to $5,000 for a first offense, $25,000 for a second, and $250,000 for a third or subsequent offense, plus disgorgement.

The distinction between licensed professionals and other entities is deliberate. A hospital corporation or data contractor that knowingly violates the CMIA can face the maximum fine from the first incident. A licensed individual doctor or nurse gets a graduated scale, though that leniency disappears by the third offense, and anyone exploiting patient data for profit faces the steepest penalties in the statute.

How the Penalties Stack

These tracks are cumulative, not alternative. A single negligent disclosure can produce a misdemeanor charge, a $1,000 nominal damages award to the patient, a $2,500 administrative fine, and an order to pay the patient’s attorney’s fees. In a breach touching thousands of patients, the per-violation math compounds quickly. The statute states that imposing one penalty does not prevent imposing others authorized by law.

The Limited Affirmative Defense

The CMIA gives defendants one narrow off-ramp. An entity that shows it took specific steps after discovering the violation, such as promptly notifying affected patients and taking corrective action, may persuade a court to decline the $1,000 nominal damages award. Actual damages proven by the patient remain owed, and the entity still pays the patient’s attorney’s fees and costs.6California Legislative Information. California Code CIV 56.36 – Penalties and Remedies

California courts have added a further wrinkle. In at least one class action involving a major health system, a court held that the nominal damages provision requires more than unauthorized possession of medical records: the information must have been actually viewed by an unauthorized person before the $1,000 per-patient award attaches. That interpretation can shift the outcome of large-scale breach litigation significantly, and anyone bringing or defending a CMIA claim should factor it in when estimating exposure.