California medical records laws give patients faster access, stricter authorization rules, and stronger privacy protections than federal law alone. The state’s Confidentiality of Medical Information Act (CMIA) works alongside HIPAA, and when the two conflict, providers must follow whichever rule protects you more. That layered system shapes how quickly you can get your records, who can see them, how they must be stored, and what happens if a provider gets it wrong.
Getting Your Own Medical Records
Under California Health and Safety Code 123110, any adult patient or authorized representative can request to inspect or copy their medical records. The deadline depends on what you ask for. To look at records in person, the provider must allow inspection during business hours within five working days of your written request. To receive paper or electronic copies, the provider has 15 days from the date of your request.1California Legislative Information. California Health and Safety Code 123110 (2025)
Those timelines are tighter than HIPAA, which allows providers up to 30 calendar days and permits one 30-day extension.2HHS.gov. Individuals’ Right Under HIPAA to Access Their Health Information California wins because it’s stricter.
If you need records to support a claim or appeal for a public benefit program like Medi-Cal, the timeline stretches to 30 days but the provider cannot charge you anything. Include proof that the records are needed for the benefit claim along with your written request.1California Legislative Information. California Health and Safety Code 123110 (2025)
For standard copy requests, providers can charge a reasonable, cost-based fee covering labor, supplies, and postage. The per-page cap is $0.25 for paper copies and $0.50 for records copied from microfilm.1California Legislative Information. California Health and Safety Code 123110 (2025)
Electronic Copies
If your records are maintained electronically, you can ask for them in a specific format, such as PDF or a structured clinical data standard. The provider must deliver the format you requested if the system can readily produce it. If they can’t, they must offer alternative electronic formats. Paper is a fallback only after you decline every available electronic option.3HHS.gov. When an Individual Exercises Her HIPAA Right to Get an Electronic Copy of Her PHI
When a Provider Can Deny Access
A California provider can withhold records if a licensed health care professional determines that releasing the information would cause substantial harm to your physical or mental health. The denial has to be documented, and the provider must tell you that you can designate another licensed professional to review the records on your behalf.1California Legislative Information. California Health and Safety Code 123110 (2025)
HIPAA adds two more grounds for denial: when a professional concludes that the information could endanger your life or someone else’s physical safety, or when the records reference another person and releasing them could cause that person substantial harm. In those cases, you can have the denial reviewed by a different licensed professional who wasn’t involved in the original decision.4eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
Authorization to Share Your Records With Others
Under the CMIA, a provider cannot release your medical information to a third party without your written authorization, unless a specific legal exception applies. California is picky about what a valid authorization looks like. It must be either handwritten by you or printed in at least 14-point type. The authorization language must be visually separated from any other text on the page. And your signature cannot serve any purpose other than executing that authorization.5California Legislative Information. California Civil Code 56.10
The form itself must specify the types of information being released, who’s allowed to disclose it, who’s authorized to receive it, the intended use, an expiration date, and a notice that you’re entitled to a copy. A general authorization for “all medical information” is not sufficient under California law.
When Records Can Be Released Without Your Consent
The CMIA carves out situations where providers must or may share records without patient authorization. Even when disclosure is legally authorized, the provider should release only the minimum information necessary for the stated purpose.
- Court orders and subpoenas. Providers must disclose records when compelled by a state or federal court order, an administrative subpoena, or a valid search warrant issued to a law enforcement agency.5California Legislative Information. California Civil Code 56.10
- Law enforcement. Outside of a court order or warrant, law enforcement access requires either prior written consent from the patient or a court order showing good cause.6Justia Law. California Penal Code 1543-1545 – Disclosure of Medical Records to Law Enforcement Agencies
- Public health reporting. Providers must report certain communicable diseases and adverse events to public health officials.
- Coroners and medical examiners. Records can be shared to identify a deceased individual, locate next of kin, or investigate deaths involving public health concerns or suspected abuse.5California Legislative Information. California Civil Code 56.10
- Workers’ compensation. Insurers and employers involved in a workers’ comp claim may access records related to the workplace injury, limited to information relevant to that specific claim.
Extra Protection for Sensitive Records
Some categories of health information get heightened confidentiality on top of the standard CMIA rules.
Psychotherapy Records
Before anyone can access outpatient psychotherapy records, they must submit a separate written request identifying the specific information sought, its intended use, how long it will be kept before destruction, and a statement that the records won’t be used for any other purpose. The requesting party must send you a copy of that written request within 30 days of receiving the records, unless you waived that notice.
HIV and AIDS Records
Public health records containing identifying information about HIV or AIDS status can only be disclosed for public health purposes or with your written authorization. These records cannot be used in any civil, criminal, or administrative proceeding, and cannot be used to determine your employability or insurability. Unauthorized disclosure carries its own penalties: up to $5,000 for negligent disclosure, and between $5,000 and $25,000 for willful or malicious disclosure.7Justia Law. California Health and Safety Code 121025-121035 – Acquired Immune Deficiency Syndrome
Substance Use Disorder Treatment Records
Federal regulations under 42 CFR Part 2 impose restrictions that go beyond both HIPAA and the CMIA. Substance use disorder treatment records cannot be used to bring criminal charges against a patient, and a general medical records authorization is explicitly not enough to permit their release. Any disclosure made with patient consent must include a written notice prohibiting the recipient from further sharing the records in legal proceedings without a court order.8eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records No California law can override these federal protections.
Parents, Minors, and Confidential Care
Parents and legal guardians generally have the right to access their minor child’s medical records, but California blocks that access in three situations under Health and Safety Code 123115: when the minor lawfully consented to the treatment, when a provider determines that parental access would harm the provider-patient relationship or the minor’s safety, and when the records relate to specific confidential care categories.9California Legislative Information. California Health and Safety Code 123115
Those confidential care categories are broader than many parents realize. A minor 12 or older can independently consent to outpatient mental health counseling, drug and alcohol treatment, and certain reproductive healthcare including contraception.10National Center for Youth Law. California Minor Consent and Confidentiality Compendium 2024 When a minor consents to any of these services, the minor controls the records. The provider cannot disclose that information to a parent without a release from the minor.
Records of a Deceased Patient
HIPAA protections for a deceased person’s health information last for 50 years after the date of death. During that period, the personal representative of the deceased, typically the executor or administrator of the estate, can exercise the same access and authorization rights the patient would have had.11HHS.gov. Health Information of Deceased Individuals
A provider may also share relevant health information with a family member or other person who was involved in the individual’s care or payment before death, unless doing so would conflict with a preference the deceased expressed while alive. Establishing your right to records usually requires the death certificate along with a court document, such as letters testamentary, showing authority over the estate.
Correcting Information in Your Record
You can ask a provider to correct information in your medical record. Under HIPAA, the provider must act on your request within 60 days, with one possible 30-day extension if they notify you of the delay in writing. They can deny the request if the information is accurate and complete, was not created by that provider, or is not part of the designated record set.12eCFR. 45 CFR 164.526 – Amendment of Protected Health Information
If your amendment is denied, you can submit a written statement of disagreement that becomes a permanent part of your record. The provider can add a rebuttal, but must include your disagreement statement with any future disclosure of the disputed information.
How Long Providers Have to Keep Records
Licensed healthcare facilities in California must retain patient records for at least seven years after the patient’s last encounter. For minors, records must be kept until at least one year after the patient turns 18, but never for less than seven years total.13Cornell Law School. California Code of Regulations Title 22, Section 72543 – Patients Health Records Individual physicians face the same seven-year minimum under Business and Professions Code 2266, and failure to maintain adequate records for that period constitutes unprofessional conduct that can trigger discipline by the Medical Board.14California Legislative Information. California Business and Professions Code 2266 (2025)
Once the retention period expires, records must be destroyed in a way that makes them completely unreadable. Paper records should be shredded, and electronic files must be permanently deleted or overwritten.
Breach Notification
California’s breach notification law is one of the most demanding in the country. If a business or individual that handles computerized personal data, including medical information, discovers a security breach affecting California residents, they must notify those residents within 30 calendar days.15California Legislative Information. California Civil Code 1798.82
The notification must be titled “Notice of Data Breach,” written in plain language, and organized under required headings: “What Happened,” “What Information Was Involved,” “What We Are Doing,” “What You Can Do,” and “For More Information.” It must include the types of information compromised, the date or estimated date range of the breach, and the entity’s contact information. Delay is permitted only to accommodate a law enforcement investigation or to determine the scope of the breach and restore system integrity.
HIPAA adds a separate federal layer. Providers must notify affected individuals within 60 days of discovering a breach of unsecured protected health information. When a breach affects 500 or more people, the provider must also notify HHS and prominent media outlets in the affected area within the same 60-day window. Smaller breaches can be reported to HHS annually, no later than 60 days after the end of the calendar year.16HHS.gov. Breach Notification Rule Because California’s 30-day deadline is shorter, California providers must meet the state timeline for notifications sent to individuals.
Penalties for Violations
Penalties under the CMIA are tiered by intent. The California Department of Public Health and the Medical Board of California both play enforcement roles, and violations can lead to fines, license discipline, and criminal charges.
State Penalties Under the CMIA
Negligent disclosure caps at $2,500 per violation. Knowingly and willfully obtaining, disclosing, or using medical information in violation of the CMIA raises the cap to $25,000 per violation for non-licensed entities. Licensed health professionals face a graduated scale: up to $2,500 on a first offense, $10,000 on a second, and $25,000 on a third or subsequent violation.17California Legislative Information. California Civil Code 56.36
When a violation is committed for financial gain, non-licensed entities face up to $250,000 per violation plus disgorgement of any profits. Licensed professionals face graduated penalties up to $250,000 by the third offense. Any CMIA violation that causes economic loss or physical injury to a patient is also punishable as a misdemeanor.17California Legislative Information. California Civil Code 56.36
You can file a private lawsuit seeking $1,000 in nominal damages per violation regardless of whether you suffered actual harm. Provable actual damages can be recovered on top of that.17California Legislative Information. California Civil Code 56.36
Federal HIPAA Penalties
Federal penalties are adjusted annually for inflation. As of 2026, the tiers are:
- Did not know, and couldn’t have known through reasonable diligence: $145 to $73,011 per violation.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation.
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation.
All four tiers share the same calendar year cap of $2,190,294 for identical violations.18Federal Register. Annual Civil Monetary Penalties Inflation Adjustment A California provider who violates both the CMIA and HIPAA can face state and federal penalties at the same time.