How CMIA Expands Individual Privacy Protections Beyond HIPAA

California’s Confidentiality of Medical Information Act expands privacy protections beyond HIPAA in several concrete ways: it requires more detailed patient authorizations, gives patients a private right to sue with $1,000 in nominal damages per violation, imposes higher tiered penalties (up to $250,000 for disclosures made for financial gain), demands breach notification within 15 business days rather than HIPAA’s 60 calendar days, and reaches businesses that HIPAA does not cover. Because HIPAA sets a floor rather than a ceiling, California providers must follow whichever rule is stricter on any given point.

Why Both Laws Apply in California

HIPAA preempts conflicting state laws, but 45 CFR ยง 160.203 carves out an exception for state laws that are “more stringent” than HIPAA.1eCFR. 45 CFR 160.203 – General Rule and Exceptions A state rule qualifies when it gives individuals greater privacy protections or greater rights over their health information.2U.S. Department of Health and Human Services. Preemption of State Law The CMIA clears that bar on multiple fronts, so a provider in California who is fully HIPAA-compliant can still violate state law. State reporting obligations for disease, injury, child abuse, and public health surveillance are also expressly exempt from HIPAA preemption, so those California requirements operate independently.

The practical consequence: HIPAA compliance is the starting point in California, not the finish line.

Stricter Authorization Requirements

HIPAA requires written authorization for disclosures outside treatment, payment, and healthcare operations, but the CMIA’s Section 56.11 goes further by dictating how that authorization must look and what it must say. A California authorization is only valid if it meets every one of these standards:

  • Handwritten by the patient or printed in type no smaller than 14-point font.
  • Clearly separated from any other language on the page.
  • Signed and dated by the patient or legal representative, with the signature serving no other purpose than executing the authorization.
  • Specific about the types of information to be disclosed, who may disclose it, who may receive it, and the permitted uses.
  • Set to expire on a stated date or triggering event, generally within one year unless the patient requests longer.

These rules block the kind of vague, catch-all consent forms that might satisfy federal standards but sweep in more information than a patient intended to share.3California Legislative Information. California Civil Code CIV 56.11

Rules on who can sign are also tighter. Minors can authorize disclosure only for records tied to care they were legally entitled to consent to on their own, such as certain reproductive or mental health services. A spouse or financially responsible party can sign only when the authorization relates to processing a health insurance application where the patient would be an enrolled dependent.3California Legislative Information. California Civil Code CIV 56.11

A Private Right to Sue, Plus Nominal Damages

The most significant gap the CMIA fills is enforcement in the patient’s own hands. HIPAA has no private right of action; a patient whose records are mishandled can file a complaint with the Office for Civil Rights but cannot personally sue for damages. California takes a different approach.

Under Section 56.36, if a person or entity negligently releases your confidential medical information, you can sue for nominal damages of $1,000 per violation without proving you suffered actual harm. You can also recover actual damages if you can show measurable losses, and the two remedies are not mutually exclusive.4California Legislative Information. California Civil Code 56.36 – Violations That $1,000-per-violation floor changes the calculus for improper disclosures at any scale.

Higher and Tiered Civil Penalties

Beyond what a patient can recover, the CMIA imposes administrative fines that scale with culpability and reach further than HIPAA’s lower tiers. The structure splits between licensed healthcare professionals and everyone else.

For non-licensed persons or entities:

  • Negligent disclosure: up to $2,500 per violation.
  • Knowing and willful violation: up to $25,000 per violation.
  • Violation for financial gain: up to $250,000 per violation, plus disgorgement of any profits.

For licensed healthcare professionals, knowing and willful violations escalate from $2,500 (first offense) to $10,000 (second) to $25,000 (third and subsequent). Financial-gain violations run from $5,000 to $25,000 to $250,000 with disgorgement across the same sequence.5California Legislative Information. California Civil Code 56.36

Any CMIA violation that causes economic loss or personal injury is also punishable as a misdemeanor, and criminal liability turns on the harm rather than the violator’s intent.4California Legislative Information. California Civil Code 56.36 – Violations

Faster Breach Notification

When a healthcare facility discovers that patient medical information has been compromised, California requires written notification to the affected patient no later than 15 business days after detecting the breach.6California Department of Public Health. Medical Information Breach Regulation Text HIPAA’s breach notification rule allows up to 60 calendar days in most cases, so California’s clock runs roughly a quarter as long.

The notice itself must be in plain language and cover what happened and when, the types of information involved (name, Social Security number, diagnosis, and similar), steps the patient should take to protect themselves, what the facility is doing to investigate and prevent recurrence, and contact information including a toll-free number.6California Department of Public Health. Medical Information Breach Regulation Text

Broader Scope of Covered Entities

HIPAA regulates covered entities (providers, health plans, clearinghouses) and their business associates. The CMIA reaches wider. Section 56.06 pulls in businesses that are not traditional healthcare providers but that offer software or hardware for maintaining medical information, or that process or store medical data. Those companies must meet the same confidentiality standards as a provider and face the same penalties for improper disclosure.7California Legislative Information. California Civil Code 56.06 Health apps, cloud storage vendors, and similar businesses can be directly liable under the CMIA even when their HIPAA status is unclear.

The CMIA also binds pharmaceutical companies and contractors handling medical data on behalf of covered entities. Under Section 56.10, none of these entities may disclose your medical information without valid authorization unless a statutory exception applies.8California Legislative Information. California Civil Code 56.10 – Disclosure of Medical Information by Providers

Extra Limits on Out-of-State Legal Demands

The CMIA restricts compliance with certain legal process that HIPAA would otherwise allow. A subpoena from another state must be accompanied by a California court order before a provider can release records in response. And California providers may not comply with out-of-state search warrants that would violate California law, including the state’s Reproductive Privacy Act.8California Legislative Information. California Civil Code 56.10 – Disclosure of Medical Information by Providers These are protections HIPAA does not provide.

Where the CMIA Does Not Add Protection

Two areas are worth flagging so you don’t assume the CMIA reaches further than it does.

The California Consumer Privacy Act generally does not apply to information already protected by the CMIA or HIPAA, so you typically cannot use CCPA rights (deletion, opt-out) against your doctor’s office for clinical records. That exemption tracks the information itself, though, not everything a healthcare organization collects. Website browsing behavior, marketing data, and app usage a healthcare company gathers may fall outside both the CMIA and HIPAA and land under CCPA instead. Enforcement at that boundary is still developing.

Records from federally assisted substance use disorder treatment programs are governed by 42 CFR Part 2, which historically required a separate written consent for any disclosure. A 2024 final rule (with compliance dates running through early 2026) aligned Part 2 more closely with HIPAA by allowing a single consent covering future treatment, payment, and healthcare operations disclosures, and HIPAA-covered recipients may now redisclose those records under standard HIPAA rules.9U.S. Department of Health and Human Services. Fact Sheet 42 CFR Part 2 Final Rule For substance use records, federal law is the primary driver.

What This Means in Practice

If you are a patient in California, the CMIA gives you leverage HIPAA does not: the ability to sue directly, a $1,000-per-violation floor without proving harm, and faster notice when something goes wrong. If you run or work for a business that touches medical information in California, HIPAA compliance is not enough. Authorization forms need the 14-point, separation, and expiration features Section 56.11 requires. Breach protocols need to hit the 15-business-day mark. And the definition of who is covered stretches to software, storage, and processing vendors that federal law might treat differently.