Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

CMIA Compliance

California’s Stricter Medical Privacy Law — What It Means for Healthcare Providers and Their IT Partners

lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned

WHAT IS THE CMIA?

HIPAA sets the federal floor. CMIA raises the ceiling — and creates a private right of action.

The California Confidentiality of Medical Information Act (CMIA), codified at California Civil Code §56 et seq., is one of the most far-reaching state medical privacy statutes in the country. Enacted in 1981 — fourteen years before HIPAA — the CMIA predates federal healthcare privacy law and in several critical respects exceeds it. Every California healthcare provider that is already HIPAA-compliant must also satisfy the CMIA, and where the two conflict, the stricter California standard prevails.

Critically, CMIA does not limit its reach to healthcare providers alone. The statute explicitly covers contractors — any company that receives, stores, transmits, or accesses individually identifiable medical information in the course of providing services to a covered entity. This includes IT managed services providers, cloud vendors, billing companies, and EHR implementation partners. CMIA obligations attach by operation of law, not by contract. Access to patient data creates the obligation.

$250K

max penalty per violation

Private

right of action for patients

1981

predates HIPAA by 14 years

Broader

scope than HIPAA

HOW CMIA DIFFERS FROM HIPAA

Stricter in five dimensions that directly affect Sacramento practices.

Dimension

HIPAA vs. CMIA

Scope of covered entities

HIPAA: covered entities + business associates. CMIA: healthcare providers, health plans, employers, AND contractors — including IT providers who access medical information

Private right of action

HIPAA: no private right of action; enforcement through OCR only. CMIA: patients may sue directly for actual damages, plus statutory damages of $1,000–$250,000 per violation

Penalties

HIPAA: up to $71,162 per violation category. CMIA: criminal fines up to $250,000 per violation; civil liability including actual damages and attorney’s fees

Breach notification timeline

HIPAA: 60 days from discovery. CMIA + Health & Safety Code §1280.15: 15 business days to notify CDPH; Civil Code §1798.82 requires notification ‘in the most expedient time possible’

Authorization standard

HIPAA: treatment, payment, and healthcare operations generally permitted without authorization. CMIA: stricter authorization requirements; fewer exceptions for employer access and marketing

Sensitive service protections

HIPAA: no specific category. CMIA (as amended by AB 254/AB 352, 2024): heightened protections for reproductive health, gender-affirming care, mental health, and substance use disorder data — cannot be disclosed without express written authorization even to policyholders

Enforcement authority

HIPAA: HHS OCR. CMIA: California AG, CDPH, and private plaintiffs simultaneously

THE CRITICAL QUESTION: DOES CMIA APPLY TO LBT?

Yes — and the scope is broader than most IT providers realize.

The CMIA defines ‘contractor’ to include any person or entity that receives medical information from a healthcare provider or health plan in connection with a service being provided. An MSP that manages a medical practice’s servers, endpoints, email, backups, or EHR infrastructure receives and has access to individually identifiable medical information as a function of providing those services. CMIA obligations attach directly — no BAA required, no separate agreement needed.

This creates a shared compliance posture between the healthcare provider and LBT. The obligations are not identical — each party carries the dimensions of the law that correspond to their role. Understanding that division clearly is essential for both parties.

CMIA RESPONSIBILITY: PROVIDER vs. IT CONTRACTOR

Healthcare Provider Obligations

LBT as IT Contractor Obligations

Obtain and document patient authorization for disclosures

Do not access medical information beyond what is necessary to perform contracted IT services

Apply minimum necessary standard to all staff access decisions

Do not disclose medical information to any third party under any circumstance

Respond to patient requests for records, access, and restrictions

Implement security controls sufficient to prevent unauthorized access to medical information on managed systems

Train clinical and administrative staff on disclosure policies

Cooperate fully with breach investigation and notification if an incident occurs on LBT-managed infrastructure

Decide whether to respond to law enforcement or legal requests

Report suspected or confirmed unauthorized access to the healthcare provider immediately upon discovery

Maintain authorizations, accounting of disclosures, and notice of privacy practices

Maintain audit logs of all access to systems containing patient data; produce logs on request

Assess and implement heightened controls for sensitive service data (AB 352)

Apply equivalent or greater technical protections to sensitive service data as required under AB 352 amendments

PENALTIES & PRIVATE RIGHT OF ACTION

The enforcement mechanism that makes CMIA uniquely dangerous for IT providers.

CMIA CRIMINAL PENALTY PER VIOLATION

Up to $250,000

Criminal fines apply per violation, not per incident. A single breach affecting hundreds of patient records can result in aggregate criminal exposure in the millions. Civil penalties and actual damages apply concurrently.

The CMIA’s private right of action is the provision that most distinguishes it from HIPAA for IT providers. Under HIPAA, a breach at an MSP triggers OCR enforcement against the covered entity — and potential indemnification claims against the BAA counterparty. Under the CMIA, plaintiffs’ attorneys can and do name IT contractors directly as defendants in civil actions, asserting that the contractor accessed or failed to protect medical information in violation of the statute.

California plaintiffs’ attorneys are actively litigating CMIA class actions. A breach of a medical practice’s systems managed by LBT could result in direct litigation against LBT as a contractor — independent of any action against the practice. LBT’s security posture is therefore not merely a service quality matter; it is a direct legal liability management function.

COMMON CMIA COMPLIANCE GAPS

Where Sacramento practices and their IT vendors most often fall short.

⚠ IT provider has no documented acknowledgment of CMIA contractor status — no written agreement defining obligations, incident response coordination, or disclosure prohibitions

⚠ No heightened technical controls for AB 352 sensitive service data — reproductive health, gender-affirming care, and mental health records stored without additional access restrictions

⚠ Breach notification timelines not aligned to CMIA’s 15-business-day CDPH requirement — most practices are only tracking HIPAA’s 60-day federal window

⚠ Audit logs insufficient or absent — CMIA’s accountability standard requires demonstrable evidence of who accessed what patient data and when

⚠ No staff training on CMIA-specific requirements — the AB 352 amendments (effective 2024) introduced new rules most practices and their IT vendors have not operationalized

⚠ Marketing and third-party tracking tools on patient-facing platforms — the California AG and OCR actively investigate use of pixel tracking on authenticated healthcare portals

HOW LBT ADDRESSES CMIA CONTRACTOR OBLIGATIONS

Built to satisfy CMIA from the IT contractor’s side of the compliance divide.

LBT’s managed program addresses the full scope of IT contractor obligations under the CMIA — and supports healthcare provider clients in building the administrative infrastructure for the provider-side obligations that sit with the practice.

✓ Contractor Acknowledgment & Written Security Agreement

LBT formalizes its CMIA contractor status in writing, documenting the specific obligations each party carries, incident response coordination procedures, and disclosure prohibitions — providing both parties with a clear compliance record.

✓ AB 352 Technical Controls for Sensitive Service Data

Implementation of additional access controls, audit logging, and segmentation for systems containing reproductive health, gender-affirming care, mental health, and substance use disorder data as required by the 2024 AB 352 amendments.

✓ 15-Business-Day Breach Notification Readiness

Incident response procedures calibrated to California’s stricter breach notification timelines — ensuring CDPH notification within 15 business days and Civil Code §1798.82 patient notification ‘in the most expedient time possible.’

✓ Audit Log Management & Access Accountability

Continuous logging of all access to systems containing patient medical information, with log retention, anomaly alerting, and on-demand reporting that satisfies CMIA’s accountability requirements and supports breach investigation.

✓ Staff & Vendor Training on CMIA Requirements

CMIA-specific security awareness training for healthcare client staff covering the AB 352 sensitive service amendments, minimum necessary standards, and the distinctions between HIPAA and CMIA obligations.

✓ Privacy-by-Design Infrastructure

Architectural review of all patient-facing digital properties — websites, portals, scheduling tools — to identify and remove third-party tracking technologies that create CMIA and California AG enforcement exposure.

Is Your Business CMIA Ready?

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

BOOK YOUR FREE CMIA COMPLIANCE ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California

© 2026 LBT Technology Group, LLC · CMIA Compliance — Healthcare · Sacramento, CA · Confidential

This document is for informational purposes only and does not constitute legal advice.

California Confidentiality of Medical Information Act

CMIA Compliance & Medical Information Protection

Translate California medical-privacy responsibilities into clear roles, controlled access, accountable handling, and an incident process your organization and technology partners can operate.

CACalifornia-specific protection

Medical-information duties can extend beyond the federal baseline.

05Operating dimensions

Scope, authorization, sensitive data, accountability, and response.

360°Shared responsibility

Organizations and contractors must coordinate people, process, and technology.

California medical privacy in practice

CMIA adds a California layer to medical-information governance.

CMIA regulates the confidentiality, use, disclosure, and protection of medical information in specified California relationships. It may apply alongside HIPAA, but the two laws are not interchangeable.

A practical program maps California obligations to the people, vendors, systems, and workflows that handle medical information, then maintains evidence that those controls continue to operate.

Who may be in scope

Responsibility follows the California medical-information relationship.

CMIA analysis should include the organization as well as contractors and technology partners that receive or maintain medical information.

01

Healthcare Organizations

California providers and health-service organizations that create or maintain medical information.

02

Plans & Employers

Health plans and employers where CMIA applies to the particular medical-information relationship or activity.

03

Contractors & IT Partners

Service providers that receive or maintain medical information while supporting an organization in scope.

Explore the operating responsibilities

Five dimensions turn CMIA requirements into daily practice.

This operational model organizes the work; it is not a statutory list of five official CMIA functions.

Scope and responsibility

Know which California relationships and information flows are in scope.

CMIA can affect healthcare providers, health plans, employers in specified circumstances, and contractors that handle medical information. The first operational step is to document roles, systems, vendors, and data flows.

What to address
  • Organization and contractor roles
  • Medical-information inventory
  • Vendor and system dependencies
Operating evidence
  • Responsibility matrix
  • Current data-flow record
  • Contractor acknowledgement

CMIA and HIPAA

Related privacy regimes with different scope and duties.

Organizations that handle California medical information should evaluate both frameworks instead of assuming one replaces the other.

01

Covered relationships

HIPAA uses federal covered-entity and business-associate categories; CMIA has California-specific provider, plan, employer, and contractor provisions.

02

Information handling

Both regulate protected medical information, but the definitions, permitted activities, and authorization requirements are not identical.

03

Contractor responsibility

An IT or service provider may carry direct California responsibilities in addition to obligations created by contract or HIPAA status.

04

California rights

CMIA can create California-specific remedies and enforcement exposure. Legal counsel should determine how they apply to a particular event.

05

Incident coordination

Federal and California duties may run together. Response plans should identify every applicable decision-maker, deadline, and notification path.

Shared operating model

Separate organizational decisions from technical execution.

The organization retains privacy and legal decision-making while the technology partner implements, documents, monitors, and supports the selected safeguards.

Organization responsibilityTechnology-partner responsibility
01

Define permitted uses and approve disclosures

Configure access, logging, safeguards, and technical restrictions

02

Identify sensitive medical-information workflows

Document systems, integrations, vendors, and data movement

03

Set workforce roles and authorization procedures

Provision least-privilege access and maintain review evidence

04

Determine legal notification obligations

Escalate quickly, preserve evidence, and support investigation

05

Maintain privacy policies and patient-facing processes

Maintain security procedures, training records, and control evidence

06

Oversee contractors and downstream relationships

Acknowledge responsibilities and manage approved subprocessors

Common compliance gaps

Medical privacy breaks down where roles, data, and response paths are unclear.

01

Unclear contractor status

The service relationship is documented commercially but not evaluated for CMIA responsibilities.

02

Incomplete data mapping

The organization cannot show where California medical information travels or who can reach it.

03

Generic authorization workflow

Disclosure approvals are not connected to actual systems, roles, and exceptions.

04

Weak sensitive-data controls

Sensitive-service information is not appropriately classified, restricted, or segregated.

05

Insufficient audit review

Logs exist, but access and disclosure activity is not consistently reviewed or escalated.

06

Uncoordinated incident response

Providers, contractors, counsel, and technical responders do not share a practiced escalation path.

How LBT supports CMIA readiness

Connect privacy requirements to documented technical operations.

The exact program follows the organization’s role, medical-information flows, sensitive services, systems, contractors, and guidance from legal counsel.

Discuss your CMIA scope
01

Contractor acknowledgement and written security agreement support

02

Technical controls for sensitive medical-information workflows

03

Breach-notification and incident-response readiness

04

Audit-log management and access accountability

05

Staff and vendor training on CMIA responsibilities

06

Privacy-by-design infrastructure and recurring review

Continuous privacy cycle

CMIA readiness should evolve with data, services, vendors, and risk.

01

Define

Map roles, medical information, permitted activity, vendors, and accountability.

02

Implement

Apply access, segregation, logging, training, and documented procedures.

03

Monitor

Review access and events, manage changes, and maintain operating evidence.

04

Respond & improve

Investigate quickly, coordinate decisions, preserve evidence, and strengthen controls.

Next step

Build a California medical-privacy program your team can operate.

Talk with LBT about your role, medical-information environment, contractors, existing HIPAA program, sensitive workflows, and priority control gaps.

Information on this page is for general educational purposes and is not legal advice. Consult qualified counsel about requirements that apply to your organization.