CMIA Compliance
California’s Stricter Medical Privacy Law — What It Means for Healthcare Providers and Their IT Partners
lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned
WHAT IS THE CMIA?
HIPAA sets the federal floor. CMIA raises the ceiling — and creates a private right of action.
The California Confidentiality of Medical Information Act (CMIA), codified at California Civil Code §56 et seq., is one of the most far-reaching state medical privacy statutes in the country. Enacted in 1981 — fourteen years before HIPAA — the CMIA predates federal healthcare privacy law and in several critical respects exceeds it. Every California healthcare provider that is already HIPAA-compliant must also satisfy the CMIA, and where the two conflict, the stricter California standard prevails.
Critically, CMIA does not limit its reach to healthcare providers alone. The statute explicitly covers contractors — any company that receives, stores, transmits, or accesses individually identifiable medical information in the course of providing services to a covered entity. This includes IT managed services providers, cloud vendors, billing companies, and EHR implementation partners. CMIA obligations attach by operation of law, not by contract. Access to patient data creates the obligation.
$250K
max penalty per violation
Private
right of action for patients
1981
predates HIPAA by 14 years
Broader
scope than HIPAA
HOW CMIA DIFFERS FROM HIPAA
Stricter in five dimensions that directly affect Sacramento practices.
Dimension
HIPAA vs. CMIA
Scope of covered entities
HIPAA: covered entities + business associates. CMIA: healthcare providers, health plans, employers, AND contractors — including IT providers who access medical information
Private right of action
HIPAA: no private right of action; enforcement through OCR only. CMIA: patients may sue directly for actual damages, plus statutory damages of $1,000–$250,000 per violation
Penalties
HIPAA: up to $71,162 per violation category. CMIA: criminal fines up to $250,000 per violation; civil liability including actual damages and attorney’s fees
Breach notification timeline
HIPAA: 60 days from discovery. CMIA + Health & Safety Code §1280.15: 15 business days to notify CDPH; Civil Code §1798.82 requires notification ‘in the most expedient time possible’
Authorization standard
HIPAA: treatment, payment, and healthcare operations generally permitted without authorization. CMIA: stricter authorization requirements; fewer exceptions for employer access and marketing
Sensitive service protections
HIPAA: no specific category. CMIA (as amended by AB 254/AB 352, 2024): heightened protections for reproductive health, gender-affirming care, mental health, and substance use disorder data — cannot be disclosed without express written authorization even to policyholders
Enforcement authority
HIPAA: HHS OCR. CMIA: California AG, CDPH, and private plaintiffs simultaneously
THE CRITICAL QUESTION: DOES CMIA APPLY TO LBT?
Yes — and the scope is broader than most IT providers realize.
The CMIA defines ‘contractor’ to include any person or entity that receives medical information from a healthcare provider or health plan in connection with a service being provided. An MSP that manages a medical practice’s servers, endpoints, email, backups, or EHR infrastructure receives and has access to individually identifiable medical information as a function of providing those services. CMIA obligations attach directly — no BAA required, no separate agreement needed.
This creates a shared compliance posture between the healthcare provider and LBT. The obligations are not identical — each party carries the dimensions of the law that correspond to their role. Understanding that division clearly is essential for both parties.
CMIA RESPONSIBILITY: PROVIDER vs. IT CONTRACTOR
Healthcare Provider Obligations
LBT as IT Contractor Obligations
Obtain and document patient authorization for disclosures
Do not access medical information beyond what is necessary to perform contracted IT services
Apply minimum necessary standard to all staff access decisions
Do not disclose medical information to any third party under any circumstance
Respond to patient requests for records, access, and restrictions
Implement security controls sufficient to prevent unauthorized access to medical information on managed systems
Train clinical and administrative staff on disclosure policies
Cooperate fully with breach investigation and notification if an incident occurs on LBT-managed infrastructure
Decide whether to respond to law enforcement or legal requests
Report suspected or confirmed unauthorized access to the healthcare provider immediately upon discovery
Maintain authorizations, accounting of disclosures, and notice of privacy practices
Maintain audit logs of all access to systems containing patient data; produce logs on request
Assess and implement heightened controls for sensitive service data (AB 352)
Apply equivalent or greater technical protections to sensitive service data as required under AB 352 amendments
PENALTIES & PRIVATE RIGHT OF ACTION
The enforcement mechanism that makes CMIA uniquely dangerous for IT providers.
CMIA CRIMINAL PENALTY PER VIOLATION
Up to $250,000
Criminal fines apply per violation, not per incident. A single breach affecting hundreds of patient records can result in aggregate criminal exposure in the millions. Civil penalties and actual damages apply concurrently.
The CMIA’s private right of action is the provision that most distinguishes it from HIPAA for IT providers. Under HIPAA, a breach at an MSP triggers OCR enforcement against the covered entity — and potential indemnification claims against the BAA counterparty. Under the CMIA, plaintiffs’ attorneys can and do name IT contractors directly as defendants in civil actions, asserting that the contractor accessed or failed to protect medical information in violation of the statute.
California plaintiffs’ attorneys are actively litigating CMIA class actions. A breach of a medical practice’s systems managed by LBT could result in direct litigation against LBT as a contractor — independent of any action against the practice. LBT’s security posture is therefore not merely a service quality matter; it is a direct legal liability management function.
COMMON CMIA COMPLIANCE GAPS
Where Sacramento practices and their IT vendors most often fall short.
⚠ IT provider has no documented acknowledgment of CMIA contractor status — no written agreement defining obligations, incident response coordination, or disclosure prohibitions
⚠ No heightened technical controls for AB 352 sensitive service data — reproductive health, gender-affirming care, and mental health records stored without additional access restrictions
⚠ Breach notification timelines not aligned to CMIA’s 15-business-day CDPH requirement — most practices are only tracking HIPAA’s 60-day federal window
⚠ Audit logs insufficient or absent — CMIA’s accountability standard requires demonstrable evidence of who accessed what patient data and when
⚠ No staff training on CMIA-specific requirements — the AB 352 amendments (effective 2024) introduced new rules most practices and their IT vendors have not operationalized
⚠ Marketing and third-party tracking tools on patient-facing platforms — the California AG and OCR actively investigate use of pixel tracking on authenticated healthcare portals
HOW LBT ADDRESSES CMIA CONTRACTOR OBLIGATIONS
Built to satisfy CMIA from the IT contractor’s side of the compliance divide.
LBT’s managed program addresses the full scope of IT contractor obligations under the CMIA — and supports healthcare provider clients in building the administrative infrastructure for the provider-side obligations that sit with the practice.
✓ Contractor Acknowledgment & Written Security Agreement
LBT formalizes its CMIA contractor status in writing, documenting the specific obligations each party carries, incident response coordination procedures, and disclosure prohibitions — providing both parties with a clear compliance record.
✓ AB 352 Technical Controls for Sensitive Service Data
Implementation of additional access controls, audit logging, and segmentation for systems containing reproductive health, gender-affirming care, mental health, and substance use disorder data as required by the 2024 AB 352 amendments.
✓ 15-Business-Day Breach Notification Readiness
Incident response procedures calibrated to California’s stricter breach notification timelines — ensuring CDPH notification within 15 business days and Civil Code §1798.82 patient notification ‘in the most expedient time possible.’
✓ Audit Log Management & Access Accountability
Continuous logging of all access to systems containing patient medical information, with log retention, anomaly alerting, and on-demand reporting that satisfies CMIA’s accountability requirements and supports breach investigation.
✓ Staff & Vendor Training on CMIA Requirements
CMIA-specific security awareness training for healthcare client staff covering the AB 352 sensitive service amendments, minimum necessary standards, and the distinctions between HIPAA and CMIA obligations.
✓ Privacy-by-Design Infrastructure
Architectural review of all patient-facing digital properties — websites, portals, scheduling tools — to identify and remove third-party tracking technologies that create CMIA and California AG enforcement exposure.
Is Your Business CMIA Ready?
Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.
BOOK YOUR FREE CMIA COMPLIANCE ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California
© 2026 LBT Technology Group, LLC · CMIA Compliance — Healthcare · Sacramento, CA · Confidential
This document is for informational purposes only and does not constitute legal advice.
