HIPAA vs CMIA Reference Guide
HIPAA vs. CMIA: What California Healthcare Practices Must Know
Both laws govern your patients’ medical information. They are not the same law — and HIPAA compliance alone does not satisfy CMIA. Every Sacramento healthcare practice operating under HIPAA must also comply with the California Confidentiality of Medical Information Act, and where the two conflict, California’s stricter standard prevails. This guide shows where the laws align, where they diverge, and what each obligation means for your IT and compliance program.
■ HIPAA Federal / HHS OCR
■ CMIA California / State AG + Private Plaintiffs
■ LBT Role What LBT manages under each framework
Dimension
■ HIPAA (Federal)
■ CMIA (California)
■ LBT Role
ORIGINS, AUTHORITY & RELATIONSHIP
Enacted
1996 — Health Insurance Portability and Accountability Act
1981 — predates HIPAA by 15 years; repeatedly amended through 2024
LBT maintains compliance documentation under both frameworks simultaneously
Governing body
HHS Office for Civil Rights (OCR) — federal enforcement
California AG, California Department of Public Health (CDPH), and private plaintiffs
LBT incident response procedures are calibrated to satisfy both enforcement timelines
Relationship between laws
Federal floor — establishes minimum national standards
California ceiling — stricter than HIPAA; where they conflict, CMIA prevails
LBT applies whichever standard is stricter, ensuring a single program satisfies both
Does HIPAA compliance satisfy CMIA?
N/A
NO — HIPAA compliance is necessary but not sufficient for California practices
LBT addresses CMIA-specific requirements that HIPAA alone does not cover
SCOPE — WHO IS COVERED
Covered healthcare providers
Licensed providers who conduct electronic transactions (claims, referrals, eligibility). Not all providers qualify automatically.
All licensed healthcare providers and clinics in California, regardless of whether they conduct electronic transactions. Broader scope than HIPAA.
LBT serves clients under both frameworks; CMIA’s broader scope means more clients have CMIA obligations than strict HIPAA covered entity status
IT providers & vendors
Business Associates — obligations defined by BAA contract; attach by agreement
Contractors — obligations attach by operation of law; no contract required. Access to medical information creates the obligation.
LBT is a Business Associate under HIPAA (BAA required) AND a CMIA Contractor by law. Both statuses apply independently.
Employers
Limited — employer health plan data may be covered; occupational health records generally excluded
Yes — employers who maintain employee medical information for HR purposes are covered under CMIA
LBT manages systems for employer clients who may hold employee health data subject to CMIA but not HIPAA
Technology companies
Business Associates only if they handle PHI on behalf of a covered entity under contract
Any company that stores or processes identifiable medical information of California residents — including health apps, wearables, and EHR vendors
LBT’s CMIA contractor status applies across all healthcare client engagements regardless of formal BAA status
WHAT INFORMATION IS PROTECTED
Defined protected information
Protected Health Information (PHI) — individually identifiable health information held by covered entities or BAs in any medium
Medical information — any individually identifiable information in medical records, including diagnoses, treatment, test results, and insurance information
LBT treats both definitions as applicable to all patient data on managed systems, applying the broader CMIA definition where it extends beyond PHI
Sensitive service data
No specific heightened category — PHI treated uniformly under Privacy Rule
Heightened protection (AB 352, 2024): reproductive health, gender-affirming care, mental health, and substance use disorder data require additional controls and cannot be disclosed without express written authorization — even to policyholders
LBT implements EHR access segmentation and additional technical controls for AB 352 sensitive service categories as a distinct compliance layer
De-identified data
Safe harbor: data meeting HIPAA’s de-identification standard is not PHI
Stricter: California courts interpret re-identification risk more broadly; CMIA protections may survive de-identification that satisfies HIPAA’s standard
LBT advises healthcare clients that HIPAA de-identification does not automatically satisfy CMIA requirements
DISCLOSURE & AUTHORIZATION
Permitted disclosures without authorization
Treatment, payment, and healthcare operations (TPO) — broad exception allows most internal and referral uses without patient consent
Narrower exceptions — some uses permitted under HIPAA TPO require explicit authorization under CMIA, particularly for marketing, employer access, and certain operational uses
LBT documents data flows and flags uses that may require CMIA authorization even when HIPAA TPO exception applies
Minimum necessary standard
Required — covered entities must limit PHI use to the minimum necessary for the stated purpose
Required — applies to all contractors and providers; CMIA’s standard is functionally equivalent but independently enforceable
LBT’s access control program implements least-privilege on managed systems to satisfy both frameworks’ minimum necessary requirements
Marketing & sale of data
Requires authorization; some exceptions for treatment communications
Stricter prohibition — CMIA significantly restricts use of medical information for marketing; AB 254 prohibits health app data sale entirely for mental/reproductive health apps
LBT reviews and removes third-party tracking pixels and analytics tools from patient-facing platforms that create CMIA marketing-use exposure
ENFORCEMENT & PENALTIES
Civil penalties
Tiered: $137–$71,162 per violation category; $2.13M annual cap per category
$1,000–$250,000 per violation; no annual cap — aggregate exposure scales with number of affected patients
LBT’s security posture reduces breach likelihood under both penalty frameworks simultaneously
Criminal penalties
Up to $250,000 fine and 10 years imprisonment for knowing violations
Up to $250,000 per violation — criminal penalties apply per violation, not per incident
LBT’s monitoring and access controls reduce criminal exposure by preventing unauthorized access and ensuring audit trails
Private right of action
NONE — patients cannot sue directly under HIPAA; enforcement only through OCR
YES — patients may sue directly for actual damages plus statutory damages. Class action exposure. Actively litigated in California.
LBT’s security program provides the documented ‘reasonable measures’ defense against CMIA private litigation
Who can be sued
Covered entities and Business Associates (via indemnification through BAA)
Healthcare providers AND their contractors directly — LBT as a CMIA contractor can be named as a defendant independently of the healthcare provider
LBT’s managed program is LBT’s own liability management, not just client service
Enforcement agency fines
HHS OCR — 2024 enforcement: $10,000–$4.75M per incident
California AG + CDPH — CDPH: up to $25,000 per patient for unauthorized access under H&S Code §1280.15
LBT’s incident response is calibrated to satisfy both agencies’ documentation and reporting requirements
BREACH NOTIFICATION
Notification to patients
Within 60 days of discovery of breach affecting 500+ individuals
‘In the most expedient time possible’ under Civil Code §1798.82 — no fixed deadline; regulators treat delays beyond 30–45 days as presumptively unreasonable
LBT’s incident response targets 30-day patient notification to satisfy California’s stricter standard
Notification to regulators
HHS OCR: within 60 days. Media: if 500+ in a state.
CDPH: within 15 business days of detecting unauthorized access under H&S Code §1280.15 — faster than HIPAA’s federal window
LBT’s IR procedures include 15-business-day CDPH notification workflow as a distinct step separate from HIPAA’s 60-day HHS reporting
Breach definition
Presumption of breach for unsecured PHI; risk assessment can rebut presumption (4-factor test)
Unauthorized acquisition or access — California’s standard is triggered more directly; less discretion to avoid notification through risk assessment
LBT advises that California breach threshold is lower; encryption is the primary safe harbor under both laws
Encryption safe harbor
Yes — encrypted PHI not subject to breach notification
Yes — encrypted medical information not subject to CMIA notification obligation. Safe harbor available under Civil Code §1798.82.
Encryption across all managed systems activates both safe harbors simultaneously — a single technical control that reduces notification obligations under both frameworks
LBT’S ROLE UNDER EACH FRAMEWORK
LBT’s legal status
Business Associate — defined and scoped by the BAA LBT executes with each covered entity client
Contractor — CMIA obligations attach by operation of law; independent of any agreement
Both statuses apply to LBT simultaneously for all healthcare clients. LBT formally acknowledges both in its client agreements.
Required agreement
Business Associate Agreement (BAA) — must be executed before accessing PHI
No California-equivalent of a BAA required by statute — but LBT documents CMIA contractor obligations in writing with each healthcare client
LBT executes a combined BAA and CMIA contractor acknowledgment with every healthcare client
Key IT controls LBT provides
24/7 monitoring, EDR, SIEM, encryption, access controls, audit logging, workforce training, annual risk assessment, incident response
All HIPAA controls PLUS: AB 352 sensitive service data segmentation, stricter breach notification timelines, CDPH notification workflow, pixel/tracker removal from patient portals
LBT’s managed program is built to satisfy the union of both frameworks — no gap between HIPAA compliance and CMIA compliance
Documentation LBT maintains
Risk assessment, BAA, security policies, training records, incident response plan, audit logs
All HIPAA documentation PLUS: CMIA contractor acknowledgment, AB 352 control documentation, CDPH-calibrated IR procedures, sensitive service access logs
Single documentation set maintained by LBT satisfies both frameworks’ evidence requirements
THREE THINGS EVERY SACRAMENTO HEALTHCARE PRACTICE MUST UNDERSTAND
01
HIPAA compliance does not equal CMIA compliance.
CMIA is stricter, broader in scope, and independently enforceable. Every California practice needs both programs running in parallel — not one in place of the other.
02
The private right of action is the critical difference.
Under HIPAA, patients cannot sue your practice directly. Under CMIA, they can — and plaintiffs’ attorneys are actively using it. A breach that triggers HIPAA penalties can also trigger direct patient litigation under CMIA.
03
Your IT provider is a CMIA contractor by law.
LBT’s CMIA obligations don’t require a signed agreement to exist — they attach the moment LBT accesses systems containing patient medical information. LBT’s security program is LBT’s own liability management, not just a service to your practice.
Does your compliance program cover both HIPAA and CMIA?
Most Sacramento practices are HIPAA-aware but CMIA-exposed. LBT’s free scoping consultation identifies exactly where gaps exist under both frameworks — at no cost and no obligation.
BOOK A FREE HIPAA + CMIA ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com
© 2026 LBT Technology Group, LLC · Sacramento, California · Confidential — For Authorized Review Only · This document is for informational purposes only and does not constitute legal advice.
