$250K
Statutory penalty exposure
CMIA violations carry steep statutory penalties — reaching up to $250,000 depending on the violation — plus administrative fines. California enforces medical privacy aggressively.
California's Confidentiality of Medical Information Act goes beyond HIPAA — broader scope, a private right of action, and penalties up to $250,000. And as of January 2026, its new sensitive-services and out-of-state-disclosure rules are fully enforceable. We map CMIA onto your HIPAA program and close the California gap.
Book a CMIA Strategy Call →// WHY CMIA, WHY NOW
$250K
CMIA violations carry steep statutory penalties — reaching up to $250,000 depending on the violation — plus administrative fines. California enforces medical privacy aggressively.
YOU CAN BE SUED
Unlike HIPAA, the CMIA lets individuals sue directly for violations. You don't have to wait for a regulator — a patient or plaintiff's attorney can bring the case.
NOW IN FORCE
AB 352's good-faith grace period for the out-of-state-disclosure rules ran out January 31, 2026. Those sensitive-services requirements are now fully enforceable.
// HIPAA DOESN'T COVER THIS
HIPAA is the federal floor; CMIA stacks California duties on top, and satisfying one doesn't satisfy the other. The CMIA reaches entities HIPAA may not — including digital health businesses pulled in by AB 254 — carries a private right of action, and now imposes concrete EHR-segregation and out-of-state-disclosure rules for sensitive services that went fully enforceable in January 2026. Where the two laws overlap, you generally have to meet the more protective one. Treating your HIPAA program as automatic CMIA coverage is exactly the gap plaintiffs look for.
// WHAT CMIA ADDS ON TOP OF HIPAA
Everything in the CMIA flows from one obligation, raised higher than HIPAA's. Protect medical information, and don't disclose it without authorization — backed by a private right of action and the newest sensitive-services rules.
The center of the CMIA: anyone who maintains or stores medical information must preserve its confidentiality, and must not disclose it without authorization unless an exception applies. California sets that bar higher than HIPAA — with broader reach, a private right of action, and steep penalties. The three layers below are how that duty becomes concrete obligations for a California organization.
// THE CORE
Confidentiality & Authorization
Store medical information confidentially; don't disclose without a valid authorization or recognized exception.
// AB 254 / AB 352
Sensitive-Services Rules
Segregate and restrict access to sensitive-services records; limit out-of-state transmission and cooperation.
// THE TEETH
Liability & Penalties
A private right of action plus statutory penalties up to $250,000 — enforcement individuals can drive themselves.
Sensitive services span behavioral health, reproductive care, SUD, gender-affirming care, and more.
// THE PATH
How California organizations build a CMIA-ready posture on top of HIPAA. The amber stages are the enforcement-facing moments — the now-passed January 2026 threshold, and a regulator or private lawsuit that puts your controls to the test.
Scope
Does CMIA Apply?
WK 1–3
Map
CMIA vs HIPAA Gaps
WK 3–6
Segregate
Sensitive-Services Data
MO 1–3
Control
Disclosure & Access
MO 2–4
Comply
Jan 2026 Threshold
NOW IN FORCE
Defend
Suit or Enforcement
IF TRIGGERED
Amber stages are the enforcement-facing moments — the January 31, 2026 threshold the grace period ran into, now in force, and a regulator action or private lawsuit where your segregation, access, and disclosure controls are tested. Everything before exists to make those go your way.
// IS THIS YOU?
// 01 // CALIFORNIA DATA
You're a provider, plan, contractor, or employer touching the medical information of California patients — so the CMIA applies on top of your HIPAA duties.
// 02 // DIGITAL HEALTH
You offer a reproductive or sexual health digital service to consumers. AB 254 may deem you a "provider of health care" — even if you're not a HIPAA covered entity.
// 03 // EHR CAN'T SEGREGATE
Your systems can't reliably restrict access to or limit out-of-state disclosure of sensitive-services records. That's live exposure now that the grace period ended.
// WHAT WE DO
// Phase 01 · Scope
We determine whether and how the CMIA applies to you — including the digital-health expansion — then map its obligations against your existing HIPAA program to find the California-specific gaps.
// Phase 02 · Implement
We implement the sensitive-services segregation, access restriction, and out-of-state-disclosure controls AB 352 now requires — the operational work in your EHR and disclosure workflows, not just policy.
// Phase 03 · Defend
We build the documented evidence and policies that demonstrate compliance, reducing your exposure to the private right of action and the penalties the CMIA puts within reach.
// THE GRACE PERIOD IS OVER
// FREQUENTLY ASKED
Yes. HIPAA is the federal floor, but the CMIA adds obligations on top, and HIPAA compliance doesn't automatically mean CMIA compliance. The CMIA is broader in ways that matter: it can reach entities outside HIPAA's definitions, including certain digital health businesses; it includes a private right of action, so individuals can sue directly; and it carries statutory penalties that can reach up to $250,000, alongside administrative fines.
Because the two laws overlap but aren't identical, the practical rule is that where both apply, you generally have to satisfy the more protective requirement. For a California healthcare organization, treat HIPAA as the baseline and layer the CMIA-specific obligations — authorization, confidentiality of stored information, and the newer sensitive-services rules — on top, rather than assuming your HIPAA work already covers them.
Both signed in September 2023, these bills expanded the CMIA's reach and added concrete technical duties. AB 254 broadened the law to expressly cover reproductive and sexual health services delivered through digital health solutions, and deems a business offering a reproductive or sexual health digital service to a consumer a "provider of health care" for CMIA purposes — pulling many app and platform companies in for the first time.
AB 352 focused on how EHR systems handle medical information about sensitive services — defined to include mental and behavioral health, sexual and reproductive health, STIs, substance use disorder, gender-affirming care, and intimate partner violence. It requires the capability to limit access to records on gender-affirming care, abortion and related services, and contraception to authorized individuals, to restrict transmitting that information out of state, and generally prohibits cooperating with out-of-state inquiries seeking to identify someone in connection with abortion services lawful in California, absent a valid authorization or recognized exception. These are operational requirements touching system configuration, access controls, and disclosure workflows — not just policy language.
Quite possibly — one of the most important shifts from the recent amendments. Under AB 254, a business that offers a reproductive or sexual health digital service to a consumer (to let the individual manage their information, or for diagnosis, treatment, or management of a medical condition) is deemed a provider of health care for CMIA purposes. That pulls digital health companies, certain apps, and platforms that assumed they sat outside health privacy law squarely within the CMIA, with all the confidentiality, authorization, and sensitive-services obligations that follow.
This is true even for organizations that are not HIPAA covered entities — exactly the gap that catches companies by surprise: they reasoned that because they aren't a hospital or health plan, health privacy law didn't reach them. The safe approach for any digital health, telehealth, or wellness business serving California consumers is to deliberately analyze whether the CMIA now applies, rather than assume it doesn't, because the penalties and private right of action make a wrong guess expensive.
No. AB 352 included a good-faith grace period stating that a provider of health care wouldn't be subject to liability or to civil or enforcement actions for failing to meet the out-of-state disclosure requirements before January 31, 2026, as long as the provider was working diligently and in good faith to comply. That date has now passed, so the grace period has ended and those requirements are enforceable.
In practical terms, organizations relying on diligent, good-faith effort as their position can no longer count on that cushion — the expectation now is actual compliance with the restrictions on out-of-state transmission of, and cooperation regarding, protected medical information. If your systems still can't reliably segregate sensitive-services records, restrict their access, or control out-of-state disclosure, that's live exposure now — compounded by the CMIA's private right of action and penalty structure. We help California organizations close exactly those gaps and document a defensible posture.
// THE NEXT MOVE
Book a 30-minute CMIA strategy call with a WatchUr6 advisor. Bring whether you handle California medical information, whether you offer any digital health service, and what your EHR can do with sensitive-services records. You'll walk away knowing if the CMIA applies, where your gaps versus HIPAA are, and a path to a defensible California posture — whether you hire us or not.
Book a CMIA Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED