WATCHUR6 // CALIFORNIA CMIA // AUDIT READINESS

HIPAA is the floor.
In California, CMIA raises the bar.

California's Confidentiality of Medical Information Act goes beyond HIPAA — broader scope, a private right of action, and penalties up to $250,000. And as of January 2026, its new sensitive-services and out-of-state-disclosure rules are fully enforceable. We map CMIA onto your HIPAA program and close the California gap.

Book a CMIA Strategy Call
CA CIVIL CODE 56 PRIVATE RIGHT OF ACTION AB 254 / AB 352 VETERAN-LED

// WHY CMIA, WHY NOW

Federal compliance isn't California compliance. Not anymore.

$250K

Statutory penalty exposure

CMIA violations carry steep statutory penalties — reaching up to $250,000 depending on the violation — plus administrative fines. California enforces medical privacy aggressively.

YOU CAN BE SUED

A private right of action

Unlike HIPAA, the CMIA lets individuals sue directly for violations. You don't have to wait for a regulator — a patient or plaintiff's attorney can bring the case.

NOW IN FORCE

The grace period ended

AB 352's good-faith grace period for the out-of-state-disclosure rules ran out January 31, 2026. Those sensitive-services requirements are now fully enforceable.

// HIPAA DOESN'T COVER THIS

We're HIPAA compliant, so our California patients are covered.
CMIA reaches further than HIPAA — and it lets patients sue you directly.

HIPAA is the federal floor; CMIA stacks California duties on top, and satisfying one doesn't satisfy the other. The CMIA reaches entities HIPAA may not — including digital health businesses pulled in by AB 254 — carries a private right of action, and now imposes concrete EHR-segregation and out-of-state-disclosure rules for sensitive services that went fully enforceable in January 2026. Where the two laws overlap, you generally have to meet the more protective one. Treating your HIPAA program as automatic CMIA coverage is exactly the gap plaintiffs look for.

// WHAT CMIA ADDS ON TOP OF HIPAA

One duty at the core. Sharper than the federal version.

Everything in the CMIA flows from one obligation, raised higher than HIPAA's. Protect medical information, and don't disclose it without authorization — backed by a private right of action and the newest sensitive-services rules.

The Heightened Duty CA Civil Code 56 · protection that exceeds HIPAA

The center of the CMIA: anyone who maintains or stores medical information must preserve its confidentiality, and must not disclose it without authorization unless an exception applies. California sets that bar higher than HIPAA — with broader reach, a private right of action, and steep penalties. The three layers below are how that duty becomes concrete obligations for a California organization.

// THE CORE

Confidentiality & Authorization

Store medical information confidentially; don't disclose without a valid authorization or recognized exception.

// AB 254 / AB 352

Sensitive-Services Rules

Segregate and restrict access to sensitive-services records; limit out-of-state transmission and cooperation.

// THE TEETH

Liability & Penalties

A private right of action plus statutory penalties up to $250,000 — enforcement individuals can drive themselves.

Sensitive services span behavioral health, reproductive care, SUD, gender-affirming care, and more.

CMIA · CA CIVIL CODE 56 ET SEQ. AB 254 / 352 · SIGNED SEP 2023 Out-of-State Rules · ENFORCEABLE JAN 2026

// THE PATH

From "does this apply?" to defensible in California.

How California organizations build a CMIA-ready posture on top of HIPAA. The amber stages are the enforcement-facing moments — the now-passed January 2026 threshold, and a regulator or private lawsuit that puts your controls to the test.

Scope

Does CMIA Apply?

WK 1–3

Map

CMIA vs HIPAA Gaps

WK 3–6

Segregate

Sensitive-Services Data

MO 1–3

Control

Disclosure & Access

MO 2–4

Comply

Jan 2026 Threshold

NOW IN FORCE

Defend

Suit or Enforcement

IF TRIGGERED

Amber stages are the enforcement-facing moments — the January 31, 2026 threshold the grace period ran into, now in force, and a regulator action or private lawsuit where your segregation, access, and disclosure controls are tested. Everything before exists to make those go your way.

// IS THIS YOU?

Three signs CMIA is your obligation.

// 01 // CALIFORNIA DATA

You handle California medical info

You're a provider, plan, contractor, or employer touching the medical information of California patients — so the CMIA applies on top of your HIPAA duties.

// 02 // DIGITAL HEALTH

You run a health app or platform

You offer a reproductive or sexual health digital service to consumers. AB 254 may deem you a "provider of health care" — even if you're not a HIPAA covered entity.

// 03 // EHR CAN'T SEGREGATE

Your EHR can't segment sensitive data

Your systems can't reliably restrict access to or limit out-of-state disclosure of sensitive-services records. That's live exposure now that the grace period ended.

// WHAT WE DO

The scope, the controls, and the California gap.

// Phase 01 · Scope

Applicability & HIPAA Mapping

We determine whether and how the CMIA applies to you — including the digital-health expansion — then map its obligations against your existing HIPAA program to find the California-specific gaps.

  • CMIA applicability and scope analysis
  • CMIA-to-HIPAA gap mapping
  • Digital-health (AB 254) scope review

// Phase 02 · Implement

Segregation & Disclosure Controls

We implement the sensitive-services segregation, access restriction, and out-of-state-disclosure controls AB 352 now requires — the operational work in your EHR and disclosure workflows, not just policy.

  • Sensitive-services data segregation
  • Access restriction and authorization controls
  • Out-of-state disclosure controls

// Phase 03 · Defend

Documentation & Exposure Reduction

We build the documented evidence and policies that demonstrate compliance, reducing your exposure to the private right of action and the penalties the CMIA puts within reach.

  • Policies, authorization forms, and evidence
  • Private-right-of-action exposure reduction
  • Ongoing CMIA monitoring and review

// THE GRACE PERIOD IS OVER

In California, a HIPAA-only program now leaves a gap a patient's attorney can walk right through.

Book a CMIA Strategy Call

// FREQUENTLY ASKED

The CMIA questions California teams keep asking.

If we already comply with HIPAA, do we still need to worry about the CMIA?

Yes. HIPAA is the federal floor, but the CMIA adds obligations on top, and HIPAA compliance doesn't automatically mean CMIA compliance. The CMIA is broader in ways that matter: it can reach entities outside HIPAA's definitions, including certain digital health businesses; it includes a private right of action, so individuals can sue directly; and it carries statutory penalties that can reach up to $250,000, alongside administrative fines.

Because the two laws overlap but aren't identical, the practical rule is that where both apply, you generally have to satisfy the more protective requirement. For a California healthcare organization, treat HIPAA as the baseline and layer the CMIA-specific obligations — authorization, confidentiality of stored information, and the newer sensitive-services rules — on top, rather than assuming your HIPAA work already covers them.

What did AB 254 and AB 352 change about the CMIA?

Both signed in September 2023, these bills expanded the CMIA's reach and added concrete technical duties. AB 254 broadened the law to expressly cover reproductive and sexual health services delivered through digital health solutions, and deems a business offering a reproductive or sexual health digital service to a consumer a "provider of health care" for CMIA purposes — pulling many app and platform companies in for the first time.

AB 352 focused on how EHR systems handle medical information about sensitive services — defined to include mental and behavioral health, sexual and reproductive health, STIs, substance use disorder, gender-affirming care, and intimate partner violence. It requires the capability to limit access to records on gender-affirming care, abortion and related services, and contraception to authorized individuals, to restrict transmitting that information out of state, and generally prohibits cooperating with out-of-state inquiries seeking to identify someone in connection with abortion services lawful in California, absent a valid authorization or recognized exception. These are operational requirements touching system configuration, access controls, and disclosure workflows — not just policy language.

We operate digital health or telehealth services. Are we now covered by the CMIA?

Quite possibly — one of the most important shifts from the recent amendments. Under AB 254, a business that offers a reproductive or sexual health digital service to a consumer (to let the individual manage their information, or for diagnosis, treatment, or management of a medical condition) is deemed a provider of health care for CMIA purposes. That pulls digital health companies, certain apps, and platforms that assumed they sat outside health privacy law squarely within the CMIA, with all the confidentiality, authorization, and sensitive-services obligations that follow.

This is true even for organizations that are not HIPAA covered entities — exactly the gap that catches companies by surprise: they reasoned that because they aren't a hospital or health plan, health privacy law didn't reach them. The safe approach for any digital health, telehealth, or wellness business serving California consumers is to deliberately analyze whether the CMIA now applies, rather than assume it doesn't, because the penalties and private right of action make a wrong guess expensive.

The out-of-state disclosure rules had a grace period. Is that still in effect?

No. AB 352 included a good-faith grace period stating that a provider of health care wouldn't be subject to liability or to civil or enforcement actions for failing to meet the out-of-state disclosure requirements before January 31, 2026, as long as the provider was working diligently and in good faith to comply. That date has now passed, so the grace period has ended and those requirements are enforceable.

In practical terms, organizations relying on diligent, good-faith effort as their position can no longer count on that cushion — the expectation now is actual compliance with the restrictions on out-of-state transmission of, and cooperation regarding, protected medical information. If your systems still can't reliably segregate sensitive-services records, restrict their access, or control out-of-state disclosure, that's live exposure now — compounded by the CMIA's private right of action and penalty structure. We help California organizations close exactly those gaps and document a defensible posture.

// THE NEXT MOVE

Close the California gap your HIPAA program leaves open.

Book a 30-minute CMIA strategy call with a WatchUr6 advisor. Bring whether you handle California medical information, whether you offer any digital health service, and what your EHR can do with sensitive-services records. You'll walk away knowing if the CMIA applies, where your gaps versus HIPAA are, and a path to a defensible California posture — whether you hire us or not.

Book a CMIA Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED