Skip to content
All articles
HIPAA9 min read

HIPAA and California Compliance Requirements for Healthcare Organizations

How federal HIPAA requirements interact with California's CMIA, CCPA/CPRA and breach-reporting rules, and the safeguards healthcare organizations operating in California need in place.

Healthcare organizations in California answer to two layers of privacy law: federal HIPAA, and California statutes that often go further. Understanding where they overlap, and where California adds obligations, is essential for avoiding penalties and protecting patients.

HIPAA: the federal foundation

The Health Insurance Portability and Accountability Act (HIPAA), strengthened by the HITECH Act in 2009, sets national standards for protecting protected health information (PHI). It applies to covered entities (health plans, clearinghouses and most providers) and to their business associates.

  • Privacy Rule — when PHI may be used and disclosed, and patients' rights to their information.
  • Security Rule — administrative, physical and technical safeguards for electronic PHI (ePHI).
  • Breach Notification Rule — notifying individuals, HHS and in some cases the media after a breach of unsecured PHI.
  • Enforcement Rule — investigations and civil money penalties.

California's additional layers

Confidentiality of Medical Information Act (CMIA)

The CMIA (California Civil Code §56 and following) protects medical information held by providers, health plans and certain other businesses, and in several areas is stricter than HIPAA:

  • Narrower circumstances in which medical information may be disclosed without written authorization.
  • Specific requirements for what a valid authorization must contain.
  • A private right of action, so patients can sue directly, in addition to administrative and civil penalties.

CCPA / CPRA

The California Consumer Privacy Act, as amended by the CPRA, gives consumers rights to know, delete and correct personal information and to opt out of its sale or sharing. Importantly, medical information governed by the CMIA and PHI governed by HIPAA are largely exempt. The CCPA matters for the other personal information a healthcare organization collects, such as website visitors, marketing contacts and some employee and applicant data, provided the organization meets the law's thresholds.

Breach reporting for licensed facilities

California Health and Safety Code §1280.15 requires licensed clinics, health facilities, home health agencies and hospices to report unauthorized access, use or disclosure of patients' medical information to the California Department of Public Health and to affected patients within a short deadline (15 business days after detection). That is considerably faster than HIPAA's outer limit of 60 days, so California organizations should plan their incident response around the state timeline.

Core safeguards to have in place

Administrative safeguards

  • A documented, current Security Risk Analysis and a risk management plan.
  • A designated Privacy Officer and Security Officer.
  • Workforce training on HIPAA and California requirements, with sanctions for violations.
  • Procedures for granting, reviewing and revoking access to PHI.
  • Business associate agreements with every vendor that handles PHI.

Physical safeguards

  • Controlled access to facilities and areas where PHI is stored.
  • Workstation security, including screen locks and placement away from public view.
  • Controls for laptops, tablets, phones and removable media, including secure disposal.

Technical safeguards

  • Unique user IDs, multi-factor authentication and automatic logoff.
  • Audit logging and regular review of access to ePHI.
  • Integrity controls that protect ePHI from improper alteration or destruction.
  • Encryption of ePHI in transit and at rest.

Staying compliant over time

  • Update the risk analysis whenever systems, locations or vendors change, and at least annually.
  • Track HHS Office for Civil Rights guidance and California legislative changes.
  • Test your incident response plan against both the HIPAA and California timelines.
  • Audit access to sensitive records, not just the systems that hold them.

How Thornshield can help

Thornshield performs HIPAA Security Risk Analyses, writes policies that reflect both federal and California requirements, and prepares breach response plans that meet the state's reporting deadlines. Learn more about our HIPAA compliance services.

This article is for general information only and is not legal advice. Requirements vary by state, payer and organization; consult qualified counsel about your specific obligations.

Find out where you stand.

Tell us about your organization and what worries you most. We'll come back with an honest view of your risks and the most practical way to address them.