Privacy Law Library

Confidentiality of Medical Information Act

CMIA

Health · Employees

California's main medical privacy law. It bars health care providers, health plans, and their contractors from disclosing medical information without the patient's written authorization except as listed, requires confidential storage and disposal, and extends these duties to consumer health apps, mental health and reproductive health digital services, and employers. Recent amendments protect reproductive and gender-affirming care records from out-of-state disclosure and (SB 81, 2025) bar disclosure for immigration enforcement without a warrant or court order.

Where
California
Citation
Cal. Civ. Code 56-56.37 (Part 2.6)
Status
In force
Last amended
2025-09-20
Enforced by
California Attorney General, district attorneys and other public prosecutors, State Department of Public Health and licensing boards; private plaintiffs
People can sue
Yes
Penalties
Private action for negligent release: $1,000 nominal damages without proof of harm plus actual damages. Administrative fines or civil penalties up to $2,500 per negligent disclosure, up to $25,000 per knowing and willful violation, and up to $250,000 per violation for financial gain; misdemeanor if the violation causes economic loss or personal injury (56.36).
Applies to
  • Providers of health care, health care service plans, pharmaceutical companies, and their contractors (56.05, 56.10)
  • Businesses deemed providers: those maintaining medical information for consumers, consumer health apps and devices, mental health digital services, reproductive or sexual health digital services, and licensed cannabis businesses receiving medical cards (56.06)
  • Employers receiving employee medical information (56.20-56.245)
  • Businesses storing electronic sensitive-services records for providers (56.101(c))

Practices it requires

  • Do not disclose medical information without the patient's written authorization, except as required or permitted in listed circumstances.Cal. Civ. Code 56.10(a)-(c)
  • Do not disclose medical information for immigration enforcement except as required by law (e.g., a valid warrant or court order).Cal. Civ. Code 56.10 · From 2025-09-20
  • Employers must protect employee medical information and may not use or disclose it without authorization except as listed.Cal. Civ. Code 56.20-56.245

Security duties

  • Create, maintain, store, and dispose of medical information in a way that preserves confidentiality; EHR systems must record every change or deletion with user identity and time.Cal. Civ. Code 56.101(a)-(b)
  • Businesses storing electronic records of sensitive services must limit access to, segregate, and be able to block out-of-state access to records about gender-affirming care, abortion, and contraception.Cal. Civ. Code 56.101(c) · From 2024-07-01

Other duties

  • Consumer health apps and devices, mental health digital services, and reproductive or sexual health digital services are treated as health care providers and must meet the same confidentiality standards.Cal. Civ. Code 56.06

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Original enactment (Stats. 1981, Ch. 782, operative 1982) not fetched; effective_date left null. | Employer provisions 56.20-56.245 not fetched; cited from part structure. | SB 81 immigration-enforcement text confirmed in 56.10 but exact subdivision not pinned.

Research reference, not legal advice.