Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

HIPAA vs CMIA Reference Guide

HIPAA vs. CMIA: What California Healthcare Practices Must Know

Both laws govern your patients’ medical information. They are not the same law — and HIPAA compliance alone does not satisfy CMIA. Every Sacramento healthcare practice operating under HIPAA must also comply with the California Confidentiality of Medical Information Act, and where the two conflict, California’s stricter standard prevails. This guide shows where the laws align, where they diverge, and what each obligation means for your IT and compliance program.

■ HIPAA Federal / HHS OCR

■ CMIA California / State AG + Private Plaintiffs

■ LBT Role What LBT manages under each framework

Dimension

■ HIPAA (Federal)

■ CMIA (California)

■ LBT Role

ORIGINS, AUTHORITY & RELATIONSHIP

Enacted

1996 — Health Insurance Portability and Accountability Act

1981 — predates HIPAA by 15 years; repeatedly amended through 2024

LBT maintains compliance documentation under both frameworks simultaneously

Governing body

HHS Office for Civil Rights (OCR) — federal enforcement

California AG, California Department of Public Health (CDPH), and private plaintiffs

LBT incident response procedures are calibrated to satisfy both enforcement timelines

Relationship between laws

Federal floor — establishes minimum national standards

California ceiling — stricter than HIPAA; where they conflict, CMIA prevails

LBT applies whichever standard is stricter, ensuring a single program satisfies both

Does HIPAA compliance satisfy CMIA?

N/A

NO — HIPAA compliance is necessary but not sufficient for California practices

LBT addresses CMIA-specific requirements that HIPAA alone does not cover

SCOPE — WHO IS COVERED

Covered healthcare providers

Licensed providers who conduct electronic transactions (claims, referrals, eligibility). Not all providers qualify automatically.

All licensed healthcare providers and clinics in California, regardless of whether they conduct electronic transactions. Broader scope than HIPAA.

LBT serves clients under both frameworks; CMIA’s broader scope means more clients have CMIA obligations than strict HIPAA covered entity status

IT providers & vendors

Business Associates — obligations defined by BAA contract; attach by agreement

Contractors — obligations attach by operation of law; no contract required. Access to medical information creates the obligation.

LBT is a Business Associate under HIPAA (BAA required) AND a CMIA Contractor by law. Both statuses apply independently.

Employers

Limited — employer health plan data may be covered; occupational health records generally excluded

Yes — employers who maintain employee medical information for HR purposes are covered under CMIA

LBT manages systems for employer clients who may hold employee health data subject to CMIA but not HIPAA

Technology companies

Business Associates only if they handle PHI on behalf of a covered entity under contract

Any company that stores or processes identifiable medical information of California residents — including health apps, wearables, and EHR vendors

LBT’s CMIA contractor status applies across all healthcare client engagements regardless of formal BAA status

WHAT INFORMATION IS PROTECTED

Defined protected information

Protected Health Information (PHI) — individually identifiable health information held by covered entities or BAs in any medium

Medical information — any individually identifiable information in medical records, including diagnoses, treatment, test results, and insurance information

LBT treats both definitions as applicable to all patient data on managed systems, applying the broader CMIA definition where it extends beyond PHI

Sensitive service data

No specific heightened category — PHI treated uniformly under Privacy Rule

Heightened protection (AB 352, 2024): reproductive health, gender-affirming care, mental health, and substance use disorder data require additional controls and cannot be disclosed without express written authorization — even to policyholders

LBT implements EHR access segmentation and additional technical controls for AB 352 sensitive service categories as a distinct compliance layer

De-identified data

Safe harbor: data meeting HIPAA’s de-identification standard is not PHI

Stricter: California courts interpret re-identification risk more broadly; CMIA protections may survive de-identification that satisfies HIPAA’s standard

LBT advises healthcare clients that HIPAA de-identification does not automatically satisfy CMIA requirements

DISCLOSURE & AUTHORIZATION

Permitted disclosures without authorization

Treatment, payment, and healthcare operations (TPO) — broad exception allows most internal and referral uses without patient consent

Narrower exceptions — some uses permitted under HIPAA TPO require explicit authorization under CMIA, particularly for marketing, employer access, and certain operational uses

LBT documents data flows and flags uses that may require CMIA authorization even when HIPAA TPO exception applies

Minimum necessary standard

Required — covered entities must limit PHI use to the minimum necessary for the stated purpose

Required — applies to all contractors and providers; CMIA’s standard is functionally equivalent but independently enforceable

LBT’s access control program implements least-privilege on managed systems to satisfy both frameworks’ minimum necessary requirements

Marketing & sale of data

Requires authorization; some exceptions for treatment communications

Stricter prohibition — CMIA significantly restricts use of medical information for marketing; AB 254 prohibits health app data sale entirely for mental/reproductive health apps

LBT reviews and removes third-party tracking pixels and analytics tools from patient-facing platforms that create CMIA marketing-use exposure

ENFORCEMENT & PENALTIES

Civil penalties

Tiered: $137–$71,162 per violation category; $2.13M annual cap per category

$1,000–$250,000 per violation; no annual cap — aggregate exposure scales with number of affected patients

LBT’s security posture reduces breach likelihood under both penalty frameworks simultaneously

Criminal penalties

Up to $250,000 fine and 10 years imprisonment for knowing violations

Up to $250,000 per violation — criminal penalties apply per violation, not per incident

LBT’s monitoring and access controls reduce criminal exposure by preventing unauthorized access and ensuring audit trails

Private right of action

NONE — patients cannot sue directly under HIPAA; enforcement only through OCR

YES — patients may sue directly for actual damages plus statutory damages. Class action exposure. Actively litigated in California.

LBT’s security program provides the documented ‘reasonable measures’ defense against CMIA private litigation

Who can be sued

Covered entities and Business Associates (via indemnification through BAA)

Healthcare providers AND their contractors directly — LBT as a CMIA contractor can be named as a defendant independently of the healthcare provider

LBT’s managed program is LBT’s own liability management, not just client service

Enforcement agency fines

HHS OCR — 2024 enforcement: $10,000–$4.75M per incident

California AG + CDPH — CDPH: up to $25,000 per patient for unauthorized access under H&S Code §1280.15

LBT’s incident response is calibrated to satisfy both agencies’ documentation and reporting requirements

BREACH NOTIFICATION

Notification to patients

Within 60 days of discovery of breach affecting 500+ individuals

‘In the most expedient time possible’ under Civil Code §1798.82 — no fixed deadline; regulators treat delays beyond 30–45 days as presumptively unreasonable

LBT’s incident response targets 30-day patient notification to satisfy California’s stricter standard

Notification to regulators

HHS OCR: within 60 days. Media: if 500+ in a state.

CDPH: within 15 business days of detecting unauthorized access under H&S Code §1280.15 — faster than HIPAA’s federal window

LBT’s IR procedures include 15-business-day CDPH notification workflow as a distinct step separate from HIPAA’s 60-day HHS reporting

Breach definition

Presumption of breach for unsecured PHI; risk assessment can rebut presumption (4-factor test)

Unauthorized acquisition or access — California’s standard is triggered more directly; less discretion to avoid notification through risk assessment

LBT advises that California breach threshold is lower; encryption is the primary safe harbor under both laws

Encryption safe harbor

Yes — encrypted PHI not subject to breach notification

Yes — encrypted medical information not subject to CMIA notification obligation. Safe harbor available under Civil Code §1798.82.

Encryption across all managed systems activates both safe harbors simultaneously — a single technical control that reduces notification obligations under both frameworks

LBT’S ROLE UNDER EACH FRAMEWORK

LBT’s legal status

Business Associate — defined and scoped by the BAA LBT executes with each covered entity client

Contractor — CMIA obligations attach by operation of law; independent of any agreement

Both statuses apply to LBT simultaneously for all healthcare clients. LBT formally acknowledges both in its client agreements.

Required agreement

Business Associate Agreement (BAA) — must be executed before accessing PHI

No California-equivalent of a BAA required by statute — but LBT documents CMIA contractor obligations in writing with each healthcare client

LBT executes a combined BAA and CMIA contractor acknowledgment with every healthcare client

Key IT controls LBT provides

24/7 monitoring, EDR, SIEM, encryption, access controls, audit logging, workforce training, annual risk assessment, incident response

All HIPAA controls PLUS: AB 352 sensitive service data segmentation, stricter breach notification timelines, CDPH notification workflow, pixel/tracker removal from patient portals

LBT’s managed program is built to satisfy the union of both frameworks — no gap between HIPAA compliance and CMIA compliance

Documentation LBT maintains

Risk assessment, BAA, security policies, training records, incident response plan, audit logs

All HIPAA documentation PLUS: CMIA contractor acknowledgment, AB 352 control documentation, CDPH-calibrated IR procedures, sensitive service access logs

Single documentation set maintained by LBT satisfies both frameworks’ evidence requirements

THREE THINGS EVERY SACRAMENTO HEALTHCARE PRACTICE MUST UNDERSTAND

01

HIPAA compliance does not equal CMIA compliance.

CMIA is stricter, broader in scope, and independently enforceable. Every California practice needs both programs running in parallel — not one in place of the other.

02

The private right of action is the critical difference.

Under HIPAA, patients cannot sue your practice directly. Under CMIA, they can — and plaintiffs’ attorneys are actively using it. A breach that triggers HIPAA penalties can also trigger direct patient litigation under CMIA.

03

Your IT provider is a CMIA contractor by law.

LBT’s CMIA obligations don’t require a signed agreement to exist — they attach the moment LBT accesses systems containing patient medical information. LBT’s security program is LBT’s own liability management, not just a service to your practice.

Does your compliance program cover both HIPAA and CMIA?

Most Sacramento practices are HIPAA-aware but CMIA-exposed. LBT’s free scoping consultation identifies exactly where gaps exist under both frameworks — at no cost and no obligation.

BOOK A FREE HIPAA + CMIA ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com

© 2026 LBT Technology Group, LLC · Sacramento, California · Confidential — For Authorized Review Only · This document is for informational purposes only and does not constitute legal advice.

California Healthcare Privacy Reference Guide

HIPAA vs. CMIA: What California Healthcare Organizations Must Know

See where federal and California medical-privacy duties overlap, where they differ, and how to operate one coordinated security and compliance program.

02Frameworks

Federal HIPAA and California CMIA may apply together.

07Comparison dimensions

From legal scope through incident response and vendor roles.

01Coordinated program

One operating model can track both sets of obligations.

Overlap does not mean equivalence

HIPAA alignment is a foundation, not the end of the California analysis.

HIPAA and CMIA both protect medical information, but they reach organizations and activities through different definitions and legal relationships. A California healthcare organization may need to satisfy both for the same data and workflow.

The practical goal is not to run two disconnected compliance programs. It is to identify where the obligations align, document where California changes the answer, and maintain controls and evidence that serve both.

Interactive comparison

Seven dimensions show where the two frameworks meet and diverge.

Select a dimension to compare HIPAA, CMIA, and the practical program response.

Origins and authority

Start with two laws that may apply at the same time.

HIPAA

A federal privacy and security framework that establishes national protections for PHI handled by covered entities and business associates.

CMIA

A California medical-privacy law with its own definitions, covered relationships, disclosure rules, and enforcement mechanisms.

Program response

Map both regimes to the same data environment, then document where California requirements add or change the operating obligation.

A practical decision path

Determine the obligation before choosing the control or disclosure path.

Legal applicability depends on the facts, but the operating questions should be consistent.

01

Identify the relationship

Document the organization, provider, plan, employer, business-associate, contractor, and subcontractor roles.

02

Identify the information

Determine what data qualifies as PHI, California medical information, or another protected category.

03

Identify the activity

Record why the information is accessed, used, disclosed, retained, or transferred and who authorizes it.

04

Apply the combined obligation

Implement the controls and response path that satisfy every applicable federal and California requirement.

Controls that support both frameworks

Shared technical discipline reduces duplicated compliance work.

The legal analysis stays distinct, while many day-to-day safeguards and evidence practices can be operated together.

01

Data mapping

Know where medical information originates, moves, rests, and leaves the environment.

02

Identity & access

Apply unique identities, least privilege, strong authentication, and recurring access review.

03

Encryption & secure exchange

Protect medical information on devices, in storage, in backup, and while transmitted.

04

Logging & accountability

Record access and security activity, review exceptions, and preserve investigation evidence.

05

Vendor governance

Maintain current agreements, role definitions, approved subprocessors, and escalation duties.

06

Incident readiness

Practice one coordinated response process with separate legal decision and notification tracks.

Five assumptions to correct

Most dual-framework gaps begin with an oversimplified rule.

01

HIPAA compliance automatically satisfies CMIA

The laws overlap, but scope, authorization, enforcement, and incident duties are not identical.

02

A BAA resolves every California obligation

A BAA addresses the HIPAA relationship; California contractor responsibilities require separate analysis.

03

Only clinical systems contain medical information

Email, collaboration tools, endpoints, backups, portals, and vendor platforms may also hold protected data.

04

Encryption is the entire compliance program

Encryption is important, but governance, access, monitoring, training, vendors, and response still matter.

05

The incident clock starts after the investigation

Escalation and legal review should begin at discovery so every applicable obligation can be evaluated promptly.

How LBT supports the combined program

Translate two legal frameworks into one managed operating environment.

The exact program follows counsel’s guidance, organizational roles, medical-information flows, vendors, systems, workforce responsibilities, and incident requirements.

Discuss your HIPAA and CMIA scope
01

Dual-framework role and data-flow assessment

02

HIPAA and CMIA control-mapping record

03

Business Associate Agreement and contractor-documentation support

04

Identity, access, logging, and sensitive-data controls

05

Workforce and vendor training with maintained evidence

06

Coordinated incident-response and notification readiness

One coordinated operating cycle

Keep the legal tracks distinct and the operational work connected.

01

Map

Identify roles, information, systems, vendors, uses, and disclosures.

02

Compare

Determine which federal and California duties apply to each workflow.

03

Operate

Implement controls, training, monitoring, agreements, and evidence.

04

Respond & update

Coordinate incidents and revise the program when facts or requirements change.

Next step

Build one healthcare security program that respects both legal tracks.

Talk with LBT about your role, data environment, existing HIPAA work, California-specific workflows, vendors, and incident readiness.

Information on this page is for general educational purposes and is not legal advice. Consult qualified counsel about requirements that apply to your organization.