California Confidentiality of Medical Information Act Explained in 2026

California Confidentiality of Medical Information Act Explained in 2026

The California Confidentiality of Medical Information Act, or CMIA, is a California law. It controls how medical information can be used and shared. CMIA works alongside HIPAA, but it has its own rules along with its own definitions, exceptions, and way of enforcing them.

You need to understand this law if you work at a medical practice or handle patient records. In some cases, it protects patients even more than HIPAA does.

This guide simply breaks down CMIA in plain language: what healthcare providers must do, and what rights patients have. 

Key Takeaways

  • CMIA is a California state law (Civil Code §56 et seq.) that regulates medical information, separate from and often stricter than HIPAA.
  • It applies to providers, health plans, employers who see employee medical records, and contractors or vendors who touch patient data.
  • Patients can sue for a flat $1,000 in nominal damages without proving actual harm, in addition to real damages.
  • Penalties scale up fast: negligent disclosures top out at $2,500, but knowing or willful violations by non-professionals can reach $250,000 per violation.
  • Under a related California law (Health & Safety Code §123110), providers must let patients inspect records within 5 working days and provide copies within 15 calendar days, both faster than HIPAA’s 30-day standard.

What Is the California Confidentiality of Medical Information Act (CMIA)?

The California Confidentiality of Medical Information Act is a state law that protects patient records. It requires healthcare providers and businesses to keep health data private. 

The law was enacted in 1981 and codified under the California Civil Code 56 et seq. CMIA recognizes that medical information is highly private. A person`s diagnosis, treatment, or other health information could affect their job, family matters, or insurance if it is shared without consent. 

California lawmakers built CMIA considering all these factors, and this law has been amended several times in recent years. You can read the current status of the law in detail on California Legislative Information, which hosts the official Civil Code text. 

Who Must Comply With CMIA?

Under California’s Confidentiality of Medical Information Act (CMIA), healthcare providers, health plans, employers that handle employee medical data, contractors, and digital health applications and software vendors are all required to comply with CMIA. 

Healthcare providers and facilities

CMIA was written for core groups including Hospitals, clinics, physicians, dentists, psychologists, and other licensed professionals. In simple terms, if you diagnose, treat, or maintain patient records in California, this law applies to you directly. 

Health care service plans and insurers

Health plans and insurers that process claims and maintain enrolled records are supposed to comply with CMIA. They must protect this information when they store it, use it, or share it with healthcare providers in their network. 

Contractors, vendors, and third-party service providers

Healthcare practices also need to protect medical information when they work with outside companies. This can include billing companies, transcription services, IT providers, and other vendors that handle patient information for the practice. Practices that bring on outsourced or virtual staff need a clear picture of how California privacy law applies to this arrangement. 

One common example is medical billing. Practices that use virtual medical billing assistants make sure providers protect patient information under CMIA requirements. A written agreement should clearly define their confidentiality and data-handling responsibilities. 

See our guide to HIPAA laws and California’s SB 81’s 2025 update on hiring virtual staff before onboarding remote help. 

Employers handling employee medical information

Employers also have responsibilities under CMIA when they collect medical information of an employee. For example, it can include information from a fitness-for-duty exam or compensation claim of a worker. 

They should keep this medical information private and separate from the employee’s regular personnel records. 

What Counts as “Medical Information” Under CMIA?

CMIA defines Medical Information broadly; it covers any information that can identify a patient and relates to their medical history, physical or mental health, or treatment. It includes diagnosis codes, treatment notes, lab results, and patient-specific billing records. 

CMIA can be applied to paper records, electronic health records, scanned documents, and archived files. Even verbal discussion can raise privacy concerns. 

A California appellate court addressed a related question in Maureen K. v. Tuschka (2013 215 Cal.App.4th 519. A surgeon declined to treat a patient after learning she was HIV-positive, citing safety concerns. The patient sued under CMIA. But the court rejected the claim because the surgeon had not disclosed her identifying medical information to any third party. The refusal itself, without a disclosure to someone else, didn’t meet CMIA’s criteria. 

The case is a useful reminder that CMIA liability turns specifically on an unauthorized disclosure to a third party. It does not depend on how a provider handles the information internally. 

CMIA Consent and Authorization Requirements

Under California’s Confidentiality of Medical Information Act (CMIA), sharing patient data without a valid, specific, and separately signed authorization is a CMIA violation. It can trigger civil penalties and a direct lawsuit from the patient. 

Vague consent forms are invalid. Whether you have a virtual medical receptionist and in-person front-desk staff, they must catch defective forms at intake to protect patient privacy and avoid serious illegal liability. 

They are responsible for collecting the form. So, Healthcare practices that use these remote or onsite receptionists need to train them to check authorizations that meet CMIA requirements, like required signature, dates, scope of information, authorized receptionist, permitted use, and expiration. 

When Can Medical Information Be Disclosed Without Authorization

CMIA usually requires authorizations before a provider discloses patient information, but Civil Code § 56.10 states specific exceptions. For example, a provider may disclose information when it is necessary for diagnosis or treatment purposes. Some of the common exceptions are as follows: 

Mandatory disclosures

Some disclosures are required regardless of patient consent. These include responding to court orders, administrative orders, and disclosures required by any other law. CMIA also permits certain public-health and abuse-reporting disclosures when required by law.

Discretionary disclosures

CMIA also allows certain disclosures without requiring a separate authorization for each instance. A provider can share patient information with another provider for the sake of continuing the treatment. Patient information can also be shared with an insurer, health plan, and other necessary measures required. 

Disclosure to family members and personal representatives

Disclosure is limited to authorized personal representatives or specific family members directly involved in care, provided strict legal standards are met.

Patient Rights Under CMIA

CMIA gives patients powerful rights over their medical records.  Providers cannot share patient records without written consent. Patients can view, copy, and restrict the sharing of their medical records. 

Right to access and copy records

Patients can look at their medical records, copy the data, or ask the provider for paper or digital copies of health records. 

California providers must permit inspection within 5 working days of a request. Copies must be provided within 15 calendar days, under Health & Safety Code §123110. It is a separate but related state law that works alongside CMIA. This is often where a virtual patient care coordinator helps by receiving, taking, and following up on record requests.  

Right to amend or add to records

Patients can ask providers to change wrong facts in the file. They can add a written note if a provider refuses to change an error. 

Right to restrict disclosure

Patients can ask providers to limit the sharing of their medical information. When a disclosure is not covered by a CMIA exception, the provider generally needs a valid written authorization before sharing it. Certain disclosures, such as those required by law or allowed for treatment and payment, can occur without separate authorization. 

Record Retention, Storage, and Destruction Requirements

CMIA requires healthcare providers to keep medical information secure while it is stored and used. Paper records should be kept safely, while electronic records should have proper access controls. A virtual medical scribe assists providers with electronic records in this matter. They handle and update patient records, so they need to follow the practice’s privacy and security procedures.

When records are no longer needed, they should be destroyed securely. Paper files should be shredded, and electronic data should be properly deleted rather than left in an unsecured location.

What Happens If CMIA is Violated? (Penalties and Private Right of Action)

CMIA violations can lead to private lawsuits, civil penalties, and other consequences. The amount depends on whether the violation was negligent, knowing, willful, or connected to financial gain. 

  • Private lawsuits: A patient can sue for a negligent release of confidential medical information and may recover $1,000 in nominal damages without proving actual harm.
  • Negligent disclosure: A provider or any other covered entity can face up to $2,500 per violation.
  • Knowing or willful violation: A non-licensed person can face up to $25,000 per violation. Licensed health professionals can face up to $2,500 per violation, $10,000 for a second violation, and $25,000 for a third or later violation.  
  • Financial gain: Penalties can reach up to $250,000 per violation for non-professionals. For licensed professionals, it can be $5,000 (first violation), $25,000 (second), and $250,000 (third or later), plus disgorgement of any profits from the violation.
  • Unauthorized access: Someone who is not permitted to receive medical information and knowingly obtains, uses, or discloses it without written authorization can face a civil penalty of up to $250,000 per violation.

How Healthcare Organizations Can Stay CMIA Compliant: Practical Checklist

Many practices lean on virtual medical administrative assistants to keep this process consistent; audit logs, authorization tracking, and access reviews are easier to maintain when one role owns them.

  • Audit who actually has access to medical information, and cut off access the moment someone changes roles or leaves.
  • Use written, specific authorization forms for every disclosure that isn’t covered by a mandatory or discretionary exception.
  • Put confidentiality clauses in every contractor and vendor agreement, and confirm your staffing partners already understand CMIA before onboarding.
  • Train front-line staff regularly, since most violations trace back to a person, not a system failure.
  • Document your records-request process so you can consistently meet the 15-business-day deadline.
  • Remove access when a contractor changes roles or stops working with the practice.
  • Don’t let staff continue using an authorization after its permitted scope or expiration date.
If staffing capacity is the bottleneck, see how virtual medical assistants help optimize healthcare revenue cycles without compromising CMIA compliance.

The Bottom Line for California Practices

CMIA is a separate California privacy law with its own requirements, penalties, and patient rights. Staying compliant means using valid authorizations, training staff, checking vendor and contractor agreements, and having a clear process for handling medical-record requests. 

As this guide covers, a lot of that responsibility now sits with the billers, receptionists, and coordinators handling records day to day, whether they’re in-house or working remotely. When a specific situation is unclear, consult California healthcare counsel rather than guessing.

If keeping that front-line staff trained and consistent is the harder part of compliance, that’s a staffing problem as much as a legal one. Which is why it is worth a look at how a staffing partner like Remote Scouts builds CMIA awareness into those roles from the start.

Most Frequently Asked Questions

What is the CMIA in California?

CMIA is a state law (Civil Code 56 et seq.) that restricts how medical information can be collected, stored, used, and disclosed and gives patients the right to sue over violations. 

CMIA applies to Healthcare providers, health care service plans, contractors and vendors who handle medical information, and employers who possess medical records. 

Yes. Patients can bring a private lawsuit for negligent disclosure and recover $1,000 in nominal damages without proving actual harm, plus any real damage they can document. 

Penalties range from $1,000 in nominal statutory damages available in a private lawsuit up to $250,000 per violation for knowing, willful violations involving financial gain. It depends on whether the violator is a licensed professional or not. 

California providers must allow patients to inspect their records within 5 working days and provide copies within 15 calendar days, under Health & Safety Code §123110.

Yes, the California Confidentiality of Medical Information Act (CMIA) covers mental health and substance use records because they fit the legal definition of medical information, but substance use records also face stricter rules under federal 42 CFR Part 2 laws. 

Subscribe to Our Newsletter
Receive occasional updates, hiring insights, and practical tips on building reliable remote teams, sent only when it’s useful.

Build Your Expert Remote Team in Less Than 10 Days.
Hiring top-tier talent is simple, fast, and reliable through Remote Scouts. 100% risk-free virtual assistant staffing with top 3% vetted candidates across multiple industries and regions. No more work delays.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Begin Your Risk-Free Hiring Process
Looking for a job? View Our Current Openings.