HIPAA Laws California: How SB 81’s 2025 Update Affects Practices Hiring Virtual Staff

If your practice is in California and you use virtual staff, your compliance window is already closed. SB 81 took effect September 20,2025, with a head deadline of November 4, 2025. Without a grace period.

Understanding HIPAA laws in California means understanding both federal requirements and the stricter state laws that sit on top of them. SB 81 just made that more complicated for practices hiring virtual staff. 

Before SB 81, CMIA protected information of patients including treatment, test results, patient`s diagnosis and other health records. 

Senate Bill 81 amended California’s Confidentiality of Medical Information Act (CMIA) to add two new categories of protected patient data. It includes:

  • A patient`s current or previous immigration status
  • A patient`s place of birth

Any virtual medical assistant who touches intake forms, scheduling, or EHR records must treat this information as protected medical information under California law. 

This article covers how  HIPAA laws in California and CMIA work together, what SB 81 changed, and what those changes mean for practices hiring virtual staff. 

What Are HIPAA Laws in California?

HIPAA laws in California refers to both federal HIPAA requirements and California privacy laws that protect patient health information. Where the two conflict, California law takes precedence. It means California practices must meet a higher compliance standard than most states. 

The primary California law is the Confidentiality of Medical Information Act (CMIA), codified at California Civil Code §56. Unlike HIPAA, which applies only to providers that conduct specific electronic transactions, CMIA applies to all healthcare providers in California, regardless of whether they handle electronic billing.

A small cash-only practice that never submits an electronic claim still falls under CMIA. HIPPA may not apply to them but it still falls under California’s stricter rules and SB 81’s expanded definition of protected data. 

HIPAA is federal law and establishes minimum national standards for protecting health information while California adds stricter requirements through laws such as Confidentiality of Medical Information Act (CMIA). 

CMIA also gives patients something HIPAA does not: a direct right to sue. Under CMIA, a patient can file a lawsuit in state court, making California one of the highest-risk states for privacy violations.

The California Medical Information Act (CMIA) vs. Federal HIPAA: Key Differences

California practices face a stricter law with a lower threshold for lawsuits and faster compliance deadlines. Here’s how the two frameworks compare: 

 

Area

HIPAA

California CMIA

Who it covers

Covered entities and business associates that conduct electronic transactions

All healthcare providers in California  including health plans and contractors

Patient record request deadline

30 days

5 days

Patient right to sue

No private right of action

Yes, patients can sue directly

Authorization requirements

Requires valid authorization for certain disclosures

Requires more detailed authorization requirements, including specific information shared, recipients, purpose, expiration date, and revocation rights 

Penalties

$145–$73,011 per violation (federal tiers)

Civil penalties: $1,000 per violation in statutory damages

Administrative fines: $2,500 to $250,000, depending on the violation.

 

What this means for your practice 

The most immediate difference is speed. CMIA requires you to respond to patient record requests within 5 days. HIPAA gives you 30. If you are following HIPPA timelines, you’re already out of compliance with California law. 

The biggest risk is legal exposure. Under HIPAA, only the federal Office for Civil Rights can take enforcement action against your practice. Patients cannot sue you directly. Under CMIA, any patient can file a lawsuit in California state court, claim $1,000 per violation in statutory damages and recover attorney’s fees. This makes CMIA class-action litigation a more immediate threat to most California practices than a federal OCR audit.

Your contracts with virtual staff are also at risk. A standard HIPAA Business Associate Agreement (BAA) covers your federal obligations. But it does not protect you from a CMIA violation. California requires contractor agreements to include CMIA-specific language: stricter disclosure rules, detailed authorization requirements, and now SB 81’s expanded data categories. A HIPAA-only BAA template leaves you exposed under state law.

What SB 81 Changed in 2025

SB 81, authored by State Senator Jesse Arreguín (D-Oakland), was signed by Governor Newsom on September 20, 2025 as an urgency statute. It took effect immediately with a 45-day compliance deadline of November 4, 2025. 

The law amends California’s confidentiality of Medical Information (CMIA) to classify a patient`s immigration and birth place as protected medical information. They cannot be disclosed without a valid patient authorization except in narrow, legally defined circumstances. 

What SB 81 prohibits:  

Healthcare providers cannot disclose a patient’s immigration status for immigration enforcement purposes, except in limited situations allowed by law. Immigration officers cannot access nonpublic areas of healthcare facilities without court order. 

The key exceptions include:

  • Disclosures required by a court order, subpoena, or government request
  • Disclosure for approved medical research purposes
  • Disclosures for healthcare oversight, quality reviews, or compliance activities
  • Disclosure needed for healthcare payment such as insurance claims and billing.
  • Disclosure to coroners, medical examiners or officials investigating deaths. 

What SB 81 requires:

  • Healthcare facilities must have documented procedures for monitoring and tracking visitor access. 
  • Staff must inform management or legal counsel in case an immigration officer asks for access or information. 
  • Staff, including volunteers, must be trained to handle immigration enforcement requests.

Who is covered:

Hospitals, clinics, licensed healthcare facilities, individual practitioners, health plans and their contractors. Residential Care Facilities for the Elderly (RCFEs) are not covered under SB 81. 

Although SB 81 focuses on patient privacy and immigration enforcement. Its expanded definition affects anyone handling patient data. This includes remote staff, virtual medical assistants, billing services and other contractors who must protect this broader category of information.  

How SB 81 Affects Practices Hiring Virtual Staff

SB 81 impacts virtual staff by expanding CMIA to strictly protect immigration status and birth place of patients. Practices that employ virtual assistants or use third party vendors must ensure that anyone handling patient information must be aware of updated privacy requirements. 

Virtual staff are business associates under HIPAA and contractors under CMIA

If a virtual assistant schedules appointments, handles intake forms, accesses EHR systems, or processes billing, they are touching Protected Health Information (PHI) and are subject to both HIPAA and CMIA.

Under HIPAA, they qualify as a Business Associate, a signed BAA. Under CMIA, they qualify as a contractor handling medical information, they must agree to protect under California’s stricter standards. But a standard HIPAA BAA is not sufficient in California. It does not cover CMIA’s stricter disclosure rules, detailed authorization requirements, or SB 81’s expanded data categories. 

Your contractor agreement must include California-specific CMIA language. 

What the SB 81 training requirement means for remote staff

SB 81 requires staff, including relevant volunteers, to receive training on how to respond to immigration enforcement requests. This requirement also applies to remote healthcare staff who handle patient information.

For virtual teams like medical assistants and remote billing assistants, this means treating a patient’s immigration status and place of birth as protected medical information. They must not record, share, or disclose this information unless permitted by law.

Practices should also document this training and confirm that remote staff have completed it. Do not assume your staffing provider handles this requirement. Verify it before giving remote staff access to patient information.

What to confirm before hiring a virtual medical assistant in California

To hire a virtual medical assistant safely in California, make sure your provider is well aware of both federal and state privacy laws. Make sure they are trained in CMIA, SB 81 training, CMIA-compliant Business Associate Agreement (BAA) and follow documented procedures for protecting sensitive patient information. 

You should also confirm that they are willing to sign a CMIA-compliant Business Associate Agreement (BAA) and have clear policies for breach reporting and incident response. You need to confirm the following factors before hiring a virtual medical assistant in California:

  • Do they provide training on both HIPAA and California CMIA, including SB 81 requirements?
  • Will they sign a CMIA-compliant Business Associate Agreement (BAA), not just a standard HIPAA BAA?
  • Do they have documented training procedures and protocols for handling sensitive patient information, including immigration status and place of birth?
  • Is their onboarding process documented to support your compliance records?
  • Do they have a clear breach escalation procedure, and does it comply with California’s breach notification requirements?

The Other California Privacy Laws Your Practice Needs to Know

HIPAA and CMIA are the primary laws most of the healthcare practices deal with, but these are not the only ones. Depending on your practice`s operations, other California laws may also apply to how patient information is collected, stored and shared. 

PAHRA (Patient Access to Health Records Act)

The Patient Access to Health Records Act (PAHRA) gives patients the right to access all information a provider maintains about them and get copies of their health records, not just the limited records covered under HIPAA. PAHRA requires providers to respond to patient record requests within 5 working days. 

This law also limits parental access to certain sensitive medical records when a minor is legally allowed to receive their own care. It includes services such as reproductive healthcare, STI testing and treatment, and certain outpatient mental health services. 

CCPA and CPRA

CCPA and CPRA are California data privacy laws. The California Consumer Privacy Act (CCPA) gives you control over your personal data. California Privacy Rights Act (CPRA) updates and makes those rules stronger. 

HIPAA-covered health care practices are exempted from CCPA rules, but only for information that qualifies as protected health information under HIPAA. Other types of data like marketing emails, website visitor information, online tracking data and employee records may still fall under CCPA/CPRA requirements. 

Virtual staff providers and other vendors may have separate CCPA and CPRA obligations if they handle personal information outside HIPAA-protected PHI. For example, website tracking tools may collect visitor data that HIPAA does not cover but CCPA/CPRA may protect. 

Medi-Cal

Healthcare practices that participate in Medi-Cal must follow additional privacy and security requirements set by California Department of Health Care Services. 

Medi-Cal rules can protect certain patient information that may not be considered protected under HIPAA and CMIA. For example, details about a patient`s income, living situation, or eligibility for assistance may require additional privacy protections when handled by Medi-Cal providers. 

A Practical Compliance Checklist for California Practices Using Virtual Staff

Before working with healthcare virtual staff, California healthcare practices should confirm that their privacy and security processes meet both HIPAA and CMIA requirements. You can use this checklist to review your current setup:

  • Confirm your virtual assistant provider offers training on both CMIA and HIPAA to their virtual assistants.
  • Sign a California-compliant agreement with CMIA-specific protections before you share any patient information.
  • Review your patient authorization forms to make sure they follow CMIA requirements, not just HIPAA rules.
  • Update your Notice of Privacy Practices to reflect that immigration status and place of birth are now protected medical information under SB 81.
  • Add Sb 81 training to your compliance records and keep record that virtual staff completed this training.
  • Create clear procedures for how virtual staff should respond if patients share immigration status during scheduling, intake or other interactions.
  • Review all vendor contracts to confirm they include CMIA obligations, not only HIPAA requirements. 
  • Verify your breach response plan covers both HIPAA reporting timelines and California-specific notification requirements. 
  • Review any non-PHI data you collect, such as website forms, marketing lists, or employee information, for possible CCPA/CPRA obligations. 
  • Conduct regular risk assessments covering both federal HIPAA requirements and California CMIA compliance. 

Is Your Virtual Staff Setup Actually CMIA-Compliant? Here’s How to Find Out

California practices need virtual healthcare staff who understand more than basic HIPAA requirements. Remote Scouts helps California practices build secure remote teams with HIPAA and CMIA-trained healthcare professionals, compliance-focused onboarding, and full documentation support for privacy requirements including SB 81.

If you are hiring your first virtual medical assistant or auditing an existing setup, we can help you identify compliance gaps before they become liability.

Most Frequently Asked Questions

Are HIPAA laws different in California than in other states?
  1. HIPAA sets the same federal minimum standards across all states. California adds stricter requirements through CMIA, and where California law is tougher, it takes precedence over HIPAA.

The California Medical Information Act (CMIA) is the state`s medical privacy law that protects patient information. It was created before HIPAA and applies to many California healthcare providers. Health plans and contractors. CMIA has its own rules to protect medical information, patient authorizations and penalties for violations. 

SB 81 amended CMIA to classify two new categories as protected medical information: a patient’s current or prior immigration status, and their place of birth. It also restricts immigration enforcement access to healthcare facilities without a valid court order, and requires staff training on how to handle such requests.

Yes. Your virtual medical assistant needs to be trained in California`s confidentiality of medical information act (CMIA) if they handle medical data or records for patients located in California. 

NO. HIPAA itself does not allow patients to sue healthcare providers directly. However CMIA provides patients with a right to sue directly under state law.

Yes, remote healthcare staff can be affected by SB 81 because it expands what counts as protected medical information under CMIA. While some SB 81 requirements focus on healthcare facility access and immigration enforcement requests, any virtual worker who handles California patient information must follow the updated privacy requirements when handling protected data.

Subscribe to Our Newsletter
Receive occasional updates, hiring insights, and practical tips on building reliable remote teams, sent only when it’s useful.

Build Your Expert Remote Team in Less Than 10 Days.
Hiring top-tier talent is simple, fast, and reliable through Remote Scouts. 100% risk-free virtual assistant staffing with top 3% vetted candidates across multiple industries and regions. No more work delays.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Begin Your Risk-Free Hiring Process
Looking for a job? View Our Current Openings.