Compliance Tool · California Overlay

California Health Privacy Checklist

A working checklist of what California layers on top of the HIPAA baseline: the Confidentiality of Medical Information Act (CMIA), the AB 352 and AB 254 sensitive-services and digital health amendments, and the state breach notification clocks that run faster than the federal one. HIPAA compliance alone does not satisfy these; where California is stricter, California controls. Check items off as you confirm them; your progress saves in this browser.

Sources: CMIA, Civ. Code §56 et seq. ↗  ·  Civ. Code §1798.82 ↗  ·  H&S Code §1280.15 ↗  ·  Compiled as of July 3, 2026

Items shown
Checked off
Complete
Current view

Items are grouped into three lanes: CMIA core (California's baseline medical-confidentiality law, which reaches some entities and adds remedies HIPAA lacks), sensitive services (the AB 352 and AB 254 rules for gender affirming care, abortion and related services, contraception, and reproductive or sexual health apps), and breach notification (California's clocks and reporting duties, some of which run far faster than HIPAA's 60 days). Items badged Beyond HIPAA have no federal equivalent, so a clean HIPAA program can still miss them.

CMIA Core

Authorization form requirements, disclosure limits, recipient restrictions, and a private right of action with nominal damages that HIPAA does not offer.

Sensitive Services · AB 352 / AB 254

EHR segregation of sensitive-services information, limits on out-of-state sharing and law enforcement cooperation, and CMIA coverage for reproductive and sexual health apps.

Breach Notification

Civil Code 1798.82 resident notice and AG reporting, plus the 15-business-day CDPH clock under Health and Safety Code 1280.15 for licensed facilities.

AB 352 and AB 254 signedSeptember 27, 2023
Main AB 352 / AB 254 provisions effectiveJanuary 1, 2024
EHR sensitive-services segregation capability deadlineJuly 1, 2024 (passed)
Good-faith law-enforcement-cooperation safe harbor expiredJanuary 31, 2026
CDPH breach report clock (licensed clinics, hospitals, home health)15 business days from detection (H&S §1280.15)
Attorney General sample noticeRequired when a breach affects more than 500 California residents (Civ. Code §1798.82)

California is not the only state that reaches past HIPAA. The Multi-State Consumer Health Data Checklist covers Washington's My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act, which apply to consumer health data on their own terms regardless of your HIPAA status. If an AI or analytics vendor touches any of this data, the AI Vendor Risk Assessment covers the contract terms.

This checklist compiles selected California health privacy requirements (the Confidentiality of Medical Information Act at Civ. Code §56 et seq. as amended by AB 352 and AB 254, breach notification under Civ. Code §1798.82, and Health and Safety Code §1280.15) as they layer on top of the HIPAA baseline, for general compliance-learning purposes. It supplements, and does not replace, your HIPAA obligations, and it is not a complete inventory of California health privacy law. This is not legal advice. Brandon Goulter is not an attorney, and using this checklist creates no professional advisory relationship. Verify current requirements against primary sources (leginfo.legislature.ca.gov) and confirm your own program's compliance with a licensed attorney before relying on this checklist. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.