HIPAA is the floor. In California, CMIA is the ceiling.
A provider network can pass a HIPAA risk assessment, sign every business associate agreement, and run a textbook breach-response process, and still be exposed in California. The reason is simple, and it catches organizations of every size: HIPAA was never the whole picture in this state. It's the starting line.
HIPAA sets a federal floor for the privacy and security of protected health information. It does not preempt state laws that protect patients more. California's Confidentiality of Medical Information Act (CMIA, codified at Civil Code section 56) is one of those laws, and in several areas it sits well above the federal floor. CMIA actually predates HIPAA by more than a decade, and it was written to be stricter.
The practical consequence is the part organizations miss: determining that a disclosure is permitted under HIPAA does not end the analysis. You still have to ask whether CMIA independently permits it. When the two laws disagree, the more protective rule controls, which in California usually means CMIA.
Where the federal floor and the California ceiling diverge
These are the gaps that most often surface when we review a network built only to the HIPAA standard.
1. A private right of action
This is the big one. HIPAA has no private right of action. Only regulators enforce it. CMIA lets the patient sue directly. A California resident whose medical information is negligently disclosed can recover nominal damages of $1,000 per person without proving any actual harm, plus actual damages where they exist. Multiply that across a breached database and add the class-action mechanism, and the exposure math changes entirely. This is why a privacy lapse that would be a regulatory matter under HIPAA becomes litigation in California.
2. Stricter authorization formatting
CMIA doesn't just require written authorization for disclosures that aren't otherwise permitted. It dictates the form of that authorization. The document must be handwritten by the signer or printed in at least 14-point type, must be clearly separated from any other language on the page, and the signature can serve no other purpose. A release that bundles authorization into a treatment-consent signature line (common on intake forms built to a generic federal template) can be invalid under California law even though it would pass federal review.
3. A wider net of covered entities
HIPAA reaches "covered entities" and their business associates. CMIA reaches further: all healthcare providers operating in California, contractors who handle medical information, pharmaceutical companies, and even health-app developers that HIPAA never touches. An organization that concluded it falls outside HIPAA's scope can still be squarely inside CMIA's.
4. Tighter timelines
California's records-access and breach-reporting clocks generally run faster than the federal equivalents, and they run independently. A breach-response plan built around HIPAA's timelines alone can miss a state deadline that fired earlier. The state clock doesn't wait for the federal one.
5. Heightened protection for sensitive services
CMIA layers extra restrictions on categories such as reproductive and sexual-health care, gender-affirming care, mental-health treatment information, and, under recent amendments, patient immigration status and place of birth. These protections, and recent laws restricting cross-jurisdictional sharing of sensitive records, have no clean federal analog. A disclosure process that doesn't flag these categories separately is a gap.
HIPAA compliance does not equal California compliance. Treating the two as the same is the single most common privacy assumption I see, and the most expensive.
What a California-ready privacy program does differently
The fix is rarely a wholesale rebuild. It's a set of deliberate adjustments layered onto a sound HIPAA foundation:
- Run the disclosure analysis in two steps (HIPAA permission first, then a separate CMIA check) rather than stopping at the federal answer.
- Rebuild authorization forms to CMIA's formatting requirements, not a generic national template.
- Track state and federal breach and access clocks on parallel, independent timelines.
- Tag sensitive-service categories in the record so they trigger the stricter handling automatically.
- Train workforce on California-specific obligations as part of privacy training, not as a footnote to HIPAA.
For provider networks and independent clinics, this is exactly the kind of exposure that hides quietly until a breach or a complaint surfaces it. The work to close it is far smaller than the cost of discovering it the hard way.
Operating in California on a HIPAA-only privacy program?
The California health privacy checklist walks CMIA, AB 352, and AB 254 alongside the federal floor, so you can see exactly where the two standards diverge for your organization. Free, and nothing you enter leaves your browser.
Run the California checklist →This article is general information, not legal advice. Brandon Goulter is not an attorney, and reading it creates no professional advisory relationship. Privacy obligations vary by organization and circumstance, and the law in this area changes frequently; confirm current requirements with a licensed attorney.