A working checklist of what California layers on top of the HIPAA baseline: the Confidentiality of Medical Information Act (CMIA), the AB 352 and AB 254 sensitive-services and digital health amendments, and the state breach notification clocks that run faster than the federal one. HIPAA compliance alone does not satisfy these; where California is stricter, California controls. Check items off as you confirm them; your progress saves in this browser.
Items are grouped into three lanes: CMIA core (California's baseline medical-confidentiality law, which reaches some entities and adds remedies HIPAA lacks), sensitive services (the AB 352 and AB 254 rules for gender affirming care, abortion and related services, contraception, and reproductive or sexual health apps), and breach notification (California's clocks and reporting duties, some of which run far faster than HIPAA's 60 days). Items badged Beyond HIPAA have no federal equivalent, so a clean HIPAA program can still miss them.
Authorization form requirements, disclosure limits, recipient restrictions, and a private right of action with nominal damages that HIPAA does not offer.
EHR segregation of sensitive-services information, limits on out-of-state sharing and law enforcement cooperation, and CMIA coverage for reproductive and sexual health apps.
Civil Code 1798.82 resident notice and AG reporting, plus the 15-business-day CDPH clock under Health and Safety Code 1280.15 for licensed facilities.
California is not the only state that reaches past HIPAA. The Multi-State Consumer Health Data Checklist covers Washington's My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act, which apply to consumer health data on their own terms regardless of your HIPAA status. If an AI or analytics vendor touches any of this data, the AI Vendor Risk Assessment covers the contract terms.
This checklist compiles selected California health privacy requirements (the Confidentiality of Medical Information Act at Civ. Code §56 et seq. as amended by AB 352 and AB 254, breach notification under Civ. Code §1798.82, and Health and Safety Code §1280.15) as they layer on top of the HIPAA baseline, for general compliance-learning purposes. It supplements, and does not replace, your HIPAA obligations, and it is not a complete inventory of California health privacy law. This is not legal advice. Brandon Goulter is not an attorney, and using this checklist creates no professional advisory relationship. Verify current requirements against primary sources (leginfo.legislature.ca.gov) and confirm your own program's compliance with a licensed attorney before relying on this checklist. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.