Palo Alto · Serving all of California

CALL US TODAY!

(650) 668-8000

HIPAA Compliance California Clinic: What Applies

hipaa-compliance-california-clinic

TL;DR — Key Takeaways

  • The usual hipaa compliance california clinic question – does HIPAA apply to us – is answerable but it is the wrong place to start. Under 45 C.F.R. 160.103 a covered entity includes “A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.” Being a health care provider is not enough on its own.
  • California’s Confidentiality of Medical Information Act does not work that way. Civil Code section 56.05 defines a “provider of health care” by licensure: any person licensed or certified under Division 2 of the Business and Professions Code, among others. A cash-pay practice can be outside HIPAA and squarely inside the CMIA.
  • And the CMIA has the thing HIPAA lacks. Section 56.36(b)(1) gives an individual nominal damages of $1,000 – the statutory figure as of drafting – for a negligent release, and “In order to recover under this paragraph, it is not necessary that the plaintiff suffered or was threatened with actual damages.” HIPAA has no private right of action.
  • Three breach clocks run, and the two state ones are shorter than the federal one. HIPAA’s outer limit under 45 C.F.R. 164.404(b) is 60 calendar days after discovery. Civil Code section 1798.82(a)(2)(A) requires disclosure within 30 calendar days of discovery or notification. And section 1798.82(f) requires a sample copy to go to the Attorney General within 15 calendar days of notifying affected consumers where more than 500 California residents are involved.
  • One California requirement is a software specification rather than a policy. Section 56.101(b)(1)(B) requires an electronic health or medical record system to “automatically record and preserve any change or deletion,” with the identity of the person, the date and time, and the change made. Small practices fail this at the vendor-selection stage and never find out.

The Direct Answer

HIPAA applies to a California clinic only if it is a covered entity or business associate, and a provider becomes a covered entity by transmitting health information electronically in a covered transaction. The California Confidentiality of Medical Information Act applies by licensure regardless, carries a $1,000 nominal-damages claim, and is often the greater exposure.

HIPAA Compliance California Clinic Analysis Starts With the Definition of a Covered Entity

Take the federal definition first, because everything downstream depends on it.

45 C.F.R. section 160.103 defines “covered entity” as a health plan, a health care clearinghouse, and a health care provider who transmits health information electronically in connection with a covered transaction.

The same section defines “health care provider” broadly – a provider of services or of medical or health services under the Medicare definitions, “and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.” A med spa or wellness clinic will usually meet that.

Paragraph (3) is where the question actually turns. A health care provider becomes a covered entity by transmitting health information electronically in connection with a covered transaction. Which transactions are covered is defined by 45 C.F.R. Part 162, which is outside this article. That is a facts question about what a particular practice actually transmits, and does hipaa apply to med spa questions cannot be answered by category.

Two practical notes that follow from the definition rather than from folklore.

A practice can back into covered entity status. The trigger is a covered electronic transaction, not a billing model. A practice that takes no insurance but runs one electronic eligibility check, or lets a vendor do it, should look at what that vendor transmits.

Business associate status is its own route in. Section 160.103 defines a business associate as a person who, on behalf of a covered entity and other than as a workforce member, “creates, receives, maintains, or transmits protected health information” for a regulated function – the definition lists claims processing, data analysis, utilization review, quality assurance, billing, benefit management, practice management and repricing – or who provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services involving disclosure of protected health information. Paragraph (3)(iii) expressly includes “A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate.”

How Does the California Confidentiality of Medical Information Act Go Further Than HIPAA?

How Does the California Confidentiality of Medical Information Act Go Further Than HIPAA

In three ways that matter to a small practice, and the first one decides whether the other two are ever reached.

It applies by licensure, not by transaction. Civil Code section 56.05 defines “provider of health care” as “a person licensed or certified pursuant to Division 2 (commencing with Section 500) of the Business and Professions Code,” a person licensed under the Osteopathic or Chiropractic Initiative Acts, a person certified under Division 2.5 of the Health and Safety Code, “or a clinic, health dispensary, or health facility licensed pursuant to Division 2 (commencing with Section 1200) of the Health and Safety Code.” There is no electronic transaction condition anywhere in it. A physician, a nurse practitioner, a registered nurse, a psychologist, a therapist or a dentist is a CMIA provider on the day the license issues.

The cmia california medical information act definition also reaches technology companies directly, and it reaches them on conditions that are easy to miss. Section 56.06(b) covers any business offering software or hardware to consumers, including a mobile application or related device, designed to maintain medical information so it can be made available to the individual or a provider at the request of either, to let the individual manage it, or for the diagnosis, treatment, or management of a medical condition. Section 56.06(a) carries the same at-the-request-of and purpose requirements for a business organized to maintain medical information. Those clauses are the definition, not decoration. In J.M. v. Illuminate Education, Inc. (2026) 19 Cal.5th 705 the California Supreme Court read both subdivisions that way and held that a vendor maintaining medical information for its institutional customers, rather than for the individual on request, fell outside them. A vendor is not a CMIA provider merely because it holds the records.

It gives the patient a claim that does not depend on harm. Section 56.36(b) permits an individual to sue a person or entity “who has negligently released confidential information or records,” and (b)(1) supplies “nominal damages of one thousand dollars ($1,000),” with the express statement that “it is not necessary that the plaintiff suffered or was threatened with actual damages.” Actual damages, if any, are recoverable in addition under (b)(2).

And the penalty ladder is steep, with a tier specifically for licensees.

Conduct Exposure Source
Violation resulting in economic loss or personal injury Punishable as a misdemeanor Civ. Code 56.36(a)
Negligent disclosure (all amounts below are the statutory figures as of drafting) Up to $2,500 per violation, irrespective of damages 56.36(c)(1)
Knowing and willful, non-professional Up to $25,000 per violation 56.36(c)(2)(A)
Knowing and willful, licensed health care professional $2,500, then $10,000, then $25,000 on a third and subsequent violation 56.36(c)(2)(B)
Knowing or willful, for financial gain, non-professional Up to $250,000 per violation, plus disgorgement 56.36(c)(3)(A)
Knowing and willful, for financial gain, licensed professional $5,000, then $25,000, then $250,000, plus disgorgement (amounts as of drafting) 56.36(c)(3)(B)

Section 56.36(c)(4) provides that no fine may be imposed under both (c)(2) and (c)(3) for the same violation.

Section 56.101(a) is the operative duty and it is worded to cover the whole lifecycle: every provider “who creates, maintains, preserves, stores, abandons, destroys, or disposes of medical information shall do so in a manner that preserves the confidentiality of the information,” with negligence in any of those acts triggering the section 56.36 remedies.

And in 2026 the Supreme Court made that duty materially easier to breach. In J.M. v. Illuminate Education, Inc. (2026) 19 Cal.5th 705, decided May 14, 2026, the court held that a plaintiff suing under section 56.101 need not allege that the information was actually viewed by an unauthorized third party; confidentiality is breached when it is “exposed to a significant risk of unauthorized access or use.” It disapproved Regents of the University of California v. Superior Court (2013) 220 Cal.App.4th 549, Sutter Health v. Superior Court (2014) 227 Cal.App.4th 1546, and Vigil v. Muir Medical Group IPA, Inc. (2022) 84 Cal.App.5th 197, to the extent those decisions are inconsistent with it. For a small practice the effect is direct: a stolen laptop, an unsecured backup or a misdirected file can breach section 56.101 without anyone proving that a stranger read anything. Loss of possession is a relevant factor but is neither necessary nor always sufficient by itself, and all the circumstances count.

What Policies and Business Associate Agreements Are Required?

For a covered entity or business associate, the Security Rule sets a floor that is specific enough to audit.

45 C.F.R. section 164.308(a)(1)(ii)(A) requires a risk analysis – “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.” It is marked Required, not Addressable. So are risk management at (B), a sanction policy at (C), and information system activity review at (D). Section 164.308(a)(2) requires a named security official.

Section 164.316(b)(2)(i) then sets the documentation clock: retain the required documentation “for 6 years from the date of its creation or the date when it last was in effect, whichever is later.”

Section 164.530(b)(1) requires a covered entity to train all workforce members on its privacy policies and procedures, and (b)(2)(i) requires training by the compliance date, for each new workforce member “within a reasonable period of time after the person joins,” and again for members whose functions are affected by a material change.

On the business associate agreement california practices actually need, two points are worth more than the template itself.

Section 164.504(e)(2) prescribes the contract’s contents, beginning with establishing the permitted and required uses and disclosures and requiring the business associate not to use or disclose otherwise, to use appropriate safeguards and comply with the Security Rule for electronic protected health information, and to report uses and disclosures not provided for by the contract.

Section 164.504(e)(1)(ii) is the part nobody reads. A covered entity is out of compliance if it knew of a pattern of the business associate’s activity amounting to a material breach of the contract “unless the covered entity took reasonable steps to cure the breach” and, failing that, terminated the contract where feasible. Subparagraph (iii) applies the same rule to a business associate and its subcontractors. A signed agreement is the start of the obligation, not the end of it.

And the California layer adds a requirement that is not a policy at all. Section 56.101(b)(1) requires an electronic health record or electronic medical record system to protect and preserve the integrity of electronic medical information and to “automatically record and preserve any change or deletion of any electronically stored medical information,” with the record of the change including “the identity of the person who accessed and changed the medical information, the date and time the medical information was accessed, and the change that was made.” That is a specification to check before signing with a vendor, and very hard to retrofit afterwards.

What Are the Breach Notification Obligations and Deadlines?

What Are the Breach Notification Obligations and Deadlines

Two clocks, and they do not match.

HIPAA. Section 164.404(b): notification “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.” Discovery is defined at section 164.404(a)(2) as the first day the breach is known “or, by exercising reasonable diligence would have been known,” with knowledge of any workforce member or agent other than the person committing the breach imputed to the entity.

Section 164.404(c)(1) lists five mandatory content elements: what happened including the dates of breach and discovery; the types of unsecured protected health information involved; steps individuals should take to protect themselves; what the entity is doing to investigate, mitigate and protect; and contact procedures including a toll-free number, email address, website or postal address. Section 164.404(c)(2) requires plain language. Section 164.404(d)(1) requires first-class mail, or email if the individual agreed and has not withdrawn.

Section 164.408 governs notice to the Secretary. For breaches involving 500 or more individuals, notice goes “contemporaneously with the notice required by section 164.404(a).” For breaches involving fewer than 500, the entity maintains a log and reports “not later than 60 days after the end of each calendar year” for breaches discovered during the preceding year.

California, to individuals. Civil Code section 1798.82(a)(2)(A): “Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.” Subparagraph (B) permits delay to accommodate the legitimate needs of law enforcement under subdivision (c), “or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system.” Subdivision (b) requires a business maintaining data it does not own to notify the owner or licensee “immediately following discovery.” Subdivision (d) prescribes the format, including that the notice be titled “Notice of Data Breach” and use the specified headings.

California, to the Attorney General, and this is the clock most often missed. Section 1798.82(f) requires an individual or business issuing a breach notification “to more than 500 California residents as a result of a single breach of the security system” to electronically submit a single sample copy of that notification, excluding personally identifiable information, to the Attorney General “within 15 calendar days of notifying affected consumers of the security breach.”

Both California clocks are new. Section 1798.82 was amended by SB 446 effective January 1, 2026, and the Legislative Counsel’s Digest for that bill records that existing law had required disclosure only “in the most expedient time possible and without unreasonable delay,” and that the bill “would require that data breach disclosure to be made within 30 calendar days” and “would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers.” An incident response plan written before 2026 was drafted against a standard with no fixed deadline in it.

And there is a deemed-compliance provision that does less than it looks. Section 1798.82(e) provides that a HIPAA covered entity “will be deemed to have complied with the notice requirements in subdivision (d)” if it has complied completely with section 13402(f) of the federal HITECH Act – and then adds that “nothing in this subdivision shall be construed to exempt a covered entity from any other provision of this section.” Subdivision (d) is the notice format and content. The 30-day clock in (a)(2)(A) and the Attorney General submission in (f) are other provisions, and they still apply.

So the hipaa breach notification california picture has three deadlines and two definitions of the triggering event, and the sensible operational answer is to run to the shortest one that applies.

What Are the Most Common Mistakes in Small Practices?

Six, drawn from what the texts above actually require rather than from a generic checklist.

Assuming cash-pay means unregulated. HIPAA may not apply. The CMIA applies by licensure, and section 56.36(b)(1) supplies a $1,000 claim per negligent release with no proof of harm.

Treating the risk analysis as optional. Section 164.308(a)(1)(ii)(A) is marked Required. It is the first document an investigator asks for and the one small practices most often cannot produce.

Signing a business associate agreement and filing it. Section 164.504(e)(1)(ii) makes knowledge of a pattern plus inaction a compliance failure by the covered entity.

Choosing an EHR without checking the audit trail. Section 56.101(b)(1)(B) requires automatic recording of every change and deletion with person, date, time and content. This is a purchasing decision, not a policy decision.

Calendaring only the federal breach clock. Thirty calendar days under Civil Code section 1798.82(a)(2)(A) is half of HIPAA’s sixty, and the Attorney General submission under section 1798.82(f) is fifteen.

Keeping documentation for the wrong period. Section 164.316(b)(2)(i) requires six years from creation or from when the document was last in effect, whichever is later – a different clock from the seven-year records rules that govern the charts themselves.

When to Bring Counsel In

Before the vendor contract is signed, and within hours of a suspected incident.

The vendor moment matters because two of the requirements above are specifications rather than policies. An electronic record system that cannot produce the section 56.101(b)(1)(B) audit trail is a compliance problem that no written policy fixes, and a business associate agreement that does not meet section 164.504(e)(2) is a defect in the contract rather than in the practice’s binder.

The incident moment is urgent because the clocks run from discovery, and discovery under section 164.404(a)(2) includes what “by exercising reasonable diligence would have been known” to any workforce member other than the person who caused it. The imputation rule means the clock can already be running when leadership hears about it.

There is also a reason to re-read a compliance file that predates 2026. Civil Code section 1798.82 was amended effective January 1, 2026, replacing an open-ended “most expedient time possible” standard with two hard deadlines, and section 56.05 was amended effective September 20, 2025. A privacy program assembled before those dates was built against different text.

Related reading includes California’s corporate practice of medicine doctrine, remediating a non-compliant med spa in California, how to legally open a med spa in California, telehealth business structure in California, what a management services agreement is, how to open an IV hydration or wellness clinic in California, fee-splitting and kickbacks in California healthcare, and whether a non-physician can own a med spa in California.

Work with Bay Legal

Bay Legal, PC advises California clinics, med spas and wellness businesses on privacy and confidentiality compliance, business associate and vendor agreements, incident response, and the entity and licensing questions that sit underneath them. (650) 668-8000 in Northern California or (213) 668-8000 in Southern California, or schedule a consultation at https://baylegal.com/contact-us/.

Frequently Asked Questions

Does HIPAA apply to a cash-pay med spa or wellness clinic?

Sometimes, and it is a facts question. Under 45 C.F.R. 160.103 a covered entity includes a health care provider “who transmits any health information in electronic form in connection with a transaction covered by this subchapter.” Being a provider is not enough; the electronic covered transaction is the trigger, and which transactions are covered is set by 45 C.F.R. Part 162, which is outside this article. A practice can also be caught as a business associate of someone else.

How does the California Confidentiality of Medical Information Act go further than HIPAA?

Three ways. It applies by licensure rather than by transaction, so Civil Code section 56.05 reaches any Division 2 licensee whether or not a claim is ever submitted. It gives patients a private claim, with nominal damages of $1,000 under section 56.36(b)(1) and no requirement to prove harm. And section 56.06 reaches some technology vendors directly – but only where they maintain medical information to make it available to the individual or a provider at their request and for a statutory purpose, which is how J.M. v. Illuminate Education, Inc. (2026) 19 Cal.5th 705 reads it.

What policies and business associate agreements are required?

For a covered entity or business associate: a risk analysis, risk management, a sanction policy and information system activity review, all Required under 45 C.F.R. 164.308(a)(1)(ii); a named security official; documentation retained six years under 164.316(b)(2)(i); and workforce training under 164.530(b). A business associate agreement must contain what 164.504(e)(2) prescribes, and 164.504(e)(1)(ii) makes knowledge of a pattern of breach plus inaction a compliance failure by the covered entity itself.

What are the breach notification obligations and deadlines?

Three clocks. HIPAA requires individual notice no later than 60 calendar days after discovery under 45 C.F.R. 164.404(b), with notice to the Secretary contemporaneous for breaches of 500 or more and annual within 60 days after year end for fewer than 500. California requires disclosure within 30 calendar days under Civil Code section 1798.82(a)(2)(A), and a sample copy to the Attorney General within 15 calendar days of notifying consumers where more than 500 residents are involved under section 1798.82(f). Section 1798.82(e)’s HIPAA deemed-compliance path covers subdivision (d) only.

What are the most common HIPAA mistakes in small practices?

Assuming cash-pay means unregulated when the CMIA applies by licensure; treating the Required risk analysis as optional; signing a business associate agreement and then ignoring a known pattern of breach; choosing an electronic record system without the automatic change-and-deletion audit trail Civil Code section 56.101(b)(1)(B) requires; calendaring only the 60-day federal breach clock when the state clock is 30 days; and retaining compliance documentation for the wrong period.

BOOK A CONSULTATION

Latest Legal Blogs

Hear From Our Clients