Health record rights in California: what state law adds
In California, as of October 3, 2026, your OK is needed before at least some businesses outside HIPAA share your health data; you get a copy of your record faster than HIPAA requires, and free in some cases; the health information exchange offers no general choice; reproductive health, mental health, HIV and genetic records each have a specific confidentiality rule; you can sue over misuse of your records; breach notices must cover medical and health insurance information; and all three rules we look for on AI in care are in force. Each answer below quotes, dates and links the law. There is no state total and no state rank.
Laws read · page updated
Not legal advice. This records what the law said on the date we read it. Laws and court orders change. Read the law itself, or ask a lawyer, before you rely on it. State laws add to the federal floor. The national score rates federal law and national infrastructure and does not change with these state profiles.
The seven answers
Do apps and wearables need your OK before sharing health data?Yes, at least for some businesses. A law in force requires your OK before they use or share your health data (opt-in). Also signed, not yet in force: CMIA: health care chatbot businesses deemed providers of health care (AB 1979) (January 1, 2027). Same answer in 26 of the 50 states, counting this one.
Can you sue if your records are misused?Yes. You can sue over unlawful collection, use or sharing of medical records or health data in general. Same answer in 11 of the 50 states, counting this one.
Are there rules for AI used in your care?All three rules are in force. You must be told when AI is used in your care. A licensed clinician decides, not AI alone. You can reach a human, or have a human review the decision. Also signed, not yet in force: AI clinical decision support: clinician keeps independent judgment (AB 1979) (January 1, 2027). No other state has this answer.
Federal law, mainly HIPAA, applies in every state; our US page explains it in plain English. Each answer below says what this state adds on top, with the law's name, citation, effective date, the words that matter and a link to the official page.
Do apps and wearables need your OK before sharing health data?
Federal floor: HIPAA does not cover most apps, wearables, websites or data brokers.
Yes, at least for some businesses. A law in force requires your OK before they use or share your health data (opt-in).
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Level 2 rests on the CMIA. It deems health apps, mental health and reproductive health digital services to be providers, which then need authorization to disclose. The CCPA gives only a right to limit sensitive data (level 1).
"Level" is the step on our rulebook's scale for this question. 0 means nothing beyond HIPAA. Higher means the law gives you more here.
Confidentiality of Medical Information Act: businesses deemed providers of health care. Cal. Civ. Code § 56.06(d)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Any business that offers a mental health digital service to a consumer for the purpose of allowing the individual to manage the individual’s information, or for the diagnosis, treatment, or management of a medical condition of the individual, shall be deemed to be a provider of health care
Who it binds, in our words: Subdivision (b) also covers “Any business that offers software or hardware to consumers, including a mobile application or other related device that is designed to maintain medical information”; subdivision (e) covers reproductive or sexual health digital services.
Confidentiality of Medical Information Act: authorization required to disclose. Cal. Civ. Code § 56.10(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
A provider of health care, health care service plan, or contractor shall not disclose medical information regarding a patient of the provider of health care or an enrollee or subscriber of a health care service plan without first obtaining an authorization
Who it binds, in our words: Providers of health care, including businesses deemed providers under Civ. Code § 56.06.
California Consumer Privacy Act: right to limit use of sensitive personal information. Cal. Civ. Code § 1798.121(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
A consumer shall have the right, at any time, to direct a business that collects sensitive personal information about the consumer to limit its use of the consumer’s sensitive personal information
Who it binds, in our words: Businesses that, among other tests, “had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95” (Civ. Code § 1798.140).
California Consumer Privacy Act: definition of sensitive personal information. Cal. Civ. Code § 1798.140(ae)
In force · effective · quote not yet matched word for word to our stored copy of the page · read October 3, 2026 · source(leginfo.legislature.ca.gov)
(B) Personal information collected and analyzed concerning a consumer’s health.
Who it binds, in our words: Listed under paragraph (2) of the definition of “Sensitive personal information”.
CMIA: health care chatbot businesses deemed providers of health care (AB 1979). Cal. Civ. Code 56.06(f), as added by Stats. 2026, ch. 854 (AB 1979)
Signed, not yet in force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Any business that offers a health care chatbot to a consumer for the purpose of allowing the individual to manage the individual's information, or for the diagnosis, treatment, or management of a medical condition of the individual, shall be deemed to be a provider of health care
Second check by a separate agent: disputed, then settled by a ruling drafted by an agent against the law's text and approved by the authors on October 3, 2026.
Do you get a copy faster or free in some cases?
Federal floor: HIPAA gives the provider 30 days, plus one 30-day extension, and allows a cost-based fee. We also count the federal information blocking rule (45 CFR Part 171).
Yes, both. A deadline shorter than 30 days, and a free copy in at least one case.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Both elements beyond the HIPAA and information blocking floor: a 15-day copy deadline and a free paper or electronic copy for public benefit claims, also open to personal representatives. Per-page caps are recorded only as facts.
Deadline in the law: 15 days.
Free copy: One free copy of the relevant portion of the record when needed to support a claim or appeal for a public benefit program (Medi-Cal, IHSS, CalWORKs, SSDI, SSI/SSP, veterans benefits, CalFresh, CAPI, housing assistance)
Free copy: Same free copy for a petition for U nonimmigrant status or a VAWA self-petition
Fee rule: “a health care provider may impose a reasonable, cost-based fee for providing a paper or electronic copy or summary of patient records”
Fee rule: “The fee from a health care provider shall not exceed twenty-five cents ($0.25) per page for paper copies or fifty cents ($0.50) per page for records that are copied from microfilm.”
Fee rule: Free-copy case does not apply to a patient represented by a private attorney paying claim costs; free-copy requests must be met within 30 days.
Goes beyond the federal floor: yes.
Patient access to health records: copies. Cal. Health & Safety Code § 123110(b)(1)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
any patient or patient’s personal representative shall be entitled to a paper or electronic copy of all or any portion of the patient records that they have a right to inspect
Who it binds, in our words: Health care providers as defined in Health & Safety Code § 123105. The same subdivision states: “The health care provider shall ensure that the copies are transmitted within 15 days after receiving the request.”
Patient access to health records: free copy for benefit claims. Cal. Health & Safety Code § 123110(d)(1)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
is entitled to a copy, at no charge, of the relevant portion of the patient’s records, upon presenting to the provider a written request, and proof that the records or supporting forms are needed to support a claim or appeal regarding eligibility for a public benefit program
Who it binds, in our words: A patient, an employee of a nonprofit legal services entity representing the patient, or the patient’s personal representative.
Second check by a separate agent: confirmed.
Can you say no to sharing through a health information exchange (a network that passes records between doctors)?
Federal floor: HIPAA lets providers share records for treatment without asking you.
No general choice. Sharing through the exchange follows HIPAA's rules, and no state rule or exchange policy offers a general choice.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Statute requires exchange under the DxF and CMIA permits treatment disclosures without authorization. No general opt-in or opt-out found. Category consent rules for exchange were not verified, so stricterForSensitive is left null.
Set by state law.
Designated exchange: None found. California uses the CalHHS Data Exchange Framework (Health & Safety Code § 130290), administered by HCAI, not a single designated HIE.
California Health and Human Services Data Exchange Framework. Cal. Health & Safety Code § 130290(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
is a collection of organizations that are required to share health information using a common set of policies and procedures in order to improve the health outcomes of the individuals they serve.
Who it binds, in our words: Hospitals, skilled nursing facilities, clinical laboratories, physician organizations and medical groups, health insurers and health care service plans, among others.
Confidentiality of Medical Information Act: disclosure for treatment without authorization. Cal. Civ. Code § 56.10(c)(1)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
The information may be disclosed to providers of health care, health care service plans, contractors, or other health care professionals or facilities for purposes of diagnosis or treatment of the patient.
Who it binds, in our words: Providers of health care, health care service plans and contractors.
Second check by a separate agent: confirmed.
Are some sensitive records, like mental health or HIV, given extra rules?
These answers record whether a rule exists and what it says. They say nothing about whether any care is legal or available.
Reproductive health records
Yes. A law in force has a specific rule on keeping these records confidential or on who may see them.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Civ. Code § 56.108 limits release of abortion-related records in response to subpoenas or requests based on other states’ laws. Civ. Code § 56.101(c) requires segregation of these records in electronic systems.
Abortion-related medical information: subpoenas and out-of-state requests. Cal. Civ. Code § 56.108(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
a provider of health care, health care service plan, contractor, or employer shall not release medical information related to an individual seeking or obtaining an abortion in response to a subpoena or request if that subpoena or request is based on either another state’s laws
Who it binds, in our words: Providers of health care, health care service plans, contractors and employers.
Electronic health records: segregation of reproductive and gender affirming care information. Cal. Civ. Code § 56.101(c)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Segregate medical information related to gender affirming care, abortion and abortion-related services, and contraception from the rest of the patient’s record.
Who it binds, in our words: Electronic health record systems and businesses described in the section.
Notice to the Attorney General before producing records on legally protected abortion or gender-affirming care (AB 1930). Cal. Civ. Code 1798.309(a)(1)(A), as added by Stats. 2026, ch. 468 (AB 1930)
Signed, not yet in force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
regarding abortion or gender-affirming health care services that are legally protected health care activities secured by the Constitution or laws of California shall provide notice to the Attorney General at least seven business days prior to producing records in response to the request
Second check by a separate agent: disputed, then settled by a ruling drafted by an agent against the law's text and approved by the authors on October 3, 2026.
Mental health records
Yes. A law in force has a specific rule on keeping these records confidential or on who may see them.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Records of services under the listed divisions are confidential and may be disclosed only in the cases the section lists.
Lanterman-Petris-Short Act: confidentiality of mental health services records. Cal. Welf. & Inst. Code § 5328(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
recipients of services are confidential. Information and records obtained in the course of providing similar services to either voluntary or involuntary recipients before 1969 are also confidential. Information and records shall be disclosed only in any of the following cases:
Who it binds, in our words: Records of services under Divisions 4, 4.1, 4.5, 5, 6 and 7 of the Welfare and Institutions Code.
Second check by a separate agent: confirmed.
HIV records
Yes. A law in force has a specific rule on keeping these records confidential or on who may see them.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Identifying disclosure of HIV test results needs written authorization unless a listed statute allows it. Penalties are paid to the subject of the test.
Disclosure of HIV test results. Cal. Health & Safety Code § 120980(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Any person who negligently discloses results of an HIV test, as defined in subdivision (c) of Section 120775, to any third party, in a manner that identifies or provides identifying characteristics of the person to whom the test results apply, except pursuant to a written authorization
Who it binds, in our words: Any person, subject to listed statutory exemptions.
Second check by a separate agent: confirmed.
Genetic records
Yes. A law in force has a specific rule on keeping these records confidential or on who may see them.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Direct-to-consumer genetic testing companies need express consent for collection, use and disclosure of genetic data, with separate consent for listed uses.
Genetic Information Privacy Act: consent for genetic data. Cal. Civ. Code § 56.181(a)(2)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Obtain a consumer’s express consent for collection, use, and disclosure of the consumer’s genetic data, including, at a minimum, separate and express consent for each of the following:
Who it binds, in our words: “a direct-to-consumer genetic testing company”
Second check by a separate agent: confirmed.
Can you sue if your records are misused?
Yes. You can sue over unlawful collection, use or sharing of medical records or health data in general.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
The CMIA lets a person sue for unlawful release, use or disclosure of medical information generally, with $1,000 nominal damages without proof of harm.
Damages a court may award: Nominal damages of $1,000 for negligent release without proof of actual damages, plus actual damages (Civ. Code § 56.36(b)). Compensatory damages, punitive damages up to $3,000, attorney fees up to $1,000 and costs (Civ. Code § 56.35).
CMIA: action for negligent release of medical information. Cal. Civ. Code § 56.36(b)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
an individual may bring an action against a person or entity who has negligently released confidential information or records concerning him or her in violation of this part, for either or both of the following: (1) Except as provided in subdivision (e), nominal damages of one thousand dollars ($1,000).
Who it binds, in our words: Any person or entity that violates the CMIA (Civ. Code Part 2.6).
CMIA: damages for unlawful use or disclosure. Cal. Civ. Code § 56.35
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
a patient whose medical information has been used or disclosed in violation of Section 56.10, 56.104, 56.107, or 56.20 or subdivision (a) of Section 56.26 and who has sustained economic loss or personal injury therefrom may recover compensatory damages, punitive damages not to exceed three thousand dollars ($3,000)
Who it binds, in our words: Violations of the listed CMIA sections.
Second check by a separate agent: confirmed.
Must you be told if health data leaks in a breach?
Yes. The breach notice law covers both medical information and health insurance information.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
Both medical and health insurance information are in the definition. SB 446 (2025) set a 30-day deadline from 2026-01-01. HIPAA deeming covers notice content only.
Deadline to tell people: 30 calendar days of discovery or notification of the data breach (subject to listed delays).
The attorney general or a regulator must also be told.
A business that follows HIPAA's breach rules is treated as following this law.
Data breach notification: definition of personal information. Cal. Civ. Code § 1798.82(h)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
(D) Medical information. (E) Health insurance information.
Who it binds, in our words: Persons or businesses that conduct business in California and own or license computerized data with personal information.
Data breach notification: deadline. Cal. Civ. Code § 1798.82(a)(2)(A)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.
Who it binds, in our words: Same as above.
Data breach notification: Attorney General copy. Cal. Civ. Code § 1798.82(f)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
more than 500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General within 15 calendar days of notifying affected consumers
Who it binds, in our words: Breaches affecting more than 500 California residents.
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
covered entity under the federal Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Sec. 1320d et seq.) will be deemed to have complied with the notice requirements in subdivision (d) if it has complied completely with Section 13402(f)
Who it binds, in our words: HIPAA covered entities, as to notice content under subdivision (d).
Second check by a separate agent: confirmed.
Are there rules for AI used in your care?
The three rules we look for: you must be told when AI is used in your care; a licensed clinician decides, not AI alone; you can reach a human, or have a human review the decision. Each counts only if the law names health care or health coverage.
All three rules are in force. You must be told when AI is used in your care. A licensed clinician decides, not AI alone. You can reach a human, or have a human review the decision.
The researcher's note
Written by the research agent for our records, in the rulebook's shorthand. The answer above is the plain version.
AB 3030 gives disclosure and a route to a human for generative AI clinical messages. SB 1120 reserves medical necessity decisions in plan utilization review to licensed clinicians. Insurance Code counterpart not opened.
You must be told when AI is used in your care: in force.
A licensed clinician decides, not AI alone: in force.
You can reach a human, or have a human review the decision: in force.
Related limit on AI (recorded, not counted in the answer): Bus. & Prof. Code § 4999.9(b): title protections “shall be enforceable against a person or entity who develops or deploys a system or device that uses one or more of those terms, letters, or phrases in the advertising or functionality of an artificial intelligence or generative artificial intelligence system” (effective 2026-01-01)
Related limit on AI (recorded, not counted in the answer): Health & Safety Code § 1367.01(k)(2): “the artificial intelligence, algorithm, or other software tool shall not deny, delay, or modify health care services based, in whole or in part, on medical necessity.”
Generative AI patient communications: disclaimer. Cal. Health & Safety Code § 1339.75(a)(1)
In force · effective · quote not yet matched word for word to our stored copy of the page · read October 3, 2026 · source(leginfo.legislature.ca.gov)
A disclaimer that indicates to the patient that the communication was generated by generative artificial intelligence.
Who it binds, in our words: “A health facility, clinic, physician’s office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information”. Does not apply when a licensed or certified provider reads and reviews the communication.
Generative AI patient communications: how to reach a human. Cal. Health & Safety Code § 1339.75(a)(2)
In force · effective · quote not yet matched word for word to our stored copy of the page · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Clear instructions describing how a patient may contact a human health care provider, employee of the health facility, clinic, physician’s office, or office of a group provider, or other appropriate person.
Who it binds, in our words: Same as § 1339.75(a)(1).
Health plan utilization review using AI: medical necessity by licensed clinician. Cal. Health & Safety Code § 1367.01(k)(2)
In force · effective · quote not yet matched word for word to our stored copy of the page · read October 3, 2026 · source(leginfo.legislature.ca.gov)
A determination of medical necessity shall be made only by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues involved in the health care services requested by the provider
Who it binds, in our words: Health care service plans, and entities they work through, that use “an artificial intelligence, algorithm, or other software tool for the purpose of utilization review or utilization management functions”.
AI and health care professional title protections. Cal. Bus. & Prof. Code § 4999.9(b)
In force · effective · quote not yet matched word for word to our stored copy of the page · read October 3, 2026 · source(leginfo.legislature.ca.gov)
shall be enforceable against a person or entity who develops or deploys a system or device that uses one or more of those terms, letters, or phrases in the advertising or functionality of an artificial intelligence or generative artificial intelligence system, program, device, or similar technology.
Who it binds, in our words: Developers and deployers of AI systems using protected health care license terms.
AI clinical decision support: clinician keeps independent judgment (AB 1979). Cal. Bus. & Prof. Code 22758.5(a), as added by Stats. 2026, ch. 854 (AB 1979)
Signed, not yet in force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
shall take reasonable steps to ensure that a licensed health care provider, acting within their scope of practice, retains the ability to exercise independent professional judgment in their care of a patient whenever that care is informed by the output of a clinical decision support system.
Second check by a separate agent: disputed, then settled by a ruling drafted by an agent against the law's text and approved by the authors on October 3, 2026.
Rights in practice: the setting
These public figures describe conditions that can affect whether people are able to use the rights above, such as health insurance and internet at home. They are not scored, not part of any answer, and not a reason for any answer. Each is the latest the source publishes for the state, checked against the publisher (the Census Bureau or the Bureau of Labor Statistics); grouped under the Healthy People 2030 social determinants of health.
Source and period on every row. Figures from DataSpine, each checked against its publisher. Not scored.
Figure
Value
Source and period
People under 65 without health insuranceHealth care access and quality
6.9%
Small Area Health Insurance Estimates, SAHIE 2024 (single-year model estimate)
Households with a computerHealth care access and quality
95.9%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Households with a broadband internet subscriptionHealth care access and quality
91.5%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Households with a smartphone and no other computerHealth care access and quality
7.5%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Median household incomeEconomic stability
$91,905 (2022 dollars)
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Unemployment rateEconomic stability
5.5%
Local Area Unemployment Statistics, December 2025, monthly, seasonally adjusted
Households without a vehicleNeighborhood and built environment
6.9%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
People who speak a language other than English at homeSocial and community context
43.9%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Households of one person aged 65 or overSocial and community context
9.7%
American Community Survey 5-year, ACS 5-year, 2018 to 2022
Not shown: the number of people below the poverty line and the number with a bachelor's degree, which are available only as counts, and counts do not compare across states of different size.
Not shown yet, with no checked state figure: Medicare members who also have Medicaid; Medicaid enrollment; primary care supply; social vulnerability, income and jobs; people in nonmetro counties; social vulnerability, housing and transport; social vulnerability, household and minority themes.
Also recorded: a data broker registry
A fact, not part of any answer above. In force The state offers a way to ask registered data brokers to delete your data.
Delete Act: data broker registration. Cal. Civ. Code § 1798.99.82(a)
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
On or before January 31 following each year in which a business meets the definition of data broker as provided in this title, the business shall register with the California Privacy Protection Agency pursuant to the requirements of this section.
Who it binds, in our words: “a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship” (Civ. Code § 1798.99.80).
In force · effective · read October 3, 2026 · source(leginfo.legislature.ca.gov)
Allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor.
Who it binds, in our words: Registered data brokers.
Another state
This study covers the 50 states and Washington, DC. It does not cover the US territories (Puerto Rico, Guam, the US Virgin Islands, the Northern Mariana Islands and American Samoa).
Built by SuperTruth, which checks whether a record can be trusted before an AI acts on it. About SuperTruth · How we used AI
Health Record Rights Index by SuperTruth. Research by AI agents built on Anthropic's Claude, checked by a second agent and ruled by the authors; how we did it. Research tool, not legal advice. Text CC BY 4.0.