Healthcare
Medical information: confidentiality
California requires certain businesses handling sensitive reproductive and gender-affirming care records to activate stronger privacy controls.
The law seeks to limit unauthorized and out-of-state access to medical information about abortion, contraception, and gender-affirming care. It makes required security measures enforceable under the Confidentiality of Medical Information Act.
What the law does
- Requires covered businesses to limit access to sensitive-service records to authorized users.
- Requires covered businesses to block disclosures, access, transfers, transmissions, and processing outside California when required by state confidentiality law.
- Requires covered businesses to segregate records involving gender-affirming care, abortion and related services, and contraception from other patient records.
- Requires covered businesses to be able to automatically disable another state's individuals and entities from accessing segregated records.
- Requires these capabilities, policies, and procedures to be developed and enabled by July 1, 2024.
Who it affects
- Businesses that electronically store or maintain sensitive-service medical information for health providers, health plans, pharmaceutical companies, contractors, or employers.
- Patients receiving gender-affirming care, abortion or abortion-related services, or contraception.
- Authorized users of electronic health and medical record systems.
Context
The requirements do not apply directly to providers, health care service plans, or contractors as defined in the CMIA.