Legis
Healthcare
AB 2448, Chapter 607, Statutes of 2026 · Sunday 27 September 2026

Medical information: confidentiality

California requires certain businesses handling sensitive reproductive and gender-affirming care records to activate stronger privacy controls.

The law seeks to limit unauthorized and out-of-state access to medical information about abortion, contraception, and gender-affirming care. It makes required security measures enforceable under the Confidentiality of Medical Information Act.

What the law does ​

  • Requires covered businesses to limit access to sensitive-service records to authorized users.
  • Requires covered businesses to block disclosures, access, transfers, transmissions, and processing outside California when required by state confidentiality law.
  • Requires covered businesses to segregate records involving gender-affirming care, abortion and related services, and contraception from other patient records.
  • Requires covered businesses to be able to automatically disable another state's individuals and entities from accessing segregated records.
  • Requires these capabilities, policies, and procedures to be developed and enabled by July 1, 2024.

Who it affects ​

  • Businesses that electronically store or maintain sensitive-service medical information for health providers, health plans, pharmaceutical companies, contractors, or employers.
  • Patients receiving gender-affirming care, abortion or abortion-related services, or contraception.
  • Authorized users of electronic health and medical record systems.

Context ​

The requirements do not apply directly to providers, health care service plans, or contractors as defined in the CMIA.