Report a HIPAA Violation in California
How to report a HIPAA violation in California: the federal HHS OCR process, whether California law lets you sue directly, and where state complaints go.
California lets you sue a health care provider directly for a careless disclosure, something federal HIPAA never allows anywhere in the country. Federal HIPAA sets the same complaint process nationwide, and California law adds its own rules on top of that floor.
California HIPAA Rules at a Glance
Federal HIPAA sets a single national floor, and California law sits on top of it rather than replacing it. Filing an HHS OCR complaint works the same in California as it does in every other state. What changes locally is whether California's own statute gives you a path federal law does not, and the table below lines up the two side by side.
| What | California rule | Federal HIPAA rule |
|---|---|---|
| Governing law | Confidentiality of Medical Information Act (CMIA), Civil Code Section 56.36 | HIPAA Privacy & Security Rules |
| Who enforces it | You, in court, plus the California Attorney General | HHS Office for Civil Rights (OCR) |
| Can you sue directly? | Yes. $1,000 nominal damages with no proof of harm required, plus actual damages, attorney fees and costs | No private right of action under federal HIPAA anywhere |
| Complaint filing deadline | Disputed in California case law between a 1-year and a 2-year limitations period; confirm the current rule with an attorney before relying on either | 180 days from discovery (extensions for good cause) |
Does California Give You More Than Federal HIPAA?
Federal HIPAA has no private right of action anywhere in the United States. A patient who believes a hospital mishandled their file cannot sue under HIPAA itself in any state, full stop. What varies is whether the state where it happened gives the patient a separate law that does allow a lawsuit, and California is one of the strongest examples of a state that does.
The CMIA lets a patient sue a health care provider, health plan, or contractor that negligently releases medical information without authorization. Section 56.36 sets nominal statutory damages of $1,000 per violation, and the patient does not have to prove the disclosure actually caused harm to collect that amount. Actual damages, attorney fees, and costs are recoverable on top of the nominal figure where the patient can show them.
That combination changes the practical calculation for a California patient. Under HIPAA alone, a mishandled record with no provable financial loss usually goes nowhere except an OCR complaint that results in a corrective action plan for the provider and nothing for the patient. Under the CMIA, the same disclosure can support a lawsuit even without a dollar of proven harm, because the statute treats the unauthorized release itself as the injury.
The CMIA reaches further than most people expect. It covers licensed providers and health plans the same way HIPAA does, but California courts have also applied it to contractors and, increasingly, consumer health apps and portals that store identifiable medical information outside a traditional clinical setting. Whether a patient must show someone actually viewed the exposed data to bring a CMIA breach claim is an actively contested question in California courts, with appellate decisions split on the point. That split matters for how strong a given breach case is, so confirm the current state of the law with a privacy attorney before assuming either reading applies to your facts.
The $1,000-with-no-harm rule has a real limit, and it catches people off guard. Section 56.36 gives a defendant an affirmative defense when the release was between two covered entities or business associates and the defendant met its notification obligations to the people entitled to notice. In plain terms, a routine, properly-handled transfer of your records between your doctor and your insurer is not the fact pattern this statute was built to punish, even though it technically moved your information without a fresh authorization. The strong case is the one where your information left the circle of covered entities, or where a provider skipped the notice it owed you. Confirm the current scope of the defense with an attorney before assuming a given transfer qualifies.
How to Report a HIPAA Violation in California
Start with the federal complaint regardless of whether you also plan to sue. Filing with HHS OCR does not cost anything, does not require a lawyer, and preserves the option to point to OCR's findings later. The main HIPAA violation guide walks through the OCR Complaint Portal step by step, and the 180-day federal filing window applies in California exactly as it does everywhere else.
A CMIA lawsuit is separate from that OCR complaint and runs on its own clock. Because it is a civil claim for damages rather than a regulatory complaint, it needs a formal filing in California superior court, which in practice means bringing in a plaintiff's attorney who handles medical privacy cases before the limitations period runs. Many privacy attorneys take these cases on contingency given the fee-shifting provision in Section 56.36, so an initial consultation is typically free.
You can also report a licensed provider to the relevant California licensing board, the Medical Board of California for physicians or the Department of Managed Health Care for health plans, alongside the OCR complaint. That will not get you money, but it creates an official record of the incident that a later lawsuit can cite.
Can You Sue for a HIPAA Violation in California?
Yes, and this is the single biggest difference between California and states with no equivalent statute. A CMIA claim needs three things: a health care provider or contractor covered by the Act, a negligent release of your individually identifiable medical information, and the absence of your authorization for that release. Intent to harm is not required. A billing clerk who emails your chart to the wrong address by mistake can still trigger CMIA liability if the disclosure was negligent.
Picture a common version of this. A clinic's front desk faxes a patient's lab results to the wrong physician's office because two providers share a similar name in the referral directory. No identity theft happens, no employer finds out, and the wrong recipient deletes the fax unread. Under HIPAA alone, that pattern usually ends with the clinic filing a breach notice and tightening its fax procedures. Under the CMIA, the same fax is a completed negligent disclosure the patient can sue over for the $1,000 nominal figure, because the statute does not ask what happened to the record after it left the clinic's hands, only whether the release itself was negligent and unauthorized.
Confirm the current statutory figure before relying on it. Damages amounts in privacy statutes are adjusted by the legislature and interpreted by courts over time, and the $1,000 nominal-damages figure above reflects the law as verified in August 2026. An attorney handling your specific claim will confirm the number that applies to your filing date.
Frequently Asked Questions
Can I sue a hospital for a HIPAA violation in California?
Not under HIPAA itself, since no state lets you sue directly under federal HIPAA. In California you can instead sue under the state's own Confidentiality of Medical Information Act (CMIA), which allows a lawsuit against a health care provider for a negligent, unauthorized disclosure of your medical information.
Do I need to prove I was harmed to win a CMIA case?
No. The CMIA sets nominal statutory damages of $1,000 per violation that do not require proof of actual harm, on top of any actual damages you can separately document.
Should I file an HHS OCR complaint if I'm also considering a CMIA lawsuit in California?
Both, generally. The OCR complaint is free, does not require a lawyer, and can produce findings useful to a later lawsuit. A CMIA claim is a separate civil filing in California court and is the route that can actually put money in your hands.
Does the CMIA cover health apps and not just hospitals?
Often, yes. California courts have extended CMIA liability beyond licensed providers to contractors and, increasingly, consumer health apps and portals that store identifiable medical information, which is broader reach than HIPAA gives you against the same kind of company.
Is there any situation where a California provider is protected from a CMIA claim?
Yes. Section 56.36 gives providers an affirmative defense when a disclosure moved strictly between covered entities or business associates and the required notice obligations were met. A transfer that stayed inside proper provider-to-provider channels is a weaker CMIA case than one where your information left that circle.
Not sure where you stand?
Check your eligibility in under 2 minutes — free, private, and no commitment required.