2.1 HIPAA Privacy Rule and California Confidentiality of Medical Information Act (CMIA)

Key Takeaways

  • While HIPAA establishes a baseline federal standard for protecting health information, California's Confidentiality of Medical Information Act (CMIA) provides stricter privacy protections, including an individual private right of action and statutory nominal damages.
  • In dental hygiene practice, protected medical information extends beyond written medical histories to clinical oral identifiers, including periodontal charts, intraoral photographs, diagnostic radiographs, and study models.
  • California law mandates disclosure in specific circumstances—such as reporting suspected child, elder, or dependent adult abuse—while routine disclosures without patient consent are restricted to Treatment, Payment, and Healthcare Operations (TPO) under the minimum necessary rule.
Last updated: September 2026

2.1 HIPAA Privacy Rule and California Confidentiality of Medical Information Act (CMIA)

The legal and ethical practice of dental hygiene requires rigorous adherence to patient privacy and confidentiality standards. In California, dental professionals operate under a dual regulatory framework comprising federal mandates established by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and state statutes codified in the California Confidentiality of Medical Information Act (CMIA, California Civil Code §§ 56 et seq.). Understanding the intersection of these laws is essential for California Registered Dental Hygienists (RDHs), as state law frequently establishes stricter requirements than federal guidelines.

Federal vs. California Privacy Framework

Federal privacy regulations stem from HIPAA's Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) and Security Rule (45 CFR Part 164, Subpart C). These federal rules set a baseline national standard for protecting individuals' medical records and personal health information. HIPAA applies to "covered entities"—which include dental practices that transmit health information electronically in connection with covered transactions (such as electronic billing)—as well as their business associates.

In contrast, California enacted the Confidentiality of Medical Information Act (CMIA) to provide comprehensive privacy protections specifically tailored to individuals within the state. The CMIA applies broadly to healthcare providers licensed under Division 2 of the Business and Professions Code (including dental hygienists and dentists), healthcare service plans, contractors, and employers. While HIPAA focuses on covered entities engaging in specific electronic transactions, the CMIA protects patient confidentiality across all California healthcare providers regardless of billing methods or practice structure.

Federal Preemption and the "Stricter State Law" Principle

A foundational doctrine in jurisprudence is federal preemption, derived from the Supremacy Clause of the United States Constitution. Under general preemption principles, federal law supersedes contrary state law. However, HIPAA contains an explicit statutory non-preemption exception (45 CFR § 160.203): HIPAA rules do not preempt state health privacy laws that are "more stringent" than federal standards. A state law is considered more stringent if it provides greater privacy protection, grants broader rights of access to individuals, or imposes more restrictive conditions on disclosures.

Because California's CMIA affords patients significantly greater rights and remedies than HIPAA, California dental hygienists must adhere to the stricter state provisions:

  1. Private Right of Action: Federal HIPAA does not grant individual citizens a private right of action. An individual whose privacy is violated under HIPAA cannot file a personal lawsuit in federal court; they may only submit an administrative complaint to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). In sharp contrast, California Civil Code § 56.35 establishes an explicit private right of action permitting patients to sue negligent or willful violators directly in California state courts.
  2. Statutory Nominal Damages: Under California Civil Code § 56.36(b), an individual whose confidential medical information has been negligently disclosed may recover $1,000 in statutory nominal damages per violation without needing to prove actual financial injury or emotional distress.
  3. Broader Definitions and Stricter Oversight: CMIA covers an expansive range of health-related data and enforces strict administrative penalties through state regulatory bodies, including the California Department of Public Health (CDPH).

Protected Health Information (PHI) and Medical Information

Under HIPAA, Protected Health Information (PHI) encompasses individually identifiable health information held or transmitted by a covered entity in any medium (electronic, paper, or oral). Under CMIA (Civil Code § 56.05(j)), "medical information" means any individually identifiable information in possession of or derived from a provider of healthcare regarding a patient's medical history, mental or physical condition, or treatment.

In dental hygiene clinical practice, protected oral health data includes:

  • Periodontal Charting Records: Probing depths, clinical attachment levels, bleeding on probing scores, furcation involvements, and mobility classifications.
  • Diagnostic Radiographs and Digital Imaging: Periapical films, bitewing surveys, panoramic images, cephalometric radiographs, and cone-beam computed tomography (CBCT) scans.
  • Intraoral and Extraoral Photographic Records: Full-face cosmetic images, retracted intraoral views, and progressive treatment photographs.
  • Study Models and 3D Scans: Physical gypsum dental casts, orthodontic diagnostic models, and digitized intraoral optical impression scans.
  • Clinical Progress Notes: Odontograms, charting notes, systemic medical assessments, and appointment schedules linking a patient's identity with treatment details.

Authorized Disclosures Without Patient Authorization

Both HIPAA and the CMIA permit healthcare licensees to disclose confidential patient information without prior written authorization in carefully delineated circumstances:

  • Treatment, Payment, and Healthcare Operations (TPO): Information may be shared among treating clinicians (such as consulting periodontists or general dentists), submitted to dental insurers for claims adjudication, or used internally for quality assurance and clinical peer reviews.
  • Mandatory Public Health Reporting: Reporting specific communicable diseases to local county public health officers or the California Department of Public Health.
  • Judicial Subpoenas and Court Orders: Responding to valid subpoenas duces tecum, court orders, or search warrants, provided statutory notice procedures are satisfied.
  • Law Enforcement Exceptions: Releasing information under specific statutory conditions, such as assisting in the identification of a deceased individual or responding to a court order.
  • Mandated Abuse Reporting: California law places mandatory reporting obligations on dental hygienists that override patient confidentiality. Under the Child Abuse and Neglect Reporting Act (CANRA, California Penal Code §§ 11164–11174.3) and the Elder Abuse and Dependent Adult Civil Protection Act (California Welfare and Institutions Code §§ 15600–15675), dental hygienists are legally mandated reporters. Suspected child abuse, elder abuse, or dependent adult abuse must be reported immediately by telephone to protective authorities, followed by a formal written report within 36 hours (for CANRA) or two working days (for elder abuse). Licensees reporting in good faith are granted statutory immunity from civil or criminal liability.

The Minimum Necessary Standard in Dental Hygiene Operations

The HIPAA Privacy Rule and CMIA require licensees to implement the "minimum necessary" standard, disclosing or accessing only the minimum amount of health data required to accomplish the intended clinical or administrative objective.

In daily dental hygiene practice, compliance demands:

  • Operatory Verbal Privacy: Dental hygienists must avoid announcing sensitive health details across operatories. Discussing medical histories or premedication requirements in open hallways violates confidentiality.
  • Acoustic Privacy in Open-Bay Settings: In pediatric, periodontal, or educational clinics featuring open operatories, clinicians must speak in lowered voices and conduct sensitive medical dialogues in private consultation alcoves.
  • Reception and Check-In Safeguards: Patient sign-in sheets must never display clinical reasons for visit or medical conditions. Display screens at the reception counter and operatory terminals must be angled away from public walkways or fitted with polarized privacy filters.

Penalties for Privacy Breaches

Violations of California privacy laws carry substantial administrative, civil, and professional consequences. Under California Civil Code § 56.36, administrative fines enforced by the state include:

  • Up to $2,500 per violation for negligent maintenance or disclosure of medical information.
  • Up to $25,000 per violation for knowingly and willfully obtaining or disclosing medical information without authorization.
  • Up to $250,000 per violation if the unauthorized disclosure was committed for financial gain or commercial advantage, along with disgorgement of profits.

In addition, injured individuals may pursue civil claims under Civil Code § 56.35 for compensatory damages, $1,000 nominal statutory damages, and punitive damages up to $3,000. Furthermore, unlawful disclosures constitute unprofessional conduct under California Business and Professions Code § 1950.5, exposing the dental hygienist to formal disciplinary action, license probation, suspension, or revocation by the Dental Hygiene Board of California (DHBC).

Regulatory DimensionHIPAA (Federal: 45 CFR Parts 160 & 164)CMIA (California: Civil Code §§ 56 et seq.)
Enforcement BodyHHS Office for Civil Rights (OCR)CDPH, California Attorney General, Civil Courts
Private Right of ActionNone (individuals cannot sue under federal statute)Yes (explicit private right under Civil Code § 56.35)
Statutory Nominal DamagesNone (penalties collected by federal government)$1,000 nominal damages per violation without proving injury
Scope of Covered EntitiesCovered entities transmitting electronic data & business associatesAll licensed healthcare providers, facilities, employers, contractors
Preemption StatusSets baseline; yields to stricter state enactmentsControls in California due to greater privacy protections
Test Your Knowledge

When comparing the federal Health Insurance Portability and Accountability Act (HIPAA) to the California Confidentiality of Medical Information Act (CMIA), which principle dictates how California registered dental hygienists must resolve discrepancies between the two laws?

A
B
C
D
Test Your Knowledge

A registered dental hygienist working in an open-bay periodontal practice needs to update a patient's medical history and discuss active periodontal disease. Which practice demonstrates compliance with the minimum necessary standard and patient confidentiality rules?

A
B
C
D
Test Your Knowledge

Under the California Confidentiality of Medical Information Act (CMIA, Civil Code §§ 56 et seq.), what is the statutory nominal damages amount an individual patient may recover for an unauthorized disclosure of medical information without proving actual financial injury?

A
B
C
D