TwinEthosRequest access

Law

California CMIA (Civ. Code 56 et seq.)

California Legislature · California (US-CA) · 1 provision encoded · verified against the official source as of 2026-09-28.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: leginfo.legislature.ca.gov.

Binding law — in force

Medical information goes to an AI vendor only with authorization or a CMIA basis, and not for uses beyond care (California)

Cal. Civ. Code 56.10(a) · official text · In force: applies since 20 Sep 2025 · California (US-CA)

California Civil Code 56.10(a) bars a health care provider, health care service plan, or contractor from disclosing a patient's medical information without the patient's authorization unless 56.10(b) or (c) applies; 56.10(c)(3) permits disclosure to a person or entity providing billing, claims management, medical data processing, or other administrative services for the provider or plan, and bars that recipient from further disclosing it in violation of the Act. 56.10(d) bars sharing, selling, using for marketing, or otherwise using medical information for a purpose not necessary to provide health care services, absent express authorization. 56.06 treats businesses offering consumer health software or apps, and mental health digital services, as providers under the Act. Detect medical information sent to a model vendor with no evidence of an authorization or covered processing arrangement, and medical information fed into AI-generated marketing.

Who it applies to

  • Duty falls on: deployer, processor
  • Sectors: healthcare, insurance
  • California providers of health care, health care service plans, and contractors, and businesses deemed providers under 56.06 (consumer software or apps that maintain medical information for management, diagnosis, or treatment; mental health digital services). Whether an AI model vendor's service is 'medical data processing, or other administrative services' under 56.10(c)(3), and whether vendor training use is a further disclosure or a use beyond health care under 56.10(d), are legal determinations. Current text of 56.10 in force since 2025-09-20 (Stats. 2025, ch. 123); 56.06 as amended effective 2024-01-01.
  • Not covered:
    • Disclosure with the patient's authorization (56.10(a))
    • Disclosures compelled under 56.10(b) or permitted under 56.10(c), such as to a person or entity providing medical data processing or other administrative services for the provider or plan (56.10(c)(3))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

A single client factory for model, embedding and transcription calls that handle health information: it looks the endpoint up in a vendor register and refuses to return a client unless the register shows the required contract (business associate agreement, or a processing agreement barring further disclosure) and the endpoint is the covered deployment with data retention and training use turned off. Call sites that cannot meet that de-identify or redact the record before building the prompt, or check a recorded patient authorization for that use. Keep the vendor register in the repository so reviewers can match each AI endpoint to its legal basis, and never route health data into marketing or other non-care generation.

Where it goes: 6 API calls and integrations, 3 config and feature flags, 7 prompt construction, 12 repository artifacts.

What this provision adds:

  • Without patient authorization, the vendor arrangement must be for billing, claims management, medical data processing or other administrative services, and bar the vendor from further disclosing the information.
  • Do not use medical information in AI-generated marketing, or for any purpose not necessary to provide health care services, without the patient's express authorization.
  • Treat consumer health software or apps that maintain medical information, and mental health digital services, as providers for this guard.

Example (Python + OpenAI SDK (Azure OpenAI)), before:

client = OpenAI()
resp = client.chat.completions.create(model='gpt-4o', messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

After:

VENDORS = load_yaml('vendors/ai_vendors.yaml')   # baa_signed, zero_data_retention per endpoint

def phi_client(name: str) -> tuple[AzureOpenAI, str]:
    v = VENDORS[name]
    if not (v['baa_signed'] and v['zero_data_retention']):
        raise PermissionError(f'{name} is not cleared for PHI')
    client = AzureOpenAI(azure_endpoint=v['endpoint'], api_key=os.environ['AZURE_OPENAI_KEY'],
                         api_version=v['api_version'])
    return client, v['deployment']

client, deployment = phi_client('azure-openai-hipaa')
resp = client.chat.completions.create(model=deployment, messages=[
    {'role': 'user', 'content': f'Summarize: {patient.clinical_note}'}])

Control: Health information sent to an external AI vendor without the contractual or legal basis the law requires. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id ca-cmia.medical-information-to-ai-vendor · review status: primary source derived