Q: What's the difference between HIPAA and CMIA?

A: HIPAA is the federal privacy floor: it binds providers and insurers, limits disclosures, and gives you the right to see your records. California's CMIA (Confidentiality of Medical Information Act) sits on top and is stricter in useful ways: it allows individuals to sue for violations directly (HIPAA doesn't), and since 2023 it explicitly covers mental health apps — companies offering digital mental health services are held to medical-confidentiality standards, not just terms-of-service promises.¹

Worked example: a clinic faxes your records to the wrong office. Under HIPAA you can file a federal complaint; under CMIA you can also personally sue for the violation — real teeth, in your hands.

Do this: to see your own records, just ask your therapist — you're entitled to access, with narrow clinical exceptions. For platform privacy questions, what happens to app data →.

Source: 1. Civil Code §56 et seq.; AB 254 (2023) — leginfo.legislature.ca.gov; HIPAA, 45 CFR Parts 160–164.

In crisis? Call or text 988 — free, 24/7.