CMIA requirements
The CMIA is California's medical privacy statute and reaches further than HIPAA in two ways that matter for tracking technologies. It applies to providers, health plans, and any business that offers software or hardware to consumers to maintain medical information, which captures health apps and websites that HIPAA does not. And it carries a private right of action with $1,000 in nominal damages per violation, without proof of actual harm, plus actual damages. Plaintiffs have paired CMIA claims with CIPA and federal wiretap claims in suits against health systems and digital health companies over Meta Pixel and similar tags on appointment, symptom, and condition pages. The statute asks whether medical information was negligently released; a tag that sent a page URL containing a condition name to an advertising platform is the usual answer.
Other Federal & Sector Laws
See what your sites and apps actually send
Get a free site analysis: every tracker, mapped to the laws that apply to it.