Loading chat...

CA AB713

Bill

Status

Passed

9/25/2020

Primary Sponsor

Kevin Mullin

Click for details

Origin

State Assembly

2019-2020 Session

AI Summary

  • Exempts deidentified medical information from CCPA requirements if deidentified according to federal HIPAA standards (45 CFR 164.514) and derived from patient information regulated by HIPAA, state Confidentiality of Medical Information Act, or Common Rule research regulations.

  • Exempts business associates of covered entities governed by federal privacy and security rules (45 CFR Parts 160 and 164) when they maintain, use, and disclose patient information in compliance with HIPAA requirements.

  • Prohibits reidentification of deidentified information except for treatment, payment, health care operations, public health activities, approved research, deidentification testing with contractual restrictions, or when required by law.

  • Requires contracts for sale or license of deidentified patient information (effective January 1, 2021) to include statements that the information is deidentified patient data, prohibit reidentification, and restrict further disclosure to bound third parties.

  • Requires businesses selling deidentified patient information to disclose in privacy policies whether they sell such information and which HIPAA deidentification methods were used (expert determination or safe harbor method).

Legislative Description

California Consumer Privacy Act of 2018.

Last Action

Chaptered by Secretary of State - Chapter 172, Statutes of 2020.

9/25/2020

Committee Referrals

Appropriations7/30/2020
Judiciary1/9/2020
Rules1/8/2020
Health6/6/2019
Rules5/29/2019
Appropriations4/1/2019
Health2/28/2019

Full Bill Text

No bill text available