Under the CCPA, a for-profit hospital group runs HIPAA-covered clinics and a public marketing website — which of its data do the health exemptions take out of scope?
answer
- data-level, not entity-level
- 'to the extent' is the key phrase
- PHI and CMIA medical information
- deidentified data has conditions
- GLBA works the same way
basics
~20 sOnly health data: under Civil Code 1798.145(c) and 1798.146, PHI, CMIA medical information and patient information handled the same way are exempt; public-site analytics not tied to patients, marketing lists and HR data stay in scope.
solid answer
~40 sThe CCPA's health exemptions work on **data**, not on the organisation. Civil Code `1798.146(a)` removes medical information governed by the CMIA and protected health information collected by a HIPAA covered entity or business associate, and exempts a covered entity or health-care provider only **to the extent** it maintains, uses and discloses patient information in the same manner as PHI or medical information. So the group's clinical records and billing handled under HIPAA are out; public-website analytics not tied to patient records, prospect marketing lists and HR data (the employee exemption ended on 2023-01-01) are in, provided the group is a CCPA business at all. HIPAA-deidentified patient data is exempt under `1798.146(a)(4)` until it is reidentified. The Gramm-Leach-Bliley exemption in `1798.145(e)` follows the same data-level logic for financial data.
go deeper
Recall that the CCPA exempts health information governed by HIPAA or California's CMIA, and that the exemption covers that data, not everything a hospital holds.
Explain 'to the extent': a covered entity is outside the CCPA only for patient information it maintains, uses and discloses the way it handles PHI or medical information.
Map a mixed estate: clinical and billing records out, marketing analytics and HR in, deidentified derivatives exempt only while the reidentification ban and contract terms hold.
Decide whether to run one privacy programme across HIPAA and CCPA data or two, weighing the cost of tagging every store by regime against the risk of misclassifying it.
## Two different questions Under the CCPA as amended by the CPRA, scoping has two layers. The **entity** question asks whether an organisation is a business under Civil Code `1798.140(d)`. The **data** question asks whether a particular body of personal information is carved out by an exemption in `1798.145` or `1798.146`. A for-profit hospital group that meets a threshold is a business; the exemptions then remove specific data, not the group. A non-profit hospital system would usually fail the first question instead: the business definition requires an entity organised or operated for its owners' profit or financial benefit. ## What the health exemptions remove Civil Code `1798.146(a)` (`1798.145(c)` carries parallel text for medical information, PHI, providers and research) says the title does not apply to: 1. **Medical information** governed by California's Confidentiality of Medical Information Act (CMIA), and **protected health information (PHI)** collected by a covered entity or business associate governed by the HIPAA privacy, security and breach notification rules in 45 CFR Parts 160 and 164. 2. A **provider of health care** governed by the CMIA, or a **HIPAA covered entity**, **to the extent** it maintains, uses and discloses patient information in the same manner as medical information or PHI. 3. A **business associate** of a covered entity, to the same extent. 4. Information **deidentified under 45 CFR 164.514** and derived from patient information originally held by an entity regulated by HIPAA, the CMIA or the Common Rule. 5. Information collected, used or disclosed in **research** conducted under the applicable HIPAA, Common Rule, ICH good clinical practice or FDA human-subject rules. The definitions of covered entity, business associate and PHI are borrowed from 45 CFR 160.103; 'medical information' and 'provider of health care' from Civil Code 56.05. ## What stays in scope for the hospital group | Data | Why | Under the CCPA | |---|---|---| | Patients' clinical records | PHI collected by a covered entity | Exempt | | Patient billing and scheduling handled under HIPAA | Patient information maintained like PHI | Exempt | | Public-website analytics and ad-pixel data not tied to patient records | Neither PHI, medical information nor handled as patient information | In scope | | Newsletter list of prospective patients | Personal information outside the patient-record system | In scope | | Job applicants' and employees' HR data | The employee exemption became inoperative on 2023-01-01 | In scope | The phrase **'to the extent'** is what an interviewer is listening for. The group is not exempt as an organisation; it is exempt for what it handles as PHI or medical information. ## Deidentified patient data has conditions - Information deidentified under HIPAA's standard and derived from patient information is exempt under `1798.146(a)(4)`. - If it is **reidentified**, it loses the exemption and becomes subject to HIPAA, the CMIA and the CCPA. - `1798.148(a)` prohibits reidentifying it except for listed purposes: treatment, payment or health care operations by or for a covered entity, public health, qualifying research, contracted testing of deidentification methods, or where law requires. - `1798.148(c)` requires any contract to sell or license such data, where a party resides or does business in California, to state that it contains deidentified patient information, to prohibit reidentification, and to bar onward disclosure to anyone not bound by the same or stricter terms. ## The financial-sector parallel The same data-level logic applies to the **Gramm-Leach-Bliley Act** exemption in `1798.145(e)`: the title does not apply to personal information collected, processed, sold or disclosed subject to that Act and its regulations, the California Financial Information Privacy Act, or the Farm Credit Act. A bank's customer-account data handled under those laws is out; its marketing-site analytics is not. Unlike the health exemptions, `1798.145(e)` states that it **does not apply to Section 1798.150**, the breach private right of action, and the Fair Credit Reporting Act exemption in `1798.145(d)` carries the same carve-back. ## The engineering consequence A data inventory for a mixed organisation must tag data by **regime**, not by department: which stores hold PHI or medical information, which hold patient information handled like PHI, which hold deidentified derivatives (with the contract terms that keep them exempt), and which hold everything else. Only the last bucket carries CCPA duties, and in a hospital group it is rarely empty: marketing, recruiting and the public website all feed it.
- The hospital group licenses HIPAA-deidentified patient data to a research firm. What must the contract say under the CCPA?Civil Code 1798.148(c) requires, where a party resides or does business in California, a statement that the data includes deidentified patient information, a statement that reidentification and attempted reidentification by the licensee is prohibited, and a bar on further disclosure to any third party not bound by the same or stricter restrictions.
- Does the GLBA exemption keep a bank's customer data out of the CCPA's breach private right of action too?No. Civil Code 1798.145(e) exempts personal information handled subject to the Gramm-Leach-Bliley Act, but its last sentence says the subdivision does not apply to Section 1798.150. The Fair Credit Reporting Act exemption in 1798.145(d) has the same carve-back, so both kinds of data stay within the breach provision.
saying these in an interview costs you the question
- Says a HIPAA covered entity is exempt from the CCPA as an organisation
- Treats hospital website analytics as exempt because a hospital owns the site
- Believes deidentified patient data stays exempt after it is reidentified
- Thinks the GLBA exemption covers every record a bank holds
- Assumes hospital HR data is exempt under a still-running employee carve-out