SubscribePrint Email

Publication

Client Alert—California’s Data Breach Notification Law Now Covers Medical and Health Insurance Information

14-Jan-2008

by Edgar D. Bueno, John L. Nicholson, Melissa M. Starry


Going well beyond the requirements of HIPAA and most state health privacy laws, California has amended its existing Database Security Breach Notification Act to require any organization that reasonably believes a breach of a California resident’s medical or health insurance information has occurred, to notify that resident. Any entity that that owns, licenses, or possesses unencrypted data containing the personal health information of any California resident should be aware of this new requirement and its potentially broad application, since those subject to this law could be anywhere in the United States.