PogoWasRight.org

Menu
  • About
  • Privacy
Menu

California’s landmark privacy law will have ‘subtle’ effect on hospitals

Posted on December 14, 2019 by pogowasright.org

Jessica Kim Cohen reports that CCPA’s impact on hospitals is not totally clear at this point, and some hospitals will be exempt because they are not-for-profit.  Here’s a snippet from her report:

Only large, investor-owned hospitals will fall under its purview, according to Lois Richardson, the California Hospital Association’s vice president and legal counsel.

But here’s the part that I see as really tricky/complex to sort out:

The law also includes carve-outs for healthcare data and won’t change patient privacy protections. The CCPA doesn’t apply to protected health information collected by organizations covered by existing privacy laws, such as HIPAA and California’s Confidentiality of Medical Information Act.

The exemptions also mean that it wouldn’t apply to data sharing that’s performed as part of business associate agreements between health systems and other companies, including tech giants like Google. The law was designed to target companies whose “business model is to collect and sell consumer information” rather than healthcare organizations, according to Richardson.

But for-profit health systems aren’t off the hook. It may require litigation to clarify the boundary between “data that’s considered health information, and data that’s considered personal information, but not health information,” Marks said.

Read more on Modern Healthcare.

I can see where I will need to attend at least a few more — and probably many more — seminars or workshops on CCPA.

Category: BreachesHealthcareLawsU.S.

Post navigation

← Update from LitLand: The ACLU Sues the Government Over the Use of Facial Recognition Technology
Facebook Won’t Change Web Tracking in Response to California Privacy Law →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others

RSS Recent Posts on DataBreaches.net

  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
©2025 PogoWasRight.org. All rights reserved.