Privacy, Medical Information, Persons Regulated by Confidentiality of Medical Information Act, Civ. Code 56, 1, 7

The Confidentiality of Medical Information Act (Civ. Code 56) broadly defines the persons subject to its requirements as including not only providers of medical services any business organized to maintain medical information for use by medical service providers or patients.  This case holds that a business which maintained records on special needs children for schools was governed by the CMIA and that plaintiff alleged a viable claim against it for violating the CMIA by waiting 5 months before notifying him of a data breach involving his medical information.  The decision also holds that the plaintiff stated a viable claim against the defendant for violating the Customer Records Act (Civ. Code 1798.82) by the same delay in disclosing the data breach.