CCPA Amendment Passes, Creating New HIPAA-related Exceptions

ccpa amendment
Print Friendly, PDF & Email

On September 25, 2020, California Governor Gavin Newsom signed AB 713 (the “Amendment”) into law, amending the California Consumer Privacy Act (“CCPA”) to implement exceptions related to consumer health data. Specifically, the CCPA amendment addresses inconsistencies between data protection afforded under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the CCPA, respectively. The Amendment took effect on September 30, 2020. 

What does the CCPA Amendment cover?

Analyzing the CCPA Amendment

The latest CCPA amendment helps align the CCPA with HIPAA so that the health care and life science industries do not remain uncertain as to their respective compliance obligations. Here are some of the key Amendment provisions:

  • Prior to the Amendment, it was possible for de-identified data under HIPAA to still be considered “personal information” under the CCPA. Under the CCPA, the definition of “Personal Information” excludes “consumer information that is de-identified.” With enactment of the Amendment, the CCPA will, effectively, defer to the de-identification standard contained in HIPAA, as long as: 1) the applicable information was originally collected by an entity subject to HIPAA, the California Confidentiality of Medical Information Act (“CMIA”), or the Federal Policy for the Protection of Human Subjects; and 2) the information at issue has not been subsequently re-identified;
  • Businesses regulated by the CCPA are prohibited from re-identifying de-identified information, except for one of the following purposes: 1) treatment, payment, or health care operations conducted by a HIPAA regulated entity; 2) public health activities or purposes described under HIPAA; 3) research; 4) pursuant to a contract in order to conduct testing, analysis, or validation of de-identification, or related statistical techniques; or 5) as required by law;
  • Effective January 1, 2021, businesses selling or licensing personal health information must include the following provisions in their contracts: 1) a statement that the de-identified information that is being sold or licensed contains de-identified patient information; 2) a statement that the purchaser or licensee of the information cannot re-identify, or attempt to re-identify, the de-identified information; and 3) that the purchaser or licensee cannot share the de-identified information with any third party unless the third party is bound by the same restrictions contained in the contract; and
  • CCPA privacy policies must be updated by businesses that sell or share information that was de-identified to disclose to their consumers the method by which the information was de-identified.

CCPA Compliance

Readers of this blog know that we have been monitoring CCPA implementation and providing necessary compliance updates. Amendments like this one, and future enforcement actions brought by the California Attorney General’s Office, will help provide regulatory compliance clarity to the marketing industry. By now, businesses should already be CCPA compliant. If they are not, companies should be working diligently to get complaint as soon as possible. 

If you need assistance with CCPA compliance, please email us at info@kleinmoynihan.com, or call us at (212) 246-0900.

The material contained herein is provided for informational purposes only and is not legal advice, nor is it a substitute for obtaining legal advice from an attorney. Each situation is unique, and you should not act or rely on any information contained herein without seeking the advice of an experienced attorney.

Attorney Advertising

Photo by National Cancer Institute on Unsplash

Related Blog Posts:

CCPA 2.0 on California’s November Ballot

Final CCPA Regulations Released

CCPA Forms: The Right to Opt-Out, Request to Know and Request to Delete

David O. Klein

David O. Klein

David Klein is one of the most recognized attorneys in the telemarketing, technology, Internet marketing, sweepstakes and telecommunications fields. Skilled at counseling clients on a broad range of technology-related matters, David Klein has substantial experience in negotiating and drafting complex licensing, marketing and Internet agreements.

Schedule a Call
In The Know

Trending Topics

New York Sweepstakes Law blog- Klein Moynihan Turco

New York Sweepstakes Law: Are You Compliant?

Print Friendly, PDF & Email

In general, a lottery exists when entrants pay for the chance to win a prize. States alone reserve the right to administer lotteries. Businesses can eliminate one element of what would otherwise be an illegal lottery, in order to transform it into a legal promotional game. If the requirement to

TCPA surveys

An Ad or not an Ad: NY Weighs in on TCPA Surveys

Print Friendly, PDF & Email

Another day, another court decision that refines constitutes a Telephone Consumer Protection Act (“TCPA”) unsolicited fax advertisement. A Manhattan-based federal court recently issued a decision that removes faxed invitations to participate in a survey from the TCPA definition of advertisement. In drawing this distinction for TCPA surveys, the Court held

NY sports gambling law- Klein Moynihan Turco

Agreement Reached to Enact NY Sports Gambling Law

Print Friendly, PDF & Email

This week, Governor Andrew Cuomo and the New York State Legislature agreed to a budget deal that will bring mobile sports betting to the State through a unique NY sports gambling law.  Upon the Governor’s signature, NY sports gambling is primed to become the nation’s largest market. However, New York

UK and US Social Media Influencer Laws

UK and US Social Media Influencer Laws

Print Friendly, PDF & Email

In September of 2020, the United Kingdom’s (“UK”) Committee of Advertising Practice (“CAP”) reviewed the Instagram accounts of 122 UK-based social media influencers to determine whether content was being properly flagged as advertising in accordance with applicable social media influencer laws. This past March, the UK Advertising Standards Authority (“ASA”)

Share on facebook
Share on google
Share on twitter
Share on linkedin