California Health Information Privacy Manual

Laws regarding patient privacy rights, use/ disclosure of PHI, and breaches

Effective August 12, 2021 CHA Manuals are available in ePub format only
The ePub includes a PDF and access to the CHA Manuals App for mobile use. CHA members may download PDFs for all CHA manuals, from the publications download library; the free CHA Manuals App may be downloaded from the Apple App Store or the Google Play Store.


This comprehensive resource addresses all state and federal laws related to the privacy of health information, and provides guidance to help hospitals comply with increasingly complex regulations. Laws covered include:

  • Health Insurance Portability and Accountability Act (HIPAA)
  • Health Information Technology for Economic and Clinical Health (HITECH)
  • Confidentiality of Medical Information Act
  • Patient Access to Health Records Act
  • Lanterman-Petris-Short Act

New for 2017

This edition incorporates into the main text information formerly found in preemption analyses charts so all information about a particular issue is in one place. The 2017 edition also addresses:

New Content
  • Photographing and filming patients
  • Searching patients and their belongings
  • Observers present in the facility
  • Audio recording confidential communications
  • Body cameras and consumer wearables
  • The Telephone Consumer Protection Act
New Laws/Court Decisions
  • Responding to attorney requests prior to the filing of a lawsuit
  • Changes regarding the release of health information in certain situations
  • Rulings narrowing the definition of “medical information” 
  • Amendments regarding the breach of unencrypted computerized data
  • HIPAA amendments regarding the FBI’s National Instant Criminal Background Check System
Office of Civil Rights Guidance Regarding
  • Ransomware attacks
  • The use of cloud computing solutions 
  • Patient’s right to have information sent to a third party
  • Fees for copying health information

(Eighth edition, 2017)


The 2017 edition is over 400 pages and contains 13 chapters. The manual includes a CD with more than 40 useful forms, many in English and Spanish, which providers may use to comply with the patients’ rights requirements. A comprehensive index has also been added.


  • Understand the Laws
  • Administrative Processes and Considerations
  • Privacy Rights and Notice of Privacy Practices
  • Use and Disclosure of PHI: Fundamentals and Special Issues
  • Use and Disclosure of PHI: CMIA Patients
  • Use and Disclosure of PHI: LPS Patients
  • Use and Disclosure of PHI: Substance Abuse Patients
  • Privacy and the Conduct of Research
  • Employee Health Information
  • Health Information Security
  • Business Associate Contracts
  • Breaches
  • Enforcement and Penalties

Preview the Manual

Click here to preview the manual.

Memo of Notable Changes

Click here to download the memo of notable changes.

ePub Terms of Use

CHA Members

Electronic copies of CHA Publications are available free to CHA members. CHA members may download each PDF for their individual use and/or post it to an Intranet or shared workstation environment.

CHA Nonmembers

Limited Use License: In purchasing this electronic publication (Publication), the individual who purchased it (Purchaser) agrees to abide by the terms of this Limited Use License. This Limited Use License: (1) gives Purchaser a non-exclusive, non-assignable, royalty free, perpetual, limited right to use this electronic publication only for his/her personal use; and (2) prohibits Purchaser from posting, reproducing, distributing, disseminating, transmitting, or otherwise allowing anyone else to access or use this Publication. CHA is and will be the sole and exclusive owner of all right, title, and interest, including intellectual property rights, in this Publication and its contents. CHA will strictly enforce the terms of this Limited Use License.

NOTE: Print functionality is disabled in the Individual PDF. Purchases that include electronic publications are not refundable. For questions about the policy, contact Publications.

Forms Policy

CHA includes hard copies of forms and appendices in its manuals for all purchasers. Electronic versions of forms, appendices, and the model compliance plan are available to CHA members for download at

Member Download


Free for Members

Digital Download (FREE)