California Changed the Rules on Protected Health Information. Here Is What It Means for You.
Por David A. Prado, Esq., Abogado de Protección al Consumidor
Revisado por un abogado con licencia

The Prado Law Firm Blog - August 2026
If your medical information was caught up in a data breach, California courts used to ask a question that was almost impossible to answer: can you prove a hacker actually looked at your records? For most people, the answer was no, and their cases were dismissed before they ever got started. In May 2026, the California Supreme Court threw that requirement out. The decision, J.M. v. Illuminate Education, Inc., is the most consequential ruling on protected health information (PHI) in years, and industries from hospitals to ed-tech companies are still adjusting to it.
Here is what happened, how different industries have reacted, and what it means whether you are a patient worried about your records or a business that touches health data.
The Case: J.M. v. Illuminate Education
Illuminate Education is an educational technology company that school districts use to track student progress. Its systems stored student medical information, including diagnoses and treatment plans. Between late December 2021 and early January 2022, an unauthorized party accessed those systems, and affected families were not notified until June 2022.
A minor student sued under California's Confidentiality of Medical Information Act (CMIA), the state law that protects medical records and allows individuals to recover $1,000 in statutory damages per violation without proving they suffered any actual financial harm. The trial court dismissed the case, the Court of Appeal revived it, and the California Supreme Court took it up to settle two questions that had divided lower courts for years.
On May 14, 2026, the Court answered both, and the ruling cuts in two directions.
First, the win for consumers. The Court rejected the "actually viewed" requirement from earlier appellate decisions. A plaintiff no longer has to prove that an unauthorized third party actually read their medical records. Confidentiality is breached when the information is exposed to a significant risk of unauthorized access or use. Courts will look at the form, duration, and extent of the breach, along with any mitigation efforts, to decide whether that risk existed. The Court disapproved three prior appellate decisions that had set the higher bar.
Second, the win for businesses. The plaintiff still lost. The Court held that Illuminate was not a "provider of health care" under the CMIA because it used the medical data for educational planning, not for medical diagnosis or treatment. In other words, the statute's teeth got sharper, but the set of companies it bites got narrower.
Why the Old Standard Was Broken
The "actually viewed" requirement asked breach victims to prove something they had no way of knowing. When hackers steal a database, the forensic evidence rarely shows which individual records were opened, and much of modern cybercrime runs on automated tools that harvest data without any human reading it. Defendants routinely won dismissal by pointing out that no one could establish their specific files were viewed. The new standard shifts the focus where it belongs: onto whether the company's conduct exposed the data to serious risk in the first place.
How Industries Have Reacted
Healthcare providers and hospitals are treating the decision as a litigation exposure problem. Defense-side firms have warned clients that more CMIA claims will now survive early dismissal motions, and the practical advice has been to strengthen data security documentation so a provider can show a breach did not create a "significant risk," pointing to encryption, fast containment, and short exposure windows.
Ed-tech, wellness platforms, and other companies that handle health data incidentally read the ruling very differently. For them, the coverage holding is the headline. Because Illuminate escaped the CMIA entirely, companies whose primary business is not managing medical information now have a stronger argument that the statute does not apply to them at all. Expect early motions in these cases to fight over what a company's business really is, not just what happened in the breach.
The plaintiffs' bar has moved quickly. Consumer firms are publicizing the decision and telling breach victims that the near-impossible proof burden is gone. With statutory damages of $1,000 per violation available in class actions, the settlement math on medical data breaches has changed significantly, and compliance analysts are already describing a 2026 trend of California courts interpreting "breach" broadly without requiring proof of downstream misuse.
Digital advertising and website operators are watching a related fight. In Wright v. TrueCare, a California federal court held in late 2025 that data collected by website tracking pixels is not PHI when it merely reflects visits to public webpages. Tracking has to reveal something about a person's actual health condition or care to trigger medical privacy protections. Together with J.M., the message is that California courts are being generous about what counts as a breach but more careful about what counts as protected health information and who is covered.
What This Means for Consumers
If you receive a breach notification involving your medical information, take it seriously even if you have not seen any fraud. Document the notice and the timeline, freeze your credit at all three bureaus, and watch for warning signs like accounts you did not open or oddly specific solicitations. Under the new standard, you may have a viable CMIA claim without proving anyone read your records, but statutes of limitation apply, so do not sit on it.
What This Means for Businesses
If you hold health information on California residents, two questions should be on your desk this quarter. First, are you actually covered by the CMIA? After J.M., that turns on whether your business maintains medical information for purposes of diagnosis, treatment, or managing individuals' medical care, and the answer determines your entire exposure. Second, if you are covered, can you document that your safeguards would prevent a breach from creating a significant risk of unauthorized access? Encryption, access controls, vendor oversight, data minimization, and a fast incident response are no longer just good hygiene. They are your defense.
One honest caveat: this area is moving fast, and lower courts are only beginning to apply the "significant risk" standard case by case. How much risk is "significant" will be litigated for years.
At The Prado Law Firm, we help consumers understand and enforce their rights when companies mishandle their information. If your medical data was exposed in a breach, reach out for a consultation.
This post is for informational purposes only and is not legal advice. Reading it does not create an attorney-client relationship.


