RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawJuly 19, 2026

CCPA and Healthcare AI: Does It Apply When HIPAA Already Does?

"We're a healthcare company, HIPAA covers us" is the single most common compliance mistake we hear from AI health-tech teams. CCPA's healthcare exemption is real, but it's tied to the data and the entity's HIPAA status — not the industry. A lot of healthcare-adjacent AI falls straight through the gap.

2
CCPA exemptions that touch healthcare — PHI data, and covered entity/BA status
0
Blanket exemption for companies just because they operate in 'health'
$7,500
Max CCPA fine per intentional violation, per consumer

The Exemption Is Narrower Than Teams Assume

CCPA carves out two related but distinct things. First, protected health information that a HIPAA-covered entity or business associate collects, creates, or maintains under HIPAA — that PHI is exempt from CCPA. Second, entities that qualify as HIPAA-covered entities or business associates get exempted with respect to that PHI activity — not across everything they do.

That second clause is where the assumption breaks. Being a covered entity or business associate doesn't make a company generally CCPA-exempt. It exempts the specific PHI processing. Employee data, marketing analytics, product telemetry, non-PHI de-identified data used for model training, and any consumer-facing service that isn't part of the treatment/payment/operations relationship are all still governed by CCPA in the ordinary way.

Where Healthcare AI Commonly Falls Outside the Exemption

Direct-to-consumer wellness and symptom-checker apps

High

No covered entity or insurer in the chain usually means no HIPAA coverage at all. CCPA applies in full, and health data collected qualifies as 'sensitive personal information' — triggering the right to limit use and disclosure, on top of standard access/delete/opt-out rights.

AI scribes' non-PHI data streams

Medium

The transcription itself may be exempt PHI. But usage analytics, error logs, billing data, and account/employee data collected by the same vendor typically are not — and are easy to overlook because the product's core function is HIPAA-adjacent.

AI models trained on 'de-identified' health data

High

HIPAA de-identification (Safe Harbor or Expert Determination) doesn't automatically satisfy CCPA's separate de-identification bar, which requires technical safeguards, a public no-reidentification commitment, and contractual controls on anyone you share the data with.

Health-adjacent marketing and lead-gen AI

High

AI-driven ad targeting, chat widgets that collect symptoms before a provider visit, and quiz-style intake tools used for marketing purposes are almost never inside the HIPAA relationship and are squarely CCPA-covered, including CCPA's sensitive-data rules.

What Actually Is Exempt

To be clear about the other side: an AI product genuinely operating as a HIPAA business associate — processing PHI on behalf of a covered provider or payer, under a business associate agreement, for treatment, payment, or healthcare operations — has a solid CCPA exemption for that specific data and activity. The exemption is doing its job in that narrow lane. The mistake is extending that same confidence to every other dataset the same company touches.

A Quick Triage for Healthcare AI Teams

  • Map the data, not the company. Which specific datasets are PHI collected under a BAA, and which aren't?
  • Check the relationship chain. Is there a covered entity (provider, plan, clearinghouse) in the loop, or is this direct-to-consumer?
  • Separate marketing/analytics data from clinical data flows — these almost never share the same exemption status.
  • Re-verify de-identification against CCPA's specific standard, not just HIPAA's, before treating training data as exempt.
  • Build CCPA rights infrastructure (access, delete, opt-out, sensitive-data limit) for anything that falls outside the PHI exemption.

See where your AI product is exposed

RatedWithAI helps SaaS teams surface compliance and trust gaps across their web properties. Start with a free scan to understand how your product presents to users and regulators alike.

Scan Your Product for Free →

Frequently Asked Questions

We signed a BAA with our hospital customers — are we fully CCPA-exempt?

Only for the PHI processed under that BAA. If the same product also collects data from consumers directly, runs marketing, or processes non-PHI operational data, those flows are evaluated under CCPA independently of the BAA relationship.

Does CCPA's sensitive personal information category include health data outside HIPAA?

Yes. CCPA defines health data as sensitive personal information regardless of HIPAA status. Non-exempt health-adjacent AI products must honor the right to limit use of sensitive data, on top of standard CCPA rights.

Can we rely on HIPAA's minimum necessary standard to satisfy CCPA data minimization?

They're similar in spirit but are separate legal standards enforced by different regulators (HHS OCR vs. the California Privacy Protection Agency). Meeting one doesn't formally satisfy the other; document compliance with each separately.

What's the penalty exposure if we wrongly assume full exemption?

CCPA penalties run $2,500 per unintentional and $7,500 per intentional violation, per affected consumer, plus a private right of action for certain data breaches. A misapplied blanket exemption across a large consumer health-app user base scales fast.

Related Guides