Insurance privacy and health information
Working draft · Version 1 · Research date 2026-09-14
1. Purpose and scope
California insurance privacy requirements address information practices, notices and disclosures. Federal HIPAA coverage is separate: health plans can be covered entities, while an insurer is not covered merely because it sells insurance.
Confirm the insurance entity, information and transaction. HIPAA is assessed separately and applies to covered health plans and other covered entities or business associates, not every insurer.
2. Adoption and accountability
The accountable policy owner must confirm the legal entity, products, customer locations, applicable laws and exemptions before adoption. Maintain an applicability register and obtain management approval of procedures, owners, retention and deadlines. This template does not claim legal review or complete compliance coverage. An industry selection is a suggestion, not evidence of a legal duty.
3. Operating controls
3.1 Map personal information and sharing
Owner: Privacy officer. Trigger: At a new data use, product or sharing arrangement.
Inventory information, purposes, recipients and legal bases. Identify which California insurance privacy provisions cover the transaction and record separate obligations arising under other laws.
Evidence: Data map and applicability assessment.
3.2 Deliver notices and honor information rights
Owner: Privacy operations lead. Trigger: When a notice, consumer choice or information-rights request is triggered.
Provide the applicable notice and sharing choices; authenticate and log requests, assign an owner, apply the governing response period and document delivery or a supported limitation.
Evidence: Notice version, delivery evidence and rights-request log.
3.3 Review disclosures and service providers
Owner: Privacy officer. Trigger: Before a new disclosure and during risk-based reviews.
Confirm the permitted disclosure basis and any authorization or choice required. Review recipient restrictions, contracts, access and retention; correct unauthorized uses promptly.
Evidence: Disclosure review and provider restrictions.
3.4 Protect health information where HIPAA applies
Owner: Health privacy officer. Trigger: Before a covered health-information use and when coverage changes.
For a confirmed covered entity or business associate, map the applicable Privacy Rule duties to notices, permitted uses, individual rights and business-associate arrangements. Assess Security and Breach Notification Rules separately. Keep uncovered insurance lines distinct.
Evidence: HIPAA role determination and privacy-control register.
4. Exceptions, review and records
Log deviations with the affected control, risk, interim action, owner and resolution date. Escalate missed statutory duties immediately to the responsible compliance lead; internal exceptions cannot waive law. Keep versioned approvals and follow the confirmed retention schedule and any legal hold. Review after material legal, product or operating changes.
5. Authorities and limitations
-
California insurance privacy regulations: 10 CCR §§2689.1 et seq.; applicable California insurance privacy law.
-
Research as of 2026-09-14; confirm the current operative requirements.
-
Template status: draft, awaiting organization-specific and legal review.
-
Company review cadences, operational steps and evidence examples are proposed implementation controls, not quotations from law.
-
HHS covered entities and HIPAA Privacy Rule apply only after the relevant role and activity are established.