📣 Heads up: Compliance is a shared responsibility. Jane provides the platform, features, and documentation to support your clinic's compliance, but your clinic is responsible for how you collect, use, and manage patient data in your day-to-day operations.
This guide is a general summary and is not intended as legal advice. For guidance specific to your practice, consult a legal professional or your regulatory body.
Is Jane CCPA compliant?
Yes, with an important clarification.
The CCPA includes a specific exemption for Protected Health Information (PHI). Under CCPA Section 1798.145(c)(1)(A), the law does not apply to PHI collected by a covered entity or business associate that is already subject to HIPAA.
Because Jane operates as a HIPAA-compliant business associate, the PHI stored and processed in Jane falls outside the scope of CCPA. Jane also does not sell or trade any personal information, as outlined in our privacy policy.
You can read the full text of the CCPA in the California Consumer Privacy Act.
It's worth noting that the CPRA (California Privacy Rights Act) significantly amended the CCPA by expanding consumer rights, tightening business obligations, and creating an entirely new enforcement agency. For more information on the CPRA, reach out to Jane's Privacy Team at [email protected].
Does that mean my clinic is automatically exempt from CCPA?
Not necessarily. Whether CCPA applies to your clinic depends on two factors: whether your clinic qualifies as a "business" under CCPA, and whether you collect personal information that falls outside the definition of PHI.
What counts as a "business" under CCPA?
Your clinic is considered a "business" under CCPA if you meet all three of the following conditions:
- You operate a for-profit business
- You do business in California
- You collect the personal information of California consumers for the purposes of processing that information
In addition, your business must meet at least one of these thresholds:
- Annual gross revenue of more than $25 million
- Collect data from more than 100,000 individuals annually
- Derive more than half of your annual revenue from selling personal information
What counts as personal information under CCPA?
Under CCPA, personal information is broadly defined as any information that identifies, relates to, or could reasonably be linked to a specific consumer or household.
The key distinction is that PHI is medical information collected by covered entities (such as clinics) or business associates (such as Jane) for healthcare purposes. Personal information under CCPA refers to data collected outside of that medical context. A few examples of data that would fall under CCPA rather than HIPAA:
- Personal information collected through referrals and used for targeted marketing
- Personal information collected through your clinic's own business website (not including Jane)
If your clinic is a for-profit business operating in California, meets one of the thresholds above, and collects personal information of this kind, CCPA obligations may apply to you. If you're unsure, consult a legal professional or your regulatory body.
For privacy-related questions, reach out to Privacy and Security Support at [email protected].