Healthcare Data Privacy
Enforcing AB 45 geofencing protections and healthcare data privacy rights under California law.
California AB 45, effective January 2026, prohibits geofencing within a specified radius of healthcare facilities to collect personal information for advertising or commercial purposes. Combined with existing CIPA protections and the Confidentiality of Medical Information Act (CMIA), California provides the strongest healthcare data privacy framework in the nation.
Available through our Los Angeles office for California residents.
AB 45 — Healthcare Geofencing Prohibition
AB 45 creates a new category of privacy protection by prohibiting the use of geofencing technology to:
- Identify or track individuals entering or leaving healthcare facilities
- Collect personal information based on proximity to healthcare locations
- Target advertising based on healthcare facility visits
- Build consumer profiles from healthcare-related location data
CIPA in the Healthcare Context
Beyond geofencing, healthcare-related websites and patient portals that deploy tracking technologies without consent violate CIPA. When a hospital website installs Meta Pixel or Google Analytics that transmit patient browsing activity to third parties, each transmission may constitute a separate CIPA violation at $5,000 per violation.
Combined Enforcement
Our healthcare privacy practice combines AB 45 geofencing claims, CIPA tracking claims, and CMIA confidentiality claims into comprehensive enforcement actions. When a healthcare facility's website is also inaccessible to patients with disabilities, we add ADA and Unruh Act claims to the action.