California Court Sets Medical Breach Standard
Coverage from Nixon Peabody, Swigart Law Group, and others

The California Supreme Court’s decision in J.
M. v. Illuminate Education establishes that plaintiffs alleging medical-information breaches under the CMIA do not need to show that an unauthorized party actually viewed the records; a fact-supported significant risk of unauthorized access or use may be sufficient. At the same time, the court limited the statutes’ reach by finding that the education technology vendor was not adequately alleged to be a healthcare provider and that the student was not the vendor’s customer under the Customer Records Act. The ruling creates a mixed framework: breach claims may survive on risk-based allegations, but statutory coverage remains dependent on the defendant’s role and the plaintiff’s relationship to the data holder.
