CMIA Confidentiality Breach Standard: “Significant Risk” of Unauthorized Access or Use (No “Actually Viewed” Requirement)
Introduction
In J.M. v. Illuminate Education, Inc. (May 14, 2026) S286699, the Supreme Court of California addressed
statutory privacy claims arising from a cyber incident affecting K–12 student data held by an educational technology
vendor. Plaintiff J.M., a minor, sued Illuminate Education, Inc. (“Illuminate”), a company providing data platforms
and technology support to school districts, after Illuminate reported unauthorized access to databases that
“may have contained” students’ medical information and related educational records. J.M. brought a putative class action
alleging violations of the Confidentiality of Medical Information Act (CMIA; Civ. Code, § 56 et seq.)
and the Customer Records Act (CRA; Civ. Code, § 1798.80 et seq.).
The trial court sustained a demurrer without leave to amend; the Court of Appeal reversed. The Supreme Court granted review
to decide whether the pleadings stated cognizable statutory claims and, in doing so, clarified (1) the scope of CMIA coverage
for nontraditional entities, (2) what constitutes a breach of “confidentiality” under CMIA negligent-release provisions, and
(3) who may sue under the CRA.
Summary of the Opinion
-
No CMIA claim on these pleadings: J.M. did not sufficiently allege Illuminate is a “provider of health care”
within the meaning of Civil Code section 56.06; therefore, CMIA sections 56.10 and 56.101 do not apply on the pleaded facts.
-
New statewide standard for CMIA confidentiality breaches: For CMIA section 56.101 (failure to preserve confidentiality),
a plaintiff need not allege that medical information was “actually viewed” by an unauthorized person. Confidentiality is breached when
the information is exposed to a significant risk of unauthorized access or use.
-
No CRA claim: J.M. did not sufficiently allege he was Illuminate’s “customer” under the CRA; the school district/office
was the purchaser of Illuminate’s services. Thus, J.M. could not sue under section 1798.84, subdivision (b).
The Court reversed the Court of Appeal and remanded, leaving to lower courts whether J.M. should be granted leave to amend in light of the holdings.
Justice Groban concurred, emphasizing additional barriers to amendment and clarifying the “significant risk” standard.
Analysis
Precedents Cited
Pleading and review posture (demurrer; operative complaint)
-
Beacon Residential Community Assn. v. Skidmore, Owings & Merrill LLP (2014) 59 Cal.4th 568:
Cited for the standard that, on demurrer, courts accept as true well-pleaded facts. This framed the Supreme Court’s approach:
it assumed the properly pleaded facts in the proposed second amended complaint.
-
Goonewardene v. ADP, LLC (2019) 6 Cal.5th 817:
Cited to support the practice of considering a proposed amended pleading when reviewing denial of leave to amend.
Statutory interpretation method
-
Apple Inc. v. Superior Court (2013) 56 Cal.4th 128:
Cited for de novo review of statutory construction and the interpretive sequence (text, ordinary meaning, statutory purpose, whole-statute context).
The Court applied this methodology to section 56.06 (CMIA coverage) and CRA’s “customer” definition.
CMIA purpose and background
-
Loder v. City of Glendale (1997) 14 Cal.4th 846:
Cited for the Legislature’s purpose in enacting CMIA: protecting confidentiality of individually identifiable medical information while permitting limited disclosures.
This undergirded the Court’s insistence on respecting the statute’s coverage limits (section 56.06) while construing remedial provisions meaningfully.
The Court’s rejection of the “actually viewed” rule
-
Regents of the University of California v. Superior Court (2013) 220 Cal.App.4th 549:
Key source of the “actually viewed” requirement in data-loss scenarios. The Supreme Court disapproved it “to the extent” inconsistent with the new standard.
The Court did not opine on the outcome in Regents, but rejected its categorical rule that breach requires pleading actual viewing.
-
Sutter Health v. Superior Court (2014) 227 Cal.App.4th 1546:
Extended Regents to stolen-computer allegations and reasoned that increased risk alone is not a statutory breach. The Supreme Court disapproved it
to the extent inconsistent, while acknowledging the policy concern about extreme damages in smash-and-grab theft scenarios.
-
Vigil v. Muir Medical Group IPA, Inc. (2022) 84 Cal.App.5th 197:
Applied the “actually viewed” rule to employee downloading misconduct. The Supreme Court likewise disapproved it to the extent inconsistent.
-
Pulliam v. HNL Automotive Inc. (2022) 13 Cal.5th 127:
Cited for the principle that remedial statutes should be construed broadly to afford the relief the Legislature indicated. This supported rejecting
a pleading/proof rule (actual viewing) that would “significantly enervate” CMIA in modern breach scenarios (including AI-enabled or automated misuse).
CRA standing and statutory limits
-
Boorstein v. CBS Interactive, Inc. (2013) 222 Cal.App.4th 456:
Cited for the proposition that to sue under section 1798.84, subdivision (b), a plaintiff must meet the statutory term “customer”
and be “injured by a violation.” The Supreme Court used Boorstein to anchor a strict, text-based standing inquiry.
-
Ferra v. Loews Hollywood Hotel, LLC (2021) 11 Cal.5th 858:
Cited for the interpretive presumption that different words carry different meanings. This supported the conclusion that the Legislature’s use of “customer”
(not “consumer”) in section 1798.84 is deliberate and limiting.
Legal Reasoning
1) CMIA coverage: why an edtech vendor was not pleaded as a “provider of health care” under section 56.06
The Court treated CMIA coverage as a threshold issue because sections 56.10 and 56.101 operate on “provider[s] of health care.”
It parsed section 56.06, subdivision (a) and (b), focusing on the statute’s purpose-driven requirements, not simply the fact that medical information is stored.
Under section 56.06, subdivision (a), a covered business maintains medical information in order to make it available
to an individual or provider of health care at the request of the individual or provider, and for one of the specified purposes:
allowing the individual to manage the information, or for diagnosis and treatment. J.M.’s allegations described Illuminate’s platforms as tools for
educators to evaluate, monitor, and develop educational plans. Critically, J.M. did not allege that the Ventura County Office of Education (or its staff)
is a “provider of health care,” nor that Illuminate makes information available to individuals/providers for diagnosis or treatment as those medical terms are used in CMIA.
The Court addressed J.M.’s dyslexia-related allegations and rejected the attempt to relabel educational screening and intervention planning as “diagnosis” under CMIA.
It relied on Education Code section 53008, subdivision (l), which specifies that dyslexia risk screening is “not as a diagnosis of a disability.”
The Court also found insufficient the complaint’s single reference that “access [is] provided to educators, students and parents,” because it was tied to
“educational evaluation” and did not plausibly plead a request-based, individual-directed medical information management or medical diagnosis/treatment purpose.
Under section 56.06, subdivision (b), the Court similarly found inadequate allegations that Illuminate offered consumer-directed software/hardware designed
to maintain medical information for request-based access for the statutory purposes. Legislative history reinforced the reading:
section 56.06 was aimed at medical information corporations (e.g., Medic Alert) and later expanded (2007, 2013) to personal health record services,
including mobile applications designed for individuals to track, manage, and share their health data.
Illuminate’s pleaded business model—contracted school-district educational data services—did not match those pleaded statutory purposes.
2) CMIA section 56.13 and “recipient” theory rejected on the pleadings
The Court rejected the Court of Appeal’s reliance on section 56.13 (limits on further disclosure by a “recipient” of medical information) because J.M.
did not allege Illuminate received medical information “pursuant to an authorization” under CMIA or under section 56.10, subdivision (c).
Without pleaded facts of CMIA-compliant “authorization,” section 56.13 could not supply coverage or liability.
3) CMIA breach standard: confidentiality is breached by exposure to a significant risk of unauthorized access or use
On the meaning of “preserve[] the confidentiality” in section 56.101, the Court rejected a categorical “actually viewed” prerequisite.
It reasoned from ordinary meaning (confidentiality is compromised by exposure) and from section 56.36, subdivision (b)(1),
which authorizes $1,000 nominal damages and explicitly provides that it is unnecessary the plaintiff “suffered or was threatened with actual damages.”
A rule requiring proof of actual viewing would sit uneasily with a statutory scheme that allows recovery even absent threatened damages, and would create
serious pleading/proof barriers in typical data breach cases where victims cannot know what happened to their data.
The Court adopted the Attorney General’s framing: the key criterion is whether the information was exposed to a “significant risk of unauthorized access or use.”
It expressly sought a flexible standard able to distinguish “smash-and-grab hardware theft” from cyber incidents targeting data, and to handle other negligent-release
scenarios (public posting, misdirected email, leaked password). Relevant circumstances may include the “form, duration, and extent” of the breach and mitigation measures.
The Court cautioned that negligent “loss of possession” is neither necessary nor always sufficient by itself; the inquiry is contextual.
The Court then disapproved Regents of the University of California v. Superior Court, Sutter Health v. Superior Court,
and Vigil v. Muir Medical Group IPA, Inc. to the extent inconsistent with the “significant risk” standard.
4) CRA standing: “customer” means a direct purchaser/service-obtainer from the business
The CRA requires certain entities that own or license data to disclose breaches “in the most expedient time possible and without unreasonable delay.”
But civil enforcement is limited: “Any customer injured” may sue (section 1798.84, subdivision (b)), and “customer” is defined as an individual who provides
personal information to a business to purchase/lease a product or obtain a service (section 1798.80, subdivision (c)).
The Court applied the definition strictly: the Ventura County Office of Education bought Illuminate’s services; J.M. provided information to the district
to obtain educational services from the district, not to purchase/obtain services from Illuminate. The Court rejected the “intended beneficiary” theory adopted below,
emphasizing that the CRA authorizes suits by “customer[s],” not all “consumers” or “beneficiaries,” and noting the Legislature’s deliberate word choice
(reinforced by Ferra v. Loews Hollywood Hotel, LLC).
Impact
1) A consequential shift in CMIA data-breach litigation
The Court’s most significant doctrinal move is replacing the “actually viewed” requirement with the “significant risk of unauthorized access or use” test.
This reorients CMIA breach litigation toward the nature of the exposure event rather than requiring proof of downstream misuse that plaintiffs rarely can plead.
It likely increases the viability of CMIA negligence claims at the pleading stage in many cyberattack scenarios—if CMIA coverage is established.
2) Coverage remains a major gatekeeper—especially for non-health-sector data holders
The decision simultaneously narrows (or, more precisely, polices) CMIA’s boundary: storing medical information does not itself make an entity a section 56.06 provider.
Plaintiffs suing vendors adjacent to health data (edtech platforms, HR systems, analytics vendors) will need careful allegations that the business makes information available
upon request for the statutory medical-information-management or diagnosis/treatment/management purposes.
3) CRA civil standing remains confined to direct “customers”
The holding forecloses CRA suits by individuals whose data is held by a vendor serving an institutional client (e.g., schools, employers, agencies),
absent a direct purchaser/service relationship. This channels plaintiffs toward other statutory regimes (the Court noted the California Consumer Privacy Act)
or toward common law theories, depending on facts and available causes of action.
4) Guidance for “significant risk” pleading and proof
Although the Court did not apply the standard to a held-covered defendant (because Illuminate was not pleaded within CMIA),
it previewed the factors that will matter: what was accessed, how, for how long, how broadly, and what mitigation occurred.
Justice Groban’s concurrence underscores that “significant risk” must be more than speculation and may be undermined by facts like robust encryption,
suggesting future litigation will focus heavily on technical breach details.
Complex Concepts Simplified
- Demurrer
-
A procedural motion testing whether a complaint states a legally sufficient claim, assuming well-pleaded facts are true.
The Court used this posture to focus on statutory elements and what was (and was not) alleged.
- CMIA “provider of health care” (section 56.06)
-
Not every entity holding medical information is covered. For certain businesses, coverage turns on why they maintain the information:
to make it available upon request for personal health record management or for medical diagnosis/treatment (and related purposes in subdivision (b)).
- “Authorization” under CMIA
-
A statutorily defined permission that must meet requirements in section 56.11 (and related provisions). A “recipient” restriction like section 56.13
depends on receiving information pursuant to such an authorization (or other specified routes), which was not pleaded here.
- Nominal damages (section 56.36, subdivision (b)(1))
-
A fixed amount ($1,000) that can be awarded even if the plaintiff did not suffer, or was not even threatened with, actual damages.
This feature helped the Court reject the notion that CMIA liability depends on proving downstream viewing or misuse.
- “Actually viewed” vs. “significant risk”
-
“Actually viewed” requires proof an unauthorized person read the medical information. The new “significant risk” standard asks whether the breach exposed the data
to a meaningful likelihood of unauthorized access or use, based on the circumstances.
- CRA “customer”
-
A “customer” is someone who provides personal information to the business to purchase/lease a product or obtain a service from that business.
Being a downstream beneficiary (e.g., a student using a district-procured platform) is not enough to sue under CRA’s civil-action provision.
Conclusion
J.M. v. Illuminate Education, Inc. draws a sharp doctrinal line with dual effects. On one hand, it limits CMIA’s reach by insisting that nontraditional entities
like edtech vendors are not “providers of health care” absent well-pleaded facts meeting section 56.06’s purpose-and-access requirements, and it confines CRA civil suits
to statutorily defined “customer[s].” On the other hand, it significantly strengthens CMIA’s remedial force where coverage exists by rejecting the “actually viewed” rule
and adopting a practical, breach-focused standard: confidentiality is breached when medical information is exposed to a significant risk of unauthorized access
or use. This new standard—paired with the Court’s disapproval of Regents of the University of California v. Superior Court, Sutter Health v. Superior Court,
and Vigil v. Muir Medical Group IPA, Inc. to the extent inconsistent—will reshape California medical-information breach litigation, moving disputes from speculative
“did someone read it?” questions toward concrete assessments of the breach’s technical and contextual risk.