Cal. Code Regs. tit. 22 § 97416

Current through Register 2024 Notice Reg. No. 49, December 6, 2024
Section 97416 - Restrictions for Public Data Products
(a) Data users shall not include PII or record-level information about patients or individual consumers in their public data products. Data users shall only include aggregated and deidentified data about patients or individual consumers in their public data products.
(1) To deidentify aggregated data, data users must use the methodology stated in Sections 4 (regarding Steps 1 to 4), 4.1 to 4.4, 5.1 to 5.4, 6.1, 6.2, 6.4, and 9 of the California Health and Human Services Agency's "Data De-Identification Guidelines (DDG)," dated September 23, 2016. Data users shall use the "Publication Scoring Criteria" stated in Section 4.3 of the DDG as their method to assess potential risk. These sections are hereby incorporated by reference.
(b) Data users shall submit draft public data products with any information about patients or individual consumers to the Department. The Department shall review these draft public data reports for compliance with subsection (a).
(1) Data users shall submit with their draft public data products documentation regarding how they aggregated and deidentified the PII or record-level information about patients or individual consumers.
(2) Data user shall not release public data products unless the Department approved the release of the public data product in writing. If the Department does not approve a draft public data product, it shall notify the data user in writing of its decision and the reasons for its decision.
(c) Data users shall not include PII or record-level data regarding individuals who are not patients or individual consumers in their public data products if the Department determines that the disclosure would be a mandatory reason for denial under section 97388(b) or if the Department determines that there is good cause to prevent the disclosure.
(1) Data Users shall notify the Department if their draft public data products include PII or record-level information regarding individuals who are not patients or individual consumers. This notice shall describe the PII or record-level information.
(2) The Department may require its review and approval of these draft public data products before release for compliance with this subsection. Data users shall not release the public data product before the Department notifies the data user whether review is required.
(3) If review is required, the following shall apply:
(A) Data users shall not release draft public data products under review unless the Department approved the release of the public data product in writing.
(B) If the Department does not approve the draft public data product, it shall notify the data user in writing of its decision and the reasons for its decision. The Department may require information about individuals to be aggregated or deidentified pursuant to subsection (a) before release.

Cal. Code Regs. Tit. 22, § 97416

Note: Authority cited: Section 127673, Health and Safety Code. Reference: Sections 127673.5, 127673.81 and 127673.82, Health and Safety Code.

1. New section filed 11-25-2024; operative 11/25/2024 pursuant to Government Code section 11343.4(b)(3) (Register 2024, No. 48).