Existing law establishes the Medi-Cal program, which is administered by the State Department of Health Care Services, under which qualified low-income individuals receive health care services. The Medi-Cal program is, in part, governed and funded by federal Medicaid program provisions. Under existing law, in-person, face-to-face contact is not required under the Medi-Cal program when covered health care services are provided by video synchronous interaction, asynchronous store and forward, audio-only synchronous interaction, remote patient monitoring, or other permissible virtual communication modalities, when those services and settings meet certain criteria. Existing law required the department, on or before January 1, 2023, to develop a research and evaluation plan that, among other things, proposes strategies to analyze the relationship between telehealth and access to care, quality of care, and Medi-Cal program costs, utilization, and program integrity. The department created that plan in December of 2022 and published the Biennial Telehealth Utilization Report in April of 2024. This bill, the Telehealth for All Act of 2025, would require the department, commencing in 2028 and every 2 years thereafter, to use Medi-Cal data and other data sources available to the department to produce analyses in a publicly available Medi-Cal telehealth utilization report. The bill would authorize the department to include those analyses in each of the department's Biennial Telehealth Utilization Reports, as specified. The bill would require the analyses to address telehealth access and utilization data, including various metrics on telehealth visits and claims, disaggregated by geographic, demographic, and social determinants of health categories to identify disparities. The bill would require the department to identify additional data elements for inclusion in future reports to help to identify and address access-to-care issues or provide greater insight into utilization of telehealth modalities.
Existing law generally governs the transactions between a rental car company, also referred to as a rental company, and its customers, as provided. Existing law prohibits a rental company from using, accessing, or obtaining any information relating to the renter's use of the rental vehicle that was obtained using electronic surveillance technology, as defined, except under specified circumstances. Existing law permits a rental company and a renter to limit the responsibilities of a renter in specified events, including loss due to theft of the rented vehicle up to its fair market value, as provided. Existing law establishes, in the situation described in the previous sentence, a presumption that the renter has no liability for loss due to theft if specified conditions are met, including that an authorized driver has possession of the ignition key or establishes that the ignition key was not in the vehicle at the time of the theft, as provided. This bill would allow a rental company to use geofence technology, as specified, to detect rental vehicle movement in prescribed circumstances. The bill, with respect to the above-described provisions relating to the renter's liability for loss due to theft, would revise the presumption that the renter has no liability for loss due to theft to instead apply this presumption if an authorized driver returns the ignition key.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Under existing law, the residence address, telephone number, and email address of a registered voter is confidential, except that under certain circumstances a county elections official must provide that information to any candidate for federal, state, or local office, to any committee for or against any initiative or referendum measure, and to any person for election, scholarly, journalistic, political, or governmental purposes. This bill would exempt the residence address, telephone number, and email address of a federal, state, or local elected official or candidate from that disclosure requirement, except that the information may be disclosed for journalistic or governmental purposes under specified conditions. The bill would require the Secretary of State to provide each county elections official with a list identifying each federal and state elected official or candidate residing in the county, require the county elections official to add each local elected official or candidate to that list, and require the county elections official to make the elected official or candidate's information confidential within 5 business days. The bill would require the county elections official to exclude the elected official or candidate's confidential information when producing any list, roster, or index. The bill would require an elected official or candidate to contact their county elections official to ensure their voter registration record has been made confidential. The bill would authorize an elected official or candidate to opt out of making their residence address, telephone number, and email address confidential. By adding new duties for county elections officials, this bill would create a state-mandated local program. This bill would incorporate additional changes to Section 2194 of the Elections Code proposed by AB 827 to be operative only if this bill and AB 827 are enacted and this bill is enacted last. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center. Existing law states that the center's mission is to reduce the likelihood and severity of cyber incidents that could damage California's economy, its critical infrastructure, or public and private sector computer networks in the state. Existing law requires the center to serve as the central organizing hub of state government's cybersecurity activities and coordinate information sharing with specified entities, including local, state, and federal agencies. This bill would require the California Cybersecurity Integration Center to develop, on or before January 1, 2027, in consultation with the Office of Information Security and the Government Operations Agency, a California AI Cybersecurity Collaboration Playbook, as specified, to facilitate information sharing across the cyber and artificial intelligence communities and to strengthen collective cyber defenses against emerging threats. The bill would require the center to review federal requirements, standards, and industry best practices, as specified, and to use those resources to inform the development of the California AI Cybersecurity Collaboration Playbook. Except as specified, the bill would provide that any information related to cyber threat indicators or defensive measures for a cybersecurity purpose shared in accordance with the California AI Cybersecurity Collaboration Playbook is confidential and would prohibit that information from being disclosed, except as specified. The bill would also make findings and declarations related to its provisions. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
The California Consumer Financial Protection Law requires the Commissioner of Financial Protection and Innovation to prepare and publish on the Department of Financial Protection and Innovation's internet website an annual report detailing actions taken during the prior year under the law and requires the report to include information on actions taken with respect to, among other things, the activities of the Financial Technology Innovation Office. This bill would additionally require the report to include information on actions taken with respect to the Office of the Ombuds.
(1) Existing law prohibits, except as required by state or federal law or as required to administer a state or federally supported educational program, school officials and employees of a school district, county office of education, or charter school from collecting information or documents regarding citizenship or immigration status of pupils or their family members. Existing law requires the superintendent of a school district, the superintendent of a county office of education, and the principal of a charter school, as applicable, to report to the respective governing board or body of the local educational agency in a timely manner any requests for information or access to a schoolsite by an officer or employee of a law enforcement agency for the purpose of enforcing the immigration laws in a manner that ensures the confidentiality and privacy of any potentially identifying information. This bill would prohibit school officials and employees of a local educational agency from allowing an officer or employee of an agency conducting immigration enforcement to enter a nonpublic area of a schoolsite, as defined, for any purpose without being presented with a valid judicial warrant, judicial subpoena, or a court order. The bill would require school officials and employees of a local educational agency, to the extent practicable, to request valid identification of any officer or employee of an agency conducting immigration enforcement seeking to enter a nonpublic area of a schoolsite. The bill would also prohibit a local educational agency and its personnel from disclosing or providing, in writing, verbally, or in any other manner, the education records of or any information about a pupil or a pupil's family and household without the pupil's parents' or guardians' written consent, a school employee, or a teacher to an officer or employee of an agency conducting immigration enforcement without a valid judicial warrant or judicial subpoena, or court order directing the local educational agency or its personnel to do so. By imposing additional duties on local educational agencies, the bill would impose a state-mandated local program. (2) Existing law requires the Attorney General, by April 1, 2018, in consultation with the appropriate stakeholders, to publish model policies limiting assistance with immigration enforcement at public schools, to the fullest extent possible consistent with federal and state law, and ensuring that public schools remain safe and accessible to all California residents, regardless of immigration status, as provided. Existing law requires local educational agencies, by July 1, 2018, to adopt those model policies developed by the Attorney General or equivalent policies. This bill would require the Attorney General, by December 1, 2025, to update those model policies to ensure that the policies align with the above-described prohibitions on school officials and employees of local educational agencies allowing an officer or employee of an agency conducting immigration enforcement to enter a nonpublic area of a schoolsite without a valid judicial warrant or judicial subpoena, or a court order and from disclosing or providing certain information to those officers or employees, as provided. The bill also would require a local educational agency to update its model policy by March 1, 2026, and to make the policy available to the State Department of Education upon request. By imposing additional duties on local educational agencies, the bill would impose a state-mandated local program. (3) This bill would make these provisions severable. (4) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above. (5) This bill would declare that it is to take effect immediately as an urgency statute.
Existing law generally regulates artificial intelligence, including by requiring the Office of Emergency Services to, as appropriate, perform a risk analysis of potential threats posed by the use of generative artificial intelligence to California's critical infrastructure, including those that could lead to mass casualty events. This bill would require the Attorney General to establish and maintain a specified program to build internal expertise in artificial intelligence, including its applications, risks, regulatory implications, and civil rights impacts. The bill would require, on or before July 1, 2027, and annually thereafter, the Attorney General to submit a public report to the Legislature describing the program, key developments in artificial intelligence law and policy, and recommendations for additional state oversight or safeguards.
Existing law makes it unlawful for any person to use a bot to communicate or interact with another person in this state online with the intent to mislead the other person about its artificial identity for the purposes of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction or to influence a vote in an election, unless the person using the bot discloses that it is a bot. Existing law defines a "bot" as an automated online account where all or substantially all of the actions or posts of that account are not the result of a person. This bill would require a person who uses a bot to autonomously communicate with another to ensure that the bot discloses to any person with whom the bot communicates when the bot first communicates with the person that the bot is a bot and not a human being, answers truthfully any query from a person regarding its identity as a bot or a human, and refrains from attempting to mislead a person regarding its identity as a bot. The bill would redefine "bot" to mean an automated online account or application that a reasonable person could believe is a human being and with respect to which substantially all of the actions or posts of that account or application are the outputs of generative artificial intelligence, as defined. The bill would exempt from its provisions a person who uses a bot that is required to comply with a more prescriptive disclosure scheme. This bill would authorize the Attorney General, a district attorney, a county counsel, a city attorney, or a city prosecutor to bring a civil action to punish noncompliance, as prescribed.
Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires specified state entities to implement the policies and procedures issued by the office. Existing law additionally authorizes the office to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. Existing law requires every state agency, as specified, to certify, by February 1 annually, to the office that the agency is in compliance with all adopted policies, standards, and procedures and to include a plan of action and milestones, as specified. This bill would require every state agency, as specified, and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. The bill would require the office's chief to develop or revise uniform technology policies, standards, and procedures for use by all state agencies in Zero Trust architecture to achieve specified maturity levels on all systems in the State Administrative Manual and Statewide Information Management Manual. The bill would require the chief to update requirements for existing annual reporting activities to collect information relating to the progress state agencies are making to increase internal defenses of agency systems. The bill would authorize the chief to update existing annual reporting activities to include how a state agency is progressing with respect to specified goals. The bill would also state the Legislature's intent that the bill's provisions be implemented in a manner consistent with the state's timely compliance with requirements that are conditions to receipt of federal funds. The bill would also make related legislative findings and declarations.