
California Governor Gavin Newsom signed three new legislative measures into law, strengthening legal protections for patients and medical providers who access or deliver reproductive and gender-affirming healthcare services. The legislation, which was sponsored by California Attorney General Rob Bonta, comes as a direct response to ongoing out-of-state legal challenges and policy actions. All three measures are scheduled to take effect on January 1, 2027.
Attorney General Bonta emphasized that the new statutes provide the state with expanded tools to safeguard sensitive medical records and defend lawful healthcare services against outside interference. Supporters of the legislation note that the rules are designed to prevent out-of-state jurisdictions from penalizing individuals for medical procedures that remain fully legal under California law.
Under Assembly Bill 1854, authored by Assemblymember Maggy Krell, California’s existing reproductive shield laws are expanded significantly. The legislation blocks financial services companies and individuals operating within California from complying with out-of-state legal demands that seek protected health information. Additionally, the statute clarifies that local law enforcement officers are prohibited from arresting an individual if the Governor chooses to deny an extradition request from another state.
This measure addresses specific cross-border legal pressures, following previous instances where out-of-state authorities attempted to reach across state lines to target local medical providers. The statute reinforces California’s constitutional provisions guaranteeing the right to abortion and related medical services.
Source: California Attorney General
Assembly Bill 1930, authored by Assemblymember Rick Chavez Zbur and co-sponsored by Equality California, establishes new reporting requirements for business entities operating inside the state. Under the new rule, any business that receives a subpoena, inquiry, or other legal demand regarding abortion or gender-affirming care must notify the Attorney General before responding. This allows the Attorney General to intervene directly in legal proceedings to block the disclosure of protected medical data.
Advocates for the measure argue that it creates a vital firewall against politically motivated investigations and prevents private institutions from being utilized to target patients and providers for receiving or administering lawful care.
Assembly Bill 2448, authored by Assemblymembers Marc Berman and Rebecca Bauer-Kahan with co-sponsorship from Planned Parenthood of California, focuses on the technical security of medical documentation. The statute requires organizations that maintain electronic health records for sensitive services to implement operational safeguards and technological tools. These measures are designed to segregate sensitive health data so that patients who receive reproductive and gender-affirming services cannot be easily identified or targeted.
Healthcare organizations must ensure their digital infrastructure meets these security standards to protect patient confidentiality and prevent unauthorized access to personal medical histories.
For ordinary people in California, these new laws reinforce medical privacy and provide stronger legal boundaries against out-of-state subpoenas and data requests. Patients seeking reproductive or gender-affirming care can expect healthcare entities to utilize segregated digital records to secure their personal information. Providers operating within the state gain explicit legal backing against outside extradition attempts and demands for confidential records.
Although the laws take effect on January 1, 2027, individuals who have concerns about how out-of-state inquiries might impact their personal medical privacy or professional practice may benefit from consulting with an attorney to understand their rights under the expanded shield statutes.
The new laws significantly lower the risk that patient medical histories related to reproductive or gender-affirming care can be handed over to out-of-state authorities.
California-based businesses and entities holding electronic health records face strict new operational requirements to segregate data and notify the Attorney General.
By granting the Attorney General power to intervene in legal demands, the state establishes a centralized defense mechanism for local healthcare providers.
Observers should monitor how out-of-state jurisdictions respond to California's refusal to comply with extradition and records requests as these laws take effect.
Affected healthcare providers and clinics should audit their electronic record systems well before January 1, 2027, to ensure compliance with data segregation rules.
| Legislation | Primary Authors | Core Function |
|---|---|---|
| AB 1854 | Assemblymember Maggy Krell | Expands shield laws; blocks financial firms from out-of-state demands. |
| AB 1930 | Assemblymember Rick Chavez Zbur | Requires businesses to notify AG of subpoenas regarding protected care. |
| AB 2448 | Assemblymembers Berman & Bauer-Kahan | Mandates tech safeguards to segregate sensitive electronic health data. |
Source: California Attorney General
This article is general information based on California Attorney General and court or agency records available at publication time. It is not legal advice; laws and deadlines differ by state and by case. Published October 1, 2026.
Source: California Attorney General
A federal judge allowed parts of a class action over genetic data sharing to proceed, focusing on law enforcement access and website tracking pixels.
Reading about the law is one thing, applying it to your own case is another. Browse verified attorneys in California by practice area.