21 August 2026

California's AB 133 requires most licensed healthcare organizations in the state to sign a single Data Sharing Agreement and exchange patient information in real time with every other signatory and as of 2026, that mandate is no longer theoretical. The final extended compliance deadline has passed, oversight has moved to a new state department, and new accountability rules are now in effect. If your organization signed the Data Sharing Agreement (DSA) years ago but never fully operationalized the exchange, or if you're only now confirming where you stand, this guide breaks down exactly what AB 133 requires, what's changed recently, and how to close the gap without disrupting clinical operations. For California providers, this is the practical starting point for AB 133 Health Information Exchange in California. For teams assessing readiness, AB 133 Health Information Exchange in California also provides a useful framework for identifying operational gaps. This practical focus is central to AB 133 Health Information Exchange in California.
AB 133 is a 2021 California law that directed the state to build a single, statewide framework for exchanging health and social services information known as the California Health and Human Services Data Exchange Framework (DxF). Instead of every hospital, health plan, and medical group negotiating separate data-sharing arrangements, AB 133 created one common Data Sharing Agreement (DSA) and one set of Policies and Procedures (P&Ps) that all mandated participants sign and follow. Once an organization signs the DSA, it is required to exchange or provide access to health and social services information with every other signatory, in real time, for purposes like treatment, payment, and care coordination. This statewide structure is the foundation of AB 133 Health Information Exchange in California. The common agreement model makes AB 133 Health Information Exchange in California more consistent across participating organizations.
AB 133 named a broad list of required participants, including general acute care and psychiatric hospitals, physician organizations and medical groups, skilled nursing facilities, clinical laboratories regulated by the California Department of Public Health, and health plans (including Medi-Cal managed care plans and disability insurers). These participant categories define much of the scope of AB 133 Health Information Exchange in California. Understanding who must participate helps organizations scope AB 133 Health Information Exchange in California correctly.
A defined set of smaller or resource-constrained organizations physician practices with fewer than 25 physicians, nonprofit clinics with fewer than 10 providers, rehabilitation and long-term acute care hospitals, acute psychiatric hospitals, critical access hospitals, and rural general acute care hospitals under 100 beds signed the DSA on the same original schedule but were given until January 31, 2026 to fully implement real-time exchange. The extended timeline is an important part of understanding AB 133 Health Information Exchange in California. Planning around the applicable deadline remains essential for AB 133 Health Information Exchange in California.
Government agencies and social services organizations aren't mandated under AB 133 itself, but the state has actively encouraged their participation, and many have joined voluntarily to support whole-person care coordination across health and social services. Voluntary participation can also strengthen the broader goals of AB 133 Health Information Exchange in California. That participation can support care coordination goals associated with AB 133 Health Information Exchange in California.
| Milestone | Deadline | Status (as of 2026) |
|---|---|---|
| CalHHS establishes the DxF, DSA, and P&Ps | July 1, 2022 | Complete |
| Mandatory signatories sign the DSA | January 31, 2023 | Complete |
| Most signatories begin real-time exchange | January 31, 2024 | Complete |
| Smaller/rural entities fully implement exchange | January 31, 2026 | Deadline has passed |
| Certain DHCS, CalPERS, and Covered California contracts require DSA signature as a contract condition | July 1, 2026 | In effect |
| Emergency medical services and licensure-exempt medical foundations execute the DSA | July 1, 2026 | In effect |
Organizations that have not yet signed the DSA or completed real-time exchange are now operating past their statutory deadline, which is a materially different compliance posture than "getting ahead of an upcoming requirement." That current compliance posture is central to AB 133 Health Information Exchange in California. Organizations should treat these obligations as part of ongoing AB 133 Health Information Exchange in California readiness.
Two developments meaningfully changed the AB 133 landscape and are frequently missing from older compliance guides: Administration moved to HCAI. In August 2025, oversight of the DxF transitioned from the California Health and Human Services Agency (CalHHS) and its Center for Data Insights and Innovation (CDII) to the Department of Health Care Access and Information (HCAI), which now runs ongoing implementation.
SB 660 added real accountability mechanisms. When AB 133 first established the DxF, the statute did not include enforcement provisions. Senate Bill 660, signed in 2025, changed that introducing transparency and accountability mechanisms that lean on public disclosure, state purchasing power, coordination with licensing bodies, and contractual obligations among participants. SB 660 also created a new Stakeholder Advisory Committee, which began meeting on an ongoing, public basis in April 2026, replacing the prior Implementation Advisory Committee. These changes are now part of the operating landscape for AB 133 Health Information Exchange in California. Keeping current with these developments helps organizations manage AB 133 Health Information Exchange in California more effectively.
Understanding AB 133 compliance requires understanding the mechanism, not just the mandate. The distinction between the legal mandate and its technical mechanism matters in AB 133 Health Information Exchange in California. This approach keeps implementation decisions aligned with the requirements of AB 133 Health Information Exchange in California.
The DSA is the single legal document every signatory executes there's no negotiating individual terms with each partner organization. The accompanying Policies and Procedures (P&Ps) spell out the operational, technical, privacy, and security requirements that make the DSA enforceable in practice: what counts as "health and social services information," what real-time exchange actually means, and how participants must identify each other in a shared Participant Directory. The DSA and P&Ps provide the operating framework for AB 133 Health Information Exchange in California. Operational readiness therefore matters as much as documentation in AB 133 Health Information Exchange in California.
The DxF is technology-agnostic the state doesn't mandate a specific platform. But most organizations can't build real-time, DSA-compliant exchange infrastructure from scratch. A QHIO is a designated intermediary that has demonstrated it can help DSA signatories meet their exchange obligations: connecting a practice's EHR to the broader network, handling the technical lookup and response logic, and maintaining the security posture the DSA requires. For most small and mid-sized California organizations, working through a QHIO is the realistic path to compliance rather than a "nice to have." For organizations choosing an implementation path, the QHIO model is a practical consideration in AB 133 Health Information Exchange in California. A suitable intermediary can reduce the technical burden of implementing AB 133 Health Information Exchange in California.
Two mechanisms typically do the actual work of exchange. A Carequality record lookup lets a requesting provider query the network in real time and pull back a patient's available record from any connected source this is how a same-day ED visit surfaces a patient's medication list from an unrelated practice across the state. A direct messaging fallback handles the gap cases: referrals, transitions of care, or records held by organizations not yet reachable through automated lookup, sent securely point-to-point instead. A compliant exchange setup needs both, because relying on lookup alone leaves gaps for partners still completing their own implementation. These exchange methods are core components of AB 133 Health Information Exchange in California. Using both pathways helps address the practical exchange requirements of AB 133 Health Information Exchange in California.
AB 133 itself didn't originally carry enforcement teeth, which is part of why some organizations treated the deadlines loosely. SB 660 changes that calculus going forward: contractual leverage through state payers (DHCS, CalPERS, Covered California), coordination with licensing entities, and public transparency about signatory status all create real exposure for organizations that remain non-compliant. Beyond regulatory risk, non-compliant organizations also carry the operational cost of incomplete patient records, duplicated testing, and slower care coordination the exact problems AB 133 was written to solve. The enforcement picture is therefore an important consideration for AB 133 Health Information Exchange in California. This makes implementation planning an important part of AB 133 Health Information Exchange in California.
"AB 133 only applies to hospitals." In reality, the mandatory signatory list spans physician organizations and medical groups, skilled nursing facilities, clinical laboratories, and health plans hospitals are one category among several. "We signed the DSA, so we're compliant." Signing the DSA is a starting point, not the finish line. Compliance requires actually exchanging health and social services information in real time under the P&Ps a technical and operational commitment, not a one-time paperwork step. "Working with a QHIO means giving up control of our patient data." A QHIO acts as a connectivity and compliance intermediary under the terms your organization agrees to it doesn't take ownership of your records or override your existing HIPAA obligations and access controls. These misconceptions can create avoidable gaps in AB 133 Health Information Exchange in California. A clear understanding of the rules can make AB 133 Health Information Exchange in California easier to operationalize.
A mid-sized independent physician association (IPA) in California had signed the DSA on schedule but was still running three disconnected EHR systems across its member practices as the January 31, 2026 implementation deadline approached. Staff were manually faxing records between practices for shared patients, and the organization had no real-time way to satisfy its DxF exchange obligations. After connecting through a QHIO-based platform, the IPA gained real-time Carequality lookup across its member practices and a direct-messaging fallback for partners still onboarding elsewhere in the state. Administrative staff reported a significant drop in manual record-request work, and clinicians began seeing more complete patient histories at the point of care turning a compliance deadline into a genuine care-coordination improvement rather than just a box to check. The example illustrates how implementation can turn AB 133 Health Information Exchange in California into an operational improvement. The result shows how better connectivity can support the goals of AB 133 Health Information Exchange in California.
Long Health is a California-based, HITRUST r2 certified health data exchange and AI healthcare technology company, and a designated Qualified Health Information Organization (QHIO) under the DxF. Long Health is HIPAA compliant, with encryption in transit and at rest, and is a member of NVIDIA Inception. The platform connects directly to the Carequality network, with direct-messaging fallback for records not yet reachable through automated lookup, and Long Health assists California organizations with CalHHS Data Sharing Agreement signing and available DxF implementation support.
Beyond DxF and QHIO connectivity, Long Health's broader platform includes AI Scribe for real-time clinical documentation, AI driven Medical Record Summarization, EvalPath for medical legal evaluation workflows, and EHR data migration and integration services all built specifically around California's interoperability requirements rather than adapted from a generic national product. This service model is designed around the practical needs of AB 133 Health Information Exchange in California. The combination of connectivity and implementation support can simplify AB 133 Health Information Exchange in California for providers.
AB 133 is no longer an upcoming requirement for California healthcare organizations it's a current operating condition, with real accountability now attached to it under SB 660. Whether your organization signed the DSA years ago and never finished implementation, or you're confirming your status for the first time, closing the gap is a technical and operational project, not a paperwork exercise. For organizations reviewing their next steps, AB 133 Health Information Exchange in California is now an active compliance and operational priority. The focus should now be on sustained operational readiness for AB 133 Health Information Exchange in California.
AB 133 is a 2021 California law requiring most licensed healthcare organizations to sign a single Data Sharing Agreement and exchange health and social services information in real time under the state’s Data Exchange Framework (DxF).
Mandatory signatories include general acute care and psychiatric hospitals, physician organizations and medical groups, skilled nursing facilities, clinical laboratories, and health plans, including Medi-Cal managed care plans.
Yes. The final extended deadline for smaller and rural organizations was January 31, 2026, and most other mandated entities were required to begin real-time exchange by January 31, 2024.
A Qualified Health Information Organization is a designated intermediary that helps DSA signatories meet their real-time exchange obligations by connecting their systems to the broader health information network.
No. AB 133 and the DxF operate alongside HIPAA and existing California privacy law — signing the DSA doesn’t change an organization’s underlying HIPAA obligations or patient consent requirements.
SB 660, signed in 2025, added transparency and accountability mechanisms to the DxF, moved administration to HCAI, and established a new Stakeholder Advisory Committee that began meeting in 2026. This distinction is especially important when evaluating AB 133 Health Information Exchange in California. The FAQ points reinforce the practical requirements of AB 133 Health Information Exchange in California.