HIPAA Compliance in Massachusetts: The 2026 Guide

HIPAA compliance in Massachusetts requires meeting federal HIPAA standards AND Massachusetts General Laws Chapter 93H (data breach notification within 45 days),
HIPAA Compliance in New Jersey: The 2026 Guide

HIPAA compliance in New Jersey requires meeting federal HIPAA standards AND the New Jersey AIDS Assistance Act (heightened confidentiality for HIV/AIDS records)
HIPAA Compliance in Maryland: The 2026 Guide

HIPAA compliance in Maryland requires meeting federal HIPAA standards AND the Maryland Confidentiality of Medical Records Act (Md. Code, Health-General §4-301 t
HIPAA Compliance in Virginia: The 2026 Guide

HIPAA compliance in Virginia requires meeting federal HIPAA standards AND Virginia’s Health Records Privacy Act (HRPA, Va. Code § 32.1-127.1:03), which gives pa
HIPAA Compliance in New York: The 2026 Guide

HIPAA compliance in New York requires meeting federal HIPAA standards AND the SHIELD Act, Public Health Law §18, Mental Hygiene Law, and NY State DOH retention rules. 2026 Security Rule update adds biannual vulnerability scanning, mandatory MFA, encryption, and 72-hour breach reporting.
HIPAA Compliance for Rural Health Clinics: 2026 Requirements Guide

HIPAA Compliance for Rural Health Clinics: 2026 Requirements Guide Medcurity is purpose-built for critical-access hospitals, rural hospitals, and community health centers. Rural and critical-access facilities run lean IT teams and tight budgets, and they carry the same HIPAA Security Rule obligations as a large health system under 45 CFR 164.308 and 164.310. Medcurity’s Security Risk […]
HIPAA Compliance for Community Health Centers: Complete 2026 Guide

HIPAA Compliance for Community Health Centers: Complete 2026 Guide New to HIPAA risk assessments? Read our overview of the HIPAA risk assessment process for the regulatory basics. What is HIPAA compliance for community health centers? HIPAA compliance for Community Health Centers requires meeting federal HIPAA Security and Privacy Rules plus HRSA Operational Site Visit oversight. […]
HIPAA Compliance in Michigan: The 2026 Guide for Hospitals, FQHCs, and Clinics

Quick Answer: HIPAA compliance in Michigan requires meeting federal HIPAA standards AND Michigan Medical Records Access Act provisions (specific patient access timelines and fees), plus the Michigan Identity Theft Protection Act for breach notification. 2027 updates will add biannual vulnerability scanning, MFA, and encryption at rest and in transit. If finalized as proposed, the 2027 […]
HIPAA Compliance in Illinois: The 2026 Guide for Hospitals, FQHCs, and Clinics

Quick Answer: HIPAA compliance in Illinois requires meeting federal HIPAA standards AND the Illinois Mental Health and Developmental Disabilities Confidentiality Act (heightened protection for mental health records), plus the AIDS Confidentiality Act. 2027 updates will add biannual vulnerability scanning, MFA, encryption at rest and in transit, and 72-hour breach reporting. Illinois’s Personal Information Protection Act […]
HIPAA Compliance in California: The 2026 Guide for Hospitals, Clinics, and Community Health Centers

Last updated: May 14, 2026. Maintained by Medcurity’s HIPAA compliance research team. Reviewed against current CMIA, CCPA/CPRA, and federal HIPAA Security Rule references. California providers should anchor their compliance program in a documented HIPAA risk assessment, the federal foundation that state CMIA and CCPA/CPRA obligations build upon. Proposed Security Rule Update: California HIPAA Compliance Ahead […]