HIPAA vs State Privacy Laws: Which Rules Apply to Your Organization?
The single most important thing to understand about HIPAA and state privacy law is that HIPAA is a floor, not a ceiling. It sets a national minimum standard for protecting health information, but it does not stop a state from demanding more. That is what makes this topic distinct: complying with HIPAA does not mean you have complied with everything, and in a growing number of cases a state law reaches data and organizations that HIPAA never touches.
How preemption actually works
HIPAA’s preemption rule lives at 45 CFR § 160.203. As a default, HIPAA overrides “contrary” state laws — but there is a critical exception: state laws that are more stringent in protecting individual privacy, or that give individuals greater rights of access, are not preempted. In practice this means you rarely get to pick one law over the other. When a state requires faster breach notice, stronger patient consent, or broader access rights than HIPAA, the state law governs, and you satisfy both by meeting the higher bar.
State medical-privacy statutes that go beyond HIPAA
Several states have long-standing medical-privacy laws stricter than HIPAA. California’s Confidentiality of Medical Information Act (CMIA), for example, imposes consent and disclosure requirements that exceed the federal baseline, and many states have heightened protections for especially sensitive categories — mental health, substance use, HIV status, genetic information, and, increasingly, reproductive-health data. If you operate in multiple states, “HIPAA-compliant” is necessary but not sufficient; you have to layer each state’s specific rules on top.
The new frontier: consumer health data laws
The fastest-moving area is health data held outside HIPAA. Washington’s My Health My Data Act and comparable state measures regulate health-related information collected by apps, websites, and other businesses that are not covered entities. These laws can apply to consumer wellness apps, marketing analytics, and health-adjacent services that HIPAA does not reach at all. The lesson is that the question is no longer just “are we HIPAA-compliant” but “which privacy regimes touch each type of data we hold.”
Breach notification: usually more than one law fires
Nearly every state has its own breach-notification statute, frequently with shorter deadlines or broader triggers than HIPAA’s 60-day rule. A single incident can simultaneously trigger HIPAA’s Breach Notification Rule and one or more state laws, each with distinct timelines, content requirements, and regulators to notify. Your incident-response plan has to account for the full stack, not just the federal piece.
Risk analysis and the proposed 2026 rule
Sorting out which rules apply starts with knowing where your patients and data live — precisely the data-flow mapping the Security Rule’s risk analysis requirement under 45 CFR § 164.308(a)(1)(ii)(A) demands. A thorough Security Risk Analysis documents what data you hold, where it goes, and which states’ residents it concerns, which is the foundation for multi-jurisdiction compliance. The proposed 2026 Security Rule update — HHS’s Notice of Proposed Rulemaking published in December 2024 — would raise the federal floor further by making safeguards like encryption and multi-factor authentication explicit requirements. It is a proposal, not final, with a 240-day compliance window once published; even so, a rising federal floor does not displace stricter state law, so both will continue to apply.
How Medcurity helps
Medcurity’s guided Security Risk Analysis documents your data flows and storage locations — the map you need before you can answer which state laws apply to which records. For multi-state organizations, that inventory turns an overwhelming question into a structured one. The platform is $499/year (about $42/month) for most practices; larger or multi-entity organizations can request a quote. For related reading, see our HIPAA Security Rule requirements guide and the HIPAA compliance checklist.
Frequently asked questions
If HIPAA and a state law conflict, which one wins?
Generally the more stringent one. HIPAA expressly preempts contrary state laws under 45 CFR § 160.203, but it carves out an exception for state laws that are more protective of individual privacy or that grant individuals greater rights. So when a state law gives patients more access, shorter breach-notice windows, or stronger consent requirements, that state law controls — you comply with both by meeting the stricter standard.
Can a state law apply to data HIPAA doesn’t cover?
Yes, and this is increasingly common. HIPAA only applies to covered entities and business associates. Newer consumer-health-data laws — such as Washington’s My Health My Data Act and similar measures — reach health-related data held by companies that are not HIPAA covered entities at all, including apps and websites. An organization can be outside HIPAA but squarely inside a state privacy law.
Do state breach notification laws still apply if we follow HIPAA?
Usually yes. Nearly every state has its own data-breach notification statute, and many have shorter deadlines or broader definitions than HIPAA’s Breach Notification Rule. A single incident can trigger both HIPAA and one or more state laws simultaneously, each with its own timeline and required content. You generally have to satisfy all of them.
How do we keep track of which laws apply?
Start by mapping where your patients and data are located, since state laws often follow the resident, not just your office. Then identify the categories of data you hold and the strictest standard that applies to each. A current risk analysis that documents data flows and locations is the foundation that makes this manageable, especially for multi-state organizations.