Medcurity Get Compliant Now

Why Veterinarians Don't Need HIPAA (But Need This Instead)

Last updated: March 2026 | 9 min read

Quick Answer

HIPAA only applies to healthcare providers treating humans, so veterinarians are NOT covered by HIPAA. However, veterinary practices must comply with state veterinary practice laws requiring confidentiality, state consumer protection laws (like CCPA in California), and ethical standards set by veterinary medical boards. While the specific legal framework differs from HIPAA, best practices for protecting pet owner information and medical records are similar.

Why Veterinarians Are Exempt From HIPAA

The Fundamental Limitation of HIPAA

HIPAA (Health Insurance Portability and Accountability Act) explicitly applies only to healthcare providers treating human patients. The statute reads:

"This rule applies to covered entities and business associates that store or transmit protected health information. Protected health information means information in a medical record or health plan about an individual..."

Since veterinary medicine treats animals, not humans, HIPAA does not apply to veterinary practices regardless of:

• Whether they bill pet insurance
• Whether they maintain electronic medical records
• Whether they transmit information electronically
• How large the practice is
• Whether they process credit cards or financial information

Clear Legal Distinction

This distinction is not ambiguous. HHS has explicitly confirmed that veterinary practices are not HIPAA-covered entities. No form of veterinary practice - from solo practitioners to large animal hospitals - is subject to HIPAA regulations.

What About Owner Information?

The critical distinction is that HIPAA protects "health information." Pet owner contact information and payment records may be subject to other laws (consumer protection, data privacy), but they are not "protected health information" under HIPAA because they don't relate to human health.

Laws That Do Apply to Veterinary Practices

State Veterinary Practice Acts

Every state has a Veterinary Practice Act that regulates veterinary medicine and includes confidentiality requirements. These acts typically require:

• Maintenance of confidential client and patient records
• Professional ethics including confidentiality
• Records retention requirements (often 2-5 years)
• Restrictions on disclosure without consent
• Discipline for violations of confidentiality

Veterinarians licensed in a state must comply with that state's veterinary practice act regardless of federal exemption from HIPAA.

State Consumer Data Protection Laws

Many states have enacted comprehensive consumer data privacy laws that may apply to veterinary practices:

California CCPA/CPRA: Applies to veterinary practices if they collect personal information about California residents and meet threshold requirements (revenue over $25M, or collecting data on 100k+ consumers). Requires privacy policies and consumer rights.

Colorado Privacy Act: Applies to veterinary practices processing personal information about Colorado residents.

Virginia Consumer Data Protection Act: Applies to veterinary practices processing Virginia residents' personal data.

Other State Laws: New Hampshire, New Mexico, Kentucky, and others have data privacy laws that may apply.

State Data Breach Notification Laws

All 50 states have data breach notification laws that apply to veterinary practices. If a data breach exposes client personal information, veterinary practices must:

• Notify affected individuals
• Notify state attorney general (if above threshold)
• Notify credit bureaus (for large breaches)
• Document notification process

Fair Credit Reporting Act (FCRA)

If veterinary practices maintain credit information, use credit reports, or allow payment plans with credit checks, they must comply with FCRA requirements including:

• Proper use of credit information
• Fair credit reporting practices
• Dispute resolution procedures

State Medical Record Laws

Several states have enacted specific laws governing veterinary medical records:

• Requirements for record maintenance and security
• Patient (owner) access rights
• Record retention periods
• Provisions for closure and record transfer

Pet Insurance Regulatory Requirements

If veterinary practices work with pet insurance companies, they may be subject to:

• Insurance company BAA-like requirements
• Specific billing and claims submission requirements
• Record access provisions for insurance investigations

Professional Ethics and Standards

AVMA Code of Professional Conduct

The American Veterinary Medical Association (AVMA) Code of Professional Conduct requires:

• Maintenance of client and patient confidentiality
• Professional responsibility in handling medical records
• Ethical handling of client information
• Confidentiality as a professional duty

While not legally binding like HIPAA, AVMA Code violations can result in professional discipline and license suspension.

State Veterinary Medical Board Standards

State boards typically enforce:

• Confidentiality of medical records
• Ethical conduct regarding client information
• Record access procedures
• Discipline for breaches of confidentiality

Comparison: HIPAA vs Veterinary Regulations

Aspect HIPAA (Human Healthcare) Veterinary Practices
Primary Regulator Federal (HHS/OCR) State veterinary medical boards
Confidentiality Required Yes, explicit federal requirement Yes, via state practice acts and professional ethics
Written Policies Required (Notice of Privacy Practices) Not federally required, but best practice
Breach Notification Within 60 days to individual, media, HHS Per state data breach law timeline
Patient Access Rights Explicit right to access records within 30 days Owner access typically recognized in practice acts
Civil Penalties $100-$50,000 per violation; $1.5M annual max License suspension/revocation (no federal fines)
Business Associates Direct HIPAA liability; BAA required No federal requirement; practice-specific

Best Practices for Veterinary Practice Privacy

Even Without HIPAA, Implement Protections

While HIPAA doesn't apply, veterinary practices should implement:

• Written privacy policies for clients
• Secure electronic record systems
• Limited staff access to records
• Encrypted digital communications
• Secure backup systems
• Staff confidentiality agreements
• Data breach response plans
• Regular security assessments

Record Retention

Check state veterinary practice act requirements. Typical recommendations:

• Maintain records for minimum of 2-5 years from last visit
• Longer for serious conditions or potential litigation
• Securely delete after retention period

Disclosure Procedures

Implement disclosure controls similar to HIPAA:

• Get written authorization before releasing records
• Document what was released and to whom
• Restrict access to necessary information only
• Maintain audit logs of access and disclosures

Frequently Asked Questions

If a pet owner's information is breached, do I still need to notify them?

Yes, under state data breach notification laws. While not HIPAA, all states require notification of personal information breaches. If client names, addresses, phone numbers, or email are exposed, you must notify affected clients per your state's timeline and notify the state attorney general if above threshold (typically 500+ residents).

Can I share a pet's medical history with a new veterinarian without owner permission?

Professional ethics and state practice acts typically require consent. While HIPAA doesn't apply, the veterinary profession's ethical standards and many state laws require you to get authorization before releasing records to another provider. This should be part of your professional standard.

If I work with pet insurance, do I need HIPAA compliance?

No federal HIPAA requirement, but insurance companies often have their own security and confidentiality requirements in their contracts. Review insurance company contracts carefully. You must also comply with state consumer protection laws and data privacy laws (if applicable in your state).

What's the penalty for violating confidentiality in a veterinary practice?

Not a federal fine like HIPAA, but violations of state veterinary practice act confidentiality requirements can result in state veterinary board discipline, including license suspension or revocation. This is the most serious consequence. Additionally, civil lawsuits from clients are possible in some states.

Implement Privacy Best Practices Even Without HIPAA

Veterinary practices should implement privacy and security protections to comply with state laws and professional ethics, protect client trust, and prepare for potential future regulations. Medcurity can help veterinary practices develop compliant privacy policies and secure data handling procedures.

Consult About Veterinary Privacy