When State Laws Override HIPAA: Preemption Guide
Quick Answer
State laws can override HIPAA when they provide stronger privacy protections. HIPAA explicitly allows more stringent state laws to apply. This is called preemption - HIPAA sets a minimum standard, not a maximum. Healthcare organizations operating in multiple states must comply with the strictest requirements across all jurisdictions. States like California, New York, and Massachusetts have laws stricter than HIPAA.
Understanding HIPAA Preemption
What is Preemption?
Preemption is a legal principle where federal law supersedes conflicting state law. Under preemption, if a state law conflicts with federal law, the federal law controls. However, HIPAA operates differently - it allows state laws to be stronger than federal requirements.
HIPAA's Unique Approach
Unlike many federal laws that completely override state requirements, HIPAA includes an explicit provision allowing state laws to apply when they are more stringent. This approach recognizes that states may choose to provide healthcare consumers with greater privacy protections.
HIPAA as a Floor, Not a Ceiling
HIPAA establishes a minimum standard for healthcare privacy. It is a floor - the lowest level of protection required. States are free to establish higher standards, and many have done so. This means:
State Privacy Laws Stronger Than HIPAA
California Consumer Privacy Act (CCPA)
California's CCPA, effective January 2020, provides broader privacy protections than HIPAA in several ways:
Healthcare organizations in California must comply with both HIPAA and CCPA, following whichever is stricter on each requirement.
California Privacy Rights Act (CPRA)
The CPRA, effective 2023, builds on CCPA with even stronger protections:
New York SHIELD Act
The New York SHIELD Act (Cybersecurity Requirements for Financial Services Companies) includes healthcare providers:
Massachusetts 201 CMR 17.00
Massachusetts has comprehensive data protection regulations requiring:
These requirements often exceed HIPAA's Security Rule specifications.
State Mental Health and Genetic Privacy Laws
Many states have specific laws protecting sensitive health information:
How to Determine Which Law Applies
Step 1: Identify All Applicable Laws
Document all federal and state laws that might apply to your organization:
Step 2: Compare Requirements Side-by-Side
For each major requirement area (access, disclosure, consent, security), compare:
Step 3: Adopt the Stricter Standard
Follow the stricter requirement for all applicable populations. This simplifies compliance and reduces violations.
Compliance Strategy for Multi-State Organizations
Approach 1: Jurisdictional Compliance
Apply different policies based on patient/customer location:
Challenge: High operational complexity and increased compliance risk.
Approach 2: Uniform Highest Standards (Recommended)
Apply the strictest requirements across all operations:
Benefit: Simpler compliance, reduced risk, better privacy for all customers.
Example of Multi-State Compliance
Organization operates in: California, New York, Florida, and Texas
Breach Notification Requirement:
Recommended Standard: 30 days for all breaches (California/Florida standard)
Frequently Asked Questions
If we comply with California law, are we automatically compliant with HIPAA?
Not necessarily. California laws like CCPA/CPRA are broader (applying to all businesses and data types) but may not cover all HIPAA requirements. Healthcare organizations need to identify which requirements are stricter from each law and comply with both. A compliance gap in one law doesn't excuse non-compliance in the other.
What if a state law and HIPAA directly conflict?
If a state law requires something that directly conflicts with HIPAA (rather than being stricter), the organization faces a compliance dilemma. In practice, healthcare legal counsel would advise contacting HHS OCR for guidance. However, most modern state laws are designed to complement rather than directly conflict with HIPAA.
Do federal employees need to comply with state privacy laws?
Yes, federal employees providing healthcare must comply with applicable state laws in states where they serve patients. Federal employees are not exempt from state privacy requirements. Veterans Administration hospitals, military hospitals, and Indian Health Services must follow state laws for applicable patients.
Which states don't have HIPAA-equivalent privacy laws?
Most states have at least some healthcare privacy laws beyond HIPAA. However, some states may have limited or outdated privacy laws. Even states without comprehensive privacy laws are bound by HIPAA, and any stricter state-specific laws (like genetic privacy or mental health laws) still apply. Consult state-specific legal counsel.
Navigate Multi-State HIPAA and Privacy Law Compliance
Healthcare organizations operating across state lines face complex overlapping requirements. Medcurity helps identify applicable state laws, compare requirements, and develop unified compliance strategies that meet the strictest standards across all jurisdictions.
Review Your Multi-State Compliance