Medcurity Get Compliant Now

When State Laws Override HIPAA: Preemption Guide

Last updated: March 2026 | 11 min read

Quick Answer

State laws can override HIPAA when they provide stronger privacy protections. HIPAA explicitly allows more stringent state laws to apply. This is called preemption - HIPAA sets a minimum standard, not a maximum. Healthcare organizations operating in multiple states must comply with the strictest requirements across all jurisdictions. States like California, New York, and Massachusetts have laws stricter than HIPAA.

Understanding HIPAA Preemption

What is Preemption?

Preemption is a legal principle where federal law supersedes conflicting state law. Under preemption, if a state law conflicts with federal law, the federal law controls. However, HIPAA operates differently - it allows state laws to be stronger than federal requirements.

HIPAA's Unique Approach

Unlike many federal laws that completely override state requirements, HIPAA includes an explicit provision allowing state laws to apply when they are more stringent. This approach recognizes that states may choose to provide healthcare consumers with greater privacy protections.

HIPAA Preemption Rule: State laws are preempted only to the extent that they are less stringent than HIPAA. State laws that are more stringent than HIPAA remain in effect and must be followed.

HIPAA as a Floor, Not a Ceiling

HIPAA establishes a minimum standard for healthcare privacy. It is a floor - the lowest level of protection required. States are free to establish higher standards, and many have done so. This means:

• HIPAA provides baseline protections nationwide
• States can require more than HIPAA
• States cannot require less than HIPAA
• Covered entities must follow the stricter standard

State Privacy Laws Stronger Than HIPAA

California Consumer Privacy Act (CCPA)

California's CCPA, effective January 2020, provides broader privacy protections than HIPAA in several ways:

• Applies to all businesses processing California residents' data, not just healthcare
• Stronger right to know (access) and right to delete requirements
• Prohibits discrimination against consumers for exercising CCPA rights
• Requires opt-in consent for certain data sales
• Lower threshold for breach notification (any unauthorized access)

Healthcare organizations in California must comply with both HIPAA and CCPA, following whichever is stricter on each requirement.

California Privacy Rights Act (CPRA)

The CPRA, effective 2023, builds on CCPA with even stronger protections:

• Expands consumer rights including right to correct and right to limit use
• Creates new category of "sensitive personal information"
• Strengthens automated decision-making protections
• Establishes California Privacy Protection Agency to enforce

New York SHIELD Act

The New York SHIELD Act (Cybersecurity Requirements for Financial Services Companies) includes healthcare providers:

• Defines "biometric information" broadly including health information
• Requires breach notification "without unreasonable delay" (potentially stricter than HIPAA's 60-day standard)
• Requires reasonable safeguards
• Applies to New York residents' data regardless of where organization is located

Massachusetts 201 CMR 17.00

Massachusetts has comprehensive data protection regulations requiring:

• Written information security program
• Access controls and authentication
• Encryption of personal information
• Regular security assessments

These requirements often exceed HIPAA's Security Rule specifications.

State Mental Health and Genetic Privacy Laws

Many states have specific laws protecting sensitive health information:

Mental Health Records: Stricter access requirements in many states (Colorado, Florida, Kentucky)
Genetic Information: Enhanced protections in New York, Texas, California
HIV/AIDS Information: Specific notice and consent requirements in most states
Substance Abuse: Many states have laws superseding 42 CFR Part 2

How to Determine Which Law Applies

Step 1: Identify All Applicable Laws

Document all federal and state laws that might apply to your organization:

• HIPAA (baseline)
• State privacy laws in every state where you operate
• Specific health information laws (mental health, genetic, etc.)
• Laws for states where patients/customers reside

Step 2: Compare Requirements Side-by-Side

For each major requirement area (access, disclosure, consent, security), compare:

• How stringent is the HIPAA requirement?
• What does the state law require?
• Which is stricter?

Step 3: Adopt the Stricter Standard

Follow the stricter requirement for all applicable populations. This simplifies compliance and reduces violations.

Example: California requires breach notification "without unreasonable delay" (potentially faster than 60 days), while HIPAA allows 60 days. A California healthcare organization should notify within the fastest requirement between the two laws, typically 30 days or less.

Compliance Strategy for Multi-State Organizations

Approach 1: Jurisdictional Compliance

Apply different policies based on patient/customer location:

• Maintain separate compliance standards by state
• Different consent forms and authorization templates
• Separate breach notification timelines
• Complex but theoretically compliant

Challenge: High operational complexity and increased compliance risk.

Approach 2: Uniform Highest Standards (Recommended)

Apply the strictest requirements across all operations:

• Identify the most stringent requirement across all states
• Apply that standard to all patients/customers
• Simplifies operations and training
• Reduces compliance violations

Benefit: Simpler compliance, reduced risk, better privacy for all customers.

Example of Multi-State Compliance

Organization operates in: California, New York, Florida, and Texas

Breach Notification Requirement:

• HIPAA: 60 days
• California: "Without unreasonable delay" (interpreted as ~30 days)
• New York: "Without unreasonable delay"
• Florida: 30 days
• Texas: 60 days

Recommended Standard: 30 days for all breaches (California/Florida standard)

Frequently Asked Questions

If we comply with California law, are we automatically compliant with HIPAA?

Not necessarily. California laws like CCPA/CPRA are broader (applying to all businesses and data types) but may not cover all HIPAA requirements. Healthcare organizations need to identify which requirements are stricter from each law and comply with both. A compliance gap in one law doesn't excuse non-compliance in the other.

What if a state law and HIPAA directly conflict?

If a state law requires something that directly conflicts with HIPAA (rather than being stricter), the organization faces a compliance dilemma. In practice, healthcare legal counsel would advise contacting HHS OCR for guidance. However, most modern state laws are designed to complement rather than directly conflict with HIPAA.

Do federal employees need to comply with state privacy laws?

Yes, federal employees providing healthcare must comply with applicable state laws in states where they serve patients. Federal employees are not exempt from state privacy requirements. Veterans Administration hospitals, military hospitals, and Indian Health Services must follow state laws for applicable patients.

Which states don't have HIPAA-equivalent privacy laws?

Most states have at least some healthcare privacy laws beyond HIPAA. However, some states may have limited or outdated privacy laws. Even states without comprehensive privacy laws are bound by HIPAA, and any stricter state-specific laws (like genetic privacy or mental health laws) still apply. Consult state-specific legal counsel.

Navigate Multi-State HIPAA and Privacy Law Compliance

Healthcare organizations operating across state lines face complex overlapping requirements. Medcurity helps identify applicable state laws, compare requirements, and develop unified compliance strategies that meet the strictest standards across all jurisdictions.

Review Your Multi-State Compliance