Get Security Assessment

HIPAA Compliance in Colorado: CPA & Healthcare Privacy

Colorado healthcare organizations must comply with federal HIPAA plus state privacy and data protection laws. This guide covers the Colorado Privacy Act (CPA), medical records statutes, Consumer Protection Act, and other Colorado requirements that extend beyond HIPAA.

Quick Answer

Colorado imposes healthcare privacy through multiple frameworks: HIPAA (federal), Colorado Privacy Act (CPA, C.R.S. §6-1-1301 et seq.), medical records laws (C.R.S. §12-36-106), and the Colorado Consumer Protection Act. The CPA, effective 2024, grants Colorado residents rights to know, access, delete, and port their personal information (including health data), with limited exemptions for HIPAA covered entities. Healthcare organizations must provide rapid access to medical records, comply with breach notification within "without unreasonable delay," and implement reasonable security measures. The CPA allows enforcement by the Colorado Attorney General and private lawsuits by consumers, creating significant compliance obligations alongside HIPAA.

How Colorado Law Extends Beyond HIPAA

Colorado law creates overlapping privacy obligations that frequently exceed HIPAA standards:

1. Colorado Privacy Act (CPA - C.R.S. §6-1-1301 et seq.)

Colorado's comprehensive consumer privacy law applies to healthcare organizations:

2. Colorado Medical Records Access Law (C.R.S. §12-36-106)

Establishes patient rights to medical records:

3. Colorado Data Breach Notification Law (C.R.S. §6-1-716)

Requires notification of breaches of personal information:

4. Colorado Consumer Protection Act (C.R.S. §6-1-101 et seq.)

Provides enforcement authority for unfair healthcare practices:

5. Colorado Mental Health & Substance Abuse Confidentiality

Additional protections for sensitive health information:

Key Colorado State Statutes & References

Colorado Revised Statutes §6-1-1301 et seq. (Colorado Privacy Act - CPA)
Comprehensive consumer privacy law granting rights to know, access, delete, and port personal information. Limited exemption for HIPAA covered entities; health data receives "sensitive" classification. Enforced by Colorado AG and private lawsuits.
Colorado Revised Statutes §12-36-106 (Patient Access to Medical Records)
Grants patients right to access medical records in reasonable time. Permits reasonable copying costs. Allows patient-requested formats. Applies to all healthcare providers.
Colorado Revised Statutes §6-1-716 (Data Breach Notification)
Requires notification of breaches of personal information without unreasonable delay. Applies to entities handling Colorado resident data.
Colorado Revised Statutes §6-1-101 et seq. (Consumer Protection Act)
Prohibits unfair and deceptive practices. Healthcare privacy violations can be pursued as consumer protection violations. Allows private right of action and damages including attorney fees.
Colorado Revised Statutes §25.5-1-104 (Mental Health Record Confidentiality)
Protects confidentiality of mental health treatment records. Requires specific authorization for disclosure. Applies to mental health providers and facilities.
Colorado Revised Statutes §27-80-404 (Substance Abuse Treatment Records)
Protects confidentiality of substance abuse treatment information. Implements federal 42 CFR Part 2 plus Colorado requirements.

Colorado Attorney General Enforcement

Colorado enforces healthcare privacy and data protection laws through multiple mechanisms:

Enforcement activity: Since CPA became effective in 2024, Colorado AG has indicated it will actively enforce the law against healthcare organizations. Private lawsuits are expected to increase as consumers become aware of their CPA rights.

Comparison: HIPAA vs. Colorado State Requirements

Area HIPAA Colorado Law More Stringent
Consumer Right to Know Data HIPAA accounting of disclosures required CPA: Right to know all personal information collected and how used Colorado
Data Access Rights 60 days to provide records Reasonable time (typically 30 days); CPA also grants data access rights Colorado
Data Deletion Rights No absolute deletion right for ongoing treatment CPA: Right to request deletion of personal information (with exceptions) Colorado
Data Portability Not explicitly required CPA: Right to obtain data in portable, transferable format Colorado
Breach Notification 60 days of discovery Without unreasonable delay Colorado
Sensitive Data Classification PHI has standard protection CPA: Health data is "sensitive"; stricter requirements Colorado
Private Right of Action No private HIPAA right for patients CPA and Consumer Protection Act allow lawsuits Colorado
Scope of Applicability Covered entities and business associates CPA applies broadly to entities processing Colorado resident data Colorado (broader)

Colorado-Specific Breach Notification & CPA Requirements

Data Breach Notification Timeline

CPA Consumer Rights Implementation

Health Data Specific Considerations

Law Enforcement Notification

Frequently Asked Questions

Does Colorado's CPA apply to HIPAA covered entities? +

Partially. The CPA provides a limited exemption for HIPAA covered entities and business associates regarding their treatment, payment, and healthcare operations functions. However, the exemption is not complete. For example, if a healthcare organization uses health data for purposes beyond HIPAA-permitted uses (e.g., marketing, profiling, non-health-related business), CPA still applies. Additionally, CPA's data deletion and portability rights still apply to certain non-treatment information. Healthcare organizations should not assume HIPAA covered entity status fully exempts them from CPA—CPA compliance should still be part of compliance strategy.

What is Colorado's "reasonable time" for providing medical records access? +

Colorado Statute §12-36-106 requires access in "reasonable time" without specifying a fixed deadline like HIPAA's 60 days. In practice, "reasonable time" is typically interpreted as 30 days or less, similar to several other states. Additionally, if a patient requests records in electronic format through the CPA, the timeline becomes 45 days under the CPA (extendable once for 45 additional days). Best practice is to respond within 30 days to align with both HIPAA and Colorado law expectations.

Can patients delete their health data under Colorado law? +

Under the Colorado Privacy Act, patients have a right to request deletion of their personal information, including health data. However, there are important exceptions: (1) Data needed for ongoing treatment cannot be deleted; (2) Data required by law to be retained (like records required by statutes of limitation) cannot be deleted; (3) Data needed for security, fraud prevention, or other legitimate purposes can be retained. Healthcare organizations must balance CPA deletion rights with healthcare record retention requirements. When a deletion request is made, evaluate whether it falls within an exception before denying it.

What does CPA's "data portability" requirement mean for healthcare organizations? +

CPA's right to data portability requires you to provide a patient's personal information in a portable, commonly used, machine-readable format (e.g., CSV, JSON, XML) upon request. For healthcare organizations, this means patients can request their health data in a format they can use in other systems. This requirement goes beyond HIPAA's records access right—patients under HIPAA can request copies in any format you already maintain; CPA requires you to convert data to commonly used formats if requested. This can require technical work and system changes. Healthcare organizations should plan for CPA portability requests by determining which systems can export data in common formats.

Ensure Your Colorado Healthcare Organization Complies

Colorado's Privacy Act creates new consumer rights and enforcement opportunities. Get a professional security assessment to ensure compliance with HIPAA, CPA, and Colorado privacy laws.

Get Your Security Assessment