Get Security Assessment

HIPAA Compliance in Florida: State Privacy & Data Protection

Florida healthcare organizations must comply with federal HIPAA plus state data protection and privacy laws. This guide covers Florida's Information Protection Act, Patient Self-Determination Act, medical records statutes, and other requirements that extend beyond HIPAA.

Quick Answer

Florida imposes healthcare privacy through multiple statutes: the Florida Information Protection Act (Fla. Stat. §501.171), Patient Self-Determination Act (Fla. Stat. §766.103), and medical records laws (Fla. Stat. §456.059, §395.3025). Florida law generally aligns with HIPAA but adds specific procedural requirements: patients have a statutory right to access records within 30 days, providers must comply with breach notification requirements that exceed HIPAA timelines for certain data types, and the Florida Attorney General enforces healthcare privacy violations. Notably, Florida requires specific informed consent for certain healthcare disclosures and has aggressive enforcement of healthcare privacy statutes by both state AG and private lawsuit rights.

How Florida Law Extends Beyond HIPAA

While Florida law often parallels HIPAA, several statutes impose additional requirements:

1. Florida Information Protection Act (Fla. Stat. §501.171)

Florida's data breach notification law applies to healthcare organizations:

2. Florida Patient Self-Determination Act (Fla. Stat. §766.103)

Healthcare-specific privacy protections:

3. Florida Medical Records Access Law (Fla. Stat. §456.059)

Establishes specific patient rights for medical records:

4. Florida Hospital Report Card Law (Fla. Stat. §395.3025)

Hospital-specific privacy and data security requirements:

5. Florida Mental Health & Substance Abuse Confidentiality

Additional protections under Florida Mental Health Act (Fla. Stat. §394.455) and substance abuse laws:

Key Florida State Statutes & References

Florida Statutes §501.171 (Florida Information Protection Act)
Requires notification of breaches of personal information without unreasonable delay. Applies to healthcare organizations and all entities processing Florida residents' data.
Florida Statutes §456.059 (Patient Access to Medical Records)
Establishes patient right to access medical records within 30 days. Permits reasonable copying and mailing fees. Applies to all healthcare providers.
Florida Statutes §766.103 (Patient Self-Determination Act)
Healthcare-specific patient rights including right to access records, request amendments, and request disclosure restrictions. Requires informed consent for certain uses and disclosures.
Florida Statutes §395.3025 (Hospital Report Card Requirements & Data Security)
Hospital-specific requirements for data security, breach reporting, and public disclosure. Hospitals must implement reasonable safeguards and report breaches to regulatory agencies.
Florida Mental Health Act §394.455 (Mental Health Treatment Records Confidentiality)
Protects confidentiality of mental health treatment records. Requires written authorization for disclosure. Applies to all mental health treatment settings.
Florida Statutes §765 (Advance Directives Act)
Governs advance directives, living wills, and healthcare surrogate designations. Healthcare providers must honor patient wishes documented in advance directives.
Florida Statutes §92.501 et seq. (Privacy Act for Public Records)
Protects medical information in public records. Even public hospital records must protect health information with exemptions for privacy.

Florida Attorney General & Enforcement

Florida enforces healthcare privacy laws through multiple mechanisms:

Enforcement activity: Florida AG has pursued healthcare providers and health insurers for data breaches, inadequate security, and delayed breach notifications. Private lawsuits are common for violations of patient access and medical records laws.

Comparison: HIPAA vs. Florida State Requirements

Area HIPAA Florida Law More Stringent
Patient Access Timeline 60 days to provide records 30 days (Fla. Stat. §456.059) Florida
Breach Notification 60 days of discovery Without unreasonable delay Florida
Authorization for Disclosure Permissive; allows routine use authorizations Specific written authorization for certain uses Florida (for some uses)
Record Format Can provide in standard format Must provide in patient-requested format when feasible Florida
Amendment Rights Provider can deny; dispute resolution required Patient right to request amendments; specific procedure Florida
Law Enforcement Notification Not explicitly required Must notify Florida law enforcement if identity theft risk Florida
Mental Health Records Psychotherapy notes protections Enhanced Florida-specific protections; written authorization required Florida
Patient Rights Scope Standard HIPAA rights Includes self-determination rights, advance directives, disclosure restrictions Florida

Florida-Specific Breach Notification Requirements

Notification Timeline & Method

Content Requirements

Breach notices must include:

Law Enforcement Notification

Public Disclosure Considerations

Encrypted Data Exemption

No notification required if data was properly encrypted and encryption key was not compromised.

Frequently Asked Questions

Does Florida law apply to out-of-state healthcare providers serving Florida patients? +

Yes. Florida's Information Protection Act, Patient Self-Determination Act, and medical records laws apply to any entity processing health information of Florida residents, regardless of where the provider is located. If you have Florida patients or residents whose data you handle, you must comply with Florida's 30-day access requirement, breach notification timelines, and other state requirements. This applies even to purely out-of-state organizations providing telemedicine or remote services to Florida residents.

What are my obligations regarding advance directives in Florida? +

Florida healthcare providers must recognize and honor advance directives (living wills) and healthcare surrogate designations under Florida Statutes §765. When a patient provides a valid advance directive, you must: (1) incorporate it into the patient's medical record, (2) follow the patient's wishes regarding treatment decisions and end-of-life care, and (3) respect healthcare surrogate decisions. You cannot discriminate against patients based on advance directive choices. This is distinct from HIPAA and requires specific knowledge of Florida law.

Can I charge patients to access their medical records in Florida? +

Yes, but only "reasonable" copying and mailing costs. Florida Statute §456.059 permits providers to charge reasonable fees for copying and mailing records. However, "reasonable" is the key standard—you cannot charge excessive fees. Charging $1-2 per page for copies is typically considered reasonable; charging $10 per page would likely be challenged. Unlike HIPAA, which allows costs-based fees, Florida focuses on the reasonableness of the charge. Additionally, patients cannot be denied access to records due to inability to pay fees.

What if my breach of Florida resident data involves mental health or substance abuse information? +

Mental health and substance abuse data in Florida receives enhanced protections. If your breach involves mental health treatment records protected by Florida Mental Health Act §394.455 or substance abuse information protected by federal 42 CFR Part 2, you must: (1) notify affected patients immediately, (2) provide specific information about the breach and safeguards being implemented, (3) offer credit monitoring if identity data was exposed, and (4) notify law enforcement if identity theft risk exists. The breach may trigger additional liability because these records are specially protected. Substance abuse records are particularly sensitive—unauthorized disclosure can result in both federal and state penalties.

Ensure Your Florida Healthcare Organization Complies

Florida's 30-day access requirement and broader privacy laws require robust compliance programs. Get a professional security assessment to identify gaps in HIPAA and Florida-specific compliance.

Get Your Security Assessment