Get Security Assessment

HIPAA Compliance in Minnesota: Health Records Act & State Laws

Minnesota healthcare organizations must comply with federal HIPAA plus state-specific privacy laws. This guide covers the Minnesota Health Records Act, Government Data Practices Act, genetic privacy statutes, and other Minnesota requirements that extend beyond HIPAA.

Quick Answer

Minnesota imposes healthcare privacy through multiple frameworks: HIPAA (federal), the Minnesota Health Records Act (Minn. Stat. §144.291-§144.298), Government Data Practices Act (Minn. Stat. §13.01 et seq.), and genetic privacy laws. The Health Records Act provides patient rights including access to records within 30 days, restrictions on disclosure, and amendment rights. Notably, Minnesota has one of the nation's strictest genetic privacy laws (Minn. Stat. §181B.01 et seq.), restricting genetic testing, disclosure of genetic information, and employment discrimination. Additionally, Minnesota's Government Data Practices Act applies to public sector healthcare, creating additional transparency and privacy requirements. Healthcare organizations must comply across all frameworks—Minnesota's healthcare-specific requirements are notably comprehensive.

How Minnesota Law Extends Beyond HIPAA

Minnesota law creates multiple healthcare-specific privacy obligations that exceed HIPAA standards:

1. Minnesota Health Records Act (Minn. Stat. §144.291 et seq.)

Establishes comprehensive patient rights to health records:

2. Minnesota Genetic Privacy Act (Minn. Stat. §181B)

One of the nation's strictest genetic privacy laws:

3. Minnesota Government Data Practices Act (Minn. Stat. §13.01 et seq.)

Applies to public sector healthcare entities:

4. Minnesota Data Breach Notification Law (Minn. Stat. §13.055)

Requires notification of breaches of personal information:

5. Minnesota Mental Health & Substance Abuse Confidentiality

Additional protections for sensitive health information:

Key Minnesota State Statutes & References

Minnesota Statutes §144.291 et seq. (Health Records Act)
Establishes patient rights to access records within 30 days, request amendments, and restrict disclosures. Requires written authorization for disclosure. Applies to all healthcare providers handling Minnesota resident records.
Minnesota Statutes §181B (Genetic Privacy Act)
Restricts genetic testing, disclosure of genetic information, and use in employment/insurance decisions. One of the nation's strictest genetic privacy laws. Provides private right of action with statutory damages.
Minnesota Statutes §13.01 et seq. (Government Data Practices Act)
Applies to public sector healthcare entities. Classifies health data as private; restricts use and disclosure. Creates stronger patient privacy protections for public hospitals and health departments.
Minnesota Statutes §13.055 (Data Breach Notification)
Requires notification of breaches of personal information without unreasonable delay. Applies to all entities handling Minnesota resident data.
Minnesota Statutes §144.335 (Mental Health Treatment Records Confidentiality)
Protects confidentiality of mental health treatment records. Requires written authorization for disclosure. Specific consent form required; blanket authorizations not permitted.
Minnesota Statutes §245C (Background Studies & Substance Abuse Confidentiality)
Protects substance abuse treatment information. Implements federal 42 CFR Part 2 plus Minnesota state enhancements.
Minnesota Statutes §626.8471 (Sexual Assault Examination Records Confidentiality)
Special confidentiality protections for sexual assault examination records. Requires specific consent for disclosure.

Minnesota Attorney General Enforcement

Minnesota enforces healthcare privacy and data protection laws through multiple mechanisms:

Enforcement activity: Minnesota AG has actively enforced healthcare privacy laws, particularly genetic privacy violations and healthcare data breaches. The state's strong privacy advocacy has resulted in robust enforcement.

Comparison: HIPAA vs. Minnesota State Requirements

Area HIPAA Minnesota Law More Stringent
Patient Access Timeline 60 days to provide records 30 days (Health Records Act) Minnesota
Amendment Request Timeline 60 days to respond with decision 15 days (Health Records Act) Minnesota
Authorization Requirements General authorization acceptable Specific written authorization required; must specify information, recipient, duration Minnesota
Genetic Information Protection Covered under PHI; standard protections Minn. Stat. §181B: Strict restrictions on testing, disclosure, employment/insurance use Minnesota
Genetic Employment Discrimination Not specifically addressed Explicit prohibition; employers cannot request or use genetic information Minnesota
Genetic Insurance Restrictions Limited restrictions Cannot use genetic information for coverage or rate decisions Minnesota
Genetic Testing Consent Informed consent required Specific written informed consent with detailed information required Minnesota
Mental Health Authorization Standard authorization acceptable Specific written authorization required; blanket forms prohibited Minnesota

Minnesota-Specific Genetic Privacy & Health Records Requirements

Health Records Access & Amendment

Genetic Privacy Act Restrictions

Employment & Insurance Protections (Genetic Act)

Data Breach Notification

Frequently Asked Questions

Can healthcare organizations perform genetic testing without specific written consent? +

No. Under Minnesota Genetic Privacy Act §181B.01, healthcare organizations must obtain specific written informed consent before performing any genetic testing. The consent must not be a blanket authorization—it must specifically explain: (1) What genetic test will be performed, (2) The purpose of the test, (3) Risks and limitations, (4) How results will be shared, and (5) How genetic information will be stored. A general HIPAA authorization is insufficient. Genetic testing performed without proper consent violates Minnesota law and exposes organizations to civil liability including statutory damages.

What are the employment law implications of Minnesota's Genetic Privacy Act? +

Under Minnesota Stat. §181B, employers cannot request genetic information, require genetic testing, or use genetic information in hiring, firing, or promotion decisions. Healthcare organizations that employ people are bound by this law. If your organization creates or maintains genetic information about employees (e.g., through workplace health programs or occupational health screening), you cannot use that information for employment decisions. Violations can result in employment lawsuits with statutory damages. Additionally, if you're a healthcare provider sharing patient genetic information with employers, that creates additional liability. The law is clear: genetic information cannot be used for employment purposes in Minnesota.

Can insurance companies use genetic information under Minnesota law? +

No. Minnesota Genetic Privacy Act §181B prohibits insurance companies from using genetic information to make coverage decisions, determine rates, or deny coverage. This is more restrictive than federal law (which allows some genetic discrimination in insurance). If your healthcare organization shares genetic test results with insurance companies for coverage purposes, you may be violating Minnesota law. Additionally, if your organization is involved in insurance-related decisions (like insurance underwriting), you cannot use genetic information. Minnesota's genetic privacy protections are among the strongest in the nation.

What's the difference between Minnesota's amendment timeline and HIPAA's? +

Minnesota's Health Records Act requires healthcare providers to respond to amendment requests within 15 days. HIPAA allows 60 days. Minnesota's timeline is much tighter. When a Minnesota patient requests a correction or addition to their medical record, you must respond within 15 days—either by making the amendment or denying it with an explanation. This creates operational challenges for large healthcare organizations managing many amendment requests. Additionally, Minnesota law requires specific handling of denials (patients can attach disagreement statements to their records), creating administrative burden. Healthcare organizations in Minnesota need efficient amendment tracking and response systems.

Ensure Your Minnesota Healthcare Organization Complies

Minnesota's strict genetic privacy law and faster health records timelines create unique compliance requirements. Get a professional security assessment to ensure compliance with HIPAA, Minnesota Health Records Act, and genetic privacy laws.

Get Your Security Assessment