Get Security Assessment

HIPAA Compliance in Virginia: VCDPA & Healthcare Privacy

Virginia healthcare organizations must comply with federal HIPAA plus state privacy laws. This guide covers the Virginia Consumer Data Protection Act (VCDPA), medical records statutes, breach notification laws, and other Virginia requirements that extend beyond HIPAA.

Quick Answer

Virginia imposes healthcare privacy through three main frameworks: HIPAA (federal), Virginia Consumer Data Protection Act (VCDPA, Va. Code §59.1-575 et seq.), and medical records statutes (Va. Code §32.1-127.1:03). The VCDPA, effective 2024, grants Virginia residents rights to know, access, delete, and port their personal information (including health data), with limited exemptions for HIPAA covered entities. Additionally, Virginia requires prompt breach notification, strict medical records access procedures, and enforcement by both the Virginia Attorney General and private consumers. Healthcare organizations must comply with overlapping requirements across all frameworks—the VCDPA adds new consumer rights that create compliance complexity alongside traditional HIPAA obligations.

How Virginia Law Extends Beyond HIPAA

Virginia law creates multiple privacy obligations that frequently exceed or extend HIPAA standards:

1. Virginia Consumer Data Protection Act (VCDPA - Va. Code §59.1-575 et seq.)

Virginia's comprehensive consumer privacy law applies to healthcare organizations:

2. Virginia Medical Records Access Law (Va. Code §32.1-127.1:03)

Establishes specific patient rights to medical records:

3. Virginia Data Breach Notification Law (Va. Code §18.2-186.6)

Requires notification of breaches of personal information:

4. Virginia Consumer Protection Act (Va. Code §59.1-200 et seq.)

Provides enforcement authority for unfair healthcare practices:

5. Virginia Mental Health & Substance Abuse Confidentiality

Additional protections for sensitive health information:

Key Virginia State Statutes & References

Virginia Code §59.1-575 et seq. (Virginia Consumer Data Protection Act - VCDPA)
Comprehensive consumer privacy law granting rights to know, access, delete, correct, and port personal information. Limited exemption for HIPAA covered entities. Health data is "sensitive" requiring stricter handling. Enforced by Virginia AG and private consumers.
Virginia Code §32.1-127.1:03 (Patient Access to Medical Records)
Grants patients right to access medical records within 15 working days. Permits reasonable copying costs for paper records; electronic copies at reasonable or no cost. Applies to all Virginia healthcare providers.
Virginia Code §18.2-186.6 (Data Breach Notification)
Requires notification of breaches of personal information without unreasonable delay. Applies to all entities handling Virginia resident data, including healthcare organizations.
Virginia Code §59.1-200 et seq. (Consumer Protection Act)
Prohibits unfair and deceptive practices. Healthcare privacy violations can be pursued as consumer protection violations. Private right of action available.
Virginia Code §37.1-84.1 (Mental Health Record Confidentiality)
Protects confidentiality of mental health treatment records. Requires authorization for disclosure. Applies to mental health providers and facilities in Virginia.
Virginia Code §54.1-2400 et seq. (Health Professions Regulations & Confidentiality)
General healthcare provider confidentiality requirements. Establishes healthcare professions' duties regarding patient privacy and record confidentiality.

Virginia Attorney General Enforcement

Virginia enforces healthcare privacy and consumer protection laws through multiple mechanisms:

Enforcement activity: Since VCDPA became effective in 2024, Virginia AG has indicated it will actively enforce the law. Given Virginia's proximity to technology hubs and healthcare industry presence, enforcement has been and will continue to be robust.

Comparison: HIPAA vs. Virginia State Requirements

Area HIPAA Virginia Law More Stringent
Patient Access Timeline 60 days to provide records 15 working days (Va. Code §32.1-127.1:03) Virginia
Right to Know Data Collected Limited right (accounting of disclosures) VCDPA: Right to know all personal information collected Virginia
Data Access Rights PHI access VCDPA: Personal information access plus HIPAA rights Virginia
Data Deletion Rights No absolute deletion right VCDPA: Right to request deletion (with exceptions) Virginia
Data Portability Not explicitly required VCDPA: Right to obtain data in portable format Virginia
Breach Notification 60 days of discovery Without unreasonable delay (interpreted as days) Virginia
Sensitive Data Classification PHI protection standard VCDPA: Health data is "sensitive"; stricter handling Virginia
Private Right of Action No private HIPAA right VCDPA and Consumer Protection Act allow lawsuits Virginia

Virginia-Specific Breach Notification & VCDPA Requirements

Data Breach Notification Timeline

VCDPA Consumer Rights Implementation

Health Data Specific Handling (VCDPA)

Medical Records Specific Requirements

Frequently Asked Questions

Do HIPAA covered entities have to comply with the VCDPA? +

Partially. HIPAA covered entities have a limited exemption from VCDPA for activities regulated under HIPAA (treatment, payment, healthcare operations). However, the exemption is not absolute. If a covered entity uses health data for purposes beyond HIPAA's permitted uses (e.g., marketing, analytics for non-healthcare purposes, profiling for non-treatment purposes), VCDPA applies to those uses. Additionally, VCDPA's rights to delete and data portability may apply even to HIPAA covered entities in certain circumstances. Healthcare organizations should not assume HIPAA covered status fully exempts them from VCDPA—selective compliance with VCDPA may still be necessary.

What's the difference between HIPAA's 60-day access requirement and Virginia's 15-day requirement? +

HIPAA allows 60 days to provide records access. Virginia law (Va. Code §32.1-127.1:03) requires access within 15 working days—significantly faster. This creates a compliance challenge: Virginia healthcare providers must meet the 15-day timeline. Additionally, VCDPA allows 45 days for personal information access requests. When a Virginia patient requests records, you must respond in the tighter timeline (15 working days). This requires efficient medical records retrieval systems and processes.

Can Virginia patients request deletion of their health data? +

Under VCDPA, yes—patients can request deletion of their personal information, including health data. However, there are important exceptions: (1) Data needed for ongoing or future treatment cannot be deleted; (2) Data required by law to be retained (statutory retention periods, fraud investigation) cannot be deleted; (3) Data needed for legitimate business purposes (security, legal compliance) can be retained. Healthcare organizations must evaluate deletion requests carefully. When denied, you must explain the reason (that the exception applies). Unlike HIPAA, which doesn't grant deletion rights, VCDPA creates an affirmative obligation to delete upon request when exceptions don't apply.

What enforcement exposure do healthcare organizations face for VCDPA violations? +

VCDPA violations can be enforced by the Virginia Attorney General (who can pursue penalties and require remediation) and by private consumers (who can sue for actual damages). While the statute doesn't specify statutory damages like some other state laws, private litigation is possible. More significantly, VCDPA violations could also be characterized as Consumer Protection Act violations, which might allow additional damages. For healthcare organizations, the primary enforcement risk is Virginia AG action and patient lawsuits. Given the competitive healthcare market in Virginia, regulatory scrutiny is likely to be active.

Ensure Your Virginia Healthcare Organization Complies

Virginia's 15-day medical records access requirement and VCDPA consumer rights create complex compliance obligations. Get a professional security assessment to ensure compliance with HIPAA, VCDPA, and Virginia privacy laws.

Get Your Security Assessment