HIPAA Compliance in Virginia: VCDPA & Healthcare Privacy
Virginia healthcare organizations must comply with federal HIPAA plus state privacy laws. This guide covers the Virginia Consumer Data Protection Act (VCDPA), medical records statutes, breach notification laws, and other Virginia requirements that extend beyond HIPAA.
Virginia imposes healthcare privacy through three main frameworks: HIPAA (federal), Virginia Consumer Data Protection Act (VCDPA, Va. Code §59.1-575 et seq.), and medical records statutes (Va. Code §32.1-127.1:03). The VCDPA, effective 2024, grants Virginia residents rights to know, access, delete, and port their personal information (including health data), with limited exemptions for HIPAA covered entities. Additionally, Virginia requires prompt breach notification, strict medical records access procedures, and enforcement by both the Virginia Attorney General and private consumers. Healthcare organizations must comply with overlapping requirements across all frameworks—the VCDPA adds new consumer rights that create compliance complexity alongside traditional HIPAA obligations.
How Virginia Law Extends Beyond HIPAA
Virginia law creates multiple privacy obligations that frequently exceed or extend HIPAA standards:
1. Virginia Consumer Data Protection Act (VCDPA - Va. Code §59.1-575 et seq.)
Virginia's comprehensive consumer privacy law applies to healthcare organizations:
- Scope: Applies to entities doing business in Virginia that process personal information (including health data) of Virginia residents
- HIPAA carve-out: Limited exemption for HIPAA covered entities and business associates, but many VCDPA rights still apply
- Consumer rights: Right to know (what data collected, how used, shared), access (obtain copy), delete (request deletion), correct (request corrections), and data portability (obtain in transferable format)
- Health data classification: Health information is considered "sensitive personal information" under VCDPA; stricter requirements for use and sharing
- Profiling restrictions: Cannot use health data for profiling without explicit opt-in consent
- Enforcement: Virginia Attorney General and private consumer lawsuits
- Timeline: Entities must respond to consumer requests within 45 days (can extend once)
2. Virginia Medical Records Access Law (Va. Code §32.1-127.1:03)
Establishes specific patient rights to medical records:
- Access timeline: Patients have right to access records within 15 working days
- Copy costs: Reasonable copying costs; electronic records should be provided at no cost or reasonable fee
- Format: Records must be provided in format requested when available
- Applicability: Applies to all healthcare providers in Virginia
3. Virginia Data Breach Notification Law (Va. Code §18.2-186.6)
Requires notification of breaches of personal information:
- Timeline: Without unreasonable delay; interpreted as prompt notification
- Scope: Applies to breaches of personal information including health data and unencrypted SSNs
- Content: Notice must describe breach, types of information involved, and available resources
- Law enforcement notification: If breach affects 250+ Virginia residents, must notify law enforcement
4. Virginia Consumer Protection Act (Va. Code §59.1-200 et seq.)
Provides enforcement authority for unfair healthcare practices:
- Private right of action: Consumers can sue for healthcare privacy violations
- Damages: Actual damages plus potential statutory damages and attorney fees
- Healthcare privacy: Can include violations of medical records access and data protection requirements
5. Virginia Mental Health & Substance Abuse Confidentiality
Additional protections for sensitive health information:
- Mental health treatment: Specific authorization required; enhanced confidentiality beyond HIPAA
- Substance abuse treatment: Federal 42 CFR Part 2 plus Virginia law applies
Key Virginia State Statutes & References
Virginia Attorney General Enforcement
Virginia enforces healthcare privacy and consumer protection laws through multiple mechanisms:
- VCDPA enforcement: Virginia AG enforces VCDPA violations against entities processing Virginia resident data
- HIPAA enforcement: Virginia AG enforces HIPAA violations in Virginia
- Data breach enforcement: Investigates breaches; can pursue enforcement for failure to comply with breach notification
- Consumer protection enforcement: AG pursues unfair healthcare privacy practices
Enforcement activity: Since VCDPA became effective in 2024, Virginia AG has indicated it will actively enforce the law. Given Virginia's proximity to technology hubs and healthcare industry presence, enforcement has been and will continue to be robust.
Comparison: HIPAA vs. Virginia State Requirements
| Area | HIPAA | Virginia Law | More Stringent |
|---|---|---|---|
| Patient Access Timeline | 60 days to provide records | 15 working days (Va. Code §32.1-127.1:03) | Virginia |
| Right to Know Data Collected | Limited right (accounting of disclosures) | VCDPA: Right to know all personal information collected | Virginia |
| Data Access Rights | PHI access | VCDPA: Personal information access plus HIPAA rights | Virginia |
| Data Deletion Rights | No absolute deletion right | VCDPA: Right to request deletion (with exceptions) | Virginia |
| Data Portability | Not explicitly required | VCDPA: Right to obtain data in portable format | Virginia |
| Breach Notification | 60 days of discovery | Without unreasonable delay (interpreted as days) | Virginia |
| Sensitive Data Classification | PHI protection standard | VCDPA: Health data is "sensitive"; stricter handling | Virginia |
| Private Right of Action | No private HIPAA right | VCDPA and Consumer Protection Act allow lawsuits | Virginia |
Virginia-Specific Breach Notification & VCDPA Requirements
Data Breach Notification Timeline
- HIPAA requirement: Within 60 days of discovery
- Virginia requirement: Without unreasonable delay—interpreted as immediate when feasible
- Law enforcement notification: If 250+ Virginia residents affected, must notify law enforcement
VCDPA Consumer Rights Implementation
- Right to know: Upon request, provide categories of personal information collected, purposes, third-party recipients
- Right to access: Provide copy of personal information in electronic format within 45 days
- Right to delete: Delete personal information upon request (with legal and security exceptions)
- Right to correct: Allow patients to correct inaccurate information
- Right to data portability: Provide information in portable, transferable format
- Timeline: Respond to consumer requests within 45 days (extendable once for 45 more days)
Health Data Specific Handling (VCDPA)
- Sensitive classification: Health information is "sensitive personal information"
- Profiling restrictions: Cannot profile using health data without explicit opt-in
- Use restrictions: Tighter limitations on health data use compared to general personal information
- HIPAA covered entity exemption: Partial exemption applies; many VCDPA rights still apply to non-treatment uses
Medical Records Specific Requirements
- Access timeline: 15 working days (distinct from VCDPA's 45-day timeline)
- Format flexibility: Must provide requested format when available
- Cost limitations: Reasonable costs for paper copies; electronic copies at minimal or no cost
Frequently Asked Questions
Partially. HIPAA covered entities have a limited exemption from VCDPA for activities regulated under HIPAA (treatment, payment, healthcare operations). However, the exemption is not absolute. If a covered entity uses health data for purposes beyond HIPAA's permitted uses (e.g., marketing, analytics for non-healthcare purposes, profiling for non-treatment purposes), VCDPA applies to those uses. Additionally, VCDPA's rights to delete and data portability may apply even to HIPAA covered entities in certain circumstances. Healthcare organizations should not assume HIPAA covered status fully exempts them from VCDPA—selective compliance with VCDPA may still be necessary.
HIPAA allows 60 days to provide records access. Virginia law (Va. Code §32.1-127.1:03) requires access within 15 working days—significantly faster. This creates a compliance challenge: Virginia healthcare providers must meet the 15-day timeline. Additionally, VCDPA allows 45 days for personal information access requests. When a Virginia patient requests records, you must respond in the tighter timeline (15 working days). This requires efficient medical records retrieval systems and processes.
Under VCDPA, yes—patients can request deletion of their personal information, including health data. However, there are important exceptions: (1) Data needed for ongoing or future treatment cannot be deleted; (2) Data required by law to be retained (statutory retention periods, fraud investigation) cannot be deleted; (3) Data needed for legitimate business purposes (security, legal compliance) can be retained. Healthcare organizations must evaluate deletion requests carefully. When denied, you must explain the reason (that the exception applies). Unlike HIPAA, which doesn't grant deletion rights, VCDPA creates an affirmative obligation to delete upon request when exceptions don't apply.
VCDPA violations can be enforced by the Virginia Attorney General (who can pursue penalties and require remediation) and by private consumers (who can sue for actual damages). While the statute doesn't specify statutory damages like some other state laws, private litigation is possible. More significantly, VCDPA violations could also be characterized as Consumer Protection Act violations, which might allow additional damages. For healthcare organizations, the primary enforcement risk is Virginia AG action and patient lawsuits. Given the competitive healthcare market in Virginia, regulatory scrutiny is likely to be active.
Ensure Your Virginia Healthcare Organization Complies
Virginia's 15-day medical records access requirement and VCDPA consumer rights create complex compliance obligations. Get a professional security assessment to ensure compliance with HIPAA, VCDPA, and Virginia privacy laws.
Get Your Security Assessment