State Privacy Laws vs. HIPAA: 21-State Chart
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Quick Answer: When Does State Privacy Law Supersede HIPAA?
Under 45 CFR § 160.203, state law supersedes HIPAA whenever it is “more stringent” — that is, the state requirement gives individuals greater rights or imposes stricter limits on disclosure than the HIPAA Privacy Rule. HIPAA sets a federal floor, not a ceiling. State law also takes precedence when it concerns public-health reporting, health-plan regulation, or when the HHS Secretary has formally determined the state requirement serves a compelling need. Outside those carve-outs, HIPAA preempts “contrary” state law that frustrates the federal standard. Source check: Last verified May 28, 2026 against the eCFR text of 45 CFR Part 160 Subpart B (date_retrieved: 2026-05-28).
How HIPAA Preemption Works
The general preemption rule at 45 CFR § 160.203 says HIPAA supersedes “contrary provisions of State law,” except in four scenarios:
- The state law is more stringent than HIPAA — meaning it provides greater privacy protections, gives individuals more rights over their data, or imposes stricter penalties (45 CFR § 160.202’s “more stringent” test)
- The state law addresses public health reporting, disease prevention, or health oversight
- The state law requires health plan reporting or addresses health plan regulation
- The Secretary of HHS determines the state law serves a compelling public health, safety, or welfare need under the formal exception-determination process at 45 CFR § 160.204
For substance-use disorder records, a separate federal rule — 42 CFR Part 2, administered by SAMHSA — applies on top of HIPAA. Part 2’s consent and re-disclosure restrictions are independently stricter than HIPAA in many situations, and state laws can layer further protections above Part 2 as well. Source check: Last verified May 28, 2026 against the SAMHSA Part 2 final rule materials (date_retrieved: 2026-05-28).
State-by-State HIPAA Exemption Matrix (21 Comprehensive Privacy Laws)
As of May 2026, 21 US states have enacted comprehensive consumer privacy laws. Every one of them carves out some space for HIPAA, but the shape of the carve-out varies in ways that change whether you, as a covered entity or business associate, are fully out of scope or only partially out. The two patterns are:
- Entity-level exemption — the entire HIPAA-covered entity is out of scope for everything it does, including data collection that has nothing to do with treatment, payment, or operations.
- Data-level exemption (PHI-only) — only the data already regulated as PHI under HIPAA is exempt. Non-PHI consumer data the same organization holds (marketing lists, web-analytics, mobile-app telemetry, payroll, employee health surveys) is still in scope.
Mis-reading this distinction is the most common HIPAA-vs-state-privacy-law mistake. Use this matrix as a starting point, but always confirm with the operative statute and the relevant Attorney General’s guidance.
| State (statute) | HIPAA carve-out shape | Notes |
|---|---|---|
| California (CCPA/CPRA) | Data-level (PHI) + entity-level (provider acting under HIPAA/CMIA) | Cal. Civ. Code § 1798.146 exempts PHI collected by a covered entity or business associate to the extent governed by HIPAA or CMIA; non-PHI consumer data is still in scope. |
| Virginia (VCDPA) | Entity-level (covered entity & business associate) | Va. Code § 59.1-576 exempts HIPAA covered entities and business associates entirely; one of the broader exemptions. |
| Colorado (CPA) | Data-level (PHI only) | CPA narrowed scope: HIPAA carve-out is for PHI only; non-PHI consumer data held by the same hospital or insurer remains regulated by the CPA. |
| Connecticut (CTDPA) | Data-level (PHI only) | Like Colorado, the CTDPA exempts PHI but not the entire HIPAA-covered entity. |
| Utah (UCPA) | Entity-level | Utah Code § 13-61-102 exempts HIPAA covered entities; combined with UCPA’s narrow thresholds this is among the most permissive carve-outs. |
| Iowa (ICDPA) | Entity-level | Iowa Code Ch. 715D exempts HIPAA covered entities and business associates. |
| Indiana (INCDPA) | Entity-level | IC 24-15 entity-exempts HIPAA covered entities. AG Todd Rokita has publicly criticized the breadth of this exemption and said he plans to recommend narrowing it. |
| Kentucky (KCDPA) | Entity-level | Tracks the Virginia model; HIPAA covered entities and business associates are out of scope. |
| Rhode Island (RIDTPPA) | Entity-level | Entity carve-out plus a separate PHI data-level exemption. |
| Tennessee (TIPA) | Entity-level | Tenn. Code § 47-18-3203 exempts HIPAA covered entities and business associates. |
| Montana (MTCDPA) | Entity-level | Mont. Code § 30-14-2802 exempts HIPAA covered entities and business associates. |
| Texas (TDPSA) | Entity-level (covered entity & business associate) | Tex. Bus. & Com. Code § 541.052 exempts HIPAA covered entities and business associates; note Texas has a separate state medical-records law (HB 300) that is independently stricter than HIPAA. |
| Oregon (OCPA) | Data-level (PHI only) | OCPA exempts PHI but generally does not exempt the entire HIPAA entity; non-PHI data held by a HIPAA entity stays in scope. |
| Delaware (DPDPA) | Data-level (PHI only) | DPDPA was deliberately drafted to follow the narrower Colorado/Connecticut data-level model rather than the Virginia entity-level model. |
| New Hampshire (NHPA) | Entity-level | RSA 507-H exempts HIPAA covered entities and business associates. |
| New Jersey (NJDPA) | Data-level (PHI only) | N.J.S.A. 56:8-166.4 et seq. exempts PHI but does not entity-exempt the controller. |
| Nebraska (NDPA) | Entity-level | Tracks the Texas model. |
| Minnesota (MCDPA) | Data-level (PHI only) | Minnesota deliberately narrowed the HIPAA carve-out and layered MN’s own pre-existing Health Records Act on top. |
| Maryland (MODPA) | Data-level (PHI only) | MODPA § 14-4602 exempts PHI but generally does not entity-exempt the covered entity for non-PHI consumer data. |
| Florida (FDBR) | Entity-level (PHI & covered entity) | Fla. Stat. § 501.704 exempts HIPAA covered entities and business associates; FDBR also has very high revenue thresholds, narrowing applicability further. |
| Oklahoma (OKCDPA, SB 546) | Entity-level (effective Jan 2027) | Tracks the Virginia model; HIPAA covered entities and business associates are out of scope when SB 546 takes effect on January 1, 2027. |
Pattern: most laws still entity-exempt HIPAA-covered entities (the Virginia model), but the more recently drafted laws — Colorado, Connecticut, Oregon, Delaware, Maryland, New Jersey, Minnesota — have shifted to a narrower data-level exemption. Indiana’s AG Rokita has publicly flagged the broader entity exemption as a target for legislative narrowing in 2026.
Where State Comprehensive Privacy Laws and HIPAA Overlap in Practice
The Gap: Non-HIPAA Health Data
Even when a state law fully exempts your HIPAA-covered entity, state privacy laws still apply to health-related data that is not regulated by HIPAA. Common examples:
- Health data collected by fitness apps, wellness platforms, and wearable devices (not covered entities under HIPAA)
- Health information collected by employers outside of group health plans
- Data collected by health-related websites that are not covered entities or business associates
- Consumer health data collected by retailers, pharmacies (for non-prescription activities), or tech companies
Washington's My Health My Data Act
Washington State enacted the My Health My Data Act (RCW 19.373) specifically to address the gap between HIPAA and consumer health data. Unlike comprehensive privacy laws, it applies broadly to “consumer health data” regardless of whether the entity is HIPAA-covered, includes a private right of action under Washington’s Consumer Protection Act, and bans geofencing around healthcare facilities. Nevada (SB 370) and Connecticut (CTDPA amendments) have adopted narrower versions of the consumer-health-data concept. Because Washington has no comprehensive consumer privacy act, MHMDA plus RCW 19.375 is effectively the whole state regime for most businesses — see our Washington state privacy law guide for what does and does not apply there. Source check: Last verified May 28, 2026 against the Washington Legislature’s RCW 19.373 statute page (date_retrieved: 2026-05-28).
Specific Areas Where State Laws Are Stricter Than HIPAA
Mental Health Records
Many states have laws that provide greater protections for mental health records than HIPAA requires. For example, some states require specific written consent before disclosing mental health treatment records, even when HIPAA might allow disclosure for treatment, payment, or operations.
Substance Abuse Records
Federal regulation 42 CFR Part 2, administered by SAMHSA, imposes stricter confidentiality and consent rules on substance-use disorder treatment records than general HIPAA rules. States may layer additional protections on top — for example, several states limit re-disclosure by third-party payors more aggressively than Part 2 alone.
HIV/AIDS Status
Nearly every state has laws that provide heightened confidentiality protections for HIV/AIDS diagnosis and testing information, going well beyond HIPAA's general requirements.
Genetic Information
Federal GINA covers insurance and employment; states like California, Illinois, Florida, Texas, and Arizona have enacted broader genetic-privacy laws restricting how consumer-facing genetic-testing companies, researchers, and law-enforcement can use genetic data. These are independent of the comprehensive privacy laws listed above.
Frequently Asked Questions
When does state privacy law supersede HIPAA?
State privacy law supersedes HIPAA whenever it is “more stringent” under 45 CFR § 160.203 — meaning it gives individuals more rights or imposes stricter limits on use or disclosure than the HIPAA Privacy Rule. State law also supersedes HIPAA for public-health reporting, health-plan regulation, or where the HHS Secretary has issued a formal exception determination under 45 CFR § 160.204.
Are HIPAA-covered entities exempt from CCPA?
Partially. California Civil Code § 1798.146 exempts PHI collected by a HIPAA covered entity or business associate to the extent it is governed by HIPAA or the California Confidentiality of Medical Information Act (CMIA). Non-PHI consumer data — marketing audiences, website analytics, mobile-app telemetry, payroll — held by the same provider remains subject to the CCPA/CPRA.
Does state privacy law apply to my hospital’s patient data?
Usually no for PHI itself, but yes for adjacent data. If your state has an entity-level HIPAA carve-out (Virginia, Texas, Utah, Iowa, Indiana, Kentucky, Tennessee, Montana, Nebraska, New Hampshire, Florida, Oklahoma), the hospital may be fully out of scope. If your state uses a data-level carve-out (California for non-PHI, Colorado, Connecticut, Oregon, Delaware, New Jersey, Minnesota, Maryland), the hospital is in scope for everything it holds that is not PHI.
Does HIPAA preempt the California CCPA?
HIPAA preempts the CCPA only for the specific data and activities HIPAA regulates. The CCPA can still apply to a HIPAA-covered entity’s non-PHI consumer data, and the CCPA does not weaken HIPAA where the two overlap — under 45 CFR § 160.203 HIPAA still preempts “contrary” state law, but the CCPA is generally designed not to be “contrary” for PHI handling.
What is the difference between an entity-level and data-level HIPAA exemption?
An entity-level exemption removes the entire HIPAA-covered organization from the state law’s scope. A data-level exemption only removes the specific data already regulated as PHI — the organization is still subject to the state law for non-PHI consumer data it holds. Colorado, Connecticut, Oregon, Delaware, New Jersey, Minnesota, and Maryland use the narrower data-level approach.
Practical Guidance for Organizations
- Do not assume HIPAA compliance is sufficient — always check the specific state laws where your patients or customers reside
- Identify your non-HIPAA health data — fitness apps, wellness programs, and employee health surveys may fall under state privacy law
- Check state-specific consent requirements — especially for mental health, substance abuse, HIV, and genetic information
- Confirm whether each state’s exemption is entity-level or data-level using the matrix above — this is the single most common compliance mis-read
- Use our privacy law calculator to determine which state privacy laws apply to your organization based on your data practices
- Monitor state legislation — new health data laws like Washington's MHMDA are being introduced in additional states
Because HIPAA-vs-state-law outcomes turn on exact statutory text, confirm every citation above against the primary source before you act — a citation-backed research tool such as CiteCanon can verify the operative statute and case law.
This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 28, 2026. Last verified: May 28, 2026.
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.