Guide

The state layer: state privacy statutes that exceed HIPAA

Summary

HIPAA is a federal floor, not a ceiling. Where a state privacy law gives patients more protection or more access than HIPAA, that state law controls and is not preempted. The layers that most often exceed HIPAA are minors' records, substance-use and mental-health information, breach-notice deadlines, and access timelines. Which rules apply depends entirely on your state, so identify your state's medical-confidentiality statute before you write a single policy.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Does state privacy law override HIPAA?

HIPAA is a federal floor, not a ceiling. Its preemption rule keeps any state privacy provision that is more stringent — one giving the patient greater protection or a greater right of access — in full force alongside the federal rule; HIPAA displaces only weaker or conflicting state law 1. So the operative question is never HIPAA or state law, but HIPAA plus whatever your state adds.

Because that addition is jurisdiction-specific, a national policy template under-complies across much of the country — it captures the HIPAA baseline and none of the state overlay. If you are not certain HIPAA reaches you at all, start with the covered-entity test; the state layer is the second question, not the first. Before writing a single privacy policy, pull your state's own medical-confidentiality statute — California's Confidentiality of Medical Information Act is the best-known example — and read it beside HIPAA.

What does 'more stringent' actually mean?

'More stringent' has a specific meaning under the preemption regulation: a state rule stands if it gives individuals more privacy protection, more access to their own information, or more control over disclosures than HIPAA provides 1. When a state rule is merely different, or weaker, HIPAA controls. When it is more protective, you comply with HIPAA by following the state rule — the two are not in tension.

Measure every state provision against HIPAA's own baseline — disclosures for treatment, payment, and health-care operations without authorization, the minimum necessary standard, and the individual-rights set 2. A state law that shrinks what you may disclose, adds a consent step, shortens a deadline, or widens patient access is the layer you actually implement. Practically, that means writing your policies to the stricter of the two rules, provision by provision, rather than to HIPAA alone.

Where do states most often go further than HIPAA?

A handful of categories account for most of the state overlay a solo practice actually encounters. The table below maps each to what HIPAA does at the floor and where state law commonly reaches further. Read it as the list of statutes to pull for your own jurisdiction — not as a statement of any single state's rule, which will differ from your neighbor's.

AreaHIPAA floorWhere state law often exceeds it
Minors' records and consentDefers to state law on who is the personal representative and controls the record 3Which services a minor may consent to alone, and whether a parent may then see those records
Sensitive categories — mental health, substance use, HIV, genetic, reproductiveGeneral PHI protection; mental-health psychotherapy notes are treated separatelyPer-disclosure written consent, re-disclosure limits, and segregation of the record
Patient access to recordsCopy within 30 days, one 30-day extension, cost-based fee 4Shorter turnaround and lower fee caps
Records retentionSix years for required policies and documentation under §164.316 5A longer clinical-record period set by your licensing board
Breach noticeA federal outer deadline for notifying affected individualsA shorter clock, plus notice to the state attorney general

Two of these deserve a note. State law can also reshape how you handle law enforcement requests and subpoenas, so the disclosure rules you learn federally are not the whole picture. And while HIPAA's six years covers policies and documentation, your board's clinical records retention rule may run years longer — the two clocks are independent, and you keep to the longer one.

Minors, capacity, and who controls the record

HIPAA hands the hardest privacy question in a family practice to the states: who controls a minor's record. Federally, a parent is usually the minor's personal representative and exercises the child's HIPAA rights — but HIPAA defers to state law where a minor can lawfully consent to a service on their own, and it recognizes narrow abuse-or-endangerment exceptions 3. So the answer to 'can this parent see this record' is set by your state, not by HIPAA.

The practical workflow: for every minor patient, determine under your state's law which services the minor may consent to alone — commonly some combination of reproductive, mental-health, and substance-use care — and treat the records of those services under the state's access rules, which often means the parent has no automatic right to them. Document the basis for each decision. When a personal representative's authority is unclear, or you suspect the representative endangers the patient, that is the moment to get a state-specific legal read before disclosing.

The tools HIPAA doesn't reach

Not every privacy obligation on a solo practice comes from HIPAA at all. Consumer-facing tools that sit outside a covered entity — a symptom-tracker app, a wellness website, a direct-to-consumer service with no business-associate relationship — can fall under the FTC's Health Breach Notification Rule instead, which reaches health data held by vendors HIPAA never covered 6. A growing set of state consumer-health-privacy laws adds another layer on the same tools.

For a clinical practice, the line is usually the business associate relationship: a vendor that creates, receives, maintains, or transmits PHI for you is inside HIPAA and needs a BAA. A tool your patients use on their own, with no BAA and no PHI flowing to you, may instead be governed by the FTC rule and by state consumer-health statutes. The upshot is that 'is it HIPAA?' is not the only question — for each tool, ask which regime actually covers it before you rely on it.

How to build your state layer

Building the state layer is a short, repeatable project, and OCR's enforcement record makes clear that small practices are not too small to be investigated 7. Start by pulling four documents for your state: the medical-confidentiality statute, the licensing board's records and privacy rules, the breach-notification statute, and any minor-consent statute. Read each beside its HIPAA counterpart and write your policy to whichever is stricter.

  • Map the four sources. Confidentiality statute, board rules, breach law, minor-consent law.
  • Write to the stricter rule, provision by provision. Where the state is silent, HIPAA governs; where it is stricter, it wins.
  • Date the volatile pieces. State consumer-health-privacy laws are changing quickly; note when you last checked.
  • Fold it into onboarding. This review is part of training a workforce of one, and it becomes part of your new-hire packet the day you hire.

Where a provision's meaning is genuinely ambiguous — cross-state telehealth, an unusual custody arrangement — that specific question, not the whole project, is what a one-hour consult with a health-law attorney in your state is for.

Common questions

Follow whichever gives the patient more protection or more access. HIPAA preempts state law only when the state rule is weaker or directly conflicts; a state rule that is more stringent survives, and you comply with HIPAA by following it. In practice you write each policy to the stricter of the two, provision by provision, rather than choosing one rulebook wholesale.

No. HIPAA sets a national floor and leaves more protective state law standing on top of it. Your state's medical-confidentiality statute, its licensing-board rules, and its breach and minor-consent laws all continue to apply where they exceed HIPAA. Treating HIPAA as the ceiling is the most common way a solo practice under-complies with the law that actually governs it.

Mostly, with two caveats. Telehealth can pull in the law of the state where the patient is physically located at the time of the visit, and records requests sometimes cross state lines. For a fully in-person, single-state practice you focus on your own state's statutes — but confirm the telehealth question before you treat anyone across a border.

Start with your state's statutes for a medical-confidentiality or health-records act, then your licensing board's regulations, its breach-notification statute, and any minor-consent statute. Your state medical or professional association usually publishes a plain-language summary. Read each source next to its HIPAA counterpart so you can see exactly where the state layer adds an obligation.

Sometimes, under a different regime. A vendor handling PHI for you is a HIPAA business associate and needs a BAA. A consumer tool with no BAA can instead fall under the FTC's Health Breach Notification Rule and a growing set of state consumer-health-privacy laws. For each tool, identify which regime governs before you assume HIPAA is the only one that matters.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Office of the Federal Register (2026). 45 CFR Part 160 — General Administrative Requirements. eCFR. linkThe HIPAA preemption framework — that a more-stringent state privacy provision is not preempted and stands alongside the federal rule.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThe HIPAA Privacy Rule baseline — TPO disclosures, minimum necessary, and individual rights — that each state provision is measured against.
  3. 3.HHS Office for Civil Rights (2026). Personal Representatives. U.S. Department of Health and Human Services. linkThat HIPAA defers to state law on who controls a minor's or incapacitated adult's record and recognizes narrow abuse/endangerment exceptions.
  4. 4.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThe federal access baseline — copies within 30 days, one extension, a cost-based fee — that stricter state access rules can tighten.
  5. 5.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe §164.316 six-year documentation-retention requirement, distinct from a longer state clinical-record retention period.
  6. 6.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). linkThat the FTC Health Breach Notification Rule reaches health data held by tools and vendors that fall outside HIPAA.
  7. 7.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR investigates and penalizes even very small practices, so building the state layer is not optional.

https://www.gale.care/for-providers/hip-state-privacy-laws-stack · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)