HIPAA has shaped how healthcare organizations think about privacy for decades. But recent state laws are expanding privacy obligations beyond HIPAA-covered data. This post outlines what healthcare leaders should understand about these emerging privacy requirements.
Table of contents
HIPAA Is No Longer the Whole Privacy Story
For more than 20 years, most of our health information has been protected from unauthorized disclosure by the Health Insurance Portability and Accountability Act, or HIPAA.
The HIPAA privacy law and implementing regulations are extensive. There are Federal and State enforcement mechanisms that investigate mistakes or intentional misuse. And they can punish persons or regulated/covered entities who disclose protected health information without authorization.
But as extensive and rigorously enforced HIPAA privacy rules are, there are new sources of health-related data becoming available that are not created or maintained by HIPAA-regulated entities.
And while a national approach to protecting consumer health data privacy seems like a natural follow-up to HIPAA, it seems unlikely that it would come about any time soon. Into this gap have jumped several states.
State Comprehensive Data Privacy Laws
At least 19 states have followed California’s lead since 2018, when it enacted the California Consumer Privacy Act, and are enacting state comprehensive data privacy laws. These laws have broad definitions of personal data/information. Most of them describe it as data that is linked or reasonably likely to be linkable to an identified or identifiable individual. Certainly sounds like that definition covers health-related data! But no, most of these laws contain an exemption for HIPAA-covered data. However, that does leave coverage for sensitive personal information related to health services or personal health data not created or maintained by HIPAA-regulated entities.
Many of these laws have several similar provisions.
In larger states, they only apply to for-profit entities that do business in the state and buy or sell the personal information of 100,000 or more state residents. Smaller states lower that threshold to 25,000 or 35,000 state residents.
Some laws apply to any entity, for-profit or not-for-profit, that conducts business in the state. Other laws apply to any entity that derives at least 20% or 25% of gross revenue from the sale of personal information collected by the business.
Some states require opt-out choices for users, while others have opt-in requirements. Almost all the laws require response periods of 45 days or less, and fines for violations range from $2,663 per violation to up to $50,000 per violation plus treble damages.
State Health Data Laws – Washington State
In comparison, only a few states have enacted laws specifically protecting consumer health data privacy. One of the first states to pass such a law was Washington State, which passed HB1155 in April 2023. This law, known as the “My Health My Data Act” (MHMDA), was aimed specifically at addressing the collection, sharing, and selling of consumer health data.
MHMDA contains some provisions similar to the state comprehensive data privacy laws mentioned above, but also defines consumer health data. The definition contains examples of physical or mental health status, but excludes HIPAA-covered data. For instance, consumer health data includes “precise location information that could reasonably indicate a consumer’s attempt to acquire or receive health services or supplies.”
Regulated entities include “any legal entity that conducts business in Washington…..and alone or jointly with others determines the purpose and means of collecting, processing, sharing, or selling of consumer health data.”
Consumers have the right to ask for a list of all third parties with whom the regulated entity has shared or sold consumer health data, and to have consumer health data deleted. Certain aspects of geofencing use electronic signals like those from cell phones to send marketing information or to track anyone within a geographic boundary around a business. These aspects are not allowed within 2000 feet around entities providing in-person health services.
This is a bare-bones description of the MHMDA. There are also provisions covering required business policies and enforcement mechanisms, and a private right of action for violations.
Other State Health Data Privacy Laws
Other states have followed the examples of California and Washington State in enacting state laws on health date privacy and consumer data protection.
- Nevada passed SB 370 in 2023, with an effective date of March 31, 2024.
- This legislation is very similar to the Washington state health data privacy law, with a few departures. For instance, SB 370 exempts HIPAA-covered entities (as opposed to HIPAA-covered data) from the provisions of the law.
- SB 370 also limits the geofencing boundary to 1,700 feet. And only the Nevada Attorney General may take legal action against a regulated entity.
- Virginia amended its Consumer Protection Act as of July 1, 2025.
- The purpose of the act is to focus on consumer health data privacy related to reproductive health and sexual health information.
- Consumers must consent specifically to the processing of personal health information, including information in the definition of reproductive health information and sexual health information.
- Colorado adopted the Colorado Privacy Act that went into effect on July 1, 2023.
- This act included the term “sex life” in its definition of sensitive data. This is much broader than even the definition of sexual health information.
- Maryland enacted the Maryland Online Data Privacy Act (MODPA) with an effective date of October 1, 2025.
- In addition to many of the provisions of other state comprehensive privacy laws, MODPA also contains a new standard for processors, those processing requests for information or services.
- Controllers must limit processing, e.g., collating, sharing, etc., of sensitive data unless the processing is strictly necessary to fulfill the customer’s request for a service or product.
- This is a higher standard than the “reasonably necessary” standard usually specified in such laws. Controllers are strictly forbidden from selling sensitive data, regardless of consent from consumers.
What Should Privacy Officers of Healthcare Providers Do Now?
Well, the first thing to do is to research any comprehensive state privacy laws that apply to your clients or patients. Keep in mind, there are now new laws directly affecting personal health information. There are also amendments to existing consumer privacy laws that affect personal health information and HIPAA-covered data and HIPAA-covered entities.
Second, find out if your hospital or other healthcare providers are collecting any personal health data that is not included in the definition of protected health information your organization creates or maintains. In previous years, we have seen hospitals that hired marketing firms for outreach and/or market research. These firms asked for – and received – personal health data from patients and non-patients alike. Depending on the size of the marketing firm, it may be subject to the terms of a state consumer health data law. And any legal actions against them may rub off on the reputation of your organization, too.
Check out the laws in surrounding states. Typically, unauthorized disclosures of protected health information have required healthcare providers to notify attorneys general in adjoining states when they have provided healthcare to residents of those states. Anytime your organization (or one of your business associates!) has suffered a breach involving hundreds or thousands of records, notification to the attorney general in the state where persons reside is required.
Of course, if your institution is involved in a breach that large, get help from attorneys yourself to manage the reaction and reporting to federal and state authorities as required.
Some states are starting to claim that their specific state laws apply to their residents even when they are seeking services out of state.
Health data privacy, beyond HIPAA-protected data, is a hot topic. Multiple states are considering new laws or amendments to existing consumer protection laws to deal specifically with health information. Stay alert for new requirements in your state, and keep your privacy officer on speed dial!
