4.3 State Law Preemption & Multi-Jurisdictional Privacy Compliance

Key Takeaways

  • Under 45 CFR Part 160 Subpart B, HIPAA establishes a federal regulatory floor; state laws that are 'contrary' to HIPAA are preempted unless the state provision is 'more stringent' (provides greater privacy protection, narrower disclosure exceptions, or broader individual access rights) or falls under statutory preemption exceptions.
  • Statutory exceptions to HIPAA preemption include state laws governing public health reporting (communicable diseases, vital statistics), child or elder abuse reporting, health oversight regulation, or laws granted an explicit preemption exception determination by the Secretary of HHS.
  • Key state statutes exceed HIPAA: California's CPRA carves out clinical PHI but regulates employee data, the Texas Medical Records Privacy Act broadens the covered entity definition and requires training within 90 days of hire, and Washington's My Health My Data Act reaches consumer health data outside HIPAA.
  • The 2024 HIPAA Reproductive Health Care Privacy Rule — including the 45 CFR § 164.502(a)(5)(iii) prohibited-purpose restriction and the § 164.509 attestation — was vacated nationwide on June 18, 2025 in Purl v. HHS, No. 2:24-cv-00228-Z (N.D. Tex.).
  • Only 45 CFR § 164.520(b)(1)(ii)(F), (G), and (H) were struck from the 2024 Notice of Privacy Practices amendments; the remaining NPP modifications survive and carry a February 16, 2026 compliance date.
Last updated: August 2026

State Law Preemption & Multi-Jurisdictional Privacy Compliance

Healthcare privacy in the United States does not exist under a single, unified federal statute. Instead, healthcare organizations navigate a multi-layered regulatory ecosystem comprising federal laws, state constitutions, state medical practice acts, and comprehensive state data privacy statutes.

Under 45 CFR Part 160, Subpart B, HIPAA acts as a federal regulatory floor, not a ceiling. Consequently, Healthcare Privacy Officers must master the statutory preemption doctrine to determine when federal law controls and when more protective state laws supersede HIPAA mandates. Furthermore, recent federal rulemaking—most notably the 2024 HIPAA Final Rule to Support Reproductive Health Care Privacy—has reshaped the boundaries of state law preemption, law enforcement disclosures, and interstate healthcare privacy compliance.


1. HIPAA Statutory Preemption Architecture (45 CFR Part 160 Subpart B)

The preemption rules of HIPAA are codified at 45 CFR §§ 160.201 through 160.205 pursuant to Section 1178 of the Social Security Act (42 U.S.C. § 1320d-7).

+---------------------------------------------------------------------------------------------------+
|                         HIPAA STATUTORY PREEMPTION DECISION FRAMEWORK                             |
|                                                                                                   |
|   STEP 1: IS THERE A CONFLICT BETWEEN STATE LAW AND HIPAA? (45 CFR § 160.202)                     |
|   - A state law is "contrary" if:                                                                 |
|     a) A covered entity would find it impossible to comply with both state and federal law; OR    |
|     b) The state law stands as an obstacle to the accomplishment of HIPAA's objectives.           |
|                                          |                                                        |
|                                          v                                                        |
|   STEP 2: IF CONTRARY, DOES THE STATE LAW MEET THE "MORE STRINGENT" TEST? (45 CFR § 160.202)      |
|   - State law is MORE STRINGENT if it:                                                            |
|     • Provides greater privacy protection for the individual                                      |
|     • Narrower permitted uses and disclosures (requires patient authorization where HIPAA doesn't)|
|     • Grants greater individual access, amendment, or accounting rights                           |
|     • Requires more detailed records retention or faster breach notification                      |
|                                          |                                                        |
|                                          v                                                        |
|   STEP 3: EVALUATE STATUTORY PREEMPTION EXCEPTIONS (45 CFR § 160.203)                             |
|   - State law survives preemption (EVEN IF LESS STRINGENT) if it governs:                         |
|     1. Public health surveillance (reporting disease, injury, child abuse, vital statistics)      |
|     2. Health oversight regulation of health plans and insurance                                  |
|     3. Explicit HHS Preemption Determination granted by the Secretary (45 CFR § 160.204)          |
+---------------------------------------------------------------------------------------------------+

The "More Stringent" Standard Applied

Under 45 CFR § 160.202, a state law is more stringent than HIPAA if it:

  1. Restricts Uses & Disclosures: Prohibits or limits a use or disclosure that would otherwise be permitted under HIPAA (e.g., state law requiring express written consent to disclose records for treatment, whereas HIPAA permits treatment disclosures without consent under § 164.506).
  2. Expands Individual Access: Grants greater rights of access or amendment to the individual (e.g., state law requiring records delivery within 15 calendar days, superseding HIPAA's 30-day window).
  3. Tightens Authorizations: Mandates narrower authorization expiration periods or requires specific statutory warnings.
  4. Reduces PHI Release Scope: Limits the amount or type of information that may be disclosed to third parties or law enforcement.

2. Landmark State Healthcare Privacy Statutes

Healthcare privacy officers operating multi-facility systems or digital health services must manage state-specific statutory expansions that exceed HIPAA's baseline requirements.

+---------------------------------------------------------------------------------------------------+
|                         LANDMARK STATE HEALTHCARE PRIVACY STATUTES                                |
|                                                                                                   |
|   TEXAS: MEDICAL RECORDS        CALIFORNIA: CMIA & CPRA       WASHINGTON: MY HEALTH               |
|   PRIVACY ACT (TMRPA)           (CAL. CIV. CODE §§ 56 & 1798) MY DATA ACT (MHMD)                  |
|   ----------------------------  ----------------------------  ---------------------------------   |
|   • Broader "Covered Entity"    • CMIA: Strict civil damages  • Protects "Consumer Health Data"   |
|     definition: any person/co.    for negligent disclosure of   broadly outside HIPAA.            |
|     handling PHI in Texas.        medical info ($1,000/patient) • Covers reproductive, genetic,   |
|   • Mandatory employee training • CPRA: HIPAA carve-out for     biometric, and location data.     |
|     within 90 DAYS of hire.       clinical PHI, but regulates • BANS geofencing around healthcare |
|   • Refresher only on MATERIAL    healthcare employee data.     facilities.                       |
|     LAW CHANGE (no 2-yr cycle). • 15-day record access rule.  • Contains PRIVATE RIGHT OF ACTION. |
|   • $5k/$25k/$250k per violation;                                                                 |
|     $1.5M/yr cap for a PATTERN.                                                                   |
+---------------------------------------------------------------------------------------------------+

A. Texas Medical Records Privacy Act (TMRPA - Tex. Health & Safety Code Ch. 181)

  • Expanded Scope: Unlike HIPAA, which applies strictly to covered entities and business associates, Texas law defines a "covered entity" as any individual or business that comes into possession of, obtains, compiles, or analyzes PHI (including IT consultants, app developers, and attorneys).
  • Mandatory Workforce Training (Tex. Health & Safety Code § 181.101): Employees must complete training on state and federal PHI law not later than the 90th day after hire. The pre-2013 biennial refresher was repealed — current law requires additional training only when a material change in state or federal PHI law affects the employee's duties, and then within a reasonable period no later than the first anniversary of that change's effective date. Each trained employee must sign a verification statement, retained until the sixth anniversary of signing.
  • Statutory Penalties (§ 181.201): Civil penalties are $5,000 per negligent violation, $25,000 per knowing or intentional violation, and $250,000 per violation where PHI was knowingly or intentionally used for financial gain. The $1.5 million annual figure is the cap a court may assess for a pattern or practice of violations — it is not a per-violation ceiling.

B. California Confidentiality of Medical Information Act (CMIA) & CPRA

  • CMIA (Cal. Civ. Code § 56): Imposes strict liability and private civil statutory damages ($1,000 nominal damages per patient without proving actual financial injury) for negligent maintenance or unauthorized disclosure of medical information.
  • California Consumer Privacy Act / CPRA (Cal. Civ. Code § 1798.100 et seq.): While clinical PHI governed by HIPAA is carved out from CPRA, healthcare employers must comply with CPRA requirements governing workforce member (employee/applicant) personal data not covered by HIPAA.

C. Washington My Health My Data Act (MHMD - RCW 19.373)

  • Consumer Health Data Scope: Broadly regulates non-HIPAA consumer health data, including reproductive/sexual health data, biometric identifiers, and precision geolocation history.
  • Geofencing Prohibition: Makes it unlawful to establish a virtual geofence around any facility providing healthcare services (e.g., reproductive health clinics, mental health centers) to identify, track, or collect data from patients.
  • Private Right of Action: Enforceable through the Washington Consumer Protection Act, granting consumers direct private litigation rights.

3. The 2024 Reproductive Health Care Privacy Rule and Its Nationwide Vacatur

On April 22, 2024, OCR issued the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976, April 26, 2024), effective June 25, 2024, with a general compliance date of December 23, 2024. The rule added a prohibited-purpose restriction at 45 CFR § 164.502(a)(5)(iii), a presumption that reproductive health care provided by another person was lawful, and a mandatory signed attestation at 45 CFR § 164.509 for certain requests under § 164.512.

[!CAUTION] That rule is no longer in force. On June 18, 2025, the U.S. District Court for the Northern District of Texas declared it unlawful and vacated most of it nationwide in Carmen Purl, et al. v. U.S. Department of Health and Human Services, No. 2:24-cv-00228-Z (N.D. Tex.). HHS OCR posts this vacatur notice on its own HIPAA and Reproductive Health page. Reciting the § 164.509 attestation as a live federal requirement in 2026 means applying a vacated regulation.

+---------------------------------------------------------------------------------------------------+
|            2024 REPRODUCTIVE HEALTH RULE: WHAT WAS VACATED vs. WHAT SURVIVES                      |
|                                                                                                   |
|   VACATED NATIONWIDE (June 18, 2025)              SURVIVING AND STILL ENFORCEABLE                 |
|   ---------------------------------------------   ---------------------------------------------   |
|   • § 164.502(a)(5)(iii) prohibited-purpose rule  • All NPP modifications made by the 2024 rule   |
|     barring use/disclosure to investigate or        OTHER THAN (F), (G), and (H) — principally    |
|     impose liability for reproductive care.         the content implementing 42 CFR Part 2.       |
|   • The presumption that reproductive health      • Compliance deadline for those surviving NPP   |
|     care provided by another person was lawful.     modifications: FEBRUARY 16, 2026 — the same   |
|   • § 164.509 mandatory signed attestation.         date as the 42 CFR Part 2 Final Rule.         |
|   • NPP provisions at § 164.520(b)(1)(ii)(F),                                                     |
|     (G), and (H) only.                                                                            |
+---------------------------------------------------------------------------------------------------+

What the Court Left Standing

The court did not vacate the whole of 45 CFR § 164.520. It struck only the three subparagraphs it found unlawful — § 164.520(b)(1)(ii)(F), (G), and (H) — and expressly left the balance of the 2024 Notice of Privacy Practices amendments undisturbed. Those surviving amendments are the ones that rewrite the NPP to account for 42 CFR Part 2 substance use disorder records, and compliance with them is required by February 16, 2026. A privacy officer whose 2026 work plan drops "NPP rewrite" because "the reproductive rule was struck down" will miss a live federal deadline.

What Governs a Reproductive-Health Records Request Today

With the prohibited-purpose rule and the attestation gone, an out-of-state demand for records of lawful reproductive care is analyzed under the baseline Privacy Rule plus state law:

  1. Baseline § 164.512 analysis. Is there a permitted-disclosure pathway at all (court order, grand jury subpoena, qualified protective order, health oversight, coroner)? If not, the disclosure requires a valid § 164.508 authorization.
  2. Permissive, not mandatory. Section 164.512 says a covered entity may disclose. Except where another law affirmatively compels production, HIPAA never obligates a covered entity to hand PHI to law enforcement; declining or narrowing an over-broad request is a lawful option.
  3. State shield statutes now carry the load. States including California, Washington, Illinois, New York, and Massachusetts have enacted reproductive- and gender-affirming-care shield laws that bar clinicians and records custodians from complying with out-of-state investigative demands. Those statutes are more stringent than HIPAA and therefore survive preemption under 45 CFR § 160.203(b).
  4. Consumer health data statutes still apply. Washington's My Health My Data Act and comparable state laws regulate reproductive and location data held outside HIPAA's perimeter and were untouched by Purl.

4. Responding to Law Enforcement, Judicial, and Cross-Border Requests

Because the attestation gate is gone, the operational burden falls back on the ordinary § 164.512 disclosure analysis. This is the highest-volume, highest-risk request stream a hospital privacy office handles, and it is heavily represented in scenario items.

+---------------------------------------------------------------------------------------------------+
|              EXTERNAL PHI REQUEST TRIAGE UNDER 45 CFR § 164.512(e) AND (f)                        |
|                                                                                                   |
|   STEP 1: WHAT INSTRUMENT IS IT?                                                                  |
|   • Court order / court-ordered warrant / grand jury subpoena -> permitted, limited to the PHI     |
|     expressly authorized by the order.                                                            |
|   • Attorney-issued subpoena or discovery request with NO court order -> permitted ONLY with       |
|     "satisfactory assurances" (§ 164.512(e)(1)(ii)): written proof the requester gave the          |
|     individual notice and time to object, OR that a qualified protective order was sought.        |
|   • Administrative request/summons from a law enforcement official -> permitted only if the        |
|     information sought is relevant, the request is specific and limited, and de-identified data    |
|     could not reasonably be used (§ 164.512(f)(1)(ii)(C)).                                        |
|                                        |                                                          |
|                                        v                                                          |
|   STEP 2: IS A MORE PROTECTIVE LAW IN PLAY?                                                       |
|   • 42 CFR Part 2 SUD records -> court order meeting Part 2 criteria required; a HIPAA-compliant   |
|     subpoena alone is NOT enough.                                                                 |
|   • Psychotherapy notes -> § 164.508(a)(2) authorization or a court order.                         |
|   • State shield law, HIV/genetic/minor-consent statutes -> more stringent state law controls.     |
|                                        |                                                          |
|                                        v                                                          |
|   STEP 3: DISCLOSE THE MINIMUM NECESSARY, THEN DOCUMENT                                           |
|   • Produce only the records the instrument reaches; do not send the full chart by default.        |
|   • Log the disclosure — § 164.512 disclosures are ACCOUNTABLE under § 164.528.                    |
+---------------------------------------------------------------------------------------------------+

The Narrow Law-Enforcement Lanes of § 164.512(f)

LaneRegulatory CiteWhat May Be Released
Legal process§ 164.512(f)(1)(ii)Only what the court order, warrant, grand jury subpoena, or qualifying administrative request reaches
Identification and location§ 164.512(f)(2)A closed list only — name, address, date and place of birth, SSN, ABO blood type and Rh factor, type of injury, date and time of treatment or death, and distinguishing physical characteristics. DNA, dental records, and tissue typing are expressly excluded.
Victims of a crime§ 164.512(f)(3)With the individual's agreement, or without it only under the narrow incapacity conditions in the rule
Decedents§ 164.512(f)(4)PHI relevant to a death the entity suspects resulted from criminal conduct
Crime on the premises§ 164.512(f)(5)PHI the entity believes is evidence of a crime committed on its premises
Off-site medical emergency§ 164.512(f)(6)Limited PHI when a provider responding off-site needs to alert law enforcement to a crime

[!CAUTION] The Two Traps That Still Generate OCR Findings: First, treating an attorney's subpoena as a court order — it is not, and disclosure without satisfactory assurances or a qualified protective order is impermissible. Second, over-production: the officer at the desk asks for "the chart," and the release-of-information clerk sends the full longitudinal record when § 164.512(f)(2) permits only the closed identification list. Both are minimum-necessary failures, and both are fully accountable disclosures under § 164.528.

Loading diagram...
External PHI Request Triage After the Purl Vacatur
Test Your Knowledge

A hospital in a state with strict privacy laws receives a request from an out-of-state health plan to disclose medical records for healthcare operations. Under the HIPAA Privacy Rule (45 CFR § 164.506), disclosures for operations are permitted without patient consent. However, the hospital's home state statute strictly mandates that no medical records may be disclosed to third parties without express, written patient consent. How must the Privacy Officer resolve this conflict under 45 CFR Part 160 Subpart B?

A
B
C
D
Test Your Knowledge

A regional hospital operating in Texas hires a new medical records clerk. Under the Texas Medical Records Privacy Act (Tex. Health & Safety Code Ch. 181), what is the statutory training obligation, and how does it compare to HIPAA?

A
B
C
D
Test Your Knowledge

In 2026, a hospital in State A receives a subpoena signed by a State B prosecutor — with no accompanying court order — demanding records of a patient who traveled to State A for lawful reproductive health care, to support a criminal investigation of the patient. How should the hospital privacy officer analyze the request?

A
B
C
D