The interaction between HIPAA and state or federal laws can be complex. This article explains when a state or federal law preempts HIPAA, how to determine which rule governs a given disclosure, and practical considerations for covered entities and business associates operating in the United States.
Overview Of Preemption In HIPAA Context
Preemption determines whether state or federal laws override HIPAA’s Privacy, Security, and Breach Notification Rules. The governing framework has three general forms: express preemption, field preemption, and conflict preemption. When analyzing preemption, the central question is whether applying HIPAA would conflict with or undermine a more protective state or federal statute or regulation.
Express, Field, And Conflict Preemption
Express preemption occurs when a federal law explicitly states it overrides state law. HIPAA itself does not contain a broad express preemption clause; instead, it relies on the interplay with state law and other federal statutes to determine scope.
Field preemption would apply if HIPAA occupies an entire regulatory field, leaving no room for state regulation. In practice, HIPAA does not preempt all state health information laws, so field preemption rarely governs HIPAA issues.
Conflict preemption applies when compliance with both laws is impossible, or when a state law stands as an obstacle to HIPAA’s objectives. In most everyday scenarios, state laws may coexist with HIPAA unless there is a direct conflict or a situation where HIPAA’s requirements would undermine a state priority.
When State Law Is More Stringent Or Additional
One of HIPAA’s core principles is that it does not preempt state laws that provide greater privacy protections or more stringent data safeguards, as long as those laws do not directly contradict HIPAA’s standards. If a state law imposes stricter privacy requirements or more robust breach notification timelines, those state provisions can apply in addition to HIPAA.
Examples include state medical privacy statutes, stricter patient consent requirements, or enhanced reporting obligations for certain entities. In these cases, entities must comply with both HIPAA and the stronger state standard where applicable, with the stricter rule prevailing for the overlapping area.
When State Law Is Not Preempted By HIPAA
HIPAA generally does not preempt state laws that regulate areas outside HIPAA’s scope or that address public health reporting, criminal activity, or other non-privacy objectives. For instance, some state laws require reporting of certain infections, abuse, or escapes from custody, which operate independently of HIPAA’s privacy framework.
Additionally, many states have robust privacy regimes that apply to health information beyond what HIPAA covers, such as licensing board requirements or state laws governing health information exchanges. In these contexts, HIPAA does not automatically override state provisions that serve state interests or enhance protections.
Key Federal Law Interactions To Consider
Beyond HIPAA, several federal laws interact with state privacy requirements and can influence preemption outcomes. Notable examples include:
- 42 CFR Part 2 — Confidentiality of Substance Use Disorder Treatment Records: This federal regulation has unique protections that can be stricter than HIPAA in certain circumstances, particularly around disclosures related to substance use treatment. In some scenarios, 42 CFR Part 2 may supersede HIPAA disclosures, especially when both laws apply to the same records.
- State breach notification laws — When applicable data breach laws impose strict timelines or notice contents, they may operate alongside HIPAA’s Breach Notification Rule, with state standards prevailing when they are more protective and do not conflict with HIPAA.
- Public health reporting statutes — State and federal public health laws may require reporting certain conditions or events, which may be mandated independent of HIPAA’s privacy provisions.
Practical Guidance For Compliance
How should organizations navigate preemption questions in practice?
- Identify Applicable Laws — Determine whether HIPAA, state privacy statutes, and other federal laws apply to the same records or disclosures.
- Assess Stringency — If a state law imposes stricter privacy protections or reporting requirements, plan to comply with the stricter standard when the overlap occurs.
- Examine Specific Disclosures — For disclosures that trigger Part 2, state law, or other regulations, review which requirement is more protective and which disclosures are allowed.
- Document Rationale — Maintain written policies that explain why a particular standard governs a given disclosure, especially when both HIPAA and a state law could apply.
- Consult Legal Counsel — When facing ambiguous preemption questions, seek guidance to avoid inadvertent noncompliance and potential penalties.
Common Misconceptions To Avoid
Several myths about HIPAA preemption can lead to risky assumptions. It is not true that HIPAA always preempts all state privacy laws, nor is it true that state laws always outrank HIPAA. Each scenario depends on the specific law at issue, the type of information, and the purpose of disclosure.
Illustrative Scenarios And Takeaways
Consider these practical examples:
- A state health information privacy statute with stronger patient consent requirements than HIPAA applies to the same PHI; entities must honor the stricter state consent standards in addition to HIPAA.
- A state reporting rule requires a rapid notification of a reportable communicable disease; HIPAA’s breach notification provisions may be superseded for those specific reports by the public health statute.
- A federal regulation outside HIPAA imposes unique confidentiality protections for genetic information in a health plan; where conflicts arise, the regulation with stricter safeguards generally governs the overlapping area.
Key takeaway: HIPAA serves as a baseline for privacy and security, but state and certain federal laws can augment or supersede HIPAA protections when they provide greater protection or address different objectives. Understanding the precise scope of each law is essential for compliant handling of health information.
