Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Sports
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Advanced Manufacturing and Industrials
    • Art and Cultural Property
    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Entertainment & Sports
    • Financial Institutions
    • Healthcare
    • Higher Education
    • Infrastructure
    • Nonprofit Organizations
    • Real Estate
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. When HIPAA compliance isn’t enough: The growing reach of state health privacy laws

      Articles

    Article

    When HIPAA compliance isn’t enough: The growing reach of state health privacy laws

    Aug 31, 2026

    LinkedInX (Twitter)EmailCopy URL

    As states continue to fill the gaps HIPAA leaves open, businesses handling health-related data should take a broader, more deliberate view of their health-related data privacy obligations.

    Authors

    • Valerie Breslin Montague

      Partner
      • Chicago +1 312.977.4485
      • vbmontague@nixonpeabody.com
      Valerie  Breslin Montague
    • Grace Connelly

      Associate
      • Chicago +1 312.977.9292
      • gconnelly@nixonpeabody.com
      Grace Connelly

    Introduction

    For decades, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) has served as the primary federal framework governing the privacy and security of health information in the United States. However, HIPAA was not designed to serve as a comprehensive privacy law. The impetus for HIPAA was to streamline the portability of health records. HIPAA’s implementing regulations, including the Privacy Rule and the Security Rule, only apply to covered entities (health plans, health care clearinghouses, and health care providers) and the individuals and entities serving as “business associates” to HIPAA covered entities. In addition, the Privacy and Security Rules only regulate “protected health information” (PHI) handled by those entities. HIPAA does not generally regulate consumer-facing health apps, wearable fitness trackers, wellness platforms, or other parties that operate outside of the covered entity and business associate framework. 

    As consumer health data moves in digital platforms that fall outside of HIPAA, states have moved to fill those regulatory gaps. The result is an expanding patchwork of state consumer health data privacy laws that impose obligations beyond HIPAA’s requirements and apply to a broader range of entities. For businesses that collect, process, or share health-related data, HIPAA compliance is the floor, not the ceiling, and those organizations that may fall outside of HIPAA regulation may fall within consumer health data regulations. 

    States with Dedicated Consumer Health Data Privacy Laws

    Washington

    Washington’s My Health My Data Act (MHMDA), effective in 2024, was the first comprehensive state consumer health data law in the country. MHMDA broadly defines “consumer health data” to encompass personal information linked or reasonably linkable to a consumer’s physical or mental health status, including data derived from non-traditional sources such as apps and wearable devices. Importantly, MHMDA applies to any entity that conducts business in Washington state or targets Washington consumers, although it carves out PHI and other data regulated under certain Washington and federal privacy laws. MHMDA requires affirmative consumer consent or authorization before the collection, sharing, or sale of consumer health data, and restricts the use of geofencing technology around health care facilities. Notably, consumers have a private right of action under MHMDA that gives them a direct avenue to litigation that HIPAA does not provide. 

    Nevada

    Subsequent to Washington’s MHMDA, Nevada enacted SB 370, a consumer health data law that largely mirrors Washington’s approach. However, Nevada’s law does not include a private right of action for consumers, and its scope of regulated entities and data is more limited than Washington’s expansive framework. 

    California

    California has two complementary data privacy frameworks relevant to health data: the California Confidentiality of Medical Information Act (CMIA) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). CMIA is a longstanding state law that predates HIPAA. It imposes medical information confidentiality obligations on a broader range of entities than HIPAA and has been amended over time to capture health apps and technology companies that handle medical information but are not otherwise subject to HIPAA, such as fertility trackers or medication reminder apps. Separately, CCPA/CPRA classifies health-related information as “sensitive personal information,” providing California consumers with increased rights to limit the use and disclosure of their data. Together, these two laws create layered obligations for entities handling health information in California. 

    Comprehensive Consumer Privacy Laws with Health Data Provisions

    Beyond these health-specific statutes, a large and growing number of states address health data through their comprehensive consumer privacy laws by classifying it as a category of sensitive data subject to heightened protections. These states include Colorado, Connecticut (with its 2023 health data amendments), Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Laws will go into effect over the course of the next two years in Alabama (2027), Louisiana (2027), Oklahoma (2027), and Vermont (2028). 

    Scope of Sensitive Data Definitions

    All of the aforementioned states include some reference to the mental or physical health condition or diagnosis of a consumer in their definitions of sensitive data. However, these are not defined identically. The narrowest states limit the category to a mental or physical health diagnosis — this approach is taken by Florida, Indiana, Iowa, Kentucky, Louisiana, Nebraska, Oklahoma, Tennessee, Texas, and Virginia. A broader group, including Alabama, Colorado, Delaware, Maryland, Minnesota, Montana, New Hampshire, Oregon, Rhode Island, and Vermont, extends the category to a mental or physical health condition or diagnosis. Connecticut, New Jersey, and Utah have the broadest definition, which includes a consumer’s mental or physical health medical history, condition, treatment, or diagnosis. 

    Opt-In Versus Opt-Out Consent for Processing Sensitive Health Data

    The majority of these states, including Colorado, Connecticut, Delaware, Florida, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia, as well as the laws not yet in effect in Alabama, Louisiana, Oklahoma, and Vermont, require businesses to obtain a consumer’s affirmative opt-in consent before processing sensitive data, including health-related sensitive data. A smaller set of states, including Iowa and Utah, take a lighter approach and only require that businesses notify consumers that data will be processed and honor a consumer’s opt-out request rather than requiring affirmative consent. 

    Geofencing Restrictions

    Geofencing-specific restrictions tied to health care facilities remain rare outside the health-specific statutes previously discussed. Connecticut is a notable exception. Its 2023 health data amendments added a prohibition on the use of geofencing around mental health, reproductive, or sexual health facilities to track consumers, collect their health data, or target them with health-related advertisements. 

    HIPAA and PHI Exemptions

    States take different approaches to exempting HIPAA-regulated information from their state privacy laws. Exemptions can be entity-level exemptions, meaning a HIPAA covered entity or business associate is excused from complying with state requirements altogether when acting in that capacity, regardless of whether the specific data at issue qualifies as PHI under HIPAA. A data-level exemption is narrower. It excuses only the specific information that falls under HIPAA’s PHI definition, leaving any other personal data the organization collects subject to state law. The distinction matters because many organizations, including hospitals, health systems, and their vendors, collect personal data that falls outside of the definition of PHI even though the organization itself is a HIPAA covered entity or business associate. For example, information might be collected by a patient-facing app, the entity’s marketing website, or a wellness program that is carved outside of the entity’s HIPAA-regulated functions. An organization operating in a data-level exemption-only state cannot assume its overall HIPAA-regulated entity status insulates it from the state privacy law. It must evaluate its compliance obligations depending on the dataset. 

    The more common approach taken by states provides an entity-level exemption for HIPAA covered entities and business associates as a category, without an express carve-out for PHI. This approach is taken by Connecticut, Florida, Indiana, Iowa, Kentucky, Montana, Nebraska, New Hampshire, Rhode Island, Tennessee, Texas, Utah, and Virginia. The second, narrower approach taken by California, Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon provides only a data-level exemption that exempts information treated as PHI under HIPAA without exempting HIPAA covered entities or business associates. 

    Practical Recommendations

    Businesses that collect, process, or share health-related data in multiple states should consider the following operational steps.

    • Do not assume HIPAA compliance is sufficient. State health data privacy laws apply not only to entities already subject to HIPAA but also, and especially, to entities that fall outside HIPAA’s scope entirely. A digital health company, wellness app developer, or data analytics provider that maintains safeguards aligned with HIPAA, or is not subject to HIPAA at all, may still face substantial obligations under state law. Enterprise-wide HIPAA compliance programs should be considered a baseline, not a guarantee of complete compliance. 
    • Review and update privacy policies and consent mechanisms. Many state health data laws require affirmative, specific consent for the collection and sharing of consumer health data. This standard may exceed what an organization’s existing privacy notices contemplate. Organizations should audit their privacy policies and implement robust opt-in mechanisms where required. Vendor contracts should also be reviewed to ensure they account for any state-law requirements that extend beyond HIPAA’s business associate framework. 
    • Monitor the evolving legislative landscape. State health data privacy law is progressing. For example, New York’s Health Information Privacy Act (NY HIPA) was passed by the state legislature but vetoed late in the 2025 session. However, the bill has since been revived and is advancing again in the 2026 legislative session. Organizations should not treat state health data privacy compliance as a one-time exercise; rather, they should ensure ongoing monitoring and periodic reassessment of compliance programs to stay ahead of new requirements as they emerge.

    Practices

    HealthcareLife Sciences & Healthcare Compliance and InvestigationsDigital Health & TelemedicineHealth Information - Privacy, Security & Data SharingCybersecurity & Privacy

    Industries

    HealthcareTechnology
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Supplier Code of Conduct
    • Nixon Peabody International LLP
    • PAL
    © 2026 Nixon Peabody. All rights reserved