Introduction
For decades, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) has served as the primary federal framework governing the privacy and security of health information in the United States. However, HIPAA was not designed to serve as a comprehensive privacy law. The impetus for HIPAA was to streamline the portability of health records. HIPAA’s implementing regulations, including the Privacy Rule and the Security Rule, only apply to covered entities (health plans, health care clearinghouses, and health care providers) and the individuals and entities serving as “business associates” to HIPAA covered entities. In addition, the Privacy and Security Rules only regulate “protected health information” (PHI) handled by those entities. HIPAA does not generally regulate consumer-facing health apps, wearable fitness trackers, wellness platforms, or other parties that operate outside of the covered entity and business associate framework.
As consumer health data moves in digital platforms that fall outside of HIPAA, states have moved to fill those regulatory gaps. The result is an expanding patchwork of state consumer health data privacy laws that impose obligations beyond HIPAA’s requirements and apply to a broader range of entities. For businesses that collect, process, or share health-related data, HIPAA compliance is the floor, not the ceiling, and those organizations that may fall outside of HIPAA regulation may fall within consumer health data regulations.
States with Dedicated Consumer Health Data Privacy Laws
Washington
Washington’s My Health My Data Act (MHMDA), effective in 2024, was the first comprehensive state consumer health data law in the country. MHMDA broadly defines “consumer health data” to encompass personal information linked or reasonably linkable to a consumer’s physical or mental health status, including data derived from non-traditional sources such as apps and wearable devices. Importantly, MHMDA applies to any entity that conducts business in Washington state or targets Washington consumers, although it carves out PHI and other data regulated under certain Washington and federal privacy laws. MHMDA requires affirmative consumer consent or authorization before the collection, sharing, or sale of consumer health data, and restricts the use of geofencing technology around health care facilities. Notably, consumers have a private right of action under MHMDA that gives them a direct avenue to litigation that HIPAA does not provide.
Nevada
Subsequent to Washington’s MHMDA, Nevada enacted SB 370, a consumer health data law that largely mirrors Washington’s approach. However, Nevada’s law does not include a private right of action for consumers, and its scope of regulated entities and data is more limited than Washington’s expansive framework.
California
California has two complementary data privacy frameworks relevant to health data: the California Confidentiality of Medical Information Act (CMIA) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). CMIA is a longstanding state law that predates HIPAA. It imposes medical information confidentiality obligations on a broader range of entities than HIPAA and has been amended over time to capture health apps and technology companies that handle medical information but are not otherwise subject to HIPAA, such as fertility trackers or medication reminder apps. Separately, CCPA/CPRA classifies health-related information as “sensitive personal information,” providing California consumers with increased rights to limit the use and disclosure of their data. Together, these two laws create layered obligations for entities handling health information in California.
Comprehensive Consumer Privacy Laws with Health Data Provisions
Beyond these health-specific statutes, a large and growing number of states address health data through their comprehensive consumer privacy laws by classifying it as a category of sensitive data subject to heightened protections. These states include Colorado, Connecticut (with its 2023 health data amendments), Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Laws will go into effect over the course of the next two years in Alabama (2027), Louisiana (2027), Oklahoma (2027), and Vermont (2028).
Scope of Sensitive Data Definitions
All of the aforementioned states include some reference to the mental or physical health condition or diagnosis of a consumer in their definitions of sensitive data. However, these are not defined identically. The narrowest states limit the category to a mental or physical health diagnosis — this approach is taken by Florida, Indiana, Iowa, Kentucky, Louisiana, Nebraska, Oklahoma, Tennessee, Texas, and Virginia. A broader group, including Alabama, Colorado, Delaware, Maryland, Minnesota, Montana, New Hampshire, Oregon, Rhode Island, and Vermont, extends the category to a mental or physical health condition or diagnosis. Connecticut, New Jersey, and Utah have the broadest definition, which includes a consumer’s mental or physical health medical history, condition, treatment, or diagnosis.
Opt-In Versus Opt-Out Consent for Processing Sensitive Health Data
The majority of these states, including Colorado, Connecticut, Delaware, Florida, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia, as well as the laws not yet in effect in Alabama, Louisiana, Oklahoma, and Vermont, require businesses to obtain a consumer’s affirmative opt-in consent before processing sensitive data, including health-related sensitive data. A smaller set of states, including Iowa and Utah, take a lighter approach and only require that businesses notify consumers that data will be processed and honor a consumer’s opt-out request rather than requiring affirmative consent.
Geofencing Restrictions
Geofencing-specific restrictions tied to health care facilities remain rare outside the health-specific statutes previously discussed. Connecticut is a notable exception. Its 2023 health data amendments added a prohibition on the use of geofencing around mental health, reproductive, or sexual health facilities to track consumers, collect their health data, or target them with health-related advertisements.
HIPAA and PHI Exemptions
States take different approaches to exempting HIPAA-regulated information from their state privacy laws. Exemptions can be entity-level exemptions, meaning a HIPAA covered entity or business associate is excused from complying with state requirements altogether when acting in that capacity, regardless of whether the specific data at issue qualifies as PHI under HIPAA. A data-level exemption is narrower. It excuses only the specific information that falls under HIPAA’s PHI definition, leaving any other personal data the organization collects subject to state law. The distinction matters because many organizations, including hospitals, health systems, and their vendors, collect personal data that falls outside of the definition of PHI even though the organization itself is a HIPAA covered entity or business associate. For example, information might be collected by a patient-facing app, the entity’s marketing website, or a wellness program that is carved outside of the entity’s HIPAA-regulated functions. An organization operating in a data-level exemption-only state cannot assume its overall HIPAA-regulated entity status insulates it from the state privacy law. It must evaluate its compliance obligations depending on the dataset.
The more common approach taken by states provides an entity-level exemption for HIPAA covered entities and business associates as a category, without an express carve-out for PHI. This approach is taken by Connecticut, Florida, Indiana, Iowa, Kentucky, Montana, Nebraska, New Hampshire, Rhode Island, Tennessee, Texas, Utah, and Virginia. The second, narrower approach taken by California, Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon provides only a data-level exemption that exempts information treated as PHI under HIPAA without exempting HIPAA covered entities or business associates.
Practical Recommendations
Businesses that collect, process, or share health-related data in multiple states should consider the following operational steps.
- Do not assume HIPAA compliance is sufficient. State health data privacy laws apply not only to entities already subject to HIPAA but also, and especially, to entities that fall outside HIPAA’s scope entirely. A digital health company, wellness app developer, or data analytics provider that maintains safeguards aligned with HIPAA, or is not subject to HIPAA at all, may still face substantial obligations under state law. Enterprise-wide HIPAA compliance programs should be considered a baseline, not a guarantee of complete compliance.
- Review and update privacy policies and consent mechanisms. Many state health data laws require affirmative, specific consent for the collection and sharing of consumer health data. This standard may exceed what an organization’s existing privacy notices contemplate. Organizations should audit their privacy policies and implement robust opt-in mechanisms where required. Vendor contracts should also be reviewed to ensure they account for any state-law requirements that extend beyond HIPAA’s business associate framework.
- Monitor the evolving legislative landscape. State health data privacy law is progressing. For example, New York’s Health Information Privacy Act (NY HIPA) was passed by the state legislature but vetoed late in the 2025 session. However, the bill has since been revived and is advancing again in the 2026 legislative session. Organizations should not treat state health data privacy compliance as a one-time exercise; rather, they should ensure ongoing monitoring and periodic reassessment of compliance programs to stay ahead of new requirements as they emerge.

