HIPAA sets a national floor, not a ceiling. State law can add obligations on top of it, and frequently does — on breach notification, record retention, minor consent, and the handling of sensitive categories like mental health and substance use records.
What surprises most practices is the direction the surprise runs in. It is not always that the state demands more. Sometimes a state law that appears to bind you specifically exempts you, and following it anyway means running a clock you do not owe.
How preemption actually works
The general rule: state law is preempted by HIPAA where the two conflict, except where the state law is more stringent. More stringent generally means more protective of the individual — a shorter notification deadline, broader patient access rights, tighter restrictions on disclosure.
So the practical question is never "does HIPAA or state law apply." It is "which one is stricter on this specific point," evaluated requirement by requirement rather than statute by statute. A single state law can be more stringent in one paragraph and preempted in the next.
The trap: state breach laws that exempt covered entities
This is the most consequential and least understood interaction.
Most states have a data breach notification statute with a deadline — commonly 30, 45, or 60 days. Many of those statutes contain an express carve-out stating the article does not apply to a HIPAA covered entity or business associate that complies with HIPAA.
The effect is significant. Where such a carve-out exists, a medical practice does not owe the state deadline at all. HIPAA's own Breach Notification Rule — 60 days from discovery — governs instead. A practice that reads the headline "45-day state deadline" and builds its incident response around it has adopted a clock that does not bind it.
The carve-outs are not uniform. Some are unconditional, turning only on whether you are subject to HIPAA. Others are conditional, requiring that you actually comply. And in several states the carve-out removes the duty to notify individuals while leaving a separate obligation to notify the state attorney general intact.
The opposite trap: carve-outs that do not help
The reverse error is just as costly. A state can appear to grant a HIPAA carve-out while functionally imposing a stricter deadline anyway.
The clearest pattern is a statute that deems a federally regulated covered entity compliant, but adds that where both laws apply, the law with the shortest time frame for notice to the individual controls. If that state's deadline is 30 days, then 30 days genuinely binds you — the carve-out language notwithstanding.
Reading only the first half of that provision produces exactly the wrong conclusion, and it is the kind of thing that gets copied between compliance blogs without anyone checking the second half.
Beyond breach: three more places state law bites
Record retention. HIPAA requires six years of retention for its own required documentation, but says almost nothing about how long to keep the medical record itself. That is state law, and it varies widely — commonly six to ten years for adults, with separate and longer rules for minors, often expressed as a period running from the age of majority.
Sensitive record categories. Mental health, substance use, HIV status, and genetic information frequently carry state protections stricter than baseline HIPAA. Substance use disorder records may additionally fall under 42 CFR Part 2, a separate federal regime with its own consent architecture that is materially different from HIPAA's.
Minor consent and parental access. States differ substantially on when a minor may consent to their own care, and consequently on whether a parent may access that portion of the record. This is one of the most common sources of front-desk error.
If you operate in more than one state
Multi-state practices face the strictest-rule problem: for each requirement, the operative standard is generally the most protective one among the states where affected individuals reside — which may not be the state your office sits in.
For breach notification specifically, the analysis follows the patients, not the practice. A single incident touching residents of four states can trigger four different analyses.
How to approach this without a law degree
Three habits cover most of the risk.
Check the actual statute, not a summary. Secondary sources routinely report a state's headline deadline while omitting the HIPAA carve-out that makes it inapplicable to you. The carve-out is usually near the end of the section, in a subsection that begins with language like "this section does not apply to."
Separate the individual-notice duty from the regulator-notice duty. They are frequently governed by different provisions and one can survive a carve-out that eliminates the other.
Re-check after amendments. State breach statutes are amended often, and deadlines have been tightened in several states in recent years.
The underlying point is that "what does my state require" has no general answer. It has fifty-one specific ones, and the difference between them is frequently the difference between a duty you owe and a clock you invented.
Part of our guide to
State ComplianceSee how GuardWell helps medical practices manage state compliance end to end — checklists, policies, training, and audit-ready documentation in one platform.
Ready to simplify compliance?
GuardWell brings HIPAA, OSHA, OIG, and 12 more compliance modules into one affordable platform built for medical practices. Start your 7-day free trial today.
Start free trialRelated Articles
HIPAA Breach Notification: Rules, Timelines, and Penalties
A complete guide to HIPAA breach notification requirements — what constitutes a breach, notification timelines, how to report to OCR, and the penalties for non-compliance.
RegulatoryYour State AG Opened a HIPAA Investigation: Practice Rights and Response Strategy
Your state attorney general has opened a HIPAA investigation against your practice. This guide covers your rights, how AG enforcement differs from OCR, penalty exposure under HITECH, and how to build an effective response.
HIPAAHIPAA Compliance Checklist for Small Medical Practices in 2026
A practical HIPAA compliance checklist for small medical practices covering the Privacy Rule, Security Rule, breach notification, risk assessments, and staff training requirements.
ComplianceMedical Practice Compliance: The Complete 2026 Guide
A comprehensive overview of medical practice compliance requirements in 2026 — covering HIPAA, OSHA, OIG, CLIA, MACRA/MIPS, DEA, CMS, TCPA, state law, and staff training for doctors offices.
