When Does a State or Federal Law Preempt HIPAA?

State law preempts HIPAA when it gives patients more privacy protection or greater rights over their health information than the federal Privacy Rule requires, and other federal laws preempt HIPAA when Congress created a separate framework for a specific type of record. HIPAA works as a federal floor: state rules can build higher, but they cannot drop below it. Answering when state or federal law preempts HIPAA in any specific situation means running the facts through the structured analysis at 45 CFR Part 160, Subpart B, which sorts state laws into ones HIPAA displaces, ones HIPAA lets stand, and ones that require a formal exception from the Secretary of HHS.

Before any of this matters, HIPAA has to apply. The Privacy Rule binds health plans, healthcare clearinghouses, providers who transmit health information electronically for covered transactions, and their business associates. It does not reach employment records, even ones with health information in them.1HHS.gov. Employers and Health Information in the Workplace If the records at issue sit outside HIPAA to begin with, preemption never enters the picture.

When a State Law Is “Contrary” to HIPAA

Preemption analysis begins with whether the state law actually conflicts. A state law is “contrary” to HIPAA under either of two tests: a covered entity literally cannot comply with both at once, or simultaneous compliance is possible but the state law undermines the purposes of HIPAA’s administrative simplification provisions.2eCFR. 45 CFR Part 160 General Administrative Requirements – Section 160.202 Definitions

A state law that blocked patients from accessing their own records would fail both tests, because HIPAA guarantees that access right. In that scenario, the federal rule overrides the state law. But most state privacy laws are not contrary at all; they add requirements on top of HIPAA, and a covered entity can satisfy both by following the stricter rule.

When State Law Wins Because It’s More Protective

The most common reason state law survives HIPAA is that it gives patients more. When a state law is “more stringent” than HIPAA in favor of the individual, the state law controls and both laws apply.3HHS.gov. Preemption of State Law

The federal regulations spell out six ways a state law can qualify as more stringent: restricting a use or disclosure that HIPAA would otherwise allow, giving patients faster or broader access to their records, requiring more detailed notice about how information will be used, demanding narrower or more specific patient consent, keeping disclosure records for longer periods, or providing greater privacy protection in any other respect.2eCFR. 45 CFR Part 160 General Administrative Requirements – Section 160.202 Definitions

In practice this shows up in several ways. Many states require explicit patient consent before a provider can release HIV status, mental health treatment records, or genetic testing results, even though HIPAA might permit those disclosures for treatment or payment without special authorization. The state consent rule controls. HIPAA gives providers 30 calendar days to respond to a records request, with one possible 30-day extension; a state that sets a 15-day deadline gives patients a greater right, and the shorter deadline applies.4U.S. Department of Health and Human Services. How Timely Must a Covered Entity Be in Responding to Individuals Requests for Access to Their PHI HIPAA allows providers to withhold psychotherapy notes from patient access requests; a state that grants patients the right to see those notes prevails.5U.S. Department of Health and Human Services. Summary of the HIPAA Privacy Rule HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach; states with shorter notification windows or broader definitions of a reportable breach layer their requirements on top.

The point is that “more stringent” state laws do not replace HIPAA. Both apply, and the covered entity has to satisfy whichever rule is stricter on each specific point.

State Laws HIPAA Leaves Alone Automatically

Several categories of state law are exempt from preemption without any showing of greater protectiveness. They are listed at 45 CFR 160.203 and do not require any petition or special determination.6eCFR. 45 CFR Part 160 Subpart B Preemption of State Law – Section 160.203

The largest category is public health and mandatory reporting. State laws that require the reporting of disease, injury, child abuse, birth, or death, and laws that authorize public health surveillance, investigation, or intervention, are all preserved. The Privacy Rule separately permits covered entities to make these disclosures without patient authorization.7eCFR. 45 CFR 164.512 Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required Every state requires healthcare professionals to report suspected child abuse or neglect. Providers routinely report communicable diseases like tuberculosis and measles to public health agencies, and many states require reporting gunshot wounds or other violent injuries to law enforcement. Complying with those state laws does not violate HIPAA.

Workers’ compensation falls in the same bucket. HIPAA permits covered entities to disclose protected health information as needed to comply with state workers’ compensation laws, and providers do not need a separate patient authorization to share treatment records with a workers’ comp insurer when the state system requires it.7eCFR. 45 CFR 164.512 Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required

The other automatic carve-outs cover state laws aimed at healthcare fraud and abuse prevention, insurance regulation to the extent expressly authorized by other statutes, controlled substances regulation, and health plan reporting for management audits, financial audits, program monitoring, or licensing.6eCFR. 45 CFR Part 160 Subpart B Preemption of State Law – Section 160.203 A state pharmacy board enforcing controlled-substance prescribing rules does not have to worry that its reporting requirements collide with HIPAA.

Court Orders and Subpoenas

A court order can force a provider to hand over medical records despite HIPAA. The Privacy Rule permits disclosures in response to a court order, limited to the specific information the order authorizes.7eCFR. 45 CFR 164.512 Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required

Subpoenas and discovery requests that come without a court order are treated differently. A covered entity can respond only if it receives satisfactory assurance that the patient was notified and had a chance to object, or that the requesting party sought a qualified protective order. A judge’s order stands on its own; a lawyer’s subpoena needs those additional safeguards before a provider can comply.

When Other Federal Laws Displace HIPAA

HIPAA is not the only federal law governing health-related information. In several contexts, Congress created separate privacy frameworks that control specific types of records.

Student Health Records Under FERPA

The Family Educational Rights and Privacy Act protects student education records maintained by schools and educational agencies.8U.S. Department of Education. Family Educational Rights and Privacy Act (FERPA) When a school nurse or campus health clinic maintains health records as part of a student’s educational file, those records are education records under FERPA and are excluded from HIPAA’s definition of protected health information entirely.9National Center for Education Statistics. Health Records FERPA and HIPAA FERPA controls who can access them.

Substance Use Disorder Records Under 42 CFR Part 2

Federal regulations at 42 CFR Part 2 impose heightened confidentiality on substance use disorder treatment records maintained by federally assisted programs.10eCFR. 42 CFR Part 2 Confidentiality of Substance Use Disorder Patient Records A 2024 final rule implementing provisions of the CARES Act aligned several aspects of Part 2 with HIPAA. Most notably, patients can now sign a single consent form that authorizes a program to share their records for all future treatment, payment, and healthcare operations, similar to how consent works under HIPAA.11HHS.gov. Fact Sheet 42 CFR Part 2 Final Rule

Part 2 still goes beyond HIPAA in critical ways. Substance use disorder treatment records cannot be used to investigate or prosecute the patient without written consent or a court order. Records obtained through audits of Part 2 programs carry the same restriction. And the 2024 rule created a new category called “SUD counseling notes” that require specific, separate consent and cannot be disclosed under a general treatment-payment-operations consent.11HHS.gov. Fact Sheet 42 CFR Part 2 Final Rule

Research and the Common Rule

The Federal Policy for the Protection of Human Subjects, known as the Common Rule (45 CFR 46), governs research involving human participants. When a research project needs protected health information from a covered entity, both the Common Rule and HIPAA apply. The Common Rule requires informed consent focused on the research; HIPAA requires a separate written authorization for the use of health information. Neither preempts the other. Researchers have to satisfy both.

Where HIPAA Sends You Back to State Law

HIPAA does not answer every question on its own. In some places, the Privacy Rule actively defers to state law to fill in the details. The clearest example is personal representatives.

Under the Privacy Rule, a personal representative is someone authorized under state or other applicable law to make healthcare decisions on behalf of another person, and a covered entity must generally treat that representative the same as the patient for purposes of accessing health information.12HHS.gov. Guidance Personal Representatives Who qualifies depends entirely on state law. A court-appointed guardian, a parent making decisions for a minor child, or someone holding healthcare power of attorney all derive their authority from the state legal system. HIPAA provides the framework; state law determines who fits into it.

Providers must consult state law to determine whether someone requesting a patient’s records actually has authority to receive them. Turning away a legitimate personal representative violates the patient’s access rights; handing records to someone without proper authority violates the disclosure restrictions.

Petitioning HHS for a Preemption Exception

When a state law is contrary to HIPAA and does not fit an automatic exception, it is not necessarily dead. The Secretary of HHS can grant a formal exception through the petition process at 45 CFR 160.204.13eCFR. 45 CFR Part 160 Subpart B Preemption of State Law

A state must submit the request through its chief elected official or a designee. The petition identifies the specific state law and the HIPAA provision it conflicts with, explains how healthcare providers and health plans would be affected, and argues that the state law meets one of the statutory exception criteria: preventing healthcare fraud, ensuring appropriate state regulation of insurance, enabling state reporting on healthcare delivery or costs, or serving a compelling public health, safety, or welfare need.14HHS.gov. Does the HIPAA Privacy Rule Preempt State Laws While the petition is pending, the federal standard remains in effect. This process is rarely used.

What Getting Preemption Wrong Costs

A covered entity that follows the wrong law when state and federal rules collide can face enforcement from more than one direction. HHS enforces HIPAA through the Office for Civil Rights using a tiered civil penalty structure adjusted annually for inflation. For 2026, penalties range from $145 per violation at the lowest tier (the entity did not know and could not reasonably have known) up to $2,190,294 per violation at the top tier (willful neglect, not corrected within 30 days). Penalties for identical violations in a single calendar year are capped at $2,190,294, but that cap applies per provision violated.15Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

On the state side, the HITECH Act gave state attorneys general independent authority to bring civil actions on behalf of their residents for HIPAA Privacy and Security Rule violations, seeking damages or injunctions.16HHS.gov. State Attorneys General A covered entity that ignores a more stringent state privacy law because it mistakenly believes HIPAA preempts it can face both a state enforcement action and a federal penalty, because the same conduct violates the state law and HIPAA’s requirement to follow the more protective standard.