A patient in Austin faxes a written request for a copy of her chart. Your policy says 30 days, because that's what the HIPAA Privacy Rule allows. Texas says 15 business days. You just missed a deadline by two weeks and your policy told you to do it.

That gap is what hipaa state law preemption is actually about. HIPAA is a federal floor, not a ceiling — where your state law is stricter or gives patients more rights, the state law wins and you have to follow it. This article walks through the legal test, the four categories of exceptions, the workflows that break most often, and the documentation your privacy officer needs on file when a state attorney general or an OCR investigator asks why you did what you did.

The Preemption Test in 45 CFR Part 160, Subpart B

Preemption analysis lives in 45 CFR §§ 160.201 through 160.205. It runs in two steps, and most practices skip the first one.

Step one: is the state law even "contrary"? Under § 160.202, a state law is contrary to HIPAA only if a covered entity would find it impossible to comply with both, or if the state law stands as an obstacle to the objectives of the administrative simplification provisions. If both laws can be satisfied at once — and they usually can — there is no conflict and both apply. You follow whichever is tighter, field by field.

Step two: if it is contrary, does an exception save it? Section 160.203 lists them. The one you will use ninety percent of the time is the "more stringent" exception at § 160.203(b).

What "More Stringent" Means, Specifically

Section 160.202 defines "more stringent" through six prongs. A state law survives preemption if it:

  • Prohibits or restricts a use or disclosure that HIPAA would permit
  • Gives the individual greater rights of access to their own PHI
  • Gives the individual greater rights to amend their PHI
  • Requires more information in a notice or authorization, or narrows the scope or duration of an authorization
  • Requires longer retention or more detailed record-keeping of disclosures
  • Otherwise provides greater privacy protection to the individual

Notice what is not on that list: administrative convenience for your practice. A state law that makes your life easier does not survive preemption. A state law that makes the patient better off does.

Does HIPAA Preempt State Privacy Law? The Short Answer

No, not usually. HIPAA preempts a contrary state law only when that law offers less privacy protection than the federal standard and no exception applies. Where a state law is more stringent — shorter records-release deadlines, written consent for HIV or mental health disclosures, tighter breach notice timelines — the state law controls and your practice must comply with it in addition to HIPAA. Preemption is not a way to escape state requirements. It is a tiebreaker that almost always resolves in favor of whichever rule protects the patient more.

The Four Exceptions That Preserve State Law Even When It Conflicts

Beyond "more stringent," § 160.203 preserves state law in three other situations, and your compliance program touches at least two of them regularly.

Public Health and Vital Statistics Reporting

State laws requiring reports of disease, injury, child abuse, birth, death, or public health surveillance and investigation are not preempted. Your communicable-disease reporting, your mandated-reporter obligations, your immunization registry submissions — those run on state rules, and HIPAA gets out of the way.

Health Plan Reporting for Audits and Program Monitoring

State laws requiring health plans to report for management or financial audits, program monitoring, or licensure survive. Relevant if you operate a plan component or a risk-bearing entity.

Secretary Exception Determinations

A state may petition HHS under § 160.204 for a determination that a contrary state law is necessary to prevent fraud and abuse, regulate insurance and health plans, report on health care delivery or costs, serve a compelling public health or safety need, or govern controlled substances. These are rare and specific. Do not assume one applies to you without checking the actual determination.

Controlled Substances and PDMP Reporting

State prescription drug monitoring program mandates fall in this territory. If your prescribers must query and report to the state PDMP, HIPAA does not excuse them.

Where the Conflict Bites: Five Workflows to Audit This Quarter

1. Records Request Turnaround

HIPAA gives you 30 days from receipt, with one 30-day extension on written notice. Several states are far shorter. Texas Health and Safety Code § 181.102 requires release of an electronic health record within 15 business days of a written request. California Health and Safety Code § 123110 requires allowing inspection within five business days and providing copies within 15 days.

Your release-of-information policy should state the operative deadline for your state, not the federal outer limit. Assign a named owner in HIM or the front office, and log the receipt date, the fulfillment date, and the format delivered. HHS's guidance on the individual right of access covers the federal baseline; your state overlay sits on top of it.

2. Breach Notification Timing and Recipients

The federal Breach Notification Rule requires individual notice without unreasonable delay and no later than 60 calendar days from discovery, with HHS notice for breaches of 500 or more individuals within the same window. Many states run shorter clocks and require notice to the state attorney general at thresholds HIPAA does not use — Texas, for example, requires attorney general notice within 30 days for breaches affecting at least 250 Texas residents.

Build your incident response runbook around the shortest applicable clock. If your patient population spans four states, the shortest of the four governs your operational timeline. Review the federal requirements at HHS's breach notification page and confirm your state AG's portal and format before you need it at 11 p.m. on a Friday.

HIPAA permits disclosure for treatment, payment, and operations without authorization. Many states do not, for specific categories:

  • HIV and STI test results
  • Mental health and psychotherapy records
  • Substance use disorder treatment (also governed federally by 42 CFR Part 2, which is stricter than HIPAA and is not a preemption question at all — it's a separate federal layer)
  • Genetic testing results
  • Reproductive and sexual health information
  • Records of care a minor consented to independently

Minor consent rules are the sharpest edge. In many states, a minor who lawfully consents to their own care controls the record — which means your parent portal proxy configuration is a preemption decision made by whoever set up your EHR access rules, probably without a memo.

4. Record Retention

HIPAA requires six years of retention for compliance documentation — policies, risk analyses, authorizations, disclosure logs. It says nothing about how long you keep the medical record itself. That comes from state law and your medical board, and it is frequently longer, especially for minors, where clocks often run from the age of majority. Write both numbers into your retention schedule and label which authority drives each.

5. Notice of Privacy Practices Content

Several states require additional NPP language — specific disclosure descriptions, state-law contact information, or acknowledgment procedures. If your NPP is a downloaded federal template with your logo dropped in, it is probably incomplete for your jurisdiction.

Building the Artifact: A State-Law Preemption Matrix

An auditor does not want to hear that you "follow the stricter rule." They want the document. Your preemption matrix is a table with one row per obligation and these columns:

  1. Obligation — records access deadline, breach notice to individuals, breach notice to AG, HIV disclosure consent, minor record access, retention period, NPP content
  2. HIPAA requirement — with citation
  3. State requirement — with statute citation
  4. Contrary? — yes/no, per § 160.202
  5. Which controls, and why — cite the exception
  6. Operative rule in our practice — the number your staff actually follows
  7. Policy and section where it's written
  8. Owner and last review date

That last column matters. Legislatures meet annually. Set a standing review after your state's session adjourns, plus an ad hoc trigger whenever you open a location or begin treating patients in a new state via telehealth. Multi-state telehealth is where preemption analysis quietly falls apart — you are typically subject to the law of the state where the patient is located.

If maintaining that matrix by hand across policies, your risk analysis, and your training materials is where this program stalls, use a system that generates and versions the whole document set together. Automated HIPAA risk analysis and policy generation keeps the federal baseline current so your team spends its hours on the state overlay, which is the part no template can guess for you.

Who Owns Which Piece

Privacy officer: owns the matrix, the annual review, and the final written determination for each row. Signs and dates it.

Legal counsel: makes the actual legal call on any row where "contrary" is genuinely ambiguous. You are not required to be a lawyer to run this program, but you should not be issuing statutory interpretations alone.

Compliance lead: pushes the operative rule into policies, job aids, and EHR configuration. A deadline that lives only in a memo does not change behavior.

Training coordinator: covers state-specific rules in onboarding and refreshers. Texas requires training within 90 days of hire and at least every two years for staff who handle PHI — a state requirement layered on top of HIPAA's less prescriptive training standard.

Front desk and HIM: execute the turnaround times and consent checks. Give them a one-page card, not a 40-page policy.

Business Associates and the State-Law Gap

Your BAA obligates the vendor to comply with the Privacy and Security Rules. It does not automatically obligate them to meet your state's shorter breach notice clock. If your state requires attorney general notice in 30 days and your BAA gives the vendor 60 days to tell you about an incident, you cannot possibly comply.

Fix it in the contract. Require notice within a defined number of days — many practices use five to ten calendar days from discovery — and state expressly that the vendor will cooperate with state-law notification. If you are rebuilding your agreements, a guided business associate agreement builder gets you to a signature-ready document you can then customize with state addenda.

Two Things That Are Not Preemption

Information blocking. The Cures Act rules include an exception where a state law prohibits a disclosure — but you must actually identify the law and document the reliance. "State privacy concerns" is not a defense. Review the information blocking exceptions before you withhold anything.

Consumer health privacy statutes. Newer state laws governing health data generally carve out PHI already covered by HIPAA. They tend to reach your marketing pixels, wellness apps, and non-covered affiliates rather than your chart. Different analysis, same privacy officer.

Your Next 30 Days

Pull your release-of-information policy and your incident response plan. Check whether either one cites a state statute. If neither does, you have a preemption gap that predates you and will outlast you unless someone writes it down.

Build the matrix for the eight obligations listed above, get counsel to review the ambiguous rows, and push the operative numbers into policies and staff job aids. Then generate your risk analysis and policy set so the federal layer is documented, dated, and defensible — and your state overlay has something solid to sit on.