More Stringent State Law
A "more stringent" state law is a state privacy law that gives individuals greater protection for their health information than the HIPAA Privacy Rule provides. While HIPAA generally overrides (preempts) conflicting state laws, it does not override state laws that offer stronger privacy protections. In those cases, healthcare organizations generally must follow the state law in addition to HIPAA.
Under HIPAA's preemption framework, a state law is generally deemed "more stringent" than the HIPAA Privacy Rule when it relates to the privacy of individually identifiable health information and provides greater privacy protections or rights to the individual than the corresponding federal standard. HIPAA generally preempts state laws that are contrary to a HIPAA privacy standard, but an exception exists where the state provision is more stringent, in which case the more protective state requirement generally continues to apply alongside HIPAA. Common examples cited in practice involve stricter authorization or consent procedures. This concept is specific to the Privacy Rule's preemption provisions and does not, by itself, address the Security Rule, Breach Notification Rule, or Enforcement Rule; the "more stringent" determination is made on a provision-by-provision basis. The precise regulatory criteria and application are governed by the HIPAA preemption regulations and should be confirmed against the current regulatory text and applicable state law, as HITECH and other frameworks may impose additional requirements.
Why it matters
HIPAA is frequently described as a national floor rather than a ceiling for health information privacy. While the Privacy Rule generally preempts contrary state laws, it does not override state provisions that give individuals greater privacy protection. This means that compliance with HIPAA alone does not guarantee compliance with the full body of privacy law applicable to a healthcare organization. Organizations that assume federal compliance is sufficient may inadvertently violate stricter state requirements, particularly around authorization, consent, and disclosure of sensitive categories of health information.
The practical stakes are highest for organizations operating across multiple states, because the "more stringent" determination is made on a provision-by-provision basis rather than statute-by-statute. A single state law may be more stringent in some respects and preempted in others, requiring a granular comparison against the corresponding HIPAA standards. This creates a patchwork compliance obligation in which the applicable rule can vary by state and by specific practice, such as the handling of consent procedures.
Because the analysis turns on the precise language of both the state law and the current HIPAA regulatory text, and because HITECH and other frameworks may impose additional requirements, organizations should treat "more stringent" analysis as an ongoing legal exercise rather than a one-time determination. Readers should confirm specific determinations against the current regulation and applicable state law, ideally with qualified legal counsel.
Who it's relevant to
Inside More Stringent State Law
Common questions
Answers to the questions practitioners most commonly ask about More Stringent State Law.