Skip to main content
Category: Regulatory Framework

Preemption of State Law

Also known as: HIPAA Preemption, Federal Preemption of State Privacy Law
Simply put

Preemption is the legal principle under which one law overrides another law that would otherwise apply. In the HIPAA context, it generally means that federal HIPAA rules can override a conflicting state law, but this is not automatic in every case. Notably, state laws that provide stronger privacy protections often remain in effect alongside HIPAA rather than being displaced by them.

Formal definition

Preemption is a constitutional doctrine under which a superseding law displaces a conflicting law that would otherwise apply. Under the HIPAA Privacy Rule, a state law is generally considered 'contrary' when it would be impossible for a covered entity to comply with both the state law and the federal requirement, or where the state law otherwise stands as an obstacle to the federal scheme. As a general matter, HIPAA establishes a federal floor rather than a ceiling: contrary state law is preempted, but state laws that are 'more stringent' (for example, those affording individuals greater privacy protections or access rights) are typically not preempted and continue to apply. HIPAA also recognizes specific exceptions to preemption, and certain state laws may not be preempted where they serve enumerated regulatory purposes. Preemption analysis is fact-specific and provision-by-provision; practitioners should not assume blanket displacement of state law. This entry addresses HIPAA-related preemption analysis and does not resolve preemption questions arising under other federal statutes. Because preemption determinations turn on the precise language of both the state law and the applicable federal provision, and because state laws and the HITECH Act may impose additional requirements, readers should verify specific outcomes against the current regulatory text and applicable state law.

Why it matters

Preemption of state law determines which rules a covered entity or business associate must actually follow when federal HIPAA requirements and state privacy laws point in different directions. Because HIPAA generally functions as a federal floor rather than a ceiling, understanding preemption is essential to avoid a common and costly mistake: assuming that compliance with HIPAA alone is sufficient. In many cases, state laws that provide stronger privacy protections, greater individual access rights, or stricter conditions on disclosure remain fully in effect alongside HIPAA and must be honored.

The practical stakes are significant because preemption analysis is fact-specific and must be conducted provision-by-provision. A state law is generally treated as 'contrary' only where it would be impossible to comply with both the state requirement and the federal requirement, or where the state law stands as an obstacle to the federal scheme. Even then, a contrary state law that is 'more stringent' typically survives preemption. This means an organization operating in multiple states may face a patchwork of obligations that layer on top of, rather than replace, HIPAA's baseline.

Getting preemption wrong can expose organizations to liability under both federal and state regimes. Because HIPAA does not displace stronger state protections, and because the HITECH Act and state statutes may impose additional requirements, compliance programs that default to HIPAA as the sole standard risk overlooking obligations that remain legally enforceable at the state level. Preemption determinations should be verified against the current regulatory text and the specific applicable state law rather than assumed.

Who it's relevant to

Privacy Officers and Compliance Officers
Privacy and compliance officers must map the state privacy laws applicable to their organizations against HIPAA requirements to determine where more stringent state protections continue to apply. They cannot assume that HIPAA compliance alone satisfies all obligations, and should build policies that account for the layered nature of federal and state requirements.
Legal Counsel and Regulatory Advisors
Attorneys advising covered entities and business associates conduct the provision-by-provision preemption analysis that determines whether a specific state law is contrary and, if so, whether it is more stringent and therefore survives preemption. Because these determinations are fact-specific and turn on precise statutory language, counsel plays a central role in reaching defensible conclusions.
Multi-State Covered Entities and Business Associates
Organizations operating across multiple states face a patchwork of state privacy laws that may layer on top of HIPAA's federal floor. They must identify which state requirements are more stringent in each jurisdiction where they operate, since those requirements generally remain enforceable alongside HIPAA rather than being displaced by it.
Policy and Governance Teams
Teams responsible for enterprise policies and procedures need to reflect that HIPAA establishes a baseline rather than a ceiling. Governance frameworks should incorporate applicable more-stringent state obligations and any requirements imposed by the HITECH Act, and should be revisited as state laws and federal guidance change over time.

Inside Preemption of State Law

General Preemption Standard
HIPAA generally preempts contrary state laws relating to the privacy of protected health information, meaning that where a state provision and a HIPAA requirement conflict, the HIPAA requirement typically controls. This standard applies to covered entities and, through defined relationships, business associates.
More Stringent State Law Exception
A key exception provides that state laws that are more stringent than HIPAA (generally those affording individuals greater privacy protections or greater rights of access to their information) are not preempted and continue to apply. Determining which law is more stringent often requires a provision-by-provision analysis rather than a blanket comparison.
Statutory Exceptions to Preemption
Certain categories of state law are generally excepted from preemption, such as those addressing public health reporting, vital statistics, and similar governmental functions, as well as state laws that the Secretary of HHS may determine warrant an exception. Readers should verify the specific categories and any determination process against the current regulatory text.
Floor, Not a Ceiling
HIPAA is generally understood as establishing a federal baseline (a floor) of privacy and security protections rather than a uniform national standard that displaces all state requirements. State laws imposing additional obligations may coexist with and supplement HIPAA where they are not contrary or are more stringent.
Scope and Interaction with Other Frameworks
Preemption analysis under HIPAA concerns the relationship between HIPAA and state law. It does not resolve obligations arising under other federal laws (such as the HITECH Act) or under private frameworks. HITRUST CSF certification, for example, is a private control framework and is not a legal requirement and does not by itself establish HIPAA compliance or affect preemption analysis.

Common questions

Answers to the questions practitioners most commonly ask about Preemption of State Law.

Does HIPAA automatically override all state privacy laws?
No. HIPAA does not automatically override all state privacy laws. The general rule is that HIPAA sets a federal floor, and state law is preempted only where it is contrary to HIPAA. A key exception is that state laws which are more stringent than HIPAA (typically those that provide greater privacy protection to individuals or greater rights of access to their own information) generally are not preempted and continue to apply. As a result, covered entities and business associates often must comply with both HIPAA and applicable state requirements. You should verify how specific provisions interact against the current regulatory text.
If we are HIPAA compliant, does that mean we automatically satisfy state law?
Not necessarily. Because HIPAA generally operates as a federal floor rather than a ceiling, more stringent state laws typically remain in effect alongside HIPAA. Meeting HIPAA obligations does not by itself guarantee compliance with state requirements that impose additional or stricter obligations, such as tighter breach notification timelines, special protections for categories like mental health, HIV, or substance use information, or broader individual rights. Compliance programs should evaluate applicable state law separately and confirm current requirements in each relevant jurisdiction.
How do we determine whether a specific state law provision is preempted?
In general, the analysis considers whether the state provision is contrary to HIPAA (meaning it would be impossible to comply with both, or the state provision stands as an obstacle to HIPAA's objectives) and, if so, whether it qualifies as more stringent. A provision that is contrary but more stringent typically is not preempted, while a contrary provision that is less protective generally is. This is a provision-by-provision analysis rather than a whole-statute analysis. Because outcomes turn on specific facts and current regulatory definitions, organizations often involve legal counsel and confirm the current standards for what qualifies as more stringent.
How should a multi-state organization handle differing state requirements?
Organizations operating across multiple states typically must identify the applicable requirements in each jurisdiction where they operate or where the individuals whose information they hold are located, then reconcile those against HIPAA. A common practical approach is to map obligations state by state and, where feasible, design policies to the most protective applicable standard, while documenting where jurisdiction-specific handling is required. Because state requirements change over time, this mapping should be reviewed periodically and confirmed against current sources.
Do business associates need to consider state preemption issues?
Yes, in many cases. While HIPAA obligations attach to business associates through defined relationships and business associate agreements, applicable state law may impose additional or more stringent requirements that are not preempted. Business associates should evaluate which state requirements apply to the information they handle and the services they provide, and coordinate with the covered entity as appropriate. The specific allocation of responsibilities is generally addressed in the business associate agreement and should be reviewed against current legal requirements.
How does preemption affect breach notification obligations?
Breach notification is an area where state law frequently imposes requirements alongside HIPAA's Breach Notification Rule. More stringent state notification laws, such as those with shorter timelines, different content requirements, or notification to state regulators, generally are not preempted and may apply in addition to HIPAA. Organizations typically need to satisfy both the federal and applicable state obligations for a given incident. Because thresholds, timelines, and required recipients vary and change over time, these should be confirmed against current HIPAA guidance and current state law for each affected jurisdiction.

Common misconceptions

HIPAA overrides all state privacy laws, so compliance officers only need to follow HIPAA.
HIPAA generally functions as a floor rather than a ceiling. State laws that are more stringent, or that fall within recognized exceptions such as public health reporting, are typically not preempted and continue to apply. Practitioners generally must comply with both HIPAA and applicable state requirements.
Determining whether a state law is preempted can be done at the level of an entire statute.
Preemption analysis is typically conducted provision by provision. A single state law may contain some provisions that are preempted and others that are more stringent and therefore not preempted, so a granular comparison is generally required.
'More stringent' simply means whichever law is harder to comply with.
'More stringent' has a specific regulatory meaning generally tied to providing individuals greater privacy protection or greater access to their own information, not to operational burden on the covered entity. Readers should confirm the precise definition against the current regulatory text.

Best practices

Conduct a provision-by-provision comparison of applicable HIPAA requirements against relevant state laws rather than assuming HIPAA displaces state law wholesale.
Maintain a jurisdiction-specific analysis for each state in which the organization operates, since more stringent state privacy laws may impose additional obligations beyond HIPAA.
Document preemption determinations, including the reasoning for why a given state provision is treated as preempted, more stringent, or within a statutory exception, and revisit these when laws change.
Involve legal counsel familiar with both HIPAA and applicable state law when resolving apparent conflicts, and confirm categories, definitions, and any HHS determinations against the current regulatory text.
Recognize that other frameworks (such as the HITECH Act) or private certifications (such as the HITRUST CSF) do not substitute for a preemption analysis and do not by themselves establish HIPAA compliance.
Build policies and workflows to the more protective applicable standard when a state law is more stringent, and periodically re-verify against current guidance as laws and regulations are updated over time.