Preemption of State Law
Preemption is the legal principle under which one law overrides another law that would otherwise apply. In the HIPAA context, it generally means that federal HIPAA rules can override a conflicting state law, but this is not automatic in every case. Notably, state laws that provide stronger privacy protections often remain in effect alongside HIPAA rather than being displaced by them.
Preemption is a constitutional doctrine under which a superseding law displaces a conflicting law that would otherwise apply. Under the HIPAA Privacy Rule, a state law is generally considered 'contrary' when it would be impossible for a covered entity to comply with both the state law and the federal requirement, or where the state law otherwise stands as an obstacle to the federal scheme. As a general matter, HIPAA establishes a federal floor rather than a ceiling: contrary state law is preempted, but state laws that are 'more stringent' (for example, those affording individuals greater privacy protections or access rights) are typically not preempted and continue to apply. HIPAA also recognizes specific exceptions to preemption, and certain state laws may not be preempted where they serve enumerated regulatory purposes. Preemption analysis is fact-specific and provision-by-provision; practitioners should not assume blanket displacement of state law. This entry addresses HIPAA-related preemption analysis and does not resolve preemption questions arising under other federal statutes. Because preemption determinations turn on the precise language of both the state law and the applicable federal provision, and because state laws and the HITECH Act may impose additional requirements, readers should verify specific outcomes against the current regulatory text and applicable state law.
Why it matters
Preemption of state law determines which rules a covered entity or business associate must actually follow when federal HIPAA requirements and state privacy laws point in different directions. Because HIPAA generally functions as a federal floor rather than a ceiling, understanding preemption is essential to avoid a common and costly mistake: assuming that compliance with HIPAA alone is sufficient. In many cases, state laws that provide stronger privacy protections, greater individual access rights, or stricter conditions on disclosure remain fully in effect alongside HIPAA and must be honored.
The practical stakes are significant because preemption analysis is fact-specific and must be conducted provision-by-provision. A state law is generally treated as 'contrary' only where it would be impossible to comply with both the state requirement and the federal requirement, or where the state law stands as an obstacle to the federal scheme. Even then, a contrary state law that is 'more stringent' typically survives preemption. This means an organization operating in multiple states may face a patchwork of obligations that layer on top of, rather than replace, HIPAA's baseline.
Getting preemption wrong can expose organizations to liability under both federal and state regimes. Because HIPAA does not displace stronger state protections, and because the HITECH Act and state statutes may impose additional requirements, compliance programs that default to HIPAA as the sole standard risk overlooking obligations that remain legally enforceable at the state level. Preemption determinations should be verified against the current regulatory text and the specific applicable state law rather than assumed.
Who it's relevant to
Inside Preemption of State Law
Common questions
Answers to the questions practitioners most commonly ask about Preemption of State Law.