HIPAA vs CIPA vs State Privacy Law: The Three Layers
Healthcare privacy isn't one law — it's three layers stacked on top of each other, and most compliance gaps come from mistaking one layer for the whole stack. Here's a clear map of all three, when you must follow state law instead of HIPAA, and which layer the website tracking lawsuits actually live in.
You must follow state law instead of (really, in addition to) HIPAA in three situations: when a state law is more stringent than HIPAA; when your data falls outside HIPAA's scope but inside a state law's (health-adjacent website data); or when the claim is a consent or wiretap matter HIPAA simply doesn't address.
The clean way to hold it all is as three layers: (1) HIPAA — the federal baseline; (2) state medical-privacy law like California's CMIA; (3) state consumer and wiretap law like CIPA and CCPA — which is where website tracking claims live. This is general information, not legal advice.
What this guide covers
If you manage a healthcare website, you've probably been handed conflicting instructions: "make sure we're HIPAA compliant," then "what about CIPA?", then "do we need to worry about the CCPA?" It feels like a pile of overlapping acronyms. It isn't. These laws occupy three distinct layers, each answering a different question, and once you can see the layers separately, the whole picture — including where your real risk sits — becomes clear. None of this is legal advice; privacy law is fact-specific and evolving, so confirm your position with qualified counsel.
Why it's three layers, not one law
The single most common healthcare privacy mistake is treating HIPAA as the whole of the law. "We're HIPAA compliant" gets used as shorthand for "we've handled privacy" — but HIPAA is only the bottom layer of a taller stack. It answers one specific question (how must covered entities handle protected health information?) and is silent on others that state laws answer.
Crucially, these layers don't replace each other — they add to each other. HIPAA is a federal floor, not a ceiling (45 CFR § 160.203): states are free to build stricter protections on top, and to regulate data and conduct HIPAA never touched. So the right question is never "HIPAA or state law?" It's "which layers apply to this data, on this page, in this state?" — usually more than one. (For the deep mechanics of how HIPAA and state law interact when they overlap, see our companion guide on when state privacy law supersedes HIPAA.)
Let's map the three layers, bottom to top.
HIPAA
Federal baselineHow covered entities and business associates must handle protected health information (PHI). Enforced by HHS and state AGs. No private right of action.
State medical-privacy law
e.g. California CMIAStricter rules on medical information — broader definitions, tighter disclosure, and often a private right of action. Sits on top of HIPAA where it's more protective.
Consent & wiretap / consumer law
e.g. CIPA, CCPA/CPRAConsent before tracking (CIPA wiretap theory) and rights over consumer/health-adjacent data (CCPA/CPRA). This is where website tracking lawsuits live — and it doesn't depend on HIPAA at all.
Layer 1 — HIPAA, the federal baseline
The bottom layer is the one everyone knows. HIPAA governs how covered entities (providers, health plans, clearinghouses) and their business associates handle protected health information — PHI. It sets the national minimum for safeguarding that data: what you can disclose, when you need authorization, and what security you must maintain.
Two features of this layer shape everything above it. First, HIPAA is a floor — it's the least protection patients are entitled to, not the most. Second, and critically for risk, HIPAA has no private right of action. An individual can't sue you under HIPAA; only HHS's Office for Civil Rights, state attorneys general, and (for criminal misuse) the DOJ enforce it. That single fact pushes most litigation risk up into the layers above, where private lawsuits are allowed. It's the reason a hospital can face an eight-figure class action over website tracking while its formal HIPAA enforcement exposure — an OCR penalty — might be a fraction of that. The money, and the volume, live where individuals can sue: the higher layers.
Layer 2 — state medical-privacy law
The middle layer is state law that governs the same kind of data as HIPAA — medical information — but often more strictly. California's Confidentiality of Medical Information Act (CMIA) is the archetype, and it out-protects HIPAA in ways that matter:
- Broader scope — CMIA's definition of "medical information" is wider than HIPAA's PHI, and it reaches entities HIPAA doesn't, such as certain businesses that maintain medical information.
- Tighter rules — stricter limits on disclosure and stronger authorization requirements.
- A private right of action — unlike HIPAA, CMIA lets individuals sue directly, with statutory damages reported around $1,000 per violation and no need to prove actual harm. Class actions have settled for tens of millions.
Because this layer is more stringent, it isn't preempted by HIPAA — it stacks on top, and you follow it where it's stricter. Other states have their own versions, and the map is expanding. This is the layer that means "we're HIPAA compliant" doesn't equal "we're compliant in California."
Layer 3 — consent and wiretap / consumer law
The top layer is the one healthcare teams most often miss, because it doesn't look like a "medical" law at all — and it's where the website tracking lawsuits actually happen. Two kinds of law occupy it:
- Wiretap / consent law — CIPA. California's Invasion of Privacy Act is a 1960s wiretapping statute now applied to websites. It asks a completely different question from HIPAA: did a third-party tracker intercept a visitor's communication without consent? It carries a private right of action with statutory damages commonly cited at $5,000 per violation, or treble damages, under Penal Code § 637.2 — and it applies regardless of whether the data is technically PHI.
- Consumer-privacy law — CCPA/CPRA. California's consumer-privacy regime reaches health-adjacent data that HIPAA never covered: website analytics, patient-portal activity, marketing lists, wellness apps, and wearables. It generally exempts the PHI already governed by HIPAA and CMIA, but the large gray zone around it — the data a consumer assumes is medical but isn't HIPAA-regulated — falls here, with its own opt-out obligations.
This layer is the crux of the whole article. It operates on a plane HIPAA doesn't touch — consent and interception, not PHI handling — which is exactly why a hospital can run a flawless HIPAA program and still lose a CIPA class action over a pixel firing before consent.
The third layer is the one most healthcare sites leave open
HIPAA and CMIA you handle with policy and counsel. The consent layer — CIPA and CCPA — is a technical control: trackers must not fire before a visitor consents. That's exactly what ConsentPixel does, and you can have it live today.
So when must you follow state law instead of HIPAA?
With the layers mapped, the headline question has a clean, three-part answer. You follow state law rather than relying on HIPAA alone whenever any of these is true:
- When the state law is more stringent. If a state medical-privacy law (Layer 2) protects the data more than HIPAA does, it isn't preempted — it controls, and you comply with both, following the stricter rule. HIPAA compliance alone isn't enough.
- When the data falls outside HIPAA but inside a state law. Health-adjacent data on your website — analytics, portal activity, marketing data — often isn't HIPAA-regulated PHI, but it is covered by Layer 3 (CCPA/CPRA). HIPAA has nothing to say about it; state consumer law does.
- When the claim is about consent or interception. A CIPA wiretap claim (Layer 3) turns on whether a tracker fired before consent — a question HIPAA doesn't ask. You can be fully HIPAA-compliant and still liable, because you're being judged under a law from a different layer.
In all three, notice it's rarely "instead of" in the sense of switching HIPAA off. It's "in addition to" — the higher layers add obligations HIPAA doesn't impose. The phrase "follow state law instead of HIPAA" really means "HIPAA wasn't the layer that governed this." For the full preemption mechanics behind point (1), see our guide on when state privacy law supersedes HIPAA.
What happens when layers overlap on the same data
A natural question once you see three layers: what if the same piece of data is touched by more than one of them at once? This is where people get tangled, so it's worth a clear rule.
The layers don't cancel each other out — they impose cumulative obligations, and you follow the strictest that applies. Consider a single event: a logged-in patient views a lab result on your portal while a marketing pixel is active. That one event can implicate all three layers simultaneously. Layer 1 (HIPAA) asks whether PHI reached a vendor without a BAA. Layer 2 (a stricter state medical-privacy law) may impose tighter disclosure limits on that same medical information. Layer 3 (CIPA) asks whether the tracker intercepted the interaction without consent. You don't get to pick the most convenient one — you have to satisfy each layer that applies.
There's one important simplification that keeps this manageable: the layers are generally designed to avoid double-regulating the identical data. State consumer-privacy laws like the CCPA typically exempt data already governed by HIPAA and CMIA, precisely so you're not subject to conflicting rules on the same record. So in practice, the PHI in your clinical systems is governed by Layers 1 and 2, while the health-adjacent tracking data on your website — which those exemptions don't reach — is governed by Layer 3. The overlap is real but bounded, and understanding where each layer's territory begins is what lets you assign the right control to each. For the detailed mechanics of how HIPAA and a stricter state law resolve when they genuinely conflict, our preemption guide walks through the "more stringent" test step by step.
Which layer your website actually lives in
Here's the part that reorganizes how most teams think about their site. When you ask "which layer governs my website," the intuitive answer is "HIPAA" — it's a healthcare site, after all. But for the tracking-and-consent question that's driving litigation, your website lives mostly in Layer 3, not Layer 1.
Think about what a third-party tracker on your site actually does: it intercepts a visitor's interaction and transmits it to an ad or analytics vendor. That's a consent and interception event — a Layer 3 question (CIPA, CCPA) — regardless of whether the specific data point qualifies as HIPAA PHI. It's why the entire healthcare pixel litigation wave was brought under wiretap and consumer-privacy theories, not HIPAA. The hospitals in those cases often had solid HIPAA programs; what they lacked was control at Layer 3.
This is the reframe that matters: your HIPAA program (Layer 1) and your medical-privacy obligations (Layer 2) are necessary, but they don't cover the tracker-fires-before-consent problem. That problem lives one layer up, and it needs its own control. A useful rule of thumb:
- PHI moving through your systems and vendors → Layer 1 (HIPAA / BAAs) and Layer 2 (state medical-privacy).
- Trackers, pixels, and analytics on your public and portal pages → Layer 3 (CIPA / CCPA consent).
Most healthcare organizations invest heavily in the first and leave the second largely unmanaged — which is precisely the gap the lawsuits exploit.
How to cover all three layers
Each layer has a distinct owner and a distinct control. Trying to solve all three with one tool or one team is how gaps form. The clean division:
- Layer 1 (HIPAA) — owned by compliance and counsel. BAAs with every vendor that touches PHI, PHI-safe data paths, authorization where required, and security safeguards. This is policy and contracts work.
- Layer 2 (state medical-privacy) — owned by counsel, state by state. Identify where you operate, whether a stricter state law like CMIA applies, and follow the stricter rule where it does. Largely a legal-analysis task.
- Layer 3 (consent & wiretap) — owned by whoever controls the website. This is a technical control, not a policy one: non-essential third-party trackers must be blocked until a visitor consents, opt-out signals honored, and consent logged as evidence. And because tags get added continuously, it needs ongoing verification, not a one-time fix.
ConsentPixel — Privacy · Verified is built for Layer 3 specifically. It blocks third-party trackers at the browser level until a visitor consents, honors opt-out signals under CCPA/CPRA, continuously scans what fires across your pages so a stray tag can't quietly reappear, and logs each consent decision as tamper-evident evidence. To be plain about our lane — because overclaiming here would undercut the whole point of understanding the layers — ConsentPixel is not a HIPAA product and does not make any website "HIPAA compliant." It doesn't touch Layer 1 or Layer 2; those stay with your compliance team and counsel. What it does is close the Layer 3 consent gap that HIPAA and CMIA were never designed to cover — the one the tracking lawsuits actually target.
The bottom line
Healthcare privacy isn't a single law you either pass or fail — it's three layers stacked together: HIPAA as the federal baseline, state medical-privacy law like CMIA above it, and state consent and wiretap law like CIPA and CCPA on top. Each answers a different question, and each can bind you independently.
So "when must you follow state law instead of HIPAA?" resolves cleanly: when the state law is more stringent, when your data falls outside HIPAA but inside a state law, or when the claim is about consent rather than PHI handling. In practice it's rarely "instead of" — it's "on top of." HIPAA compliance is necessary and never sufficient by itself.
And the layer most healthcare sites leave open is the top one. Your website's tracking-and-consent exposure lives in Layer 3, where a flawless HIPAA program gives you no protection at all. That's the layer to close deliberately — block trackers until consent, honor opt-outs, and keep the proof — because it's the one the lawsuits were built to find.
Close the layer HIPAA doesn't cover
ConsentPixel handles Layer 3 — blocking third-party trackers until visitors consent, honoring opt-outs, and logging the evidence. Start a 14-day trial, or scan your site first to see what fires before consent.
Start your 14-day free trial →No credit card · from $8.99/domain/mo · or run a free scan first · information, not legal advice
We build prevention-first consent tooling for the state-law consent layer: blocking trackers until visitors genuinely consent, honoring opt-out signals, continuously verifying what fires, and logging each decision as evidence. We cover Layer 3 — honestly — and we'll always tell you plainly what sits in the layers we don't touch. This article is information, not legal advice; privacy law is fact-specific and evolving, so verify your position with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm and does not make any website "HIPAA compliant."
Frequently asked questions
When must you follow state law instead of HIPAA?
In three situations, though it's usually "in addition to" rather than truly "instead of." First, when a state law is more stringent than HIPAA — HIPAA is a federal floor, not a ceiling (45 CFR § 160.203), so a stricter state medical-privacy law like California's CMIA isn't preempted and you must follow it. Second, when your data falls outside HIPAA's scope but inside a state law's — health-adjacent website data like analytics and portal activity often isn't HIPAA PHI but is covered by consumer-privacy law like the CCPA. Third, when the claim is about consent or interception rather than PHI handling — a CIPA wiretap claim turns on whether a tracker fired before consent, a question HIPAA doesn't address. This is general information, not legal advice.
What are the three layers of healthcare privacy law?
Layer 1 is HIPAA — the federal baseline governing how covered entities and business associates handle protected health information, enforced by regulators with no private right of action. Layer 2 is state medical-privacy law, such as California's CMIA, which governs the same kind of data but often more strictly and typically allows individuals to sue directly. Layer 3 is state consent and wiretap law plus consumer-privacy law — CIPA and CCPA/CPRA in California — which governs consent before tracking and rights over health-adjacent consumer data. The layers stack rather than replace each other: more than one usually applies at once, and each answers a different question.
Can I be compliant with HIPAA but still break state law?
Yes, and it's common. HIPAA and the higher layers answer different questions, so a flawless HIPAA program leaves gaps that state law fills. You can handle PHI perfectly under HIPAA and still violate CMIA if a stricter state rule applies, or violate CIPA if a third-party tracker on your site fires before a visitor consents. The healthcare pixel litigation wave is exactly this scenario: hospitals with solid HIPAA programs lost class actions brought under state wiretap and privacy law, because those claims lived in a layer HIPAA doesn't reach. Being HIPAA compliant is necessary but never sufficient by itself.
Does CIPA apply to my healthcare website even if I follow HIPAA?
Yes. CIPA — California's Invasion of Privacy Act — is a wiretapping statute that asks whether a third party intercepted a visitor's communication without consent. It applies regardless of whether the data is HIPAA-regulated PHI, and regardless of how strong your HIPAA program is. If a tracker on your site transmits a visitor's activity to an ad or analytics vendor before that visitor consents, that can be a CIPA violation with statutory damages commonly cited at $5,000 per violation under Penal Code § 637.2. This is why the tracking lawsuits target the consent layer, not the HIPAA layer. This is general information, not legal advice.
Which layer does website tracking fall under?
Mostly Layer 3 — consent and wiretap law (CIPA) and consumer-privacy law (CCPA/CPRA). Although it's a healthcare site, the specific act of a third-party tracker intercepting and transmitting a visitor's activity is a consent-and-interception event, which is a Layer 3 question rather than a HIPAA one. That's why the entire healthcare pixel litigation wave was brought under wiretap and consumer-privacy theories, not HIPAA. Your PHI systems and vendor relationships live in Layers 1 and 2; your trackers, pixels, and analytics live in Layer 3. Most organizations manage the first two heavily and leave the third largely unmanaged, which is the gap the lawsuits exploit.
How do I make sure I'm covered on all three layers?
Assign each layer its proper owner and control. Layer 1 (HIPAA) belongs to compliance and counsel: BAAs with every vendor touching PHI, PHI-safe data paths, and security safeguards. Layer 2 (state medical-privacy) belongs to counsel: identify where a stricter state law like CMIA applies and follow the stricter rule. Layer 3 (consent and wiretap) belongs to whoever controls the website and is a technical control: block non-essential trackers until visitors consent, honor opt-out signals, and log consent as evidence, with ongoing verification since tags get added continuously. Trying to cover all three with one team or tool is how gaps form. ConsentPixel handles Layer 3; the others stay with your compliance team and counsel. This is general information, not legal advice.