ConsentPixel – Privacy · Verified

HomeBlogHealthcare › State Law vs HIPAA
Healthcare · State Law vs HIPAA

When Does State Privacy Law Supersede HIPAA?

It's the question every multi-state healthcare operator eventually asks — and the common answer is subtly wrong. State privacy law almost never replaces HIPAA. In the cases that matter most, it stacks on top of it. Here's exactly when a state law controls, why "supersede" is the wrong mental model, and why the state layer — not HIPAA — is where the lawsuits actually land.

By ConsentPixel TeamUpdated July 202613 min readInformation, not legal advice
The short answer

State privacy law "supersedes" HIPAA in one specific situation: when the state law is more stringent — when it protects health information more, or gives patients more rights, than HIPAA does. In that case the stricter state rule controls.

But "supersede" is misleading. HIPAA is a federal floor, not a ceiling (45 CFR § 160.203). A more-stringent state law doesn't erase HIPAA — you comply with both, following whichever is stricter on each point. And because state laws like CIPA, CMIA, and CCPA carry a private right of action that HIPAA lacks, the state layer is where the class actions and settlements happen. This is general information, not legal advice.

If you run a hospital, clinic, or health-adjacent business that touches more than one state, you've probably had this exact worry: you've done the HIPAA work — the policies, the training, the Business Associate Agreements — and then someone mentions California's privacy laws, or a wiretapping statute, or a class action, and you're left wondering whether HIPAA even governs anymore. Does state law override it? Do you follow one or the other? Which one wins?

The honest answer reframes the question. "Supersede" implies a winner-take-all contest where one law switches off the other — and that's not how the HIPAA–state-law relationship works in most cases. Understanding the real mechanism — a floor with stricter state laws layered on top — is the difference between a defensible posture and a false sense of security that ends in a demand letter. None of this is legal advice; healthcare privacy law is unsettled and moving, so confirm your specific position with qualified counsel.

First principle: HIPAA is a floor, not a ceiling

Everything about the HIPAA–state-law relationship follows from one idea, and it's worth internalizing before anything else. HIPAA does not set the maximum privacy protection a person is entitled to. It sets the minimum.

In the regulation's own words, the HIPAA Privacy Rule provides "a Federal floor of privacy protections, with States free to impose more stringent privacy protections should they deem appropriate." Congress built it this way deliberately, through Section 264(c)(2) of HIPAA and Section 1178 of the Social Security Act. It was never the last word on health privacy — only the national baseline every covered entity must at least meet.

Once you see HIPAA as a floor, the whole "which law wins?" question dissolves into something clearer:

  • A state law that offers less privacy protection than HIPAA, and conflicts with it, is generally preempted — HIPAA wins, because you can't drop below the floor.
  • A state law that offers more privacy protection than HIPAA is generally not preempted — the state law controls on that point, because states are free to build above the floor.

So the real question is never "does state law supersede HIPAA?" in the abstract. It's "on this specific point, is the state law stricter or looser than HIPAA?" That comparison — done point by point — determines which rule you follow.

When HIPAA actually preempts state law

Start with the default rule, because it's the part people get right. Under 45 CFR § 160.203, HIPAA preempts state laws that are "contrary" to it. That's the general rule: a contrary state provision is overridden by the federal standard.

The important word is "contrary," which has a precise regulatory meaning under 45 CFR § 160.202. A state law is "contrary" to HIPAA in one of two situations:

  • Impossibility — it would be impossible for a covered entity to comply with both the state law and HIPAA at the same time; or
  • Obstacle — the state law stands as an obstacle to accomplishing the purposes and objectives of HIPAA's Administrative Simplification provisions.

If a state law is contrary in one of these ways and no exception applies, HIPAA preempts it and you follow HIPAA. This is the "federal law overrides conflicting state law" principle most people already have in mind — and for state laws that are weaker than HIPAA, it's the end of the story.

But notice what "contrary" does not mean. A state law that simply adds a stricter requirement on top of HIPAA usually isn't "contrary" at all — you can comply with both by following the stricter one. And even when a state law is contrary, there's a large exception that swallows much of the practical action.

The exception that changes everything: "more stringent"

Here is the part most "supersede" answers miss, and it's the heart of the matter. Section 160.203 lists exceptions to HIPAA preemption — and the biggest one, at § 160.203(b), is for state laws that are "more stringent" than the HIPAA Privacy Rule.

When a state law relates to the privacy of individually identifiable health information and is more stringent than HIPAA, it is not preempted. It survives. It controls. Even though it's "contrary" to HIPAA in the technical sense, the more-stringent exception keeps it alive — and now you must follow it instead of (really, on top of) the HIPAA baseline.

Regulatory definition · 45 CFR § 160.202
What "more stringent" means

A state law is "more stringent" than HIPAA when, on a given point, it does things like: prohibits or restricts a use or disclosure that HIPAA would permit; gives individuals greater rights of access to or amendment of their own information; requires more information be given to individuals about how their data is used; or otherwise provides greater privacy protection for the individual.

Paraphrased from 45 CFR § 160.202. Verify the exact text with counsel.

In plainer terms: whenever the state is more protective of the patient, the state wins. That's the only sense in which state law "supersedes" HIPAA — and it's a specific, testable condition, not a blanket rule.

There are a few other, narrower exceptions worth knowing exist — state laws that require reporting of disease, injury, child abuse, birth, or death, or that provide for public health surveillance, are also preserved (§ 160.203(c)), as are certain health-plan reporting requirements (§ 160.203(d)). But for a modern healthcare operator worried about privacy exposure, the "more stringent" exception is the one that shapes daily reality.

The line that catches people out

Because a more-stringent state law is folded into the federal standard, failing to follow that state law can itself be treated as failing the HIPAA standard. The two aren't neatly separable. A privacy incident can simultaneously trigger an OCR question under HIPAA and a state-law claim — from the same underlying facts.

Why the answer is almost always "comply with both"

Put the pieces together and a practical rule falls out. For any given data practice, you're not choosing between HIPAA and state law — you're identifying, point by point, which one is stricter, and following that one. Since HIPAA is the floor, "follow the stricter rule on each point" collapses to a simple operating principle: comply with both, and let the more protective requirement govern wherever they differ.

FLOOR, NOT CEILING HIPAA — the federal floor (every covered entity meets this) CMIA — stricter medical-info rules & patient authorization CIPA — consent before tracking / interception CCPA / CPRA — opt-out & health-adjacent data more protective →

You don't pick one layer. On each specific requirement, the highest (most protective) applicable rule governs — HIPAA at the base, stricter state laws stacked above it. For the full three-layer breakdown, see our healthcare tracking & consent pillar.

This is why privacy attorneys repeat that "compliance with HIPAA does not guarantee compliance with state law." A hospital can run a textbook HIPAA program and still be offside on California's CMIA or CIPA, because those laws demand things HIPAA never did. HIPAA training alone, in a state like California, is generally not sufficient — and assuming otherwise is the gap that produces litigation.

Not sure what your website sends before consent?

The state-law layer usually bites on your public site and patient portal — through trackers firing before a visitor consents. See exactly what fires on your site, in about 10 seconds. It's the same scan a plaintiff's firm would run.

Scan your site free →

No account needed · then a 14-day free trial, no credit card, from $8.99/mo

The reason this actually matters: who is allowed to sue

Here's the practical punchline that turns an academic preemption question into a business-risk question. The single most important difference between HIPAA and the state laws that "supersede" it isn't the rules themselves — it's who can enforce them.

HIPAA has no private right of action. An individual patient cannot sue you directly for a HIPAA violation. Enforcement runs through the HHS Office for Civil Rights and state attorneys general. That's a real constraint on your exposure — it means HIPAA risk is regulatory, not a floodgate of private lawsuits.

The more-stringent state laws are a different animal entirely, because many of them do carry a private right of action:

  • CMIA (California's Confidentiality of Medical Information Act) lets individuals sue directly, with nominal statutory damages reported around $1,000 per violation — without having to prove actual harm. Class actions under it have settled for tens of millions.
  • CIPA (California Invasion of Privacy Act) provides a private right of action with statutory damages commonly cited at $5,000 per violation, or treble actual damages, under Penal Code § 637.2 — the engine behind the website cookie-and-pixel wiretapping wave.
  • CCPA/CPRA provides a private right of action for certain data breaches, alongside enforcement by the California Privacy Protection Agency.

Sit with that contrast. The federal law you spent the most effort on is the one an individual can't sue you under. The state laws layered on top — the ones that quietly "supersede" HIPAA where they're stricter — are the ones that put a plaintiff's attorney and a class of patients on the other side of the table. That is why the state layer, not HIPAA, is where the demand letters and settlements come from.

CIPA, CMIA, and CCPA: the "more stringent" layer in practice

Abstract rules become concrete once you see how California's three big health-relevant statutes each go beyond HIPAA. California is the sharpest example because its laws are among the strictest in the country, but the same pattern is spreading as more states pass privacy laws.

CMIA — stricter than HIPAA on medical information

The Confidentiality of Medical Information Act predates HIPAA and out-protects it in several ways. It defines "medical information" more broadly than HIPAA defines PHI, and it reaches more entities — for example, businesses that offer software or hardware designed to maintain medical information can be treated as a "provider of health care" under CMIA even when they aren't HIPAA-covered. It tightens the rules on disclosure and authorization. And critically, it gives patients that private right of action. Because it's more stringent, it isn't preempted — it stacks on top of HIPAA and controls where it's stricter.

CIPA — a consent layer HIPAA never imposed

CIPA is a 1960s wiretapping statute now applied to website tracking. It has nothing to do with HIPAA's framework — it asks a different question entirely: did a third-party tracker intercept a visitor's communications without consent? For a healthcare website running a Meta Pixel, Google Analytics, or a session-replay tool before a visitor consents, CIPA can apply regardless of how airtight the HIPAA program is. This is the clearest illustration that "we're HIPAA compliant" answers the wrong question — CIPA operates on a plane HIPAA doesn't touch.

CCPA / CPRA — the health-adjacent gray zone

The CCPA (as amended by the CPRA) generally exempts PHI already governed by HIPAA and CMIA. But it reaches the growing category of health-adjacent data HIPAA never covered: website analytics, patient-portal activity, marketing lists, wellness apps, and wearables. A wellness app or a hospital's marketing site can collect data a consumer assumes is "medical" and protected when it actually falls under CCPA/CPRA — with its own opt-out obligations and enforcement. Being HIPAA-covered doesn't give you a free pass on this data.

QuestionHIPAA (federal floor)State laws layered on top
Can an individual sue you directly?No private right of actionYes — CMIA, CIPA, CCPA (for breaches)
Consent before web trackers fire?Not its frameworkCIPA turns on pre-consent interception
Scope of protected dataPHI held by covered entitiesBroader — CMIA "medical information"; CCPA health-adjacent data
Statutory damages without proving harm?N/A (regulatory)CMIA ~$1,000/violation; CIPA ~$5,000/violation
Who enforcesHHS OCR & state AGsPrivate plaintiffs + agencies + AGs

The pattern is consistent: each state law is preserved precisely because it's more protective than HIPAA on its axis, and each adds enforcement muscle — private lawsuits — that HIPAA withholds. For a deeper walk-through of how these fit together as distinct layers, see our companion guide on CIPA and the three-layer framing in the pillar.

Where this bites first: your website and portal

For most healthcare operators, the state-law layer doesn't first show up in the medical record or the clinical system — it shows up on the website and patient portal, through tracking technologies. This is the single most common way a HIPAA-diligent organization gets blindsided by a state-law claim.

The mechanism is simple and has driven a wave of litigation. A healthcare site runs third-party tags — a Meta Pixel, Google Analytics, a session-replay tool — that fire the moment a page loads, before the visitor consents, transmitting activity to third parties. Under CIPA, that pre-consent transmission is the alleged unlawful interception; under CMIA, an unauthorized disclosure of medical information is the violation; under CCPA/CPRA, health-adjacent data collected without honoring opt-outs is the exposure. None depends on a HIPAA failure — it's the state layer doing its own work.

The trap for the HIPAA-confident

The teams most exposed here are often the ones most confident about HIPAA. They've secured the clinical systems and signed the BAAs — and then instrumented the public website and portal with the same marketing tags as any other business, assuming HIPAA compliance covered them. It doesn't. The website tracking layer is governed by the state laws that sit above HIPAA, and it's where the pixel-litigation wave has concentrated.

What to actually do

Turning the legal picture into action, here's the honest order of operations for an organization that wants to close the state-law gap most people miss:

  1. Stop thinking "HIPAA or state law." Adopt the floor model: HIPAA is the baseline; identify where state laws are stricter and follow those on top. Assume you comply with both.
  2. Map your states. If you touch California, CMIA and CIPA and CCPA/CPRA are live for you; other states have their own privacy statutes and the list is growing. A point-by-point preemption analysis, documented, is the defensible approach — and one to do with counsel.
  3. Audit your website and portal first. This is the highest-frequency source of state-law exposure and the easiest to fix. See what third-party trackers fire, and when — especially anything firing before consent.
  4. Block non-essential trackers until consent. This is the CIPA/CCPA consent layer in practice. The tag must not load and transmit until the visitor opts in — not load-and-record-later.
  5. Keep the evidence. A timestamped, tamper-evident record showing consent was obtained before each tracker fired is the artifact that shortens or defeats a state-law claim.
  6. Solve the HIPAA layer separately. Where PHI genuinely flows to a vendor, that's a BAA / PHI-safe-path question, handled with counsel — distinct from the state-law consent layer above.

ConsentPixel — Privacy · Verified is built for that state-law consent layer: it blocks third-party trackers at the browser level until a visitor consents, honors opt-out signals, continuously scans what fires across your pages, and logs each consent decision as evidence. To be clear about our lane — and we'd rather be clear than oversell — ConsentPixel is not a HIPAA product and does not make any website "HIPAA compliant." It addresses the CIPA/CCPA/state-law consent layer that sits alongside HIPAA and where the tracking lawsuits actually happen. The HIPAA layer — BAAs, authorizations, PHI-safe data paths — is a separate matter you solve with your counsel and your HIPAA tooling.

The bottom line

State privacy law rarely "supersedes" HIPAA in the way the word implies. HIPAA is a federal floor, not a ceiling (45 CFR § 160.203). It preempts state laws that are weaker and contrary — but the big exception, at § 160.203(b), preserves state laws that are more stringent, and those control wherever they're stricter. The realistic answer to "which law do I follow?" is almost always both, with the more protective rule governing on each point.

The reason this is more than a technicality: HIPAA has no private right of action, while the state laws layered on top — CIPA, CMIA, CCPA — do. That's why the state layer, not HIPAA, is where the demand letters, class actions, and settlements come from. And for most organizations, that layer bites first on the website and patient portal, through trackers firing before consent.

So the practical takeaway isn't "state law beats HIPAA." It's this: being diligent on HIPAA and assuming you're covered is exactly the mistake that leaves the state-law layer — where the lawsuits live — wide open. Close that layer deliberately, and close it where it starts: your website.

See your state-law exposure in about 10 seconds

The fastest way to find the gap this article describes is to scan your own site for trackers firing before consent — the exact pattern behind the CIPA and CMIA lawsuits. Free, no account needed.

Scan your site free →

Then a 14-day free trial, no credit card · from $8.99/domain/mo · information, not legal advice

CP
The ConsentPixel Team

We build prevention-first consent tooling that blocks trackers until visitors genuinely consent, continuously verifies what fires on your pages, and logs each decision. We cover the state-law consent and detection layers — honestly — and we'll always tell you plainly what sits outside our lane. This article is information, not legal advice; healthcare privacy law and HIPAA preemption are evolving, so verify current interpretations with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm, is not a HIPAA authorization mechanism, and does not make any website "HIPAA compliant."

Frequently asked questions

Does state privacy law override HIPAA?

Only in one specific way. HIPAA is a federal floor, not a ceiling (45 CFR § 160.203). It preempts state laws that are "contrary" to it and less protective. But state laws that are "more stringent" — that provide greater privacy protection or greater patient rights — are not preempted, and they control wherever they're stricter. So a state law doesn't switch HIPAA off; it layers on top, and you comply with both, following the more protective rule on each point. This is general information, not legal advice.

When exactly does a state law count as "more stringent" than HIPAA?

Under 45 CFR § 160.202, a state law is "more stringent" when, on a given point, it does something like prohibit or restrict a use or disclosure that HIPAA would permit, give individuals greater rights to access or amend their own information, require more disclosure to individuals about how their data is used, or otherwise provide greater privacy protection. The comparison is done point by point, not law by law — a single state statute can be more stringent on some requirements and not others. Where it's more stringent, it isn't preempted and you must follow it. Where it isn't, HIPAA's baseline applies.

Is HIPAA a state or a federal law?

HIPAA is a federal law — the Health Insurance Portability and Accountability Act — enforced nationally by the U.S. Department of Health and Human Services' Office for Civil Rights. Its preemption rules (45 CFR § 160.203) govern how it interacts with state privacy laws: it sets a national floor that every covered entity must meet, while allowing individual states to enact stricter privacy laws on top. That's why healthcare organizations in states like California face both the federal HIPAA baseline and additional, more stringent state statutes such as CMIA, CIPA, and the CCPA/CPRA at the same time.

If I'm fully HIPAA compliant, am I automatically compliant with state privacy law?

No — and assuming so is a common and costly mistake. Because state laws can be more stringent than HIPAA, complying with HIPAA does not guarantee compliance with a state law that demands more. California is the clearest example: an organization can run a textbook HIPAA program and still violate CMIA (broader medical-information rules and a private right of action) or CIPA (consent before website tracking) because those laws require things HIPAA never did. Privacy attorneys routinely note that HIPAA training alone is generally not sufficient in states with stricter laws. You need to analyze state requirements separately and comply with both.

Why do the lawsuits come from state law and not HIPAA?

Because of who is allowed to sue. HIPAA has no private right of action — an individual can't sue you directly for a HIPAA violation; enforcement runs through HHS and state attorneys general. Many of the more-stringent state laws, by contrast, carry a private right of action. CMIA lets individuals sue with statutory damages reported around $1,000 per violation without proving harm; CIPA provides statutory damages commonly cited at $5,000 per violation or treble damages under Penal Code § 637.2; and CCPA/CPRA provides a private right of action for certain breaches. That combination — stricter rules plus the ability for a class of plaintiffs to sue directly — is why the demand letters and multi-million-dollar settlements come from the state layer, not from HIPAA.

Where does state privacy law most commonly catch healthcare websites?

On the public website and the patient portal, through tracking technologies. The typical pattern: a site runs third-party tags — a Meta Pixel, Google Analytics, an ad tracker, or a session-replay tool — that fire before the visitor consents, transmitting activity to third parties. Under CIPA that pre-consent transmission is the alleged unlawful interception; under CMIA an unauthorized disclosure of medical information is the violation; under CCPA/CPRA it's health-adjacent data collected without honoring opt-outs. None of these requires a HIPAA failure, which is why HIPAA-confident organizations are often the ones caught out. The fastest way to find your exposure is to scan your own site for what fires before consent. This is general information, not legal advice.

Not legal advice. This article is general information and does not constitute legal advice or create an attorney–client relationship. HIPAA preemption and state privacy law are complex, fact-specific, and evolving; the summaries here (including 45 CFR §§ 160.201–160.203 and the CMIA, CIPA, and CCPA/CPRA references) are simplified and may not reflect the latest developments or your specific circumstances. The $5,000-per-violation figure reflects statutory damages under California Penal Code § 637.2; CMIA damages figures are as commonly reported. Verify current requirements and your preemption analysis with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm, is not a HIPAA authorization mechanism, and does not make any website "HIPAA compliant." It addresses the state-law consent and detection layer that sits alongside HIPAA.
Scroll to Top