HIPAA Is the Floor, Not the Ceiling
Most practices treat "HIPAA compliant" as the finish line for privacy diligence. Legally, it is the starting line. HIPAA explicitly allows states to enforce stricter rules, and a growing number do. If you practice in - or treat patients from - one of those states, your obligations and your vendors' obligations are broader than federal law alone.
This guide covers the state laws clinic administrators ask us about most, what each adds on top of HIPAA, and the questions to put to any documentation vendor before PHI moves.
Texas: HB 300 Reaches Further Than HIPAA
The Texas Medical Records Privacy Act - known as HB 300 - applies privacy duties to a much wider set of organizations than HIPAA's "covered entities," requires documented workforce privacy training, and tightens timelines for releasing electronic records. Practical effect: almost any business touching Texans' health information carries Texas-specific duties, including out-of-state vendors serving Texas practices.
California: CMIA and a Private Right of Action
The Confidentiality of Medical Information Act governs how medical information is used and disclosed in California - and unlike HIPAA, it lets patients sue directly for violations. For clinics, that changes vendor risk math: a mishandled chart is not just a regulatory issue but potential civil litigation. California practices should demand specifics about access controls and disclosure practices from every vendor.
Minnesota: Consent Beyond HIPAA
The Minnesota Health Records Act requires patient consent for many disclosures HIPAA alone would permit, including some routine exchanges other states take for granted. Documentation workflows serving Minnesota practices need to be consent-aware, and vendors should be able to explain how they limit processing strictly to producing your documentation.
Washington: My Health My Data
Washington's My Health My Data Act, effective 2024, is among the broadest health-privacy laws in the country - it reaches consumer health data held by companies HIPAA never covered. Washington clinics should note that the act's reach means adjacent services (apps, analytics, marketing tools) may carry obligations, not just clinical vendors.
New York and Florida: Security and Storage Rules
New York's SHIELD Act imposes data-security and breach-notification duties on anyone holding New York residents' private information, with "reasonable safeguards" requirements that reach vendors. Florida went a different direction: its Electronic Health Records Exchange Act requires patient records held by Florida providers to be stored in the continental U.S., its territories, or Canada - a direct constraint on where your vendors process and store data.
What This Means for Vendor Selection
Every one of these laws shares a theme: your exposure travels with your data. Before any documentation vendor touches PHI, get written answers to four questions. Where is data processed and stored? Is PHI used for anything besides producing our documentation? How is access restricted and audited? Will you sign a BAA before anything moves? At Sunrise, the answers are: U.S.-based only, no secondary use, role-restricted with audit logging, and always - which is why practices in stricter-law states choose us. See how we handle security on our HIPAA compliance page, or explore requirements in your state from our service areas hub.