HIPAA State Law Preemption — Questions and Answers
Question 1: Under HIPAA, when does federal law preempt (override) a state health privacy law?
- In all circumstances, because federal law always supersedes state law under the Supremacy Clause
- Only when the state has not enacted its own comprehensive health privacy statute
- Whenever state law provides less protection for individuals than HIPAA requires (Correct answer)
- Whenever state law grants patients more rights than HIPAA
Correct answer: Whenever state law provides less protection for individuals than HIPAA requires
HIPAA preempts state law when the state law is less protective — meaning it allows disclosures that HIPAA prohibits or provides fewer individual rights. State laws that are MORE protective than HIPAA are generally not preempted and must be followed in addition to HIPAA.
Question 2: A state law requires written patient consent before disclosing HIV test results to public health authorities, a step HIPAA does not require. Which law must a covered entity follow?
- HIPAA, because federal law is supreme under the Supremacy Clause
- The provider may choose whichever law is operationally simpler
- Neither law — the provider must obtain a court order in this situation
- The state law, because it affords patients greater privacy protection than HIPAA (Correct answer)
Correct answer: The state law, because it affords patients greater privacy protection than HIPAA
When a state law is more stringent than HIPAA — meaning it provides greater privacy protections — it is not preempted and the covered entity must comply with both the state law and HIPAA. The state's consent requirement for HIV disclosures grants patients more protection, so the state law governs.
Question 3: The principle that HIPAA sets a 'floor' rather than a 'ceiling' for health privacy means:
- All state privacy laws are automatically invalidated by HIPAA
- States are prohibited from enacting any health privacy laws that differ from HIPAA
- States may enact more protective health privacy laws that go beyond HIPAA's minimum requirements (Correct answer)
- Federal regulators alone determine the maximum permissible level of health privacy protection
Correct answer: States may enact more protective health privacy laws that go beyond HIPAA's minimum requirements
HIPAA establishes minimum baseline standards ('floor') for health information privacy. States are free to enact laws that provide greater protections, and those more protective state laws are not preempted by HIPAA. However, states cannot enact laws that offer less protection than HIPAA.
Question 4: A covered entity operates clinics in State X, which has a mental health privacy law stricter than HIPAA, and State Y, which has no supplemental mental health privacy law. How must the entity handle mental health records?
- Apply State X's stricter standard for State X patients; apply HIPAA minimums for State Y patients (Correct answer)
- Apply HIPAA standards uniformly across both states for operational consistency
- Request a federal preemption waiver to use only HIPAA standards in State X
- Apply the least restrictive standard in both states to minimize operational burden
Correct answer: Apply State X's stricter standard for State X patients; apply HIPAA minimums for State Y patients
In each jurisdiction, the covered entity must comply with whichever law is more protective. In State X, the stricter state mental health law applies (in addition to HIPAA). In State Y, where there is no supplemental law, HIPAA's requirements govern. Operating uniformly at the HIPAA level in State X would violate that state's law.
Question 5: Which of the following is an example of a state law that would NOT be preempted by HIPAA?
- A state law permitting PHI disclosure without patient consent for marketing purposes
- A state law eliminating the requirement for a covered entity to issue a Notice of Privacy Practices
- A state law removing a patient's right to request restrictions on certain disclosures
- A state law requiring additional patient authorization for releasing psychotherapy notes beyond HIPAA's requirements (Correct answer)
Correct answer: A state law requiring additional patient authorization for releasing psychotherapy notes beyond HIPAA's requirements
A state law requiring additional authorization for psychotherapy notes goes beyond what HIPAA mandates, making it more protective of patient privacy. Such laws survive HIPAA preemption. The other options all weaken patient protections below HIPAA's floor and would be preempted because they conflict with HIPAA's purposes.
Question 6: Under HIPAA, a 'contrary' state law is defined as one that:
- Was enacted prior to HIPAA's passage in 1996
- Applies only to electronic health records and not paper records
- Makes it impossible to comply with both the state law and HIPAA simultaneously, or stands as an obstacle to HIPAA's purposes (Correct answer)
- Covers only health plans but not individual healthcare providers
Correct answer: Makes it impossible to comply with both the state law and HIPAA simultaneously, or stands as an obstacle to HIPAA's purposes
HIPAA regulations define a 'contrary' state law as one where it is impossible to comply with both the state law and HIPAA, or where the state law stands as an obstacle to accomplishing HIPAA's purposes. 'Contrary' state laws are generally preempted unless an exception applies (e.g., the state law provides more privacy protection).
Under HIPAA, when does federal law preempt (override) a state health privacy law?