Obtainer
Blog / State Laws 8 min read

HIPAA Exemption From State Privacy Laws: Entity-Level vs Data-Level by State

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

Nine states with comprehensive privacy laws exempt HIPAA covered entities and business associates at the entity level, which means the state law does not apply to the organization at all: Connecticut, Florida, Indiana, Iowa, Montana, Tennessee, Texas, Utah, and Virginia. Six exempt only the data. California, Colorado, Delaware, Minnesota, New Jersey, and Oregon carve out protected health information but not the company holding it, so every piece of personal information a health system collects that is not PHI stays fully in scope, with access, correction, and deletion rights on a 45-day clock.

That single distinction decides whether a hospital's privacy team has one workflow or two. It is also the assumption that most often turns out to be wrong, because the phrase compliance teams remember is "HIPAA entities are exempt," and in the six largest data-level states that sentence is not true. A health system in California is subject to the CCPA for its marketing lists, its website analytics, its retail pharmacy and gift shop customers, and, since the employee exemption expired on January 1, 2023, for its own staff.

Which states exempt HIPAA covered entities and which only exempt PHI

The table below is the verified split. Confirm it against the statute before you rely on a row, because exemption language is one of the most frequently amended parts of these laws. New Jersey is the live example: it broadened its carve-out on January 20, 2026.

StateComprehensive lawHIPAA exemption scope
ConnecticutCTDPAEntity level. Covered entities and business associates are outside the law.
FloridaFDBREntity level.
IndianaINCDPAEntity level.
IowaICDPAEntity level.
MontanaMCDPAEntity level.
TennesseeTIPAEntity level.
TexasTDPSAEntity level.
UtahUCPAEntity level.
VirginiaVCDPAEntity level.
CaliforniaCCPA and CPRAData level. PHI and provider information maintained in the same manner as PHI are exempt. The entity is not. Employees included since January 1, 2023.
ColoradoCPAData level. PHI is exempt; other personal data held by the covered entity is not.
DelawareDPDPAData level.
MinnesotaMCDPAData level.
New JerseyNJDPAData level. Assembly Bill A5017, enacted January 20, 2026, also exempts certain non-PHI handled to HIPAA privacy and security standards. Still a data test, not a blanket pass.
OregonOCPAData level.

Five comprehensive-law states are deliberately absent from that table: Maryland, Nebraska, New Hampshire, Rhode Island, and Kentucky. Their exemption language was not covered by the sources used here, and guessing would defeat the point of the table. Read those statutes directly, or ask counsel, before you decide which column they belong in. If you are still working out which laws reach you at all, start with the threshold guide to which state privacy laws apply to your business.

Is HIPAA exempt from the CCPA?

No, not as an organization. The CCPA exempts protected health information collected by a covered entity or business associate governed by HIPAA and the California Confidentiality of Medical Information Act, along with information a provider maintains in the same manner as PHI, and de-identified information created under the AB 713 rules. What it does not do is exempt the business. A hospital, a health plan, or a business associate that meets the CCPA thresholds is a covered business for everything else it holds.

The practical consequence is that the same organization can owe a patient a HIPAA response in 30 days and a consumer response in 45 days about different data, arriving through different channels, verified to different standards. The CCPA applicability thresholds are what decide whether you are a covered business, and revenue is only one of the three.

What personal data at a healthcare organization is not PHI?

More than most teams expect, and it is rarely stored anywhere near the chart. HIPAA attaches to individually identifiable health information created or received by a covered entity in connection with treatment, payment, or health care operations. Data that never touches that pipeline is simply not PHI, no matter who collected it.

The recurring categories are these. Website and mobile app analytics on public-facing pages, including everything logged before a person signs into a portal. Advertising and campaign data, prospect and lead lists, and the audience segments a marketing team builds. Newsletter subscribers and event registrations. Donor and foundation records at a nonprofit system. Retail operations: the gift shop, the cafeteria loyalty program, the over-the-counter side of a pharmacy. Job applicants, employees, contractors, and board members, which California brought fully into scope in 2023 and which are the subject of a growing share of employee subject access requests. Patient satisfaction surveys run through a third-party platform. And anything a website tool collects on its own initiative, including a chat widget that answers questions on your website, which can capture a symptom description from someone who has never been your patient and therefore has no PHI to exempt.

In the six data-level states, all of that carries full consumer rights: the right to know, access, correct, delete, obtain a portable copy, and opt out of sale, sharing, targeted advertising, and profiling. In Minnesota it also carries the right to question a profiling decision. In California it carries the right to limit the use of sensitive personal information.

Does HIPAA preempt state privacy laws?

Only where they conflict, and only in one direction. HIPAA sets a federal floor and expressly preserves state laws that are more stringent, meaning laws that give individuals greater privacy protection or greater rights of access. A state law that grants a patient broader access than 45 CFR 164.524 stands. A state law that would let a covered entity disclose PHI more freely than HIPAA allows does not.

Comprehensive state privacy laws mostly sidestep the question by writing the exemption themselves rather than relying on preemption, which is exactly why the entity-versus-data distinction matters so much. The exemption is a legislative choice, made state by state, and it has been trending toward the narrower data-level version. Colorado, Oregon, and Minnesota built theirs that way, and New Jersey's 2026 amendment adjusted the scope of a data-level exemption rather than converting it to an entity-level one.

What about health data laws that are not comprehensive privacy laws?

They are a separate layer, and they are aimed squarely at the gap. Washington's My Health My Data Act regulates consumer health data held by organizations HIPAA does not reach, has no revenue or headcount threshold, and is the one US privacy law a consumer can enforce against you personally. Nevada's Senate Bill 370 is its close sibling. Connecticut added consumer health data provisions to its comprehensive law. The full picture is in the guide to consumer health data privacy laws by state, and the operational detail for Washington sits on the My Health My Data Act compliance page.

Note the inversion here, because it catches people. Under these laws, the more of your data HIPAA covers, the less exposure you have, since PHI is carved out. A hospital is comparatively well protected. A fertility tracking app, a supplement retailer, or an ad platform that logs location near a clinic is not covered by HIPAA at all and is therefore fully inside the health data laws.

What this changes about how you handle requests

If you are in one of the nine entity-level states and nowhere else, the answer is genuinely simple: run HIPAA, and the comprehensive state law does not reach you. Almost nobody is in that position. Health systems have patients from neighboring states, health plans sell across state lines, digital health companies are national from day one, and the rights attach to where the individual lives, not where you are.

For everyone else, three things follow. First, intake has to be able to tell the two request types apart, because a HIPAA access request and a CCPA access request from the same person are different obligations with different deadlines, different denial grounds, and different verification standards. Second, you need to know where non-PHI personal data actually sits, and it is scattered by design across the marketing stack, the CRM, the analytics warehouse, the HR system, and a long tail of vendor tools that no one inventoried, which is what personal data discovery is for. Third, you need to be able to show what you did. In the HIPAA cases OCR has settled under its Right of Access Initiative, the failure was almost never a decision to refuse. It was a request that landed somewhere nobody was watching.

The operational side of all of this, including the 30-day HIPAA clock running alongside the 45-day state clock, is what the HIPAA right of access page covers in detail. Obtainer helps you comply. It is not legal advice, and the exemption calls stay with your team.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.