When your state law beats HIPAA

HIPAA is a floor, not a ceiling. What preemption actually means, the categories where states routinely go further, and why a multi-state ABA operator cannot run one compliance program and call it done.

Last verified: 2026-07-12

A clinic owner who has done the work reads the whole Privacy Rule, builds the program, and concludes they are compliant. Then they open a second location across a state line, and a family in the new state asks for records, and the timeline they have trained everyone on is wrong.

HIPAA is a floor, not a ceiling, and a clinic that has only ever read the floor does not know how high the walls are in the states it operates in.

The rule, in one paragraph

A standard, requirement, or implementation specification of the HIPAA rules that is contrary to a provision of state law preempts that state law (45 CFR 160.203). “Contrary” has a definition: it would be impossible to comply with both, or the state law stands as an obstacle to the federal purpose (45 CFR 160.202).

“HIPAA is a floor, not a ceiling, and a clinic that has only ever read the floor does not know how high the walls are in the states it operates in”

But the preemption has exceptions, and the one that matters most is this: state law that is more stringent than the federal requirement is not preempted. It controls (45 CFR 160.203(b)).

“More stringent” also has a definition (45 CFR 160.202), and it is worth reading rather than summarizing loosely: broadly, a state provision is more stringent where it prohibits or restricts a use or disclosure that HIPAA would permit, gives individuals greater rights of access or amendment or more information about uses and disclosures, requires more from an authorization or consent, keeps records or produces reports that are more extensive, or otherwise provides greater privacy protection for the individual.

So the operating rule for a clinic is short: where state law protects the client more, follow the state. Where HIPAA protects them more, follow HIPAA. You do not choose between the rulebooks; you obey the stricter of the two, requirement by requirement.

Two other exceptions exist for completeness: state laws HHS has granted an exception to, and state laws about public health reporting, oversight of health plans, and certain regulatory needs (45 CFR 160.203(a), (c), (d)).

Where states actually go further

This page will not tell you your state’s answer, and you should be suspicious of any page that claims to, because these change and they change unevenly. What it can give you is the map of where to look, because the categories are consistent.

Breach notification. This is the one that bites hardest and fastest. HIPAA gives you up to 60 days to notify individuals (45 CFR 164.404). Some states are considerably shorter, some require notification to the state attorney general, and some define breach and personal information differently than HIPAA does, which means an event that is not a HIPAA breach can still be a state-reportable one. A multi-state operator that has trained its team on “60 days” has trained them on the federal floor, which is the wrong number in some of their states.

Minor consent and parental access. The heart of it for ABA. HIPAA generally treats a parent as the personal representative of an unemancipated minor, but it explicitly defers to state law in defined situations (45 CFR 164.502(g)), and state law is where the actual answer lives: at what age a minor may consent to certain care themselves, and what that does to the parent’s access to those records. This varies enormously, it interacts with custody, and it is exactly the question that arrives on a bad afternoon.

Mental and behavioral health records. Many states impose heightened protections on mental health information beyond HIPAA’s baseline (HIPAA’s own special category, psychotherapy notes, is narrow and, as we have covered, almost never reaches ABA session notes). State law may reach further and cover behavioral health records more broadly, which is directly relevant to your file.

Records retention. HIPAA’s six-year rule (in 164.316 and 164.530(j)) governs compliance documentation, not clinical records. How long you keep the clinical chart is a state and payer question, and states commonly require longer for minors, often measured from the age of majority rather than the date of service.

Right of access timelines and fees. HIPAA says 30 days with one 30-day extension (45 CFR 164.524). Some states are faster, and some cap copying fees below what HIPAA’s reasonable cost-based standard would allow. Faster and cheaper are more protective, so the state wins.

State privacy statutes generally. A growing number of states have consumer or health privacy laws with their own reach, and some cover health data that HIPAA does not, held by entities HIPAA does not cover. Whether any of them touch a covered ABA clinic is a state-specific question, and the answer changes.

What multi-state actually means for your program

The instinct of a growing operator is to run one program: one policy set, one training, one breach procedure. That instinct is right about structure and wrong about content.

Build one program, with the strictest applicable rule per requirement, per state, written into the policies. Where the difference is trivial (a shorter access timeline), adopt the strictest rule everywhere; a clinic that answers every records request in 15 days is compliant in all fifty states and has one number to train. Where the difference is substantive (minor consent rules that genuinely differ, breach notification to a specific attorney general), the policy has to branch, and the branch has to be written down rather than living in someone’s memory of what a lawyer once said.

And keep a state register: for each state you operate in, the breach timeline and recipients, the minor consent posture, the records retention period, and the access timeline. Four rows per state. That document costs an afternoon with a local lawyer and it is the difference between an answer and a guess on the day it matters.

The honest limits of this page

We will not tell you what your state requires, because a page that tried would be wrong somewhere and would be wrong quietly, which is the worst way to be wrong. Two states change a rule and the page becomes a trap for the clinics that trusted it.

What we can tell you is the shape of the problem: HIPAA is the floor, more protective state law controls, and four or five categories are where states routinely climb higher. Take that list to a lawyer in each state you operate in, ask those specific questions, write the answers down, and you will have spent a few hours to close the single largest blind spot in a growing ABA operation.

The short version

  • HIPAA preempts contrary state law, except where the state law is more stringent, in which case the state law controls.
  • More stringent generally means more protective of the individual or granting greater rights of access; the definition is in the regulation.
  • States routinely go further on breach notification deadlines, minor consent, mental health records, and their own privacy statutes.
  • Multi-state operators cannot run one program on the federal floor; the strictest applicable rule governs each client.
  • This page will not tell you your state's answer; it tells you the test, the categories to check, and what to ask a local lawyer.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

One clinic, several rulebooks.

Multi-state operations mean the strictest applicable rule governs each client. WiseUpHIPAA holds the determinations and the policies behind them, so the answer is written down before someone needs it.