What's Happening?
The landscape of health data privacy in the U.S. is rapidly evolving, with states enacting new laws that go beyond the federal Health Insurance Portability and Accountability Act (HIPAA). While HIPAA has
historically been the primary framework for health information privacy, it primarily applies to covered entities like health plans, healthcare clearinghouses, and providers, as well as their business associates. It does not typically regulate consumer-facing health apps, wearable fitness trackers, or other entities outside this scope. States are now stepping in to fill these regulatory gaps, leading to a complex patchwork of consumer health data privacy laws. Examples include Washington's My Health My Data Act (MHMDA), which broadly defines 'consumer health data' and requires affirmative consumer consent, and Nevada's SB 370, which largely mirrors Washington's approach but with a more limited scope. California also has robust frameworks with the Confidentiality of Medical Information Act (CMIA) and the California Consumer Privacy Act (CCPA/CPRA), which classify health-related information as 'sensitive personal information.' Many other states, including Colorado, Connecticut, and Virginia, are addressing health data through comprehensive consumer privacy laws that classify it as sensitive data subject to heightened protections, often requiring opt-in consent for processing.
Why It's Important?
This expansion of state-level health privacy laws has significant implications for U.S. businesses, particularly those operating in the digital health sector or handling any form of health-related data. Companies that previously relied solely on HIPAA compliance may find themselves subject to substantial new obligations, even if they fall outside HIPAA's traditional scope. The varying approaches taken by states, including different definitions of 'sensitive data,' consent requirements (opt-in versus opt-out), and exemptions for HIPAA-regulated information, create a complex compliance environment. Businesses must now navigate a fragmented regulatory landscape, where an entity-level HIPAA exemption in one state might not apply in another, which only offers a data-level exemption. This means organizations, including hospitals and health systems, must reassess their compliance programs to account for personal data that falls outside of HIPAA's Protected Health Information (PHI) definition but is covered by state laws. The potential for private rights of action, as seen in Washington's MHMDA, also introduces new litigation risks for non-compliant entities.
What's Next?
Organizations that collect, process, or share health-related data across multiple states will need to implement robust and continuously monitored compliance programs. This is not a one-time exercise, as the legislative landscape is constantly evolving, with new bills like New York's Health Information Privacy Act (NY HIPA) advancing. Businesses should proactively monitor these developments and periodically reassess their compliance strategies to stay ahead of emerging requirements. This includes understanding the nuances of each state's definition of sensitive data, consent mechanisms, and the scope of HIPAA exemptions. Companies will likely need to invest in systems and processes that can adapt to these diverse regulations, ensuring that data handling practices align with the strictest applicable laws. Furthermore, the trend of states addressing health data through broader consumer privacy laws suggests that more states will likely follow suit, further complicating the compliance environment for businesses operating nationally.
Beyond the Headlines
The proliferation of state health privacy laws reflects a broader societal concern about the control and use of personal health information in the digital age, especially as technology allows for the collection of health data from non-traditional sources like apps and wearables. This shift highlights a growing recognition that HIPAA, while foundational, was not designed to address the full spectrum of modern health data practices. The varying state approaches could lead to a de facto national standard driven by the most stringent state laws, as businesses seek to avoid the complexity of managing disparate compliance regimes. This could also spur calls for a more comprehensive federal privacy law that harmonizes these state-level efforts, providing clearer guidelines for businesses and stronger protections for consumers. The ethical implications of data collection from consumer devices, particularly concerning sensitive health information, are also coming to the forefront, pushing companies to adopt more transparent and consent-driven practices.






