State Health Privacy Laws Expand Beyond HIPAA, Creating New Compliance Challenges for U.S. Businesses
The landscape of health data privacy in the U.S. is rapidly evolving, with states enacting new laws that go beyond the federal Health Insurance Portability and Accountability Act (HIPAA). While HIPAA has historically been the primary framework for health information privacy, it primarily applies to covered entities like health plans, healthcare clearinghouses, and providers, as well as their business associates. It does not typically regulate consumer-facing health apps, wearable fitness trackers, or other entities outside this scope. States are now stepping in to fill these regulatory gaps, leading to a complex patchwork of consumer health data privacy laws. Examples include Washington's My Health My Data Act (MHMDA), which broadly defines 'consumer health data' and requires affirmative consumer consent, and Nevada's SB 370, which largely mirrors Washington's approach but with a more limited scope. California also has robust frameworks with the Confidentiality of Medical Information Act (CMIA) and the Cal...