
Most healthcare organizations still think of privacy compliance as a HIPAA problem. That assumption is increasingly wrong, and it's becoming an expensive one. States have spent the last three years building an entirely separate layer of privacy law that applies on top of HIPAA — sometimes to the same organizations or data and often to health-adjacent data that HIPAA never touched in the first place.
HIPAA only covers "covered entities" and "business associates" - providers, health plans, clearinghouses, and their vendors handling protected health information. It says nothing about the wellness app, the patient engagement platform, the marketing pixel on your website, or the subscription health service that collects data but isn't a covered entity itself. States have moved aggressively to close that gap.
Washington's My Health My Data Act (MHMDA) is the clearest example. It regulates "consumer health data" far more broadly than HIPAA does as it covers anything that identifies a person's past, present, or future physical or mental health status, collected by virtually any entity doing business with Washington consumers, regardless of whether that entity is a traditional healthcare provider. It requires opt-in consent before collecting or sharing this data, a separate signed authorization before selling it, and bans geofencing near healthcare facilities outright. Crucially, it carries a private right of action, meaning individual consumers, not just the state attorney general, can sue, with courts able to award treble damages up to $25,000. Nevada too has since passed a similar law.
For a Florida-based organization, it's tempting to assume the Florida Digital Bill of Rights (FDBR) doesn't apply and move on. In one sense, that's often true: FDBR generally exempts HIPAA-covered entities, business associates, and health records outright, and even where it does apply, its scope is narrow as it only reaches controllers with over $1 billion in global revenue meeting specific criteria.
But that narrow scope cuts both ways. It means Florida law isn't providing a safe harbor so much as staying out of the way, and it says nothing about Washington, Nevada, or the growing list of other states whose laws apply the moment you have a customer, user, or patient there. A Florida-based wellness platform, digital health tool, or consulting client operating nationally can be squarely inside Washington's MHMDA while sitting entirely outside FDBR's scope. "We're a Florida company" is not a compliance strategy.
A few things make this more urgent than a typical regulatory update:
Treating state privacy law as something you check once and file away doesn't work anymore. It requires:
The idea that HIPAA compliance equals privacy compliance is outdated, and the states writing these laws know it. If your organization touches health data in any form — clinical, wellness, or otherwise — knowing your HIPAA obligations is no longer sufficient. Knowing which states you're exposed to, and what each one requires, is now part of the job.
CohesiveIQ helps healthcare organizations navigate the growing patchwork of state and federal privacy obligations, from HIPAA to emerging state consumer health data laws. Contact us to assess your exposure.
.avif)