Why Healthcare Companies Can't Treat State Privacy Law as a One-Time Checkbox

Most healthcare organizations still think of privacy compliance as a HIPAA problem. That assumption is increasingly wrong, and it's becoming an expensive one. States have spent the last three years building an entirely separate layer of privacy law that applies on top of HIPAA — sometimes to the same organizations or data and often to health-adjacent data that HIPAA never touched in the first place.

HIPAA Was Never the Whole Picture

HIPAA only covers "covered entities" and "business associates" - providers, health plans, clearinghouses, and their vendors handling protected health information. It says nothing about the wellness app, the patient engagement platform, the marketing pixel on your website, or the subscription health service that collects data but isn't a covered entity itself. States have moved aggressively to close that gap.

Washington's My Health My Data Act (MHMDA) is the clearest example. It regulates "consumer health data" far more broadly than HIPAA does as it covers anything that identifies a person's past, present, or future physical or mental health status, collected by virtually any entity doing business with Washington consumers, regardless of whether that entity is a traditional healthcare provider. It requires opt-in consent before collecting or sharing this data, a separate signed authorization before selling it, and bans geofencing near healthcare facilities outright. Crucially, it carries a private right of action, meaning individual consumers, not just the state attorney general, can sue, with courts able to award treble damages up to $25,000. Nevada too has since passed a similar law.

Florida Isn't as Simple as It Looks

For a Florida-based organization, it's tempting to assume the Florida Digital Bill of Rights (FDBR) doesn't apply and move on. In one sense, that's often true: FDBR generally exempts HIPAA-covered entities, business associates, and health records outright, and even where it does apply, its scope is narrow as it only reaches controllers with over $1 billion in global revenue meeting specific criteria.

But that narrow scope cuts both ways. It means Florida law isn't providing a safe harbor so much as staying out of the way, and it says nothing about Washington, Nevada, or the growing list of other states whose laws apply the moment you have a customer, user, or patient there. A Florida-based wellness platform, digital health tool, or consulting client operating nationally can be squarely inside Washington's MHMDA while sitting entirely outside FDBR's scope. "We're a Florida company" is not a compliance strategy.

Why This Matters Right Now

A few things make this more urgent than a typical regulatory update:

  • The laws don't line up. MHMDA's opt-in consent model, geofencing ban, and private right of action have no real equivalent in HIPAA or in most comprehensive state privacy laws like California's.
  • Enforcement is real and growing. Florida's Attorney General has already brought its first FDBR enforcement action and stood up a dedicated unit scrutinizing healthcare data practices, including foreign data transfers. Given Washington's private right of action means plaintiffs' attorneys, not just regulators, are watching.
  • The gap keeps expanding. Wellness apps, remote monitoring tools, patient portals, and subscription health platforms are exactly the kind of non-traditional entities these laws were written to capture, precisely because they fall outside HIPAA.

What Staying Current Requires

Treating state privacy law as something you check once and file away doesn't work anymore. It requires:

  • An inventory of where your data goes which states your users, patients, or members are in, and which laws that triggers
  • A recurring legal review, not a one-time policy draft, since state legislatures are amending and adding to this patchwork every session
  • Clear internal ownership of the difference between HIPAA obligations and separate state consumer-privacy obligations, since they are not interchangeable
  • Vendor and marketing scrutiny of tracking pixels, ad platforms, and analytics tools are common sources of unintended violations

The Bottom Line

The idea that HIPAA compliance equals privacy compliance is outdated, and the states writing these laws know it. If your organization touches health data in any form — clinical, wellness, or otherwise — knowing your HIPAA obligations is no longer sufficient. Knowing which states you're exposed to, and what each one requires, is now part of the job.

CohesiveIQ helps healthcare organizations navigate the growing patchwork of state and federal privacy obligations, from HIPAA to emerging state consumer health data laws. Contact us to assess your exposure.

blogs and articles

Latest insights and trends

The Governance Gap: Why AI Needs a Program, Not Just a Policy

A committee isn't a governance program.

The Attacker Just Got a Co-Pilot: Cybersecurity in the Age of AI

AI didn't break security. It sped up the clock.

The Data You Hold Isn't All Governed the Same Way

HIPAA covers less of your data than you think.

M&A Due Diligence Doesn't Wait for You to Be Ready

Compliance gaps show up in the price, not just the audit.

What Your RCM Coding and Billing Audits Might Not be Catching

Coding compliance alone isn't enough anymore.

Why an Independent Assessment of Your Compliance Program Isn't Optional Anymore

DOJ and OIG now expect proof, not paperwork.

Stop retrofitting compliance after the fact.

The earlier you build it in, the cheaper and faster it gets.