When State Law Goes Further Than HIPAA
HIPAA establishes a federal floor for privacy protections, not a ceiling. RHIA candidates must understand that when state law is more stringent than HIPAA, the more protective state law generally applies. This concept, known as preemption analysis, appears regularly on the exam.
What Makes a State Law More Stringent
A state law is considered more stringent if it provides individuals with greater privacy protections, gives patients more rights of access, requires more restrictive conditions on disclosure, or requires more detailed record retention. Common examples include state laws governing mental health records, HIV and AIDS status, substance use disorder treatment records, and genetic information.
Common Examples of Stricter State Provisions
- Shorter timeframes for responding to patient access requests than the HIPAA 30-day standard
- Special authorization requirements for releasing behavioral health or substance abuse records
- Minor consent laws that restrict parental access to certain adolescent health records
- Genetic privacy statutes that limit insurer and employer access to genetic test results
- Data breach notification laws with shorter reporting windows than HIPAA
42 CFR Part 2 as a Special Case
While technically a federal regulation rather than a state law, 42 CFR Part 2 governing substance use disorder treatment records is a frequently tested example of a stricter privacy standard that HIM professionals must apply alongside HIPAA. Part 2 requires specific consent elements before disclosure, even for treatment purposes, which is more restrictive than the HIPAA treatment, payment, and operations exception.
Practical Application for HIM Professionals
Health information managers must know both HIPAA and their state's specific privacy statutes to build compliant release of information policies. This often means creating separate handling procedures for categories of sensitive information that carry extra state protections.
Exam Strategy
- When a question presents a conflict between state and federal law, ask which law offers greater protection to the patient
- Remember that stricter state provisions on privacy survive preemption, but state laws that are less protective do not
- Pay special attention to behavioral health, HIV status, and substance use disorder scenarios, as these are the most commonly tested exceptions
Key Takeaway
Compliance professionals must layer state requirements on top of the HIPAA floor. The RHIA exam tests your ability to recognize when a more restrictive state law should control the outcome.