For three decades, HIPAA has been the reference point for healthcare privacy. Every compliance program, every risk assessment, every board conversation about patient data has started there. That reference point is no longer sufficient on its own.
Healthcare data now flows through wearables, symptom-checker apps, patient portals, third-party analytics tools, and AI-driven diagnostic platforms. Much of that data never touches a HIPAA covered entity or business associate, yet it still reveals intimate details about a person’s body, mind, and life choices.
Lawmakers noticed the gap, and they are closing it fast. Understanding what sits beyond HIPAA is the difference between a defensible privacy program and a costly blind spot.
Why HIPAA Alone No Longer Covers the Full Healthcare Risk Picture?
HIPAA regulates covered entities and their business associates: hospitals, clinics, insurers, clearinghouses, and the vendors who handle protected health information on their behalf. That scope made sense when medical data lived mostly inside hospital systems and insurance databases.
It does not reflect how health information moves today. A fertility app, a mental wellness platform, a fitness tracker, and a retail loyalty program can each collect data that reveals a pregnancy, a diagnosis, or a course of treatment, and none of them are HIPAA covered entities. States and federal agencies have stepped into that space with laws built specifically for consumer health data that falls outside HIPAA’s boundaries.
State Consumer Health Data Laws Are Reshaping the Landscape
Washington’s My Health My Data Act, often shortened to MHMDA, was the first law of its kind in the country. It defines consumer health data broadly enough to capture information that can be used to infer a person’s physical or mental health status, including data drawn from location, purchases, or search activity. The act requires disclosures and consumer consent for collecting and sharing health information, gives consumers the right to have their data deleted, prohibits selling consumer health data without authorization, and bans geofencing around healthcare facilities. Enforcement runs through the state Attorney General and, notably, a private right of action, meaning individual consumers can sue directly.
Nevada followed with SB 370, a close parallel to Washington’s law that took effect in January 2026 and imposes similar consent requirements. Minnesota has joined the trend too, extending privacy obligations to a broad category of consumer health data beyond traditional protected health information. New York has taken a related approach with its Health Information Privacy Act, which broadens the definition of protected health data and imposes consent, transparency, and data minimization obligations on entities outside HIPAA’s scope. California layers requirements on top through the CPRA, granting consumers rights to access, delete, and restrict use of sensitive personal information, alongside the Delete Act’s data broker deletion mandates.
The common thread is a broad, inference-based definition of health data. If a data point can reasonably be used to infer someone’s health status, most of these statutes treat it as regulated, regardless of who collected it. That is a different starting point than HIPAA’s entity-based approach, and it pulls marketing, product, and vendor management teams inside the compliance perimeter, not just clinical and IT departments.
The FTC’s Health Breach Notification Rule Closes Another Gap
The Federal Trade Commission enforces its own breach notification requirement for health-adjacent businesses that HIPAA does not reach. The rule requires organizations not covered by HIPAA to notify customers, the FTC, and in some cases the media, following a breach of unsecured, individually identifiable health information. Amendments finalized in 2024 made clear that makers of health apps, connected devices, and similar products must comply.
The FTC has already tested this authority. Settlements with GoodRx and a fertility tracking app publisher centered on allegations that consumer health data was shared with advertising platforms without proper disclosure. The rule’s broad definition of breach, covering unauthorized disclosure and not just malicious intrusion, catches organizations off guard when data sharing with ad tech or analytics vendors is treated as a business decision rather than a privacy event. A breach response plan built solely around HIPAA’s own Breach Notification Rule may miss this entire category of obligations.
Comprehensive State Privacy Laws Still Matter, Even With HIPAA Exemptions
Most comprehensive state privacy statutes exempt data already covered by HIPAA, but that exemption is narrower than many teams assume. It typically protects the HIPAA-regulated data itself, not the entire entity that holds it. A hospital system running a wellness rewards program, a research recruitment tool, or a patient engagement app may generate data streams that fall outside the HIPAA exemption and squarely inside a law like Virginia’s VCDPA or Colorado’s CPA, both of which treat health information as sensitive data requiring opt-in consent and data protection assessments. Assuming an entire organization is exempt because part of it is HIPAA regulated is one of the more common gaps governance teams uncover during a privacy audit.
Reproductive and Behavioral Health Data Carry Extra Weight
Since the Supreme Court’s Dobbs decision, states have paid particular attention to reproductive health information. Shield laws in states such as California and New York restrict disclosure of reproductive health data in response to out-of-state legal requests, and several consumer health data laws explicitly name reproductive and gender-affirming care as categories requiring heightened consent.
Substance use disorder records carry their own long-standing federal protections under 42 CFR Part 2, which governs confidentiality for patients in federally assisted treatment programs. Recent alignment efforts brought Part 2 closer to HIPAA’s breach and enforcement structure, but consent rules remain stricter, particularly around redisclosure. Organizations handling behavioral health or substance use data need a separate compliance lane for this category.
International Obligations Reach Further Than Many Expect
Healthcare organizations with an international patient population, research collaboration, or cloud infrastructure touching the European Union need to account for the GDPR, which treats health data as a special category requiring explicit consent or another narrow legal basis for processing. Business associate agreements increasingly fold GDPR-style principles into breach protocols and vendor terms, even for US-based organizations, simply because supply chains and cloud vendors now span multiple jurisdictions by default.
Building a Compliance Program That Covers the Full Picture
A privacy program built only around HIPAA’s covered entity and business associate framework leaves real exposure on the table. A more resilient approach includes a few concrete steps:
- Map every data flow that touches health-adjacent information, including marketing pixels, analytics SDKs, wellness apps, and consumer-facing digital products, not just what sits inside your HIPAA risk assessment.
- Reassess vendor contracts so business associate agreements address state consumer health data laws and the FTC rule, not HIPAA alone. Many existing BAAs predate these newer obligations.
- Separate consent and disclosure processes for consumer health data from your standard HIPAA notice of privacy practices, since several state laws require a distinct, standalone health data privacy policy.
- Build a breach response plan that checks HIPAA, FTC, and state law obligations in parallel, since timelines and notification recipients differ across each.
This is exactly where a program built on HIPAA alone starts to show its limits, a shift our team has covered in detail: why healthcare compliance now extends well past HIPAA and into a continuous, security-driven governance model.
Where This Leaves Governance Leaders
The regulatory perimeter around health data has moved well past hospital walls and insurance databases. State consumer health data laws, the FTC’s Health Breach Notification Rule, comprehensive state privacy statutes, and international frameworks all now claim a piece of the same information HIPAA was built to protect, often with different triggers and enforcement paths. Treating HIPAA compliance as the finish line rather than the starting point is one of the hidden gaps that leaves healthcare organizations exposed during a real incident.
Understanding the difference between covered entities and business associates is still the right starting point, paired with a clear view of where AI tools and third-party vendors introduce obligations HIPAA was never built for, a challenge explored further in how AI is reshaping HIPAA compliance for healthcare organizations. Mapping these overlapping frameworks also pays off during audits.
| Talk to Ampcus Cyber to build a healthcare privacy program that holds up across HIPAA, state health data laws, and every regulator watching your data today. |
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










