Short answer: No, state law doesn't override HIPAA in the sense of replacing it — but HIPAA generally acts as a floor, not a ceiling. When a state law provides greater privacy protection or imposes stricter requirements than HIPAA, the stricter state law generally applies on top of HIPAA's baseline, rather than being preempted by it. A small practice needs to comply with HIPAA and whatever additional state-specific requirements apply to it.
Why this comes as a surprise to a lot of practices
It's a reasonable assumption that a federal law would be the final word, especially one as prominent as HIPAA. But HIPAA's preemption rule specifically works the other direction for most privacy protections: it sets minimum standards, and states remain free to impose additional or stricter requirements. A practice that's fully HIPAA compliant by federal standards can still be out of compliance with its own state's specific health privacy laws.
Areas where states commonly go further than HIPAA
Breach notification timelines. Some states require notification to affected individuals faster than HIPAA's 60-day window, or have their own separate notification requirements to a state attorney general or agency.
Genetic information and specific condition protections. A number of states have additional protections for particularly sensitive categories of health information — genetic testing results, mental health records, HIV status, and substance use treatment records commonly receive extra protection beyond HIPAA's baseline in various states.
Minor consent and parental access. State law, not HIPAA, generally governs when a minor can consent to their own care without parental involvement, and correspondingly what health information parents can or cannot access for a minor patient in specific circumstances.
Data breach definitions and thresholds. Some states define a reportable breach more broadly than HIPAA does, or apply their general data breach notification laws (which often cover more than just health information) in parallel with HIPAA's specific requirements.
What this means practically for a small practice
If your practice operates in a single state, you need to understand not just HIPAA's requirements but your specific state's health privacy and breach notification laws layered on top. If you provide telehealth services to patients across state lines, this gets more complex — you may need to account for the requirements of multiple states depending on where your patients are located, not just where your practice is physically based.
The safest approach
Rather than treating HIPAA compliance and state law compliance as two separate research projects, the more reliable approach is building your compliance program to meet the stricter of the two wherever they differ. In most cases, a practice that has a strong, comprehensive HIPAA compliance program is already close to meeting most state-specific requirements too, but it's worth explicitly confirming rather than assuming.
Getting clarity for your specific state
General guidance about HIPAA can't tell you what your specific state requires — that genuinely does require checking your state's specific health privacy statutes, or consulting legal counsel familiar with your state, especially around breach notification timing and any state-specific protected categories of health information.