HIPAA isn’t the only privacy, security, and breach notification law in the country. In fact, HIPAA is designed to work with state laws, and in cases where state laws are stricter or prescribe a higher level of privacy or security, HIPAA explicitly directs covered entities and business associates to follow state law. A covered entity or business associate that isn’t in compliance with state privacy, security, and breach notification laws is not in compliance with HIPAA, and is at risk of both federal and state action.
