The Gap Between HIPAA and State Health Privacy Laws
HIPAA regulates covered entities—primarily healthcare providers, health plans, and their business associates. If your organization operates a consumer health app, a wellness platform, a fertility tracker, or a telehealth service that does not meet HIPAA's definition of a covered entity, you have historically operated outside its scope.
That regulatory gap has closed in three states. Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's SB 3 impose privacy obligations on organizations that collect, process, or share consumer health data—regardless of whether HIPAA applies. These laws took effect in 2024 and carry civil penalties that can reach tens of thousands of dollars per violation.
The business consequence is not theoretical. State attorneys general now have enforcement authority over health data practices that were previously unregulated for many digital health companies. Leadership is accountable for compliance, but in most organizations, no single executive owns the assessment, gap analysis, policy development, or ongoing monitoring these laws require.
What These Laws Cover
All three state laws define consumer health data broadly. Washington's My Health My Data Act covers personal information that identifies or is reasonably linked to a consumer and relates to the past, present, or future physical or mental health of the consumer. This includes data from health apps, wearables, period trackers, mental health platforms, and telehealth services.
Nevada's SB 370 applies to any business that conducts business in Nevada or produces products or services targeted to Nevada residents and that collects consumer health data. Connecticut's SB 3 similarly reaches any person that conducts business in Connecticut or produces products or services targeted to Connecticut residents.
The laws generally require:
- Explicit consumer consent before collecting or sharing consumer health data
- Clear privacy policies that explain what data is collected, how it is used, and with whom it is shared
- The right for consumers to withdraw consent
- Prohibition on selling consumer health data without valid authorization
- Data security practices appropriate to the sensitivity of the information
- Geofencing restrictions that prevent collecting health data near certain facilities
Organizations subject to HIPAA are generally exempt from these state laws when acting in their capacity as covered entities or business associates. However, many digital health companies serve both HIPAA-covered and non-covered functions, creating compliance complexity that requires careful segmentation.
Why This Matters to the Business
The immediate risk is enforcement. State attorneys general can pursue civil penalties, injunctive relief, and in some cases, private rights of action allow consumers to sue directly. Washington's law allows the attorney general to seek civil penalties per violation. When violations affect thousands of users, exposure accumulates rapidly.
The operational risk is harder to quantify but equally significant. Without clear governance, organizations often discover compliance gaps during due diligence, customer audits, or—worst case—after a complaint triggers investigation. Retrofitting consent mechanisms, rewriting privacy policies, and remediating data sharing practices under time pressure is expensive and disruptive.
The strategic risk is that these laws are not isolated. More states are considering similar legislation, and federal proposals are in active discussion. Organizations that build compliance capabilities now are preparing for a regulatory environment that will only expand.
Who Owns This and What Adequate Ownership Looks Like
In most digital health companies, responsibility for state health privacy laws falls into a gap. Legal counsel understands the statutory language but may lack visibility into data flows and technical controls. Engineering owns the systems but does not interpret regulatory requirements. Product leadership controls user experience but depends on others to define what consent mechanisms are required.
Adequate ownership requires an executive who can:
- Interpret regulatory requirements in operational terms
- Map those requirements to existing data practices and identify gaps
- Translate gaps into specific, sequenced remediation work
- Coordinate across legal, engineering, product, and compliance functions
- Maintain an ongoing monitoring posture as laws evolve and the business changes
- Report status and risk to the board and executive leadership in business terms
This is not a project; it is an ongoing governance function. In larger organizations, a Chief Privacy Officer or dedicated privacy team may own this work. In smaller or mid-sized companies, the function often does not exist, and attempting to distribute it across existing roles produces accountability gaps.
A virtual CISO with experience in healthcare privacy can provide this executive ownership without requiring a full-time hire. Heights' vCISO service is designed to fill exactly this gap: translating regulatory requirements into operational controls, coordinating remediation, and reporting progress to leadership.
Relationship to Broader Regulatory Readiness
State health privacy laws do not exist in isolation. They interact with broader privacy regulations, including state consumer privacy laws like the California Consumer Privacy Act, sector-specific requirements, and federal proposals. The FTC has also indicated that it will enforce against deceptive or unfair health data practices under its existing authority.
Organizations that build a structured approach to regulatory readiness can address multiple requirements through common controls. For example, maintaining an accurate data inventory supports both state health privacy compliance and broader privacy law obligations. Implementing role-based access controls and encryption serves both security and privacy goals.
Frameworks like the NIST Privacy Framework and NIST Cybersecurity Framework provide structured approaches to identifying, assessing, and managing privacy and security risks. These are voluntary tools, but they offer a common language and methodology that translates across multiple regulatory requirements.
The challenge is that frameworks describe what should be done, not who will do it or in what sequence. Leadership still requires someone to interpret the framework in the context of specific laws, prioritise gaps, and coordinate implementation. This is the executive function that most organizations lack.
What Leadership Should Do Next
If your organization collects consumer health data and operates in Washington, Nevada, or Connecticut—or plans to—the following steps establish a defensible position:
Confirm Applicability
Determine whether your organization is subject to these laws. This requires understanding what data you collect, how it is used, whether HIPAA exemptions apply, and whether you conduct business or target consumers in the regulated states. Do not assume HIPAA coverage exempts you without verifying how each state law defines its scope.
Inventory Data Practices
Map what consumer health data you collect, where it is stored, how it is processed, and with whom it is shared. This inventory is foundational to every subsequent compliance step and is required by most privacy regulations. If you do not have an accurate, current data inventory, you cannot assess compliance.
Assess Current Practices Against Requirements
Compare your current consent mechanisms, privacy policies, data sharing practices, and security controls to what the laws require. Identify specific gaps. This assessment should be documented and reviewed by legal counsel familiar with these statutes.
Assign Executive Accountability
Designate a single executive responsible for privacy compliance, gap remediation, and ongoing monitoring. This person must have authority to coordinate across functions and to escalate risks to the CEO and board. If no internal candidate has the necessary expertise, consider engaging a virtual CISO to provide this leadership.
Develop a Remediation Plan
Translate identified gaps into specific, sequenced work. Prioritise based on legal risk, operational impact, and implementation dependencies. Assign owners, set deadlines, and establish a mechanism to track progress. Report status to executive leadership and the board monthly until remediation is complete.
Establish Ongoing Governance
Privacy compliance is not a one-time project. As your product evolves, new data practices will be introduced. As laws change, new requirements will take effect. Establish a process to review new features for privacy implications, monitor regulatory developments, and update policies and controls accordingly.
How Heights Can Help
Heights provides virtual CISO leadership for organizations that need executive accountability for privacy and security but do not require or cannot justify a full-time hire. This includes regulatory readiness for state health privacy laws, HIPAA, and other sector-specific requirements.
Our approach is strategy-first: we begin by understanding your business model, data practices, and risk tolerance, then translate regulatory requirements into a practical, sequenced plan. We coordinate across your legal, engineering, and product teams, provide ongoing governance, and report progress to your board in terms they can act on.
If you are facing state health privacy compliance without clear ownership, we can help you establish a defensible position. Contact us for a confidential consultation to discuss your specific situation and determine whether vCISO leadership is the right approach for your organization.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.