Almost half the US states have passed comprehensive consumer data privacy protections that go beyond federal health privacy rules, known as Health Insurance Portability and Accountability Act (HIPAA).
The legislative push aims to close a widening security gap as more care, communication, and personal data move online — and beyond HIPAA’s limited scope.
While the laws are designed to protect consumers, they’re also reshaping expectations around how healthcare organizations should handle non-HIPAA-protected data in an increasingly digital landscape.
Much of the shift stems from the growth in telehealth, apps, and direct-to-consumer (DTC) health services, where HIPAA-covered environments such as patient portals aren’t the norm.
Consumer health data accumulates quickly. Consumers might search their symptoms online, enter their vitals into a fitness tracker, or discuss their mental health concerns with an artificial intelligence chatbot. Even hospital and physician websites may collect visitor data through tracking pixels or cookies, capturing search terms, website clicks, and location data for marketing purposes.
Regulatory Gray Zone
This information falls outside HIPAA’s tightly defined protections, becoming the growing regulatory gray zone that state consumer data laws target, Carmel Shachar, JD, MPH, assistant clinical professor and faculty director of the Health Law and Policy Clinic at the Center for Health Law and Policy Innovation at Harvard Law School, Cambridge, Massachusetts, told Medscape Medical News.
“What’s happening now, pioneered by California, is more like the European General Data Protection Regulation,” she said. These laws expand privacy protections beyond medical records to a broader range of personal and health data that are shared and collected online and through technology.
Data analytics tools often aggregate this information and are widely used across industries for marketing and to track consumers’ behaviors and interests.
But they raise concerns in healthcare because they could capture information subject to HIPAA and, now, emerging state consumer privacy laws.
The tools have caused problems before.
Nearly three dozen major health systems were found to have Meta’s tracking pixel embedded on their websites in 2022, with some linked directly to patient portals. In 2023, BetterHelp paid $7.8 million after the Federal Trade Commission found the DTC platform shared users’ sensitive mental health data with Meta for advertising.
State Laws Similar but Not Identical
California was the first state to pass a comprehensive consumer privacy law in 2018. Roughly 20 more states have adopted some version of the protections since then, with Indiana, Kentucky, and Rhode Island following on January 1.
Maryland’s version, the Online Data Privacy Act, took effect on October 1. The law uses a similar definition as Washington’s, and while it exempts HIPAA-protected information, it doesn’t categorically exclude nonprofits or HIPAA-covered entities. Those requirements mean Maryland-based healthcare organizations should still review how they collect and handle data flowing through public-facing websites and third-party tools such as wearables and apps, Gene Ransom, JD, CEO of MedChi, The Maryland State Medical Society, told Medscape Medical News.
“This affects all practitioners, whether they’re in long-term care, private practices, or hospitals. Essentially any clinician [in Maryland] who uses an electronic medical record needs to be really careful when they’re using vendors and make sure that the data protections are properly disclosed and they’re compliant not only with HIPAA but also with the stricter state rules,” he said.
Most states’ laws share common goals: They require clear disclosure of how consumer information is used, limit or prohibit its sale to third parties, and give consumers the right to review or delete their data. Under these laws, personal information is generally defined as any non-HIPAA-protected data that can identify or be linked to a person, from email addresses and internet browsing history to genetic or biometric details. Several states also include reproductive and sexual healthcare and gender-affirming treatment in that definition.
However, several of the laws apply only to businesses that meet certain size or data-processing thresholds, and some, like California, exclude specific sectors such as nonprofits.
Washington’s My Health My Data Act goes further, applying to nearly any business, regardless of size, that collects personal information “linked or reasonably linkable to…the consumer’s past, present, or future physical or mental health status.”
Who Controls the Data?
Organizations should take a hard look at every product and vendor contract. “Ask who controls the data,” Ransom said. “Does the app sell it or use it for advertising? Is it processing sensitive personal data? If the answer is yes to any of that, take a step back.” It’s also critical to secure written assurances and indemnity clauses to avoid being left solely liable if a vendor mishandles data, he added.
Beyond noncompliance risks and fines, organizations could face costly litigation. “The cost to comply is much lower than the risk,” said Ransom. “If you don’t do it, you’re putting yourself at real risk for civil liability,” he said.
Still, most of the necessary changes will likely be handled by organizations’ compliance teams, and physicians won’t see a major impact on their day-to-day practice.
“All the ways I interact with consumer health data are HIPAA compliant,” Sarah Prager, MD, ob/gyn and complex family planning physician at the University of Washington School of Medicine in Seattle, told Medscape Medical News. “The My Health My Data Act was really designed to cover information that falls outside HIPAA’s reach.”
While the law adds consumer safeguards, Prager, who also works at an independent abortion clinic in the state, still reminds patients that data shared in apps such as fertility or cycle trackers may not be secure. She said more of her patients are expressing concern about how their reproductive, LGBTQ, and other stigmatized care is documented and shared, highlighting the benefits of ongoing transparent patient-provider discussions.
A Fragmented Future
The patchwork of stricter state laws is not surprising, Kyle Zebley, senior vice president of public policy for the American Telemedicine Association (ATA) and executive director of ATA Action, told Medscape Medical News.
“In the absence of a federal framework with the credibility that HIPAA has long had, states are going to get antsy and feel the need to update their laws accordingly,” he said. “The largest companies will find a way to comply, but small and mid-sized organizations will spend enormous time and money trying to navigate each state’s rules.”
To address that complexity, the association has developed Health Data Privacy Principles, a roadmap toward a single, national framework for securing patient data.
While those policy-level discussions continue, expectations for clinicians are also evolving.
“For many years, physicians didn’t necessarily consider if I recommend an app, how good are its privacy protections?” said Shachar. Given their “information fiduciary duty” to patients, she said the new laws may encourage clinicians to reconsider which digital resources they recommend while pushing app developers and businesses to take consumer privacy more seriously.
Without a federal solution, Zebley said to expect more movement at the state level.
“We’d like to see the federal government adapt to our new reality of digital health tools, but I’m not sure it’s going to happen soon.”
Steph Weber is a Midwest-based freelance journalist specializing in healthcare and law.
Admin_Adham