• PRO
  • Events
  • About
  • Blog Popular
  • Login
  • Register
  • PRO
  • Resources
    • Latest updates
    • Q&A
    • In-depth
    • In-house view
    • Practical resources
    • FromCounsel New
    • Commentary
  • Research tools
    • Global research hub
    • Lexy
    • Primary sources
    • Scanner
    • Research reports
  • Resources
  • Research tools
  • Learn
    • All
    • Masterclasses
    • Videos
  • Learn
  • Experts
    • Find experts
    • Influencers
    • Client Choice New
    • Firms
    • About
    Introducing Instruct Counsel
    The next generation search tool for finding the right lawyer for you.
  • Experts
  • My newsfeed
  • Events
  • About
  • Blog
  • Popular
  • Find experts
  • Influencers
  • Client Choice New
  • Firms
  • About
Introducing Instruct Counsel
The next generation search tool for finding the right lawyer for you.
  • Compare
  • Topics
  • Interviews
  • Guides

Analytics

Review your content's performance and reach.

  • Analytics dashboard
  • Top articles
  • Top authors
  • Who's reading?

Content Development

Become your target audience’s go-to resource for today’s hottest topics.

  • Trending Topics
  • Discover Content
  • Horizons
  • Ideation

Client Intelligence

Understand your clients’ strategies and the most pressing issues they are facing.

  • Track Sectors
  • Track Clients
  • Mandates
  • Discover Companies
  • Reports Centre

Competitor Intelligence

Keep a step ahead of your key competitors and benchmark against them.

  • Benchmarking
  • Competitor Mandates
Home

Back Forward
  • Save & file
  • View original
  • Forward
  • Share
    • Facebook
    • Twitter
    • Linked In
  • Follow
    Please login to follow content.
  • Like
  • Instruct

add to folder:

  • My saved (default)
  • Read later
Folders shared with you

Register now for your free, tailored, daily legal newsfeed service.

Questions? Please contact [email protected]

Register

How State General Privacy Laws Apply to Healthcare Providers
Blog Privacy & Security Law Blog

Davis Wright Tremaine LLP

To view this article you need a PDF viewer such as Adobe Reader. Download Adobe Acrobat Reader

If you can't read this PDF, you can view its text here. Go back to the PDF .

USA January 31 2023

With 2023 underway, healthcare providers have a more complex patchwork of privacy laws than ever before to navigate. Five states have enacted general privacy laws: California, Colorado, Connecticut, Utah, and Virginia. These laws include varying exemptions for protected health information (PHI), HIPAA de-identified information, healthcare providers, HIPAA covered entities, HIPAA business associates, and non-profits.

While all of the laws exempt PHI, healthcare providers may have obligations under these laws with respect to other personal information, such as employee information or website data.

To help healthcare providers navigate these laws, we have put together the following table:

* For purposes of the applicability threshold, we are assuming that healthcare providers do not derive 25% or more of their annual revenues from selling or sharing consumers' personal information.

Takeaways

Some takeaways based on the above:

  • Healthcare providers that are HIPAA covered entities appear to be completely exempt from the Connecticut, Utah, and Virginia general privacy laws.
  • For-profit healthcare providers should evaluate whether they meet CCPA's applicability threshold and, if so, should comply with the CCPA with respect to: (1) personal information collected from their websites that is not PHI; and (2) employee information.
  • Nonprofit healthcare providers should evaluate whether they share common branding with a for-profit affiliate that meets CCPA's applicability threshold and, if so, should comply with the CCPA with respect to: (1) personal information collected from their websites that is not PHI; and (2) employee information.
  • Healthcare providers (regardless of tax exemption status) should: (1) evaluate whether they meet the Colorado law's applicability threshold and, if so, should comply with the Colorado Privacy Act with respect to personal information collected from their websites that is not PHI; and (2) evaluate whether they sell or license HIPAA de-identified information and, if so, whether they must comply with CCPA's contractual restrictions with respect to such data.

If you would like assistance with determining applicability of state privacy laws or complying with such laws, you may contact the author or the DWT attorney with whom you work.

Davis Wright Tremaine LLP - Adam H. Greene

Back Forward
  • Save & file
  • View original
  • Forward
  • Share
    • Facebook
    • Twitter
    • Linked In
  • Follow
    Please login to follow content.
  • Like
  • Instruct

add to folder:

  • My saved (default)
  • Read later
Folders shared with you

Filed under

  • USA
  • Healthcare & Life Sciences
  • IT & Data Protection
  • Davis Wright Tremaine LLP

Topics

  • Personal data

Laws

  • Health Insurance Portability and Accountability Act 1996 (USA)
  • California Consumer Privacy Act 2018 (USA)

If you would like to learn how Lexology can drive your content marketing strategy forward, please email [email protected].

Powered by Lexology

More from Privacy & Security Law Blog

  1. Now We Are Six: Iowa Becomes the Sixth State to Enact a Comprehensive Privacy Law
  2. Data Breach Notification Law Update: Utah and Pennsylvania
  3. Lessons Learned from OCR Reports to Congress on HIPAA Compliance and Data Breaches
  4. FTC Targets Tracking Pixels Amid Data Sharing Settlements with GoodRx, BetterHelp
  5. CISA Announces Launch of Ransomware Prevention Initiative

Related practical resources PRO

  • Checklist Checklist: Complying with cookie requirements under the PECR and the GDPR (UK) Recently updated
  • How-to guide How-to guide: How to establish a valid lawful basis for processing personal data under the GDPR (UK) Recently updated
  • Checklist Checklist: Data subject access rights under the GDPR (UK) Recently updated
View all

Related research hubs

  • Health Insurance Portability and Accountability Act 1996 (USA)
  • California Consumer Privacy Act 2018 (USA)
  • USA
  • Healthcare & Life Sciences
  • IT & Data Protection
Back to Top
Resources
  • Daily newsfeed
  • Commentary
  • Q&A
  • Research hubs
  • Learn
  • In-depth
  • Lexy: AI search
  • Scanner
Experts
  • Find experts
  • Legal Influencers
  • Firms
  • About Instruct Counsel
More
  • About us
  • Blog
  • Events
  • Popular
Legal
  • Terms of use
  • Cookies
  • Disclaimer
  • Privacy policy
Contact
  • Contact
  • RSS feeds
  • Submissions
 
  • Login
  • Register
  • Follow on Twitter
  • Follow on LinkedIn

© Copyright 2006 - 2023 Law Business Research

Law Business Research