If your organization operates under the Health Insurance Portability and Accountability Act (HIPAA) or the Gramm-Leach-Bliley Act (GLBA), privacy compliance is not new to you. Both laws have their own privacy rules and obligations; however, they were designed around specific data types, held by specific entity types, in specific contexts. State-level consumer privacy laws were built around a different premise entirely, and the relationship between what these federal frameworks cover versus what state-level privacy laws exempt varies significantly depending on where you operate.

Federal Privacy Rules and Consumer Privacy Laws: Understanding the Difference

HIPAA and GLBA both carry their own privacy obligations, and it is a reasonable assumption that meeting those obligations puts you in a strong position when it comes to state consumer privacy law (and vice versa). In practice, the relationship between federal sector law and state consumer privacy law is more complicated than that, and understanding when each law applies and what data is covered in a range of different scenarios is where complexity sets in.

HIPAA governs Protected Health Information (PHI), defined as individually identifiable health information held by covered entities such as hospitals, insurers, and healthcare clearinghouses, and their business associates. GLBA governs financial information held by regulated financial institutions such as banks, credit unions, and mortgage brokers. Both laws require specific privacy notices, restrict how certain information can be used and shared, and give individuals some degree of rights over their data.

State consumer privacy laws such as the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), and others operate differently. Rather than focusing on a specific data type or entity type, they apply broadly to personal information collected about residents, regardless of industry or context. They also introduce a wider set of consumer rights, including the right to delete, the right to correct, the right to access, and the right to opt out of the sale or sharing of personal information.

The result is that a regulated organization can be running a compliance program in line with the requirements of HIPAA or GLBA and still have significant consumer privacy obligations that those frameworks do not (or do not need to) address. The question is not whether a gap exists between the two, because it does, but whether an exemption exists that affects how large that gap is and what it means for your organization specifically.

Exemptions: What They Are, Why They Matter, and Where They Exist

Before looking at where federal and state privacy requirements overlap, the more important question is whether state consumer privacy law applies to your organization at all. The answer depends on which states you operate in and what kind of exemption, if any, exists in each of those states for your organization or your data.

Many state privacy laws include exemptions for regulated entities or regulated data, but those exemptions are not the same from state to state. This inconsistency is what creates the patchwork that regulated organizations have to navigate.

There are two types of exemptions to understand. An entity-level exemption removes the entire organization from the scope of the state law. A HIPAA-covered entity or GLBA-regulated financial institution operating in a state with an entity-level exemption has no additional obligations under that state’s consumer privacy law, and Federal compliance is sufficient for that jurisdiction. Whereas a data-level exemption is narrower. The organization remains subject to the state law, but specific categories of data such as PHI or GLBA-regulated financial information are carved out. All other personal information the organization holds is subject to the state law.

The table below shows how four key states handle this for both HIPAA and GLBA. It is illustrative rather than exhaustive, as more than twenty state privacy laws are now active and the landscape continues to change. Always verify current obligations against a live tracker such as OneTrust DataGuidance or with qualified legal counsel.

StateLawHIPAA Exemption TypeGLBA Exemption Type
VirginiaVCDPAEntity-levelEntity-level
CaliforniaCCPAEntity-level*Data-level
New JerseyNJDPAData-levelEntity-level
DelawareDPDPAData-levelEntity-level

From the table above, Virginia offers the clearest position. Both HIPAA-covered entities and GLBA-regulated financial institutions are exempt at the entity level under the VCDPA. Therefore, an organization operating only in Virginia can rely on its federal compliance program and has no additional obligations under that law.

California is more nuanced. For GLBA-regulated financial institutions, only covered data is carved out as an exemption, meaning a bank operating in California is still subject to the CCPA for all customer data that GLBA does not already govern. For HIPAA-covered entities and healthcare providers governed by California’s Confidentiality of Medical Information Act (CMIA), PHI and CMIA medical information is exempt. The organization itself is also exempt, but only if it treats all general personal information it holds about its patients to the same standard it applies to PHI and CMIA medical information. Where that condition is not met, only PHI and CMIA medical information is exempt, and everything else remains subject to the CCPA.

As a further example, New Jersey and Delaware both offer entity-level exemptions for GLBA-regulated financial institutions, meaning banks operating in either state are fully out of scope. But both only offer a data-level exemption for HIPAA-covered entities. So, a hospital operating in New Jersey or Delaware remains subject to the relevant state law for all data outside the definition of PHI.

Still following? Good, because this difference matters. A financial services organization and a healthcare organization operating in the same states can face entirely different consumer privacy obligations, even though both are federally regulated. That is why the exemption question has to be answered separately for each entity type, in each state, and why a comprehensive, up-to-date data inventory is so important.

Where the State Law Applies: Understanding What Remains

Once you have established your exemption status in each state where you operate, the next question is what your existing federal compliance program actually covers within the scope that remains.

Consumer Rights Frameworks Differ

HIPAA gives patients rights over their personal health information (PHI). GLBA gives customers a limited opt-out over certain data sharing. Both are rights frameworks, and most regulated organizations have processes in place to support them. However, they do not map to state consumer privacy rights. The CCPA grants rights to delete, correct, access, opt out of sale or sharing, and limit the use of sensitive personal information, across a broader range of data types with different operational requirements. An organization with a well-run HIPAA patient rights process has relevant experience to draw on, but the underlying rules, data scope, and triggers are different enough that the existing process cannot simply be applied to consumer privacy rights requests. Processes need to be built to include both sets of obligations, and they must extend to cover the additional requirements that come with them.

Privacy notices are not interchangeable 

HIPAA’s Notice of Privacy Practices (NPP) and GLBA’s privacy notice were designed for specific disclosure purposes within their respective frameworks. Neither wholly satisfies state consumer privacy disclosure requirements. The CCPA, for example, requires disclosures about the categories of personal information collected, the purposes of use, third-party sharing practices, the consumer rights available, and how to exercise them, including a mechanism to opt out of sale or sharing. That content does not exist in an NPP or a GLBA notice. A separate consumer-facing privacy notice is required for any organization operating in a state with a data-level exemption.

Some digital activity falls outside sectoral compliance scope

This is the gap that is easiest to miss. Consider a straightforward example where a hospital runs a public webinar on women’s health, open to anyone. Registrants submit their name, email address, and employer details. They are not patients; the data being collected is not PHI, and it does not fall within the hospital’s HIPAA compliance program. But it is personal information, collected from residents of states where the hospital may have consumer privacy obligations, and without an entity-level exemption, it is subject to state privacy law in full. 

The same applies to the tracking technology on the hospital’s public website, the pixels connected to its marketing campaigns, and the analytics platforms it uses. None of that is HIPAA-governed data. It is consumer data, generated by people who may never become patients, and it sits entirely outside the scope of sector-specific compliance. Most regulated organizations have a meaningful volume of this kind of consumer-facing digital activity. Identifying and addressing it is a distinct workstream, not an extension of the existing federal program.

Federal data inventory scope is narrower 

HIPAA and GLBA programs typically scope their data inventories around covered data categories e.g., PHI or regulated financial information. That makes sense within the federal framework, but it means the data map is often significantly incomplete when viewed through a consumer privacy lens. State consumer privacy laws apply to more broadly defined personal information, which can include employee data, marketing data, website visitor data, and any other personal information the organization collects that does not fall within an exempt category. Before an organization can assess what its consumer privacy obligations are, it needs a data inventory that reflects that broader scope, not just the data its federal program was built around.

Neither HIPAA nor GLBA creates the kind of consent and preference management framework that state consumer privacy laws require. State laws such as the CCPA require organizations to give consumers the ability to opt out of the sale or sharing of their personal information, limit the use of their sensitive personal information, and in some cases provide affirmative consent for certain processing activities. Managing those preferences at scale, across consumer touchpoints and down through the technology stack, requires dedicated tooling and processes that sit outside the scope of what a federal compliance program is designed to do. Specific privacy-enhancing technologies and tools offer consent and preference management capabilities that regulated organizations can use to address this gap.

Making It Manageable

An organization operating across multiple states, subject to HIPAA or GLBA (or both in cases such as Health Savings Accounts providers), with consumer-facing digital activity, can face a matrix of obligations that looks different in almost every jurisdiction. The starting point for making that manageable is to work through the obligations in the right sequence rather than assuming your existing program covers more than it does.

This often means running parallel processes rather than simply updating what you already have. Take privacy notices as an example. A HIPAA-covered entity operating in California still needs to maintain its NPP for HIPAA purposes, but will also need to write a separate CCPA-compliant consumer privacy notice alongside it. Those two notices have different content requirements, different triggers for updating them, and different processes for keeping them current. 

In the same light, this is true for rights management as well. A HIPAA patient rights workflow and a CCPA consumer rights workflow run alongside each other, but they are not the same. Your existing policies and procedures are likely a good starting point, but the operational reality is that you will have two tracks operating in parallel, not one updated version of what you already have.

The sequence that works is as follows: 

  • First, map the states where you operate and determine your exemption status in each, at the entity level and data level, for HIPAA and GLBA where relevant. 
  • Second, identify the data and activity that falls outside your exempt categories in each applicable state. 
  • Third, assess what your existing rights processes, notices, and governance structures actually cover within that remaining scope. 
  • Fourth, build or extend your program for what is not covered, particularly consumer rights workflows, consumer-facing privacy notices, and other digital activity.

A privacy program assessment is typically the right starting point for this exercise. It gives you an accurate picture of where you stand before you start building. If you are working through this for the first time, our Privacy Program Assessment is designed for exactly this stage.

The federal frameworks that govern HIPAA- and GLBA-regulated organizations represent real privacy infrastructure, and compliance with those frameworks is not a small undertaking. The issue is not that they fall short of what they were designed to do but that state consumer privacy laws were designed to do something different, and the relationship between the two frameworks is uneven enough across states. This leaves organizations in a position where they can easily assume compliance coverage without checking, which is where gaps tend to emerge. Start by understanding and answering the exemption question. From there, you can assess what your existing program covers and what needs to be added. 

If you’re a federally regulated organization and are having a hard time getting your head around state-level consumer privacy, we’d love to chat. 

Downloadable Resource

2026 Privacy Checklist