The Compliance Gap Between HIPAA, GLBA, and State Privacy Law

Table of Contents

A hospital runs a public webinar on heart health. Registrants who are not patients submit their name, email, and employer. A regional bank places a marketing pixel on its public website to track campaign conversions. A health system’s patient portal loads a third-party analytics tag that captures browsing behavior alongside login activity. None of this is Protected Health Information under HIPAA. None of it is GLBA-regulated financial data. All of it is personal information collected from state residents, and in the majority of states where these organizations operate, none of it is exempt from state consumer privacy law.

This is not a hypothetical risk. The U.S. Department of Health and Human Services Office for Civil Rights issued guidance in December 2022, reaffirmed in 2024, specifically addressing tracking technologies on hospital and health system websites and patient portals, warning that pixel and analytics tools can create HIPAA exposure when they transmit identifiable data to third parties without proper authorization. Separately, hospital systems including Advocate Health and Novant Health have faced litigation and regulatory scrutiny tied to Meta Pixel and similar tracking tools capturing patient interaction data. On the financial side, the FTC has pursued enforcement against health-adjacent platforms like GoodRx and BetterHelp under the Health Breach Notification Rule for sharing consumer health data with advertising platforms without authorization, demonstrating that “we’re a regulated entity” is not a defense once data moves outside the sectoral framework that regulation was built around.

The organizations named above all had HIPAA or GLBA compliance programs in place. None of those programs were designed to catch this kind of exposure, because the exposure exists in the space between what federal sectoral law covers and what state consumer privacy law reaches. Understanding exactly where that space is, and how it differs by state, is the difference between a defensible privacy program and a false sense of coverage.

Two Different Regulatory Models, Built for Two Different Problems

HIPAA and GLBA are both mature, well-established privacy regimes, and meeting their requirements is genuinely difficult. But both were built around a narrow premise: specific data types, held by specific categories of regulated entities, in specific contexts. HIPAA covers Protected Health Information held by covered entities and their business associates. GLBA covers nonpublic personal financial information held by financial institutions. Both come with mandated notices, use and disclosure restrictions, and defined rights frameworks for the individuals whose data is covered.

State consumer privacy laws, from the California Consumer Privacy Act to the more recently enacted statutes in states like Colorado, Connecticut, Texas, and Oregon, were built around a different premise entirely. Rather than scoping to a data type or entity category, they generally apply to personal information collected about state residents across essentially any business context, and they layer on a broader set of consumer rights: access, correction, deletion, opt-out of sale or sharing, and in many states, the right to limit use of sensitive personal information.

The overlap between these two models is not automatic, and it is not consistent. Whether your federal compliance program leaves you with meaningful state-law exposure depends entirely on whether, and how, each state you operate in exempts HIPAA-covered entities and GLBA-regulated financial institutions.

Entity-Level vs. Data-Level Exemptions

There are two distinct exemption models used across the twenty-plus active state consumer privacy laws, and the difference between them determines how much of your organization’s activity remains in scope.

An entity-level exemption removes the organization entirely from the state law’s scope, based on its regulatory status. A GLBA-regulated bank operating in a state with an entity-level GLBA exemption has no consumer privacy obligations under that state’s law, full stop, regardless of what other data it holds.

A data-level exemption is narrower. The organization remains subject to the state law, but the specific regulated data category, PHI or GLBA-covered financial information, is carved out. Every other category of personal information the organization holds, including marketing data, employee data, website visitor data, and any consumer data collected outside the regulated context, remains fully subject to the state law.

The practical difference between these two models is enormous, and most state laws do not apply the same model consistently across both HIPAA and GLBA, or across different states.

How This Plays Out Across State Lines

The table below reflects the exemption structure across a broader set of active state consumer privacy laws. This is illustrative, not exhaustive; more than twenty states now have active consumer privacy statutes, several have been amended since enactment, and exemption language should always be verified against current statutory text or a live regulatory tracker before you rely on it for a compliance determination.

State Law HIPAA Exemption Type GLBA Exemption Type
Virginia VCDPA Entity-level Entity-level
Colorado CPA Entity-level Entity-level
Connecticut CTDPA Entity-level Entity-level
Utah UCPA Entity-level Entity-level
Texas TDPSA Entity-level Entity-level
Montana MTCDPA Entity-level Entity-level
Iowa ICDPA Entity-level Entity-level
Tennessee TIPA Entity-level Entity-level
California CCPA Conditional entity-level* Data-level
New Jersey NJDPA Data-level Entity-level
Delaware DPDPA Data-level Entity-level
Oregon OCPA Data-level Data-level

*In California, HIPAA-covered entities are entity-level exempt only if they treat all personal information the same way they treat PHI and CMIA-covered medical information. Where that condition is not met, only the regulated medical data is exempt, and every other category of personal information the organization holds remains subject to the CCPA.

Several patterns are worth calling out. Most states that adopted the Virginia/Colorado template offer entity-level exemptions for both HIPAA-covered entities and GLBA-regulated financial institutions, meaning federal compliance is genuinely sufficient in those jurisdictions. California is the clearest exception, applying a data-level exemption to GLBA and a conditional entity-level exemption to HIPAA that most organizations will not automatically satisfy. New Jersey and Delaware split the two differently, offering banks a clean entity-level exemption while leaving hospitals and other HIPAA-covered entities with a narrower data-level carve-out. Oregon applies the narrowest model of the states listed here, exempting only the specific regulated data category under both frameworks rather than the entity itself.

The result is that a hospital system and a regional bank, operating in the exact same set of states, can end up with meaningfully different state-law exposure, because the exemption question has to be answered separately for each entity type, in each state.

What Remains In Scope Once You Know Your Exemption Status

Consumer rights frameworks do not transfer

A HIPAA-covered entity’s patient rights process and a GLBA-regulated institution’s opt-out process are both mature, established workflows. Neither maps to the broader rights structure under state consumer privacy law. The right to delete, correct, and access, along with opt-out of sale or sharing and limitation of sensitive data use, apply across a much wider range of data types and triggers than either federal framework was built to handle. Existing rights infrastructure is a useful foundation, but it is not a substitute for a parallel consumer rights workflow built to the state law’s specifications.

Privacy notices are not interchangeable

HIPAA’s Notice of Privacy Practices and GLBA’s privacy notice satisfy their own frameworks and nothing else. State consumer privacy laws require disclosures about categories of personal information collected, purposes of processing, third-party sharing, the specific rights available to consumers, and the mechanism for exercising an opt-out of sale or sharing. That content simply does not exist in a federally mandated notice. Any organization operating under a data-level exemption in any state needs a separate, state-law-compliant consumer privacy notice.

Consumer-facing digital activity is the most commonly missed exposure

This is where the OCR guidance and the pixel litigation trend become directly relevant. Public-facing webinars, marketing campaigns, website analytics, and tracking pixels routinely collect personal information from people who are not patients or customers in the regulated sense, meaning the data was never PHI or GLBA-covered financial information to begin with. In states without an entity-level exemption, that activity is subject to state privacy law in full, and it is frequently the single largest source of consumer data a regulated organization holds outside its federal compliance program’s field of view.

Federal data inventories are scoped too narrowly

A data inventory built around PHI or regulated financial information will not surface employee data, marketing data, website visitor data, or any other personal information collected outside the exempt category. Before an organization can accurately determine its state-law obligations, it needs an inventory built to the broader definition of personal information that state consumer privacy laws use, not the narrower one its federal program was designed around.

Consent and preference management is a separate technical layer

Neither HIPAA nor GLBA requires a consumer-facing consent and preference management infrastructure of the kind state laws increasingly mandate, including opt-out of sale or sharing, limitation of sensitive data use, and in some states affirmative consent for specific processing activities. Operationalizing these preferences across a consumer-facing technology stack requires dedicated tooling that sits entirely outside what a federal sectoral compliance program was built to provide.

A Practical Sequence for Getting This Right

  1. Map every state where you operate and determine your exemption status for each entity type. Answer the HIPAA question and the GLBA question separately, at both the entity level and data level, for every applicable jurisdiction. Do not assume the answer is consistent across states just because it was consistent in one.
  2. Identify the data and activity that falls outside your exempt categories in each state. This typically includes marketing data, website analytics and tracking technology, employee data, and any consumer-facing digital activity involving non-patients or non-customers.
  3. Audit your existing rights processes, notices, and governance structures against what actually remains in scope. Determine specifically what your current HIPAA or GLBA program covers, and what it does not, rather than assuming broad coverage.
  4. Build a consumer privacy notice separate from your NPP or GLBA notice, for every state requiring one. Treat this as a parallel document with its own update triggers, not a revision of an existing federal notice.
  5. Stand up a parallel consumer rights workflow. Run it alongside your existing patient or customer rights processes rather than merging the two, since the data scope, timelines, and verification requirements differ.
  6. Extend your data inventory to the full definition of personal information used by state law. Include employee, marketing, and website data that your federal program was never scoped to capture.
  7. Implement consent and preference management infrastructure for consumer-facing properties. This is the layer most federally regulated organizations are missing entirely, and it is where tracking pixel and analytics exposure specifically lives.
  8. Re-run this analysis whenever you expand into a new state or launch new consumer-facing activity. Exemption status and scope both shift as your footprint and digital activity change.

The Bottom Line

Being HIPAA-covered or GLBA-regulated is real, substantive privacy infrastructure, and none of the above diminishes how difficult those programs are to run well. The issue is that state consumer privacy laws were designed to solve a different problem, for a broader category of data, and the exemption question has to be answered on a state-by-state, entity-by-entity basis before an organization can know what its actual obligations are. Organizations that assume federal compliance is sufficient, without checking, are the ones most likely to discover the gap only after a regulator, plaintiff’s firm, or a guidance document points it out for them.

Frequently Asked Questions

Does HIPAA compliance automatically satisfy state consumer privacy law requirements?

No. Whether it does depends entirely on whether the state where you operate provides an entity-level exemption for HIPAA-covered entities. Several states do, but others, including California, New Jersey, Delaware, and Oregon, apply either a narrower data-level exemption or a conditional entity-level exemption, leaving significant personal information subject to state law.

What is the difference between an entity-level and data-level exemption?

An entity-level exemption removes the entire organization from a state privacy law’s scope. A data-level exemption only carves out the specific regulated data category, such as PHI or GLBA-covered financial information, leaving all other personal information the organization holds subject to the law.

Are website tracking pixels and analytics tools covered by HIPAA?

Generally not, unless they transmit individually identifiable health information to a third party without proper authorization, which is the exact exposure the U.S. Department of Health and Human Services Office for Civil Rights addressed in its guidance on tracking technologies. Even where HIPAA does not apply, this kind of data is frequently subject to state consumer privacy law in full.

Can a GLBA-regulated financial institution still have consumer privacy obligations under state law?

Yes, in states applying a data-level GLBA exemption, such as California. Only the GLBA-covered financial data is exempt; marketing data, website visitor data, and other personal information the institution collects remain subject to the state consumer privacy law.

What is the first step for a regulated organization trying to assess its state privacy law exposure?

Map every state of operation and determine exemption status separately for each entity type, at both the entity and data level, before assuming existing federal compliance covers state-law obligations.

Captain Compliance helps HIPAA- and GLBA-regulated organizations with their privacy compliance requirements. Schedule a demo below to see how we handle multi-state exemption mapping and consent management in one platform.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.