HIPAA Compliance in Arizona: The Records Law Still Applies to You

Practical guidance for healthcare teams and business associates

A Tucson practice manager reads a summary of Arizona's data breach law and finds the 45-day notice deadline, the Attorney General filing at 1,000 people, and the $500,000 penalty cap. She builds the incident response plan around those numbers. Then an attorney points to the last subsection of the statute, the one the summaries skip: the article "does not apply to" a "covered entity or business associates as defined under regulations implementing" HIPAA. The plan was built for a law that does not reach the practice, while the state law that does reach it, the medical records statute, was never read.

Federal enforcement in Arizona is not theoretical. OCR (the HHS Office for Civil Rights) settled a HIPAA investigation with an Arizona hospital system following cybersecurity hacking (February 2, 2023), and years earlier settled with Phoenix Cardiac Surgery for lack of HIPAA safeguards (April 13, 2012). What Arizona adds sits in a different title of its code than most people expect.

This guide covers the federal floor, the Arizona statutes that actually stack on top of it, the breach law and its HIPAA exemption, the penalties on both sides, and what it means for hospitals, dental offices, behavioral health practices, and home health agencies.

HIPAA Compliance Arizona: How the Federal and State Rules Interact

HIPAA (the Health Insurance Portability and Accountability Act) sets a floor. 45 CFR 160.203 states the general rule: a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," then lists the exceptions. Paragraph (b) preserves state law that "relates to the privacy of individually identifiable health information and is more stringent than" the federal Privacy Rule. Arizona's medical records statutes were drafted to sit inside that space, and several of them cite HIPAA by name as a source of permitted disclosures.

Where Arizona is stricter, Arizona wins. Where HIPAA is stricter, HIPAA wins. An Arizona covered entity meets both at once, with one twist: the state breach statute removed itself from the equation for HIPAA entities.

Who Is a Covered Entity in Arizona

The definition is federal. 45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Every Arizona provider that bills electronically qualifies. Arizona's own medical records article, A.R.S. 12-2291, separately defines a health care provider to include a person licensed under Title 32 who maintains medical records, a licensed health care institution, an ambulance service, and a licensed health care services organization.

Who Is a Business Associate in Arizona

Also federal. A business associate under 160.103 is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing." Each needs a signed B.A.A. (Business Associate Agreement); the BAA guide lists the required terms. Arizona's breach statute exempts business associates by the same subsection that exempts covered entities, so a billing company's Arizona duties also flow through the B.A.A. and the federal rule.

Arizona Statutes That Stack on Top of HIPAA

Confidentiality and Release of Medical Records (A.R.S. 12-2291 to 12-2297)

This article is the state's health privacy law for providers. A.R.S. 12-2292(A) sets the rule: "all medical records and payment records, and the information contained in medical records and payment records, are privileged and confidential. A health care provider may only disclose that part or all of a patient's medical records and payment records as authorized by state or federal law or written authorization signed by the patient or the patient's health care decision maker." Note the two objects: the statute covers payment records alongside the chart, which pulls the billing office inside the same confidentiality rule.

A.R.S. 12-2293 governs release to the patient. On "the written request of a patient or the patient's health care decision maker," the provider "shall provide access to or copies of the records." Denial is allowed only on the listed grounds, among them that access "is reasonably likely to endanger the life or physical safety of the patient or another person," and a denial must be noted in the record with "a written explanation of the reason for the denial." The section sets no day count, so the federal 30-day clock at 45 CFR 164.524(b)(2) governs timing. The section is stricter than HIPAA in one direction: the state grounds for denial are narrower than a practice might assume, and the written explanation is mandatory.

Record Retention: 6 Years (A.R.S. 12-2297)

HIPAA sets no retention period for the chart; it requires that policies and required documentation be kept "for 6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i) and 164.530(j)(2)). Arizona sets the chart period by statute. Under A.R.S. 12-2297(A), a health care provider "shall retain the original or copies of a patient's medical records" for an adult "for at least six years after the last date the adult patient received medical or health care services from that provider," and for a child "either for at least three years after the child's eighteenth birthday or for at least six years after the last date the child received medical or health care services from that provider, whichever date occurs later." Source data such as x-rays and diagnostic images "must be retained for six years from the date of collection." A provider who retires or sells a practice "shall take reasonable measures to ensure that the provider's records are retained." Nursing care institutions keep records six years after discharge. The record retention guide covers the federal-versus-state split.

Communicable Disease Information (A.R.S. 36-664)

A person who obtains communicable disease related information, which includes HIV status, "shall not disclose or be compelled to disclose that information except as authorized by state or federal law, including the health insurance portability and accountability act privacy standards (45 Code of Federal Regulations part 160 and part 164, subpart E)," or under the section's own list: the protected person or decision maker, an occupationally exposed health care provider or first responder on a documented written request, agents of the provider "to provide health services to the protected person" or "for billing or reimbursement," public health officers where disclosure is mandated, and others. The section folds HIPAA in as a permitted source rather than fighting it, but it narrows everything outside the list.

Mental Health Records (A.R.S. 36-509)

A health care entity providing behavioral health services "must keep records and information contained in records confidential and not as public records," disclosing them "only as authorized by state or federal law, including the health insurance portability and accountability act privacy standards," or to the listed recipients: treating providers, persons the patient authorizes, persons under a court order, qualified researchers, and family members or friends under the section's own consent and inference rules, which mirror 45 CFR 164.510. Substance use disorder programs may also be under 42 CFR Part 2.

Arizona Breach Notification: Read the Last Subsection First

The federal rule first, because for a HIPAA entity in Arizona it is the only breach clock. 45 CFR 164.404(b) requires notice to affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." A breach involving 500 or more individuals goes to HHS "contemporaneously" with the individual notice (164.408(b)); smaller breaches are logged and reported "not later than 60 days after the end of each calendar year" (164.408(c)); a breach involving "more than 500 residents of a State or jurisdiction" also goes to prominent media serving that state (164.406(a)). A business associate has the same 60-day ceiling to notify the covered entity (164.410(b)).

Arizona's statute, A.R.S. 18-552, is a modern one. A person that owns unencrypted computerized personal information must investigate a security incident, and if a breach is confirmed must, "within forty-five days after the determination," notify affected individuals and, if more than 1,000 individuals require notice, notify "the three largest nationwide consumer reporting agencies" and "the attorney general and the director of the Arizona department of homeland security, in writing." Personal information under A.R.S. 18-551 includes a name linked to a health insurance identification number or to "information about an individual's medical or mental health treatment or diagnosis by a health care professional." The Attorney General may impose a civil penalty "not to exceed the lesser of $10,000 per affected individual or the total amount of economic loss sustained by affected individuals," capped at $500,000 "from a breach or series of related breaches."

Then subsection N: "This article does not apply to" "A covered entity or business associates as defined under regulations implementing the health insurance portability and accountability act of 1996, 45 Code of Federal Regulations section 160.103 (2013)." The Attorney General's own FAQ says the same thing in plain words: entities covered by HIPAA "are exempt." A HIPAA covered entity or business associate in Arizona owes its breach notices under 45 CFR Part 164, Subpart D, not under Title 18.

Two cautions before anyone relaxes. First, the exemption belongs to entities that are covered entities or business associates; a practice's non-HIPAA affiliate, a marketing subsidiary, or an employee benefits operation may be inside the state statute. Second, the federal rule is not softer. Its 60-day ceiling is a ceiling, discovery is defined at 164.404(a)(2) as the day the breach "would have been known" with reasonable diligence, and 164.402 presumes an impermissible disclosure is a breach unless a four-factor risk assessment shows a low probability of compromise.

ObligationFederal HIPAA (applies to Arizona practices)A.R.S. 18-552 (HIPAA entities exempt)
TriggerBreach of unsecured P.H.I. (Protected Health Information), 164.402Confirmed breach of unencrypted, unredacted computerized personal information
Individual notice deadlineNo later than 60 calendar days after discoveryWithin 45 days after the breach determination
Government noticeHHS: contemporaneous if 500 or more; annual log if fewerAttorney General and Department of Homeland Security director if more than 1,000 individuals
Credit bureausNot requiredThree largest nationwide agencies if more than 1,000 individuals
Vendor to clientNo later than 60 days (164.410)As soon as practicable
PenaltyTiers at 45 CFR 160.404 and 102.3Up to the lesser of $10,000 per individual or actual loss; $500,000 cap per breach

The working rule for an Arizona practice: run the federal process from the breach notification guide, write the HIPAA exemption into the incident response plan so nobody rebuilds it around Title 18 during an incident, and have counsel confirm whether any affiliated non-HIPAA entity is inside the state statute.

HIPAA Penalties in Arizona

Federal OCR Penalty Tiers

45 CFR 160.404 sets four culpability tiers, and the amounts are inflation-adjusted each year at 45 CFR 102.3. Under the 2025 adjustment, the per-violation ranges are: $145 to $73,011 where the entity did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect not corrected. The calendar-year cap for identical violations is $2,190,294. OCR has applied a Notice of Enforcement Discretion with lower annual caps for the first three tiers; those figures are not quoted here. The penalty amounts post tracks the numbers.

Arizona State Enforcement

For HIPAA entities the state breach penalties above do not apply. The medical records article is enforced through licensing and civil litigation: A.R.S. 12-2292(B) states that the article "does not limit the effect of any other federal or state law governing the confidentiality of medical records and payment records," and the licensing boards under Title 32 treat records failures as professional conduct matters. The Attorney General's Consumer Fraud Act authority under A.R.S. 44-1522, which the breach statute invokes for non-exempt entities, remains available for deceptive privacy practices generally.

HIPAA Compliance for Arizona Healthcare Providers

Arizona Hospitals and Health Systems

The OCR settlement with an Arizona hospital system following cybersecurity hacking (February 2, 2023) is the local reference point, and the federal Security Rule is where large-system enforcement concentrates: a $950,000 settlement over Security Rule failures (July 1, 2024) and a $1.19 million penalty against Gulf Coast Pain Consultants for Security Rule violations (December 3, 2024) are recent titles. The Arizona layer for a system lives in health information management: the 12-2297 retention schedule with its pediatric extension, the 12-2293 denial procedure, and the 36-664 and 36-509 release lists.

Arizona Dental Practices

A dental office is a covered entity with its first electronic claim; the dental compliance page covers the federal program. Arizona adds the six-year retention rule for adults and the three-years-past-eighteen rule for children, which matters in a pediatric-heavy practice, plus the payment-records confidentiality rule that covers the front desk. OCR's dental enforcement runs to patient access and social media: three right of access cases with dental practices in one announcement (September 20, 2022) and a $10,000 case over social media disclosures of patients' P.H.I. (October 2, 2019).

Arizona Behavioral Health Providers

A.R.S. 36-509 governs behavioral health records, and 42 CFR Part 2 may apply to substance use records. The federal enforcement pattern in this sector is patient access: OCR imposed a $100,000 penalty against a mental health center for failure to provide timely access to patient records (November 19, 2024). The 30-day deadline in 45 CFR 164.524(b)(2) applies to a counseling practice exactly as it applies to a hospital. The behavioral health compliance page covers the program.

Arizona Home Health and Long-Term Care

Home health agencies and nursing care institutions move P.H.I. on phones and paper across long distances. The $3 million OCR settlement over failure to encrypt mobile devices (November 5, 2019) is the sector's warning: encrypted devices fall outside the federal definition of unsecured P.H.I. A.R.S. 12-2297(D) gives nursing care institutions their own six-year retention rule measured from discharge, with the same pediatric extension. Every vendor needs a B.A.A. with a notice deadline written in.

Arizona HIPAA Compliance Checklist

RequirementSourceTimingEvidence to keep
Security risk analysis and risk management planFederal, 164.308(a)(1)Documented; reviewed at least annually in practiceRisk analysis report, remediation plan
Workforce trainingFederal, 164.530(b), 164.308(a)(5)New hires; when policies change; annual in practiceTraining log with dates and names
Signed B.A.A. with every P.H.I. vendorFederal, 164.504(e), 164.314(a)Before access; include a vendor notice deadlineExecuted agreement per vendor
Breach procedure built on the federal rule, with the A.R.S. 18-552(N) exemption notedFederal 164.402 to 164.410; A.R.S. 18-552(N)Letters within 60 days of discovery; HHS contemporaneously at 500 or moreIncident log, risk assessment memo, notice copies, counsel memo on affiliates
Record retention scheduleA.R.S. 12-2297Adults 6 years from last service; children 3 years past 18 or 6 years, whichever later; source data 6 yearsWritten schedule, destruction log
Records release and denial procedureA.R.S. 12-2292, 12-2293; federal 164.524Within 30 days; written explanation on any denialRequest log, denial notes in the record
Communicable disease and mental health release workflowsA.R.S. 36-664, 36-509Before any non-treatment disclosureWritten requests, consent forms, release log

One note on timing. The proposed update to the HIPAA Security Rule, published in January 2025, would add express requirements such as encryption and multifactor authentication. It is a proposal, not current law, and OCR is not enforcing it. Nothing in this guide depends on it.

---

FAQ

Does Arizona's data breach law apply to medical practices?

Not to HIPAA covered entities or business associates. A.R.S. 18-552(N) states that the article does not apply to a covered entity or business associate as defined at 45 CFR 160.103, and the Arizona Attorney General's FAQ says HIPAA-covered entities are exempt. Those organizations follow the federal Breach Notification Rule instead. A non-HIPAA affiliate may still be inside the state statute.

How long must Arizona providers keep medical records?

Under A.R.S. 12-2297, at least six years after the last date of service for an adult, and for a child either three years after the eighteenth birthday or six years after the last service, whichever is later. Source data such as imaging is kept six years from collection. Nursing care institutions keep records six years after discharge. HIPAA separately requires compliance documentation to be kept six years.

How fast must an Arizona practice notify patients after a breach?

Under 45 CFR 164.404(b), without unreasonable delay and no later than 60 calendar days after discovery, with HHS notified contemporaneously for 500 or more individuals. The state's 45-day deadline in A.R.S. 18-552 applies to entities that are not exempt under subsection N.

Can an Arizona provider deny a patient access to records?

Only on the grounds listed in A.R.S. 12-2293, such as a health professional's determination that access is reasonably likely to endanger the life or physical safety of the patient or another person, and the denial must be noted in the record with a written explanation. HIPAA's 45 CFR 164.524 has its own denial grounds and review rights, and the practice must satisfy both.

Who enforces HIPAA in Arizona?

OCR enforces the federal rules and has settled with an Arizona hospital system (February 2, 2023) and with Phoenix Cardiac Surgery (April 13, 2012). Arizona's breach statute is enforced only by the Attorney General and does not reach HIPAA entities; the medical records article is enforced through licensing boards and civil litigation.

Conclusion

The federal program comes first: risk analysis, written policies, workforce training, and signed B.A.A.s. The Arizona layer is a retention schedule, a records-release procedure that matches A.R.S. 12-2293, and a breach plan that knows the state statute steps aside for HIPAA entities. One Guy Consulting's Full-Scope plan builds the federal program and documents the state overlay alongside it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading