A physical therapy group in Colorado Springs discovers that a former front desk employee's login still works, four months after she left. Someone has been using it. The federal rule gives the practice 60 days from discovery to notify patients. Colorado gives it 30 days from the moment it determines a breach occurred, and if 500 or more Coloradans are affected, the Attorney General gets a filing inside the same 30 days.
OCR (the HHS Office for Civil Rights) has been to Colorado before. Its public enforcement list includes a December 11, 2018 settlement titled "Colorado hospital failed to terminate former employee's access to electronic protected health information," and a $548,265 penalty against Children's Hospital Colorado for HIPAA Privacy and Security Rules violations, announced December 5, 2024. This article covers how federal and state rules interact, who is a covered entity or business associate in Colorado, the state statutes that stack on HIPAA, the breach rules with their 30-day clock, the penalties, provider-type notes, and a checklist.
HIPAA Compliance Colorado: How the Federal and State Rules Interact
HIPAA (Health Insurance Portability and Accountability Act) is the floor. Under 45 CFR 160.203, a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. 45 CFR 160.202 counts a state law as more stringent when, among other things, it "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted" or "provides for the retention or reporting of more detailed information or for a longer duration."
Colorado's approach is unusual in one respect. Its breach statute, C.R.S. 6-1-716, says outright that when a regulated entity's federal rules and the state rule set different deadlines for notifying individuals, "the law or regulation with the shortest time frame for notice to the individual controls." The broader framework is in state privacy laws vs federal HIPAA.
Who Qualifies as a Covered Entity in Colorado
Federally, 45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Hospitals, physician groups, dental offices, behavioral health providers, home health agencies, and nursing facilities that bill electronically all qualify. The test is explained in what is a covered entity under HIPAA.
A terminology trap: Colorado's breach and data security statutes also use the phrase "covered entity," and they mean something different. Under 6-1-716(1)(b), a covered entity is any "person ... that maintains, owns, or licenses personal information in the course of the person's business, vocation, or occupation." Every practice, HIPAA-covered or not, is a Colorado covered entity for breach purposes.
Who Qualifies as a Business Associate in Colorado
The federal definition at 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, plus subcontractors. Each one signs a business associate agreement.
Colorado calls the same vendor a "third-party service provider," meaning "an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity." Two state duties attach. Under 6-1-716(2)(b), the provider must notify the practice of a breach "in the most expedient time possible, and without unreasonable delay following discovery," and cooperate. Under 6-1-713.5(2), the practice must require the provider by contract to "implement and maintain reasonable security procedures and practices" appropriate to the data. A HIPAA business associate agreement, which already carries security terms under 45 CFR 164.314, covers that requirement if it is signed.
Colorado Privacy Laws That Stack on Top of HIPAA
C.R.S. 6-1-716: Notification of Security Breach
Colorado's breach statute counts medical information as personal information. Under 6-1-716(1)(g), personal information is a resident's first name or initial and last name combined with a Social Security number, a student, military, or passport identification number, a driver's license or ID card number, "medical information," a health insurance identification number, or biometric data, when not encrypted or redacted. "Medical information" means "any information about a consumer's medical or mental health treatment or diagnosis by a health-care professional." A breach of diagnoses alone, which triggers HIPAA, also triggers the Colorado statute.
C.R.S. 6-1-713 and 6-1-713.5: Disposal and Reasonable Security
Section 6-1-713 requires every covered entity that keeps paper or electronic documents with personal identifying information to "develop a written policy for the destruction or proper disposal" of them, by "shredding, erasing, or otherwise modifying" the information to make it unreadable. Section 6-1-713.5 requires "reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business." Both sections say an entity regulated by state or federal law that follows its regulator's rules "is in compliance." A practice with a documented Security Rule program, including the media disposal standard at 45 CFR 164.310(d)(2)(i), satisfies both by reference.
C.R.S. 6-1-1301 and Following: The Colorado Privacy Act
The state consumer privacy act applies to controllers that process personal data of 100,000 or more consumers a year, or 25,000 or more while earning revenue from selling personal data, and, from July 1, 2025, to any controller that processes biometric identifiers. Under 6-1-1304(2), it "does not apply to" protected health information "collected, stored, and processed by a covered entity or its business associates," health care information governed by the patient records statutes in Title 25, or 42 CFR Part 2 records. A HIPAA-covered practice can set the act aside for its PHI; a practice that runs a fingerprint time clock for staff should have counsel look at the biometric provision.
C.R.S. 25-1-801 and 25-1-802: Patient Records
These sections are Colorado's patient access rules, and they lean on HIPAA rather than replace it. Records in the custody of a facility (25-1-801) or an individual practitioner (25-1-802) "must be available to the patient or the patient's personal representative" for inspection "at reasonable times and upon reasonable notice," except records withheld in accordance with 45 CFR 164.524(a). Copies go to the patient "upon request and payment of the fee a covered entity may impose in accordance with" HIPAA, and must be delivered "in electronic format if the person requests electronic format, the original medical records are stored in electronic format, and the medical records are readily producible in electronic format." Inspection is free. Third parties with a HIPAA-compliant authorization, subpoena, or court order pay "reasonable fees," capped at $18.53 for the first ten pages, $0.85 per page for the next thirty, and $0.57 per page after that, plus postage. The federal access rules are in the right of access guide.
C.R.S. 27-65-123: Behavioral Health Records
Records created in providing services under the state's behavioral health article are "confidential and privileged matter" and "may be disclosed only" in the situations the section lists: between qualified professionals and facilities in providing services, to persons the recipient designates, for claims, under court order, and, in limited form, to family members and lay caregivers actively participating in treatment. That is narrower than HIPAA's treatment, payment, and operations permission. Programs holding substance use disorder records also answer to 42 CFR Part 2, covered in 42 CFR Part 2 vs HIPAA.
Record Retention
Colorado does not set a physician record retention period by statute; the Medical Board and hospital licensing regulations handle it, and those periods are not stated here. HIPAA's six-year rule at 45 CFR 164.316(b)(2)(i) covers compliance documentation, not the chart; see how long to keep medical records.
Colorado Breach Notification Requirements
The federal rule first: 45 CFR 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," 164.408 requires HHS notice at the same time for breaches of 500 or more individuals and an annual log for smaller ones, and 164.406 requires media notice for breaches involving "more than 500 residents of a State or jurisdiction." The walkthrough is in the Breach Notification Rule guide.
The Colorado Trigger and the 30-Day Clock
Under 6-1-716(1)(h), a security breach is "the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information." Encrypted data counts if the key "was also acquired or was reasonably believed to have been acquired." When a practice "becomes aware that a security breach may have occurred," it must "conduct in good faith a prompt investigation to determine the likelihood that personal information has been or will be misused," and must notify residents unless the investigation "determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur."
The clock: notice "must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred." "Determination" means "the point in time at which there is sufficient evidence to conclude that a security breach has taken place."
Attorney General and Consumer Reporting Agency Notice
Under 6-1-716(2)(f), if the breach "is reasonably believed to have affected five hundred Colorado residents or more," the practice must notify the Colorado Attorney General "not later than thirty days after the date of determination." The Attorney General's office takes these through its online Data Breach Reporting Form and answers questions at databreach@coag.gov. If more than 1,000 residents must be notified, 6-1-716(2)(d) adds notice to the nationwide consumer reporting agencies of the anticipated date and approximate number.
What the Colorado Notice Must Say
Section 6-1-716(2)(a.2) requires the date or estimated date range of the breach, a description of the personal information acquired, contact information for the practice, the numbers and websites of the consumer reporting agencies and the Federal Trade Commission, and a statement about fraud alerts and security freezes. One letter can carry those and the federal elements at 164.404(c).
Does Following HIPAA Satisfy Colorado?
Partly, and this is where Colorado is blunt. Under 6-1-716(3)(b), an entity regulated by state or federal law that follows its regulator's breach procedures "is in compliance with this section; except that notice to the attorney general is still required pursuant to subsection (2)(f)." And then: "In the case of a conflict between the time period for notice to individuals that is required pursuant to this subsection (3) and the applicable state or federal law or regulation, the law or regulation with the shortest time frame for notice to the individual controls." For a Colorado practice, the individual notice deadline is 30 days from determination, not 60 from discovery, and the Attorney General filing stays regardless.
| Item | Federal HIPAA | Colorado 6-1-716 |
|---|---|---|
| Trigger | Breach of unsecured PHI under 164.402, presumed unless a four-factor risk assessment shows a low probability of compromise | Unauthorized acquisition of unencrypted personal information; notice unless a prompt good-faith investigation finds misuse has not occurred and is not reasonably likely |
| Data covered | Any P.H.I. (Protected Health Information) | Name plus SSN, ID numbers, medical information, health insurance ID, or biometric data; also username plus password |
| Individual notice | Without unreasonable delay, no later than 60 calendar days after discovery | Most expedient time possible, no later than 30 days after determination; shortest deadline controls |
| Regulator notice | HHS, with individual notice if 500 or more; annual log if fewer | Attorney General within 30 days if 500 or more residents |
| Other notices | Media if more than 500 residents of a state | Consumer reporting agencies if more than 1,000 residents |
| Substitute notice | Website or media posting when contact information is missing for 10 or more | Cost over $250,000, more than 250,000 residents, or no contact information |
HIPAA Penalties in Colorado
Federal OCR Enforcement
Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. Context is in the 2026 penalty amounts post.
Colorado Attorney General Enforcement
Under 6-1-716(4), the Attorney General "may bring an action in law or equity to address violations of this section, section 6-1-713, or section 6-1-713.5," and may recover "direct economic damages resulting from a violation." The breach statute sits inside the Colorado Consumer Protection Act, whose civil penalty section, 6-1-112, allows "not more than twenty thousand dollars for each such violation," with each affected consumer or transaction counting as a separate violation, and up to $50,000 when the violation was committed against an elderly person. Whether a breach notice failure is charged under that section is a question for counsel.
HIPAA Compliance for Colorado Healthcare Providers
Colorado Hospitals and Health Systems
Health systems along the Front Range carry the full federal program plus the 25-1-801 posting and admission-packet rules. Breaches at this scale almost always clear the 500-resident line, so the Attorney General filing should be a pre-drafted template, and the BAA list needs an annual review.
Colorado Dental Practices
A dental office is a covered entity from its first electronic claim, and a Colorado covered entity for breach purposes from its first patient. Billing files carry the Social Security numbers and insurance IDs that put a lost laptop squarely inside 6-1-716, so device encryption is the control that matters most.
Colorado Behavioral Health Providers
Providers under the behavioral health article live with the 27-65-123 disclosure list, which is narrower than HIPAA's treatment permission, mental health treatment or diagnosis is "medical information" under the breach statute, and substance use programs add 42 CFR Part 2.
Colorado Home Health and Long-Term Care
Field devices are the exposure: encrypted data without the key is not a breach, so full-disk encryption on every phone and laptop is the difference between a lost device and a 30-day notification project. Every field vendor is a third-party service provider under state law and a business associate under federal law; both roles need the contract.
Colorado HIPAA Compliance Checklist
| Requirement | Federal or State | Deadline or Frequency | Documentation |
|---|---|---|---|
| Security risk analysis and risk management | Federal, 164.308(a)(1) | Ongoing; review at least annually | Signed risk analysis, remediation plan |
| Written disposal policy | State, 6-1-713; federal, 164.310(d)(2) | In place; follow at every disposal | Policy, destruction log |
| Vendor contracts with security terms | State, 6-1-713.5(2); federal, 164.314 and 164.504(e) | Before access; review annually | Signed BAA per vendor |
| Breach determination and investigation | State, 6-1-716(2)(a); federal, 164.402 risk assessment | Promptly on awareness | Dated investigation memo, four-factor assessment |
| Breach notice to individuals | State and federal | 30 days from determination (shortest controls) | Letters, mailing proof |
| Attorney General notice | State, 6-1-716(2)(f) | 30 days if 500 or more residents | Data Breach Reporting Form confirmation |
| Consumer reporting agency notice | State, 6-1-716(2)(d) | If more than 1,000 residents | Notice copies |
| Patient records access | State, 25-1-801 and 802; federal, 164.524 | 30 days federal; reasonable notice state; electronic if requested | Request log |
A Note on the Proposed Security Rule Update
The January 2025 proposed Security Rule update (explicit encryption, multifactor authentication, asset inventories) is proposed, not final, and OCR is not enforcing it. Colorado practices already have a state reason to encrypt: encrypted data with the key intact is outside the state breach definition, and the 30-day clock does not wait. This article is educational information, not legal advice; a practice facing a real incident should involve counsel early.
---
FAQ
Does Colorado have its own HIPAA law?
Not a health privacy act as such. Colorado stacks a breach statute that counts medical information as personal information (C.R.S. 6-1-716), a written disposal policy requirement (6-1-713), a reasonable security requirement with vendor contract terms (6-1-713.5), patient access rules (25-1-801 and 25-1-802), and behavioral health confidentiality (27-65-123) on top of federal HIPAA, which still applies in full.
How quickly must a Colorado practice report a data breach?
Federal HIPAA allows up to 60 calendar days after discovery. Colorado requires notice to residents in the most expedient time possible and no later than 30 days after the date the practice determines a breach occurred, and the statute says the shortest deadline controls. If 500 or more Colorado residents are affected, the Attorney General must be notified within the same 30 days.
Does following HIPAA satisfy Colorado's breach law?
Only in part. C.R.S. 6-1-716(3)(b) deems a federally regulated entity that follows its regulator's procedures compliant, except that notice to the Attorney General is still required, and when the federal and state individual notice deadlines conflict, the shorter one controls. For a HIPAA covered entity that means 30 days from determination.
What does the Colorado Privacy Act mean for a medical practice?
Under 6-1-1304(2), the act does not apply to protected health information collected, stored, and processed by a HIPAA covered entity or its business associates, or to health care information governed by the Title 25 patient records statutes. A practice that collects biometric identifiers for other purposes, such as staff time clocks, should have counsel review the biometric provisions that took effect July 1, 2025.
Who enforces health privacy law in Colorado?
OCR enforces federal HIPAA. The Colorado Attorney General enforces the breach, disposal, and security statutes and may seek direct economic damages; the Consumer Protection Act's civil penalty section allows up to $20,000 per violation. The Attorney General's office receives breach reports through its online Data Breach Reporting Form.
Conclusion
In Colorado the federal program is the foundation and the state layer is mostly about speed: a 30-day clock, an Attorney General filing, and a shortest-deadline-wins rule that only works when the incident process is already written down. One Guy Consulting's Full-Scope plan builds that program and maps the Colorado deadlines onto it. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.203 (preemption of state law)
- 45 CFR 160.202 (definition of more stringent)
- 45 CFR 160.103 (definitions)
- 45 CFR 164.404 (breach notification to individuals)
- 45 CFR 164.408 (breach notification to the Secretary)
- 45 CFR 160.404 (civil money penalty tiers)
- 45 CFR 102.3 (adjusted penalty amounts)
- Colorado Revised Statutes 2024, Title 6 (Office of Legislative Legal Services PDF: 6-1-112, 6-1-713, 6-1-713.5, 6-1-716, 6-1-1304)
- Colorado Revised Statutes 2024, Title 25 (25-1-801 and 25-1-802, patient records)
- Colorado Revised Statutes 2024, Title 27 (27-65-123, behavioral health records)
- Colorado Attorney General: Consumer Data Protection Laws FAQ and Data Breach Reporting Form
Related Reading