A patient in Montgomery County asks her orthopedic practice for a copy of her chart. The front desk says the request is "in the queue." The practice is thinking about the federal 30-day access rule, if it is thinking at all. Maryland has a sharper edge: a provider that knowingly refuses to disclose a record within 21 working days is liable for actual damages, and a knowing and willful violation of the state records act is a misdemeanor.
Maryland is also where OCR (the HHS Office for Civil Rights) entered the oldest civil money penalty on its public enforcement list, against Cignet Health of Prince George's County, announced February 4, 2011. Below: how the two layers interact, the state statutes that stack on HIPAA, the breach rules, the penalties, provider-type notes, and a checklist.
HIPAA Compliance Maryland: How the Federal and State Rules Interact
HIPAA (Health Insurance Portability and Accountability Act) is the floor. Under 45 CFR 160.203, a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. 45 CFR 160.202 counts a state law as more stringent when it "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted," gives greater access or amendment rights, or "provides for the retention or reporting of more detailed information or for a longer duration."
Maryland has two statutes that matter. The Confidentiality of Medical Records Act, Health-General Article sections 4-301 through 4-309, is a full state privacy law for medical records with its own disclosure rules, access rules, and penalties. The Personal Information Protection Act (PIPA), Commercial Law Article sections 14-3501 through 14-3508, is the breach and data security law, and it contains a clause that deems a HIPAA-compliant business compliant with PIPA. The general framework is in state privacy laws vs federal HIPAA.
Who Qualifies as a Covered Entity in Maryland
Federally, 45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Hospitals and health systems, physician groups, dental offices, behavioral health providers, home health agencies, and nursing facilities that bill electronically qualify; see what is a covered entity under HIPAA.
Maryland's records act reaches wider. Health-General 4-301 defines "health care provider" by a list of licensed professions and facilities and adds that the term "includes an agent, employee, officer, or director" of any of them. Every licensed provider owes the state confidentiality duty whether or not it bills electronically, and so does every employee personally.
Who Qualifies as a Business Associate in Maryland
The federal definition at 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, plus subcontractors. Each one signs a business associate agreement.
PIPA adds two state duties around the same vendor. Under Commercial Law 14-3503(b), a business that discloses personal information to a nonaffiliated third-party service provider under a written contract "shall require by contract that the third party implement and maintain reasonable security procedures and practices." A business associate agreement with Security Rule terms satisfies that. Under 14-3504(c), a business that maintains data it does not own must notify the owner of a breach "as soon as practicable" and "not later than 10 days" after discovery, and must share information about the breach. That is far faster than the federal 60-day deadline at 45 CFR 164.410.
Maryland Privacy Laws That Stack on Top of HIPAA
The Confidentiality of Medical Records Act (Health-General 4-301 to 4-309)
Section 4-302(a) states the duty: a health care provider "shall keep the medical record of a patient or recipient confidential" and "disclose the medical record only as provided by this subtitle or as otherwise provided by law." Two definitions give the act its reach. "Disclose" under 4-301 includes "an acknowledgment that a medical record on a particular patient or recipient exists," so confirming that someone is a patient is itself a disclosure. And 4-302(e) flatly provides that "a person may not disclose by sale, rental, or barter any medical record,"
Redisclosure. Section 4-302(d): "A person to whom a medical record is disclosed may not redisclose the medical record to any other person" unless the person in interest authorizes it or the subtitle permits it.
Permitted disclosures. Section 4-305 lists what a provider may disclose without authorization: to its own staff for treatment and payment, to another provider "for the sole purpose of treating the patient," to payors for billing and claim review, in emergencies, and to family members or close contacts, limited to information "directly relevant to the individual's involvement in the patient's health care" after the patient has had a chance to object. The list tracks HIPAA's treatment, payment, and operations permission but is narrower in places.
Access. Section 4-304 requires a provider to comply "within a reasonable time" with a written request from a person in interest to receive a copy or to see and copy the record, and 4-309(a) sets the outer limit: a provider "that knowingly refuses to disclose a medical record within a reasonable time but no more than 21 working days" is liable for actual damages. Copy fees are capped at 76 cents per page plus a preparation fee of up to $22.88 and postage; for electronic copies, 75 percent of the per-page fee up to $80, subject to the federal fee limits in 45 CFR 164.524. The federal 30-day deadline runs in parallel; see the right of access guide.
Mental health records. Section 4-307 adds limits for any record "developed in connection with the provision of mental health services": when disclosed without authorization, "only the information in the record relevant to the purpose for which disclosure is sought may be released," and a provider's separately kept "personal note" is outside the medical record entirely.
Retention. Section 4-403 provides that, unless the patient is notified, "a health care provider may not destroy a medical record or laboratory or X-ray report about a patient for 7 years after the record or report is made," and for a minor, until "the patient attains the age of majority plus 7 years." Destruction requires advance notice to the patient with a retrieval window. HIPAA's six-year rule at 45 CFR 164.316(b)(2)(i) and 164.530(j)(2) governs policies and compliance documentation, not the chart; see how long to keep medical records.
The Personal Information Protection Act (Commercial Law 14-3501 to 14-3508)
PIPA is broader than most state breach laws because health information is personal information. Under 14-3501(e), personal information is a name combined with a Social Security number or other government ID, a driver's license or state ID number, a financial account number with its code, "health information, including information about an individual's mental health," a health insurance policy or subscriber number, or biometric data, when not encrypted or redacted. "Health information" means "any information regarding an individual's medical history, medical condition, or medical treatment or diagnosis." Section 14-3503(a) requires "reasonable security procedures and practices that are appropriate to the nature of the personal information" and the size of the business.
The clause that matters most is 14-3507(d)(1): "A business that is subject to and in compliance with the federal Health Insurance Portability and Accountability Act of 1996 shall be deemed to be in compliance with this subtitle." The deeming is conditional. A practice that has skipped its risk analysis, has no policies, or missed a federal breach deadline is not in compliance with HIPAA and cannot claim the PIPA safe harbor. The federal program has to be real.
Maryland Breach Notification Requirements
The federal rule first: 45 CFR 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," 164.408 requires HHS notice at the same time for breaches of 500 or more individuals and an annual log for smaller ones, and 164.406 requires media notice for breaches involving "more than 500 residents of a State or jurisdiction." The walkthrough is in the Breach Notification Rule guide.
The PIPA Trigger and the 45-Day Clock
Under 14-3504(a), a breach is "the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business," excluding good faith acquisition by an employee. On discovery, the business "shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information of the individual has been or will be misused," and must notify the individual unless it "reasonably determines that the breach ... does not create a likelihood that personal information has been or will be misused." If the business decides not to notify, it must keep records of that determination for 3 years.
The clock: notice "shall be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach."
The Attorney General Goes First
Section 14-3504(h) is the rule that trips practices: "Prior to giving the notification required under subsection (b) of this section ... a business shall provide notice of a breach of the security of a system to the Office of the Attorney General." The filing must include the number of affected Maryland residents, a description of the breach "including when and how it occurred," the steps taken or planned, and "the form of notice that will be sent to affected individuals and a sample notice." There is no size threshold.
What the PIPA Notice Must Say
Section 14-3504(g) requires a description of the categories of information acquired, the business's contact information, the numbers of the major consumer reporting agencies, the numbers and websites of the Federal Trade Commission and the Office of the Attorney General, and a statement that those sources explain how to avoid identity theft. One letter can carry those and the federal elements at 164.404(c).
Does the HIPAA Safe Harbor Cover Breach Notice?
Section 14-3507(d) deems a HIPAA-compliant business "in compliance with this subtitle," which includes 14-3504, so a covered entity that follows the federal breach rule correctly has, on the face of the statute, satisfied PIPA. A late or defective federal notice forfeits the safe harbor and revives the 45-day clock and the Attorney General-first rule. Whether to file with the Attorney General regardless is a decision for counsel.
| Item | Federal HIPAA | Maryland PIPA |
|---|---|---|
| Trigger | Breach of unsecured PHI under 164.402, presumed unless a four-factor risk assessment shows a low probability of compromise | Unauthorized acquisition of computerized personal information; notice unless a prompt investigation finds no likelihood of misuse |
| Data covered | Any P.H.I. (Protected Health Information) | Name plus SSN, ID numbers, financial account, health information, health insurance number, or biometric data |
| Individual notice | Without unreasonable delay, no later than 60 calendar days after discovery | As soon as reasonably practicable, no later than 45 days after discovery |
| Regulator notice | HHS, with individual notice if 500 or more; annual log if fewer | Office of the Attorney General, before individuals, any size |
| Vendor to owner | Business associate: 60 days (164.410) | Maintainer: 10 days (14-3504(c)) |
HIPAA Penalties in Maryland
Federal OCR Enforcement
Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. Context is in the 2026 penalty amounts post.
Maryland State Penalties
PIPA violations are unfair or deceptive trade practices under 14-3508, enforced by the Attorney General's Consumer Protection Division. Under Commercial Law 13-410, the civil penalty is up to $10,000 per violation and up to $25,000 for each repeated violation. The records act carries its own set under Health-General 4-309: a knowing and willful violation is a misdemeanor with a fine of up to $1,000 for a first offense and $5,000 for each subsequent conviction; knowingly obtaining a record under false pretenses or knowingly disclosing one in violation of the act is a misdemeanor punishable by up to $50,000 and one year, rising to $100,000 and five years when committed under false pretenses and $250,000 and ten years when done "for commercial advantage, personal gain, or malicious harm." Any knowing violation also makes the provider liable for actual damages, and the 21-working-day refusal rule carries actual damages of its own.
HIPAA Compliance for Maryland Healthcare Providers
Maryland Hospitals and Health Systems
Baltimore's academic centers and the suburban systems around Washington carry the full federal program, the records act for every department, and PIPA for every record with health information in it. Directory information rules under 4-302(c) require telling patients what may be disclosed and letting them restrict it. Review the BAA list annually.
Maryland Dental Practices
A dental office is a covered entity from its first electronic claim and a Maryland health care provider from its first patient. The 21-working-day access limit, the 76-cent copy cap, and the 7-year retention rule all apply, and billing files carry the Social Security numbers that make a lost unencrypted laptop a PIPA event.
Maryland Behavioral Health Providers
Section 4-307 governs every mental health record: relevance-limited disclosures, the personal note exception, and special rules for psychological test data and group therapy records. Programs holding substance use disorder records also answer to 42 CFR Part 2, which 4-302(b) expressly carves out of the state act.
Maryland Home Health and Long-Term Care
Nurses and social workers are named providers under 4-403, so the 7-year retention and destruction notice rules apply to agency records. Field devices with health information on them are inside PIPA, and every field vendor needs a BAA and owes the agency a 10-day state notice after a breach.
Maryland HIPAA Compliance Checklist
| Requirement | Federal or State | Deadline or Frequency | Documentation |
|---|---|---|---|
| Security risk analysis and risk management | Federal, 164.308(a)(1); state, 14-3503(a) reasonable security | Ongoing; review at least annually | Signed risk analysis, remediation plan |
| BAA with security terms for every vendor | Federal, 164.504(e) and 164.314; state, 14-3503(b) | Before access; review annually | Signed BAA per vendor |
| Records access | Federal, 164.524; state, 4-304 and 4-309(a) | 30 days federal; no more than 21 working days state | Request log with dates |
| Redisclosure and no-sale controls | State, 4-302(d) and (e) | Every disclosure | Authorization on file, disclosure log |
| Record retention and destruction notice | State, 4-403 | 7 years; minors to majority plus 7; notice before destruction | Retention schedule, notice copies |
| Breach investigation and decision record | State, 14-3504(b); federal, 164.402 | Promptly; keep no-notice determinations 3 years | Dated investigation memo |
| Attorney General notice | State, 14-3504(h) | Before individual notice, any size (unless HIPAA safe harbor applies) | Filed notice with sample letter |
| Breach notice to individuals | Federal and state | 60 days federal; 45 days state | Letters, mailing proof |
A Note on the Proposed Security Rule Update
The January 2025 proposed Security Rule update (explicit encryption, multifactor authentication, asset inventories) is proposed, not final, and OCR is not enforcing it. Maryland practices have a state reason to encrypt already: PIPA's definition of personal information excludes data that is encrypted. This article is educational information, not legal advice; a practice facing a real incident should involve counsel early.
---
FAQ
Does Maryland have its own HIPAA law?
Yes, in effect. The Confidentiality of Medical Records Act (Health-General 4-301 through 4-309) sets its own confidentiality, disclosure, access, and penalty rules for every licensed provider, and the Personal Information Protection Act (Commercial Law 14-3501 through 14-3508) governs breaches and data security, counting health information as personal information. Federal HIPAA applies in full alongside them.
How quickly must a Maryland practice report a data breach?
Federal HIPAA allows up to 60 calendar days after discovery for individual notice. Maryland's PIPA requires notice as soon as reasonably practicable and no later than 45 days after discovery, and requires notice to the Office of the Attorney General before individuals are notified, with no size threshold. A vendor that maintains data it does not own must tell the owner within 10 days.
Does following HIPAA satisfy Maryland's breach law?
Commercial Law 14-3507(d) deems a business that is subject to and in compliance with HIPAA to be in compliance with PIPA. The safe harbor is conditional on actual compliance, so a practice with no risk analysis or a missed federal deadline cannot rely on it. Many practices notify the Attorney General regardless; that is a decision for counsel.
How long must Maryland providers keep medical records?
Health-General 4-403 bars destroying a medical record or laboratory or X-ray report for 7 years after it is made unless the patient is notified, and for minors until the age of majority plus 7 years. Destruction requires advance notice with a retrieval window.
Who enforces health privacy law in Maryland?
OCR enforces federal HIPAA. The Maryland Attorney General's Consumer Protection Division enforces PIPA, with civil penalties of up to $10,000 per violation and $25,000 for repeat violations. Violations of the medical records act can be prosecuted as misdemeanors with fines up to $250,000 and ten years in the worst cases, and patients may recover actual damages.
Conclusion
Maryland gives a practice a clean deal: run a genuine HIPAA program and PIPA deems the practice compliant, but the Confidentiality of Medical Records Act still has to be met on its own terms, down to the 21-working-day access rule and the 7-year retention clock. One Guy Consulting's Full-Scope plan builds the federal program and maps the Maryland statute onto it. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.203 (preemption of state law)
- 45 CFR 160.202 (definition of more stringent)
- 45 CFR 160.103 (definitions)
- 45 CFR 164.404 (breach notification to individuals)
- 45 CFR 164.408 (breach notification to the Secretary)
- 45 CFR 164.524 (access of individuals)
- 45 CFR 160.404 (civil money penalty tiers)
- 45 CFR 102.3 (adjusted penalty amounts)
- Md. Code, Health-General 4-301 (definitions)
- Md. Code, Health-General 4-302 (confidentiality, redisclosure, no sale)
- Md. Code, Health-General 4-304 (access and copy fees)
- Md. Code, Health-General 4-305 (disclosures without authorization)
- Md. Code, Health-General 4-307 (mental health records)
- Md. Code, Health-General 4-309 (refusal to disclose, penalties)
- Md. Code, Health-General 4-403 (record retention and destruction)
- Md. Code, Commercial Law 14-3501 (PIPA definitions)
- Md. Code, Commercial Law 14-3503 (reasonable security, vendor contracts)
- Md. Code, Commercial Law 14-3504 (breach notification)
- Md. Code, Commercial Law 14-3507 (HIPAA deemed compliance)
- Md. Code, Commercial Law 14-3508 (enforcement)
- Md. Code, Commercial Law 13-410 (civil penalties)
Related Reading