HIPAA Compliance in Michigan: The Statutes That Move the Baseline

Practical guidance for healthcare teams and business associates

A Grand Rapids practice gets a records request from a former patient's attorney: a signed, dated authorization and a demand for the full chart. The front desk quotes a flat "records fee" the practice has charged for years. Under Michigan law that fee is capped, itemized, and waived for some patients, and the clock on the response is set by statute. Under HIPAA a second clock runs alongside it. Most Michigan practices know one of these clocks. Few know both.

Michigan is unusual in one respect: its breach notification statute says a person that complies with HIPAA "is considered to be in compliance with this section." That single sentence leads many practices to assume state law has nothing to add. The Public Health Code, the Mental Health Code, and the Medical Records Access Act say otherwise. OCR (the HHS Office for Civil Rights), for its part, imposed a $100,000 penalty against a mental health center for failure to provide timely access to patient records (November 19, 2024), and settled a $4.75 million malicious insider cybersecurity investigation (February 6, 2024). Neither title names a state; both describe failures that happen in Michigan offices every week.

This guide covers the federal floor, the Michigan statutes that stack on top of it, the breach law and its HIPAA clause, the penalties on both sides, and what it all means for hospitals, dental offices, behavioral health practices, and home health agencies.

HIPAA Compliance Michigan: How the Federal and State Rules Interact

HIPAA (the Health Insurance Portability and Accountability Act) sets a floor. 45 CFR 160.203 states the general rule: a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," then lists the exceptions. Paragraph (b) preserves state law that "relates to the privacy of individually identifiable health information and is more stringent than" the federal Privacy Rule. 45 CFR 160.202 defines "more stringent" to include state law that "permits greater rights of access or amendment" and law that provides "for the retention or reporting of more detailed information or for a longer duration."

Michigan's record retention and records access statutes are exactly that kind of law. Where Michigan is stricter, Michigan wins. Where HIPAA is stricter, HIPAA wins. A Michigan covered entity meets both at once.

Who Is a Covered Entity in Michigan

The definition is federal. 45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Every Michigan hospital, physician group, dental office, behavioral health practice, pharmacy, home health agency, and nursing facility that bills electronically qualifies.

Who Is a Business Associate in Michigan

Also federal. A business associate under 160.103 is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing." Each needs a signed B.A.A. (Business Associate Agreement); the BAA guide lists the required terms. Michigan's Medical Records Access Act adds its own category, the "medical records company," which is bound by the same access and fee rules as the provider it serves.

Michigan Statutes That Stack on Top of HIPAA

Record Retention: 7 Years (MCL 333.16213 and 333.20175)

HIPAA sets no retention period for the chart; it requires that policies and required documentation be kept "for 6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i) and 164.530(j)(2)). Michigan sets the chart period by statute. Under MCL 333.16213(2), a licensee "shall keep and retain each record" "for a minimum of 7 years from the date of service to which the record pertains," unless a longer period is required elsewhere. MCL 333.20175 imposes the same 7-year minimum on health facilities and agencies. A recent amendment to both sections extends the period to 15 years for records of certain services involving intimate examinations, with listed exceptions; read the amended text before setting a schedule. The record retention guide covers the federal-versus-state split.

The Medical Records Access Act (MCL 333.26261 to 333.26271)

This 2004 act governs how patients and their authorized representatives get copies. Three provisions change day-to-day practice:

  • The request. Under MCL 333.26265(2), the request must be "signed and dated by that individual not more than 60 days before being submitted." A stale authorization can be refused.
  • The response clock. The provider must act "as promptly as required under the circumstances, but not later than 30 days after receipt of the request or if the medical record is not maintained or accessible on-site not later than 60 days after receipt of the request." HIPAA's own clock at 45 CFR 164.524(b)(2) is 30 days with one 30-day extension on written notice; the two run together, and the practice satisfies both by treating 30 days as the deadline.
  • Fees. MCL 333.26269 caps charges at "an initial fee of $20.00 per request," then "One dollar per page for the first 20 pages," "Fifty cents per page for pages 21 through 50," and "Twenty cents for pages 51 and over," plus actual costs for non-paper media, postage, and retrieval of records "7 years old or older and not maintained or accessible on-site." The act adjusts the figures by the Detroit consumer price index. Fees "shall" be waived for a medically indigent individual, one set of copies per provider. HIPAA's fee limit at 164.524(c)(4) also applies to a patient's own request, and the lower figure governs.

OCR enforces the federal access rule aggressively; the Right of Access post in Related Reading covers that side.

HIV Records (MCL 333.5131)

"All reports, records, and data pertaining to testing, care, treatment, reporting, and research" associated with HIV infection "are confidential," and may be released "only pursuant to this section." Court-ordered disclosure requires a finding that other means are unavailable and that "the public interest and need for the disclosure outweigh the potential for injury to the patient." Subsection (8) sets the penalty: a misdemeanor "punishable by imprisonment for not more than 1 year or a fine of not more than $5,000.00, or both," plus civil liability "for actual damages or $1,000.00, whichever is greater, and costs and reasonable attorney fees." The same subsection reaches the employer "unless the employer had in effect at the time of the violation reasonable precautions designed to prevent the violation." Written policies and training are those precautions.

Mental Health Records (MCL 330.1748)

Under the Mental Health Code, "Information in the record of a recipient, and other information acquired in the course of providing mental health services to a recipient, shall be kept confidential and is not open to public inspection," and may be disclosed outside the holder only under the conditions in that section and section 748a. When it is disclosed, "the identity of the individual to whom it pertains shall be protected and shall not be disclosed unless it is germane to the authorized purpose." An adult recipient's own request for records must be met "as expeditiously as possible but in no event later than the earlier of 30 days after receipt of the request or, if the recipient is receiving treatment from the holder of the record, before the recipient is released from treatment." Substance use disorder programs may also be under 42 CFR Part 2.

Michigan Breach Notification: The HIPAA Clause and What It Does Not Cover

The federal rule first. 45 CFR 164.404(b) requires notice to affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." A breach involving 500 or more individuals goes to HHS "contemporaneously" with the individual notice (164.408(b)); smaller breaches are logged and reported "not later than 60 days after the end of each calendar year" (164.408(c)); a breach involving "more than 500 residents of a State or jurisdiction" also goes to prominent media serving that state (164.406(a)). A business associate has the same 60-day ceiling to notify the covered entity (164.410(b)).

Michigan's Identity Theft Protection Act, MCL 445.72, requires a person that owns or licenses data in a database to notify each affected Michigan resident "without unreasonable delay" when unencrypted personal information "was accessed and acquired by an unauthorized person," unless the person determines the breach "has not or is not likely to cause substantial loss or injury to, or result in identity theft." Personal information under MCL 445.63 means a name linked to a Social Security number, a driver's license or state ID number, or a financial account or card number with its access code; medical information is not on the list. Notice to more than 1,000 residents also triggers notice to the nationwide consumer reporting agencies. There is no Attorney General notice requirement in the section.

Then the clause everyone quotes, subsection (10): "A person or agency that is subject to and complies with the health insurance portability and accountability act of 1996, Public Law 104-191, and with regulations promulgated under that act, 45 CFR parts 160 and 164, for the prevention of unauthorized access to customer information and customer notice is considered to be in compliance with this section." Read the conditions. The safe harbor belongs to a person that "complies with" the federal rules. A practice with no risk analysis, no breach procedure, and a late notice is not complying, and the clause does not shelter it. The way to earn the Michigan safe harbor is to run the federal breach process from the breach notification guide and document it.

ObligationFederal HIPAAMichigan (MCL 445.72)
TriggerBreach of unsecured P.H.I. (Protected Health Information), 164.402Unauthorized access and acquisition of unencrypted personal information likely to cause loss, injury, or identity theft
Individual notice deadlineNo later than 60 calendar days after discoveryWithout unreasonable delay
Government noticeHHS: contemporaneous if 500 or more; annual log if fewerNone to the Attorney General
Credit bureausNot requiredNationwide agencies if more than 1,000 residents
Vendor to clientNo later than 60 days (164.410)Without unreasonable delay (subsection (2))
HIPAA clauseNot applicableEntity that complies with 45 CFR Parts 160 and 164 is deemed compliant (subsection (10))

HIPAA Penalties in Michigan

Federal OCR Penalty Tiers

45 CFR 160.404 sets four culpability tiers, and the amounts are inflation-adjusted each year at 45 CFR 102.3. Under the 2025 adjustment, the per-violation ranges are: $145 to $73,011 where the entity did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect not corrected. The calendar-year cap for identical violations is $2,190,294. OCR has applied a Notice of Enforcement Discretion with lower annual caps for the first three tiers; those figures are not quoted here. The penalty amounts post tracks the numbers.

Michigan State Enforcement

Under MCL 445.72(13), a person that "knowingly fails to provide any notice of a security breach required under this section may be ordered to pay a civil fine of not more than $250.00 for each failure to provide notice," an action "the attorney general or a prosecuting attorney may bring." Subsection (14) caps aggregate fines from one breach at $750,000.00. The HIV statute carries its own criminal and civil penalties, described above, and the Mental Health Code and Medical Records Access Act are enforced through licensing and civil actions. Subsection (15) preserves "any civil remedy for a violation of state or federal law," so the fine schedule does not cap a negligence suit.

HIPAA Compliance for Michigan Healthcare Providers

Michigan Hospitals and Health Systems

Systems already run federal programs. The Michigan layer lands in health information management: the 7-year (and where applicable 15-year) retention schedule under 333.20175, the 30-day and 60-day response clocks and fee caps of the Medical Records Access Act, and the HIV and mental health consent workflows. The $950,000 OCR settlement over Security Rule failures (July 1, 2024) and the $4.75 million malicious insider settlement (February 6, 2024) are the federal reference points for large organizations.

Michigan Dental Practices

A dental office is a covered entity with its first electronic claim; the dental compliance page covers the federal program. The state adds the 7-year retention rule for licensees and the Medical Records Access Act fee caps, which replace the flat records fee many offices still charge. OCR's dental enforcement runs to patient access and social media: it settled three right of access cases with dental practices in one announcement (September 20, 2022) and a $10,000 case over social media disclosures of patients' P.H.I. (October 2, 2019).

Michigan Behavioral Health Providers

MCL 330.1748 governs confidentiality for community mental health programs, licensed facilities, and contract providers, with its own 30-day access rule for adult recipients; 42 CFR Part 2 may apply to substance use records. OCR's $100,000 penalty against a mental health center for failure to provide timely access (November 19, 2024) shows the federal enforcement pattern. The behavioral health compliance page covers the program.

Michigan Home Health and Long-Term Care

Home health agencies and nursing facilities move P.H.I. on phones and paper across counties. The $3 million OCR settlement over failure to encrypt mobile devices (November 5, 2019) is the sector's warning. Encryption keeps a lost device out of the federal definition of unsecured P.H.I. and out of Michigan's "unencrypted and unredacted" trigger. Every vendor on the agency's list needs a B.A.A. with a notice deadline written in.

Michigan HIPAA Compliance Checklist

RequirementSourceTimingEvidence to keep
Security risk analysis and risk management planFederal, 164.308(a)(1)Documented; reviewed at least annually in practiceRisk analysis report, remediation plan
Workforce trainingFederal, 164.530(b), 164.308(a)(5)New hires; when policies change; annual in practiceTraining log with dates and names
Signed B.A.A. with every P.H.I. vendorFederal, 164.504(e), 164.314(a)Before access; include a vendor notice deadlineExecuted agreement per vendor
Breach procedure documented and followed (earns the MCL 445.72(10) safe harbor)Federal 164.402 to 164.410; MCL 445.72Letters within 60 days; credit bureaus if more than 1,000 residentsIncident log, risk assessment memo, notice copies
Record retention scheduleMCL 333.16213, 333.201757 years from date of service; 15 years where the amendment appliesWritten schedule, destruction log
Records request procedure with state fee capsMCL 333.26265, 333.26269; federal 164.524Respond within 30 days (60 if off-site)Request log, fee schedule, indigent waiver policy
HIV and mental health release workflowsMCL 333.5131, 330.1748Before any non-treatment disclosureConsent forms, release log, written precautions policy

One note on timing. The proposed update to the HIPAA Security Rule, published in January 2025, would add express requirements such as encryption and multifactor authentication. It is a proposal, not current law, and OCR is not enforcing it. Nothing in this guide depends on it.

---

FAQ

Does HIPAA compliance satisfy Michigan's breach notification law?

For a practice that actually complies with 45 CFR Parts 160 and 164, yes: MCL 445.72(10) deems such a person in compliance with the state breach section. The clause does not cover the Public Health Code, the Mental Health Code, or the Medical Records Access Act, and it does not protect a practice whose federal program is missing.

How long must Michigan providers keep medical records?

A minimum of 7 years from the date of service under MCL 333.16213 (licensees) and 333.20175 (facilities), with a 15-year period for certain records involving intimate examinations under a recent amendment. HIPAA separately requires compliance documentation to be kept six years.

How fast must a Michigan provider respond to a records request?

Not later than 30 days after receipt under MCL 333.26265, or 60 days if the record is not maintained on-site. HIPAA's 45 CFR 164.524(b)(2) also allows 30 days with one 30-day extension on written notice. Treat 30 days as the deadline.

What can a Michigan provider charge for copies of records?

Under MCL 333.26269, an initial fee of $20 per request, $1 per page for the first 20 pages, 50 cents for pages 21 through 50, 20 cents for pages 51 and over, plus actual costs for non-paper media, postage, and retrieval of off-site records 7 years or older, adjusted by the Detroit consumer price index. Fees are waived for medically indigent patients. HIPAA's fee limit also applies to a patient's own request.

Who enforces HIPAA in Michigan?

OCR enforces the federal rules. The Michigan Attorney General or a prosecuting attorney may seek civil fines of up to $250 per failure to notify under MCL 445.72(13), capped at $750,000 per breach. The HIV confidentiality statute carries criminal and civil penalties of its own, and the licensing boards enforce the records statutes.

Conclusion

The federal program comes first: risk analysis, written policies, workforce training, and signed B.A.A.s. The Michigan layer is a retention schedule, a records-request procedure with the state fee caps, and consent workflows for HIV and mental health records. One Guy Consulting's Full-Scope plan builds the federal program and documents the state overlay alongside it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading