A family practice in St. Cloud refers a patient to an orthopedic surgeon across town and faxes over the last two visit notes and the imaging report. Under HIPAA that is a routine treatment disclosure, no authorization needed. Under Minnesota law, unless the two clinics are part of the same related health care entity or the patient signed and dated a consent, the practice has just released a health record without the consent the state requires.
Federal enforcement is the same in Minnesota as anywhere else. OCR (the HHS Office for Civil Rights) settled HIPAA Security Rule failures for $950,000 in a case announced July 1, 2024, one of a long series built on missing risk analyses. The state layer is what makes Minnesota different. Below: how the two layers interact, the state statutes that stack on HIPAA, the breach rules, the penalties, provider-type notes, and a checklist.
HIPAA Compliance Minnesota: How the Federal and State Rules Interact
HIPAA (Health Insurance Portability and Accountability Act) is the floor. Under 45 CFR 160.203, a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. The first test of "more stringent" in 45 CFR 160.202 is a state law that "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted under this subchapter." Minnesota's consent rule survives preemption, and it controls.
Minnesota has three statutes that matter for a practice: the Minnesota Health Records Act (sections 144.291 to 144.298), the hospital records retention statute (145.32), and the general breach notification statute (325E.61). The 2024 Minnesota Consumer Data Privacy Act steps aside for HIPAA entities and health records. The general framework is in state privacy laws vs federal HIPAA.
Who Qualifies as a Covered Entity in Minnesota
Federally, 45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Health systems in the Twin Cities, Rochester, and Duluth, physician groups, dental offices, behavioral health providers, home care agencies, and nursing facilities that bill electronically all qualify; see what is a covered entity under HIPAA.
The Minnesota Health Records Act reaches wider. Under 144.291, subdivision 2(i), a "provider" is any person licensed to furnish health care under the practice acts for physicians, nurses, dentists, pharmacists, psychologists, and other listed professions, plus licensed home care providers, licensed health care facilities, and licensed assisted living facilities. Electronic billing is irrelevant; the license is the trigger. A cash-only therapist who never files a claim is a Minnesota provider with every duty in the act.
Who Qualifies as a Business Associate in Minnesota
The federal definition at 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, plus subcontractors. Each one signs a business associate agreement.
Minnesota adds two state duties for the same vendor. The Health Records Act consent rule in 144.293, subdivision 2 binds "a provider, or a person who receives health records from a provider," so a billing company or transcription vendor holding Minnesota records may not release them without a consent or a specific Minnesota authorization. And under 325E.61, subdivision 1(b), a business that maintains data it does not own "shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery." That is far shorter than the federal 60-day deadline at 45 CFR 164.410.
Minnesota Privacy Laws That Stack on Top of HIPAA
The Minnesota Health Records Act: The Consent Rule
Section 144.293, subdivision 2 is the sentence that changes daily practice: "A provider, or a person who receives health records from a provider, may not release a patient's health records to a person without: (1) a signed and dated consent from the patient or the patient's legally authorized representative authorizing the release; (2) specific authorization in Minnesota law; or (3) a representation from a provider that holds a signed and dated consent from the patient authorizing the release." A "health record" under 144.291 is "any information, whether oral or recorded in any form or medium," about a patient's health, care, or payment.
The exceptions are narrow. Subdivision 5 allows release without consent "for a medical emergency when the provider is unable to obtain the patient's consent," "to other providers within related health care entities when necessary for the current treatment of the patient," and to a licensed facility when a patient is returning to it or resides there and cannot consent. "Related health care entity" means an affiliate of the releasing provider. Two independent clinics are not related, so the referral fax in the opening scene needs a consent. Subdivision 4 makes a consent good for one year unless it says otherwise, and subdivision 6 lets certain consents, such as one covering a consulting provider involved in current treatment, run without expiring if the patient explicitly agrees. Subdivision 9 requires a provider that releases records without consent under a Minnesota exception to document the release in the patient's record. The practical answer for most practices is a Minnesota-compliant consent signed at intake that names the treating team and the consulting relationships the patient expects, alongside the federal HIPAA release form.
The Health Records Act: Access, Copies, and Fees
Section 144.292 gives patients the right to their records and sets the state clock. Under subdivision 2, a provider "shall supply to a patient within 30 calendar days of receiving a written request" complete and current information about diagnosis, treatment, and prognosis, "in terms and language the patient can reasonably be expected to understand," and under subdivision 5 must furnish copies within the same 30 days. Subdivision 6 caps fees: for paper copies, $1 per page plus $10 for retrieval, with totals capped at $30 for up to 25 pages, $50 for up to 100 pages, 20 cents per page beyond that, and $500 for any request; $30 total for X-rays; and $20 total for electronic copies. No fee may be charged when the patient wants the record "for purposes of reviewing current medical care." Subdivision 4 requires a written notice of records practices and rights, satisfied by posting it prominently. The federal 30-day deadline at 45 CFR 164.524(b)(2) and the federal fee limits run alongside; see the right of access guide.
The Health Records Act: Mental Health Provisions
Section 144.294 handles mental health records: on written request of a spouse, parent, child, or sibling, a provider must ask a patient being evaluated for or diagnosed with mental illness whether to authorize that person to receive treatment information; a provider must disclose the minimum necessary to a law enforcement agency responding to a mental health crisis when needed to protect the patient or another person; and a mental health provider may share a defined set of information with a caregiver who lives with or monitors the patient, after a written request and after the patient is informed and does not object. Substance use programs also answer to 42 CFR Part 2.
Section 145.32: Hospital Records Retention
Hospitals must permanently retain the portions of a record that make up the "individual permanent medical record" as defined by the Commissioner of Health, which "includes outpatient diagnostic and laboratory test results." Other portions "may be divested and destroyed after seven years," and records of minors must be kept "for seven years or until the individual reaches the age of majority, whichever occurs last." Retention periods for clinics and individual practitioners are set by their licensing boards and are not stated here. HIPAA's six-year rule at 45 CFR 164.316(b)(2)(i) and 164.530(j)(2) covers policies and compliance documentation, not the chart; see how long to keep medical records.
The Minnesota Consumer Data Privacy Act
Chapter 325O took effect July 31, 2025. It applies to businesses that process personal data of 100,000 or more consumers a year, or 25,000 or more while deriving over 25 percent of revenue from selling it. Under 325O.03, subdivision 2, it does not apply to protected health information under HIPAA, to "health records, as defined in section 144.291," to 42 CFR Part 2 records, or to information intermingled with them that a covered entity, business associate, or Minnesota provider holds. A HIPAA-covered practice can set it aside.
Minnesota Breach Notification Requirements
The federal rule first: 45 CFR 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," 164.408 requires HHS notice at the same time for breaches of 500 or more individuals and an annual log for smaller ones, and 164.406 requires media notice for breaches involving "more than 500 residents of a State or jurisdiction." The walkthrough is in the Breach Notification Rule guide.
The Minnesota Trigger and Clock
Under 325E.61, subdivision 1(d), a breach is "unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information," excluding good faith acquisition by an employee. Personal information under subdivision 1(e) is a name combined with a Social Security number, a driver's license or Minnesota ID number, or an account or card number with its access code, when not encrypted, or when encrypted but the key was also taken. Medical information is not on the list.
The clock under subdivision 1(a): disclosure "must be made in the most expedient time possible and without unreasonable delay," allowing for law enforcement needs and the work of determining scope and restoring the system. No day count is written into the statute. If more than 500 persons must be notified, subdivision 2 requires notice to the nationwide consumer reporting agencies "within 48 hours" of the timing, distribution, and content of the notices. Substitute notice is permitted when the cost would exceed $250,000, more than 500,000 persons are affected, or contact information is missing.
No Attorney General Notice, and No HIPAA Exemption
Two things the statute does not contain: a requirement to notify the Attorney General (the Attorney General enforces the section under 8.31 but is not on the notice list), and an exemption for HIPAA-regulated entities. Subdivision 1(h) deems a business compliant if it follows its own notification procedures "consistent with the timing requirements of this section," so a covered entity that sends its federal letter without unreasonable delay has met the state timing rule; the 48-hour consumer reporting agency notice is the piece the federal rule does not cover.
| Item | Federal HIPAA | Minnesota 325E.61 |
|---|---|---|
| Trigger | Breach of unsecured PHI under 164.402, presumed unless a four-factor risk assessment shows a low probability of compromise | Unauthorized acquisition of unencrypted computerized personal information (or encrypted data plus the key) |
| Data covered | Any P.H.I. (Protected Health Information) | Name plus SSN, license or state ID number, or account number with access code |
| Individual notice | Without unreasonable delay, no later than 60 calendar days after discovery | Most expedient time possible and without unreasonable delay; no day count |
| Regulator notice | HHS, with individual notice if 500 or more; annual log if fewer | None; Attorney General enforces but is not notified by statute |
| Other notices | Media if more than 500 residents of a state | Consumer reporting agencies within 48 hours if more than 500 persons |
| Vendor to owner | Business associate: 60 days (164.410) | Immediately following discovery |
HIPAA Penalties in Minnesota
Federal OCR Enforcement
Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. Context is in the 2026 penalty amounts post.
Minnesota State Remedies
The Health Records Act has teeth of its own. Under 144.298, subdivision 1, a violation "may be grounds for disciplinary action against a provider by the appropriate licensing board." Under subdivision 2, a person who "negligently or intentionally requests or releases a health record" in violation of the act, forges or alters a consent, obtains records under false pretenses, or intentionally accesses a record locator service without authorization "is liable to the patient for compensatory damages caused by an unauthorized release or an intentional, unauthorized access, plus costs and reasonable attorney fees." For the breach statute, the Attorney General enforces under 8.31, which allows a court-determined civil penalty of up to $25,000 per violation plus injunctive relief.
HIPAA Compliance for Minnesota Healthcare Providers
Minnesota Hospitals and Health Systems
Large systems benefit from the "related health care entity" exception, which lets affiliated clinics and hospitals share records for current treatment without a new consent. The exception stops at the system's edge; referrals to unaffiliated specialists need the consent. Section 145.32 governs retention, and the BAA list needs an annual review.
Minnesota Dental Practices
Dentists are providers under 144.291, so the consent rule, the 30-day access clock, and the fee caps apply from the first patient. Sending records to an unaffiliated oral surgeon is a release that needs a signed and dated consent, and billing files carry the Social Security numbers that put a lost unencrypted laptop inside 325E.61.
Minnesota Behavioral Health Providers
Section 144.294's family inquiry duty, crisis disclosure to law enforcement, and caregiver disclosure rules sit on top of the general consent requirement, and substance use programs add 42 CFR Part 2.
Minnesota Home Care and Assisted Living
Licensed home care providers and assisted living facilities are named providers under 144.291, subdivision 2(i), including the facility exception for a returning or resident patient who cannot consent. Field devices carry the breach exposure, and every field vendor needs a BAA and owes the agency immediate state notice after a breach.
Minnesota HIPAA Compliance Checklist
| Requirement | Federal or State | Deadline or Frequency | Documentation |
|---|---|---|---|
| Security risk analysis and risk management | Federal, 164.308(a)(1) | Ongoing; review at least annually | Signed risk analysis, remediation plan |
| Workforce training, including the Minnesota consent rule | Federal, 164.530(b) and 164.308(a)(5); state, 144.293 | New hires, material changes, annual refresh | Completion records |
| BAA with every PHI vendor | Federal, 164.504(e) and 164.314 | Before access; review annually | Signed BAA per vendor |
| Signed and dated release consent | State, 144.293 subd. 2 | Before any release outside the related entity; valid one year unless stated | Consent on file, expiration tracked |
| Records access and copies | State, 144.292; federal, 164.524 | 30 calendar days | Request log with dates |
| Hospital record retention | State, 145.32 | Permanent record permanently; other portions 7 years; minors 7 years or majority | Retention schedule |
| Breach notice to individuals | Federal and state | 60 days federal; most expedient time state | Letters, mailing proof |
| Consumer reporting agency notice | State, 325E.61 subd. 2 | Within 48 hours if more than 500 persons | Notice copies |
A Note on the Proposed Security Rule Update
The January 2025 proposed Security Rule update (explicit encryption, multifactor authentication, asset inventories) is proposed, not final, and OCR is not enforcing it. Minnesota practices have a state reason to encrypt now: under 325E.61, encrypted data without the key is not personal information. This article is educational information, not legal advice; a practice facing a real incident should involve counsel early.
---
FAQ
Does Minnesota have its own HIPAA law?
Yes. The Minnesota Health Records Act (sections 144.291 to 144.298) requires a signed and dated patient consent for most releases of health records, including many treatment disclosures HIPAA would permit, sets a 30-day access deadline with fee caps, and gives patients a private right of action for damages. It applies to every licensed provider whether or not it bills electronically.
Can a Minnesota clinic send records to another provider for treatment without consent?
Only within related health care entities, meaning affiliates of the releasing provider, when necessary for current treatment, or in a medical emergency, or to a licensed facility for a returning or resident patient who cannot consent. A referral to an unaffiliated provider needs a signed and dated consent, or a representation from a provider that holds one.
How quickly must a Minnesota practice report a data breach?
Federal HIPAA requires individual notice without unreasonable delay and no later than 60 calendar days after discovery. Minnesota's 325E.61 requires notice in the most expedient time possible and without unreasonable delay when unencrypted personal information such as Social Security numbers is acquired, plus notice to consumer reporting agencies within 48 hours when more than 500 persons are affected. The statute does not require notice to the Attorney General.
What are the penalties for violating the Minnesota Health Records Act?
Licensing board discipline, and liability to the patient for compensatory damages plus costs and reasonable attorney fees for a negligent or intentional unauthorized release or an intentional unauthorized access, under 144.298. The Attorney General enforces the breach statute under 8.31, which allows civil penalties of up to $25,000 per violation.
Does the Minnesota Consumer Data Privacy Act apply to medical practices?
Not to protected health information, health records as defined in 144.291, or 42 CFR Part 2 records, and not to information intermingled with them that a covered entity, business associate, or Minnesota provider holds. The act took effect July 31, 2025 and applies to businesses that meet consumer-count thresholds for other personal data.
Conclusion
Minnesota is the clearest example of a state that is more stringent than HIPAA on the thing practices do every day, releasing records, and the fix is a consent form that is built into the workflow rather than hunted for afterward. One Guy Consulting's Full-Scope plan builds the federal program and layers the Minnesota consent, access, and breach rules onto it. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.203 (preemption of state law)
- 45 CFR 160.202 (definition of more stringent)
- 45 CFR 160.103 (definitions)
- 45 CFR 164.404 (breach notification to individuals)
- 45 CFR 164.408 (breach notification to the Secretary)
- 45 CFR 164.524 (access of individuals)
- 45 CFR 160.404 (civil money penalty tiers)
- 45 CFR 102.3 (adjusted penalty amounts)
- Minn. Stat. 144.291 (Health Records Act, definitions)
- Minn. Stat. 144.292 (patient rights, access, fees)
- Minn. Stat. 144.293 (release or disclosure of health records)
- Minn. Stat. 144.294 (records relating to mental health)
- Minn. Stat. 144.298 (penalties)
- Minn. Stat. 145.32 (hospital records retention)
- Minn. Stat. 13.384 (medical data held by government entities)
- Minn. Stat. 325E.61 (data warehouses; notice required for certain disclosures)
- Minn. Stat. 8.31 (Attorney General enforcement, civil penalties)
- Minnesota Session Laws 2024, Chapter 121 (Minnesota Consumer Data Privacy Act, chapter 325O)
Related Reading