HIPAA Compliance in New Jersey: What State Law Adds On Top

Practical guidance for healthcare teams and business associates

A practice manager in Bergen County gets the call every compliance consultant dreads: a billing laptop is missing, it was not encrypted, and it held a spreadsheet with patient names and Social Security numbers. The federal clock starts. What most New Jersey offices do not know is that a second clock starts at the same moment, and that one puts the State Police first in line.

Federal enforcement in the state is real. OCR (the HHS Office for Civil Rights) imposed a civil money penalty on a New Jersey nursing facility for failing to provide timely access to patient records (April 1, 2024), and reached an agreement with a New Jersey health care provider that disclosed patient information in response to negative online reviews (June 5, 2023).

This guide covers the federal floor, the New Jersey statutes that stack on top of it, the two breach clocks, the penalties on each side, and what it all means for hospitals, dental offices, behavioral health practices, and home health agencies.

HIPAA Compliance New Jersey: How the Federal and State Rules Interact

HIPAA (the Health Insurance Portability and Accountability Act) sets a national floor, not a ceiling. 45 CFR 160.203 states the general rule: a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," and then lists the exceptions. The one that matters most for practices is paragraph (b): state law survives when it "relates to the privacy of individually identifiable health information and is more stringent than" the federal Privacy Rule.

In plain words: where New Jersey is stricter, New Jersey wins. Where HIPAA is stricter, HIPAA wins. A New Jersey covered entity has to satisfy both at once, and the state has not written a HIPAA carve-out into its breach statute.

Who Is a Covered Entity in New Jersey

The definition is federal and does not change at the state line. 45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." In New Jersey that sweeps in hospitals, physician groups, dental and behavioral health practices, pharmacies, home health agencies, nursing facilities, and any solo practitioner who bills insurance electronically.

Who Is a Business Associate in New Jersey

Also federal. 160.103 defines a business associate as a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing." Billing companies, EHR vendors, cloud hosts, IT firms with system access, answering services, shredding companies, and their subcontractors. Each needs a signed B.A.A. (Business Associate Agreement); the BAA guide covers the required terms. New Jersey's breach statute does not use the term; it applies to any "business," however organized, that holds residents' personal information, with or without a B.A.A.

New Jersey Privacy Statutes That Stack on Top of HIPAA

New Jersey has no single comprehensive health privacy code the way California or Texas does. It has narrower statutes, and each adds something the federal rule does not require.

The Identity Theft Prevention Act (N.J.S.A. 56:8-161 to 56:8-166)

Enacted as P.L.2005, c.226 and effective January 1, 2006, this is the state's breach notification and data-handling law. Three provisions apply to every practice, breach or no breach:

  • Record destruction (56:8-162). Records containing personal information that are no longer retained must be destroyed "by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable, undecipherable or nonreconstructable through generally available means." A disposal standard with the force of state law, and it applies to paper.
  • Social Security number handling (56:8-164). No entity may publicly post an individual's Social Security number, print it on a mailed document unless law requires it, print it on any card used to access services, require it to be sent over an unsecured internet connection, or use it alone as a website login.
  • Breach notification (56:8-163). Covered in its own section below.

The statute's definition of personal information is narrower than HIPAA's definition of P.H.I. (Protected Health Information). It means a first name or initial and last name linked with a Social Security number, a driver's license or state identification number, or an account or card number with the code that would permit access to the account. A clinical note with no identifier from that list is P.H.I. under HIPAA and not "personal information" under the New Jersey act. A billing file with Social Security numbers is both.

The New Jersey Data Privacy Act (N.J.S.A. 56:8-166.4 et seq.)

P.L.2023, c.266 was approved January 16, 2024 and took effect on the 365th day after enactment, which put it in force in January 2025. Section 10 states that nothing in the act "shall apply to" "protected health information collected by a covered entity or business associate subject to the privacy, security, and breach notification rules" of 45 CFR Parts 160 and 164.

Read that carefully. It exempts the data, not the organization. Website analytics, an email list, or a marketing pixel aimed at people who are not patients is personal data that is not P.H.I., and the act's thresholds (personal data of at least 100,000 consumers, or 25,000 consumers plus revenue from selling personal data) decide whether the act reaches it. Most solo practices fall below the thresholds; groups with a marketing arm should ask counsel. The Attorney General has "sole and exclusive authority" to enforce the act, and it creates no private right of action.

HIV Records and Record Retention

New Jersey's AIDS Assistance Act (N.J.S.A. 26:5C-5 and following) restricts disclosure of HIV-related records beyond HIPAA's treatment, payment, and operations permissions, generally requiring written consent outside listed exceptions. The statute text could not be pulled from a state-hosted source during drafting, so treat this as a flag: if the practice tests for or treats HIV, the consent form needs a New Jersey-specific review by counsel.

Retention is a state matter too. HIPAA sets no retention period for the chart itself; it requires that policies and required documentation be kept for "6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i) and 164.530(j)(2)). The Board of Medical Examiners regulation (N.J.A.C. 13:35-6.5) sets the physician record period, commonly cited as seven years; confirm the current figure with the board before writing a retention schedule. The record retention guide covers the federal-versus-state split.

New Jersey Breach Notification: Two Clocks, One Incident

The federal rule first. 45 CFR 164.404(b) requires notice to affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." Under 164.408(b), a breach involving 500 or more individuals goes to HHS "contemporaneously" with the individual notice; under 164.408(c), smaller breaches are logged and reported "not later than 60 days after the end of each calendar year." Under 164.406(a), a breach involving "more than 500 residents of a State or jurisdiction" also goes to prominent media serving that state. A business associate has the same 60-day ceiling to notify the covered entity (164.410(b)).

Now the state rule, N.J.S.A. 56:8-163. A business that "compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person." Four features distinguish it from HIPAA:

  • No fixed day count. Disclosure must be made "in the most expedient time possible and without unreasonable delay." There is no 60-day ceiling to lean on. A practice that waits 59 days because HIPAA allows it may still be late under state law.
  • State Police first. Subsection c.(1): a business "shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling." There is no numeric threshold; the duty attaches to every notifiable breach.
  • A documented misuse determination. Disclosure is not required "if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years." That is a separate analysis from HIPAA's four-factor risk assessment in 164.402, with a different question and its own retention period.
  • Vendors and credit bureaus. A business that maintains records "on behalf of another business" must notify that business "immediately following discovery," faster than HIPAA's 60-day ceiling and worth writing into the B.A.A. A breach requiring notice to "more than 1,000 persons at one time" also requires notice to the nationwide consumer reporting agencies.

The state definition of breach of security is "unauthorized access to electronic files, media or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable."

ObligationFederal HIPAANew Jersey (N.J.S.A. 56:8-163)
TriggerBreach of unsecured P.H.I. (164.402)Unauthorized access to unencrypted computerized "personal information"
Individual notice deadlineNo later than 60 calendar days after discoveryMost expedient time possible; no fixed day count
Government noticeHHS: contemporaneous if 500 or more; annual log if fewerDivision of State Police, before customer notice, every breach
MediaProminent outlets if more than 500 residents of a stateOnly as substitute notice when direct notice is impractical
Credit bureausNot requiredNationwide agencies if more than 1,000 persons
Vendor to clientNo later than 60 days (164.410)Immediately following discovery
No-notice determinationFour-factor risk assessment (164.402)Written finding that misuse is not reasonably possible, kept five years

The working rule for a New Jersey practice: run the federal breach process from the breach notification guide, and add two lines. Line one: report to the State Police before any letter is mailed. Line two: mail as soon as the facts are known, not on day 59.

HIPAA Penalties in New Jersey

Federal OCR Penalty Tiers

45 CFR 160.404 sets four culpability tiers, and the dollar amounts are inflation-adjusted each year at 45 CFR 102.3. Under the 2025 adjustment, the per-violation ranges are: $145 to $73,011 where the entity did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect not corrected. The calendar-year cap for identical violations is $2,190,294. OCR has also applied a Notice of Enforcement Discretion with lower annual caps for the first three tiers; those figures are not quoted here. Recent OCR case titles show the pattern: a $950,000 settlement over Security Rule failures (July 1, 2024), a $3,000,000 phishing settlement with Solara Medical Supplies (January 14, 2025), and a $600,000 phishing settlement with a health care network (April 23, 2025). The penalty amounts post tracks the numbers.

New Jersey Attorney General Enforcement

N.J.S.A. 56:8-166 makes it "an unlawful practice and a violation of" the Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.) to "willfully, knowingly or recklessly violate" the breach notification, record destruction, and Social Security number sections. The office uses those tools. In May 2023 the New Jersey Attorney General co-led a $2.5 million multistate settlement with EyeMed over a data breach the office said compromised the personal and medical information of approximately 2.1 million people, more than 52,000 of them in New Jersey, in violation of state law and HIPAA. Neither state statute gives patients a private right of action for a breach, but negligence suits after breaches are routine, and that risk sits outside both laws.

HIPAA Compliance for New Jersey Healthcare Providers

New Jersey Hospitals and Health Systems

Large systems already run federal programs. The state layer shows up in three places: the State Police report step in the incident response plan, the Social Security number rules in patient-facing documents and portals, and vendor contracts, which should carry the state's "immediately following discovery" notice term. Hospitals that treat HIV also need the AIDS Assistance Act consent workflow reviewed by counsel.

New Jersey Dental Practices

Dental offices are covered entities the moment they submit an electronic claim; the dental compliance page covers the federal program. The New Jersey additions are practical: intake forms with a Social Security number cannot come back on a postcard, retired paper charts must be shredded rather than bagged, and a lost unencrypted laptop with patient financial data triggers the State Police report. The OCR case against a dental practice for social media disclosures of patients' P.H.I. ($10,000, October 2, 2019) is a reminder that dental violations usually start with a review reply, not a hacker.

New Jersey Behavioral Health Providers

For most New Jersey behavioral health practices the federal rules do the heavy lifting: psychotherapy notes have their own protection under HIPAA, substance use disorder records may fall under 42 CFR Part 2, and the OCR penalty against a mental health center for failing to provide timely access to records ($100,000, November 19, 2024) shows where enforcement lands. State confidentiality provisions for psychiatric facility records exist and should be checked with counsel. The behavioral health compliance page covers the program.

New Jersey Home Health and Long-Term Care

Home health agencies and nursing facilities carry long vendor lists and a workforce that moves patient data on phones and in cars. Each vendor needs a B.A.A.; each device needs encryption, which keeps a lost phone out of both breach statutes. The April 1, 2024 OCR penalty against a New Jersey nursing facility for failing to provide timely access to records is the local warning: the 30-day access deadline in 45 CFR 164.524(b)(2) applies to a nursing home exactly as it applies to a hospital.

New Jersey HIPAA Compliance Checklist

RequirementSourceTimingEvidence to keep
Security risk analysis and risk management planFederal, 164.308(a)(1)Documented; reviewed at least annually in practiceRisk analysis report, remediation plan
Workforce trainingFederal, 164.530(b), 164.308(a)(5)New hires; when policies change; annual in practiceTraining log with dates and names
Signed B.A.A. with every P.H.I. vendorFederal, 164.504(e), 164.314(a)Before access; add the state "immediately" notice termExecuted agreement per vendor
Breach procedure with a State Police report stepFederal 164.404 to 164.410; N.J.S.A. 56:8-163(c)State Police before customer notice; letters without unreasonable delayIncident log, report confirmation, notice copies
Written no-notice determination, if relied onN.J.S.A. 56:8-163(a)At the time of the decisionSigned memo, kept five years
Record destruction and Social Security number handlingN.J.S.A. 56:8-162, 56:8-164; federal 164.310(d)Ongoing; review forms and portals annuallyWritten policy, shredding certificates, form inventory
Medical record retention scheduleState licensing board rulePer board ruleWritten retention schedule

One note on timing. The proposed update to the HIPAA Security Rule, published in January 2025, would add express requirements such as encryption and multifactor authentication. It is a proposal, not current law, and OCR is not enforcing it. Nothing in this guide depends on it.

---

FAQ

Does HIPAA compliance satisfy New Jersey's breach notification law?

No. The Identity Theft Prevention Act has no HIPAA carve-out. A practice that follows the federal 60-day rule still owes New Jersey residents notice "in the most expedient time possible" and must report the breach to the Division of State Police before notifying customers.

How fast must a New Jersey practice notify patients after a breach?

Federal: without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404(b)). State: in the most expedient time possible and without unreasonable delay, with no fixed day count. Follow the faster of the two, which in practice means as soon as the facts are known.

Who must be told about a breach in New Jersey besides the patients?

The Division of State Police (before customer notice, for every notifiable breach), the nationwide consumer reporting agencies if more than 1,000 persons are notified, HHS under the federal rule, and prominent media if more than 500 New Jersey residents are affected. The state statute itself does not require a separate Attorney General filing.

Does the New Jersey Data Privacy Act apply to medical practices?

Its exemption covers protected health information held by a covered entity or business associate, not the organization as a whole. Non-patient data such as website analytics or marketing lists sits outside the exemption and is covered only if the practice meets the act's thresholds (100,000 consumers, or 25,000 plus revenue from selling personal data). Ask counsel if the practice has a marketing operation.

Who enforces HIPAA in New Jersey?

OCR enforces the federal rules and has penalized New Jersey providers, including a nursing facility (April 1, 2024) and a provider that disclosed patient information in response to online reviews (June 5, 2023). The New Jersey Attorney General enforces the Identity Theft Prevention Act through the Consumer Fraud Act and has sole authority over the Data Privacy Act.

Conclusion

The federal program comes first: risk analysis, written policies, workforce training, and signed B.A.A.s. The New Jersey layer is a short addendum to the breach procedure plus a few state-specific consent and retention checks. One Guy Consulting's Full-Scope plan builds the federal program and documents the state overlay alongside it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading