HIPAA Compliance in North Carolina: The State Rules That Sit On Top

Practical guidance for healthcare teams and business associates

A Charlotte practice closes for the weekend with a box of old paper charts by the loading dock, waiting for a shredding pickup that was never scheduled. On Monday the box is gone. Nothing was hacked, no computer was touched, and under federal HIPAA this is a breach of unsecured P.H.I. (Protected Health Information). Under North Carolina law it is also a breach, because the state statute covers personal information "in any form (whether computerized, paper, or otherwise)," and it comes with a filing the practice has probably never heard of.

OCR (the HHS Office for Civil Rights) has settled cases over exactly this kind of failure: a $950,000 settlement over Security Rule failures (July 1, 2024), a $3 million settlement for failure to encrypt mobile devices (November 5, 2019), and a settlement over improper disposal of protected health information (August 23, 2022). The federal rules apply the same way in Raleigh, Asheville, and Wilmington.

This guide covers the federal floor, the North Carolina statutes that stack on top of it, the state breach law and its Attorney General report, the penalties on both sides, and what it means for hospitals, dental offices, behavioral health practices, and home health agencies.

HIPAA Compliance North Carolina: How Federal and State Rules Interact

HIPAA (the Health Insurance Portability and Accountability Act) is a floor. 45 CFR 160.203 states the general rule: a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," then lists the exceptions. Paragraph (b) is the one that matters for a practice: state law survives when it "relates to the privacy of individually identifiable health information and is more stringent than" the federal Privacy Rule. Paragraph (c) also preserves state laws that provide "for the reporting of disease or injury, child abuse, birth, or death, or for the conduct of public health surveillance."

Where North Carolina is stricter, North Carolina wins. Where HIPAA is stricter, HIPAA wins. Several North Carolina statutes were written to point back at HIPAA, which makes the state's rules easier to reconcile than most.

Who Is a Covered Entity in North Carolina

The definition is federal. 45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Every North Carolina provider that bills electronically qualifies.

Who Is a Business Associate in North Carolina

Also federal. A business associate under 160.103 is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing." Every such vendor needs a signed B.A.A. (Business Associate Agreement); the BAA guide lists the required terms.

North Carolina's breach statute uses its own word, "business," defined in N.C.G.S. 75-61(1) as "a sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit." A vendor holding residents' personal information is a "business" under state law with or without a B.A.A.

North Carolina Privacy Statutes That Stack on Top of HIPAA

The Identity Theft Protection Act (N.C.G.S. 75-60 to 75-66)

Article 2A of Chapter 75 is the state's breach and data-handling law. Beyond the notification section covered below, two provisions apply to every practice every day:

  • Destruction of personal information records (75-64). A business "must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal." The statute spells the measures out: policies "that require the burning, pulverizing, or shredding of papers containing personal information," policies requiring "the destruction or erasure of electronic media," and "describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity." A written disposal policy is not optional in North Carolina.
  • Personal information. Under 75-61(10) it means a first name or initial and last name combined with "identifying information as defined in G.S. 14-113.20(b)," a list that includes Social Security and taxpayer numbers, driver's license, state ID, and passport numbers, checking and savings account numbers, card numbers, PINs, digital signatures, biometric data, fingerprints, passwords, and a parent's maiden name. Health information as such is not on the list, so a breach of purely clinical data is a HIPAA breach that may not be a state breach; a breach of a billing file with Social Security numbers is both.

Communicable Disease Records (N.C.G.S. 130A-143)

Records that "identify a person who has or may have a disease or condition required to be reported" under the public health article "shall be strictly confidential." Release is permitted only in listed circumstances, and the list was written with HIPAA in mind: with "the written consent of the person or persons identified," or "for purposes of treatment, payment, research, or health care operations to the extent that disclosure is permitted under 45 Code of Federal Regulations §§ 164.506 and 164.512(i)." HIV, hepatitis, tuberculosis, and other reportable conditions fall under this section. The state adds no second consent form for treatment and payment disclosures, but it locks down everything else.

Mental Health Records (N.C.G.S. 122C-52)

"Confidential information acquired in attending or treating a client" of a mental health, developmental disabilities, or substance abuse facility may not be disclosed except as authorized in 122C-53 through 122C-56. The statute again defers to the federal rule for downstream use: a HIPAA covered entity or business associate that receives the information "may use and disclose such information as permitted or required under 45 Code of Federal Regulations Part 164, Subpart E." Unauthorized disclosure "is a Class 3 misdemeanor and is punishable only by a fine, not to exceed five hundred dollars ($500.00)." Substance use disorder programs may also be under 42 CFR Part 2.

Provider Disclosures and Copy Fees (N.C.G.S. 90-21.20B and 90-411)

Section 90-21.20B lets a provider disclose P.H.I. to law enforcement "only to the extent that the information may be disclosed under" 45 CFR 164.512(f), and for treatment, payment, or operations "to the extent that disclosure is permitted under 45 C.F.R. § 164.506." Section 90-411 caps record copy fees at 75 cents per page for the first 25 pages, 50 cents for pages 26 through 100, and 25 cents beyond that, with a minimum fee of up to $10. HIPAA's own fee rule at 164.524(c)(4) still applies to patient requests, and the practice must satisfy both.

Medical Record Retention

HIPAA sets no retention period for the chart. It requires that policies and required documentation be kept "for 6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i) and 164.530(j)(2)). North Carolina does not set one statewide chart retention period by statute for every provider type; the Medical Board's position statement and facility licensing rules govern, and they were not reviewed for this article. Check the applicable board rule before writing a retention schedule. The record retention guide covers the federal-versus-state split.

North Carolina Breach Notification: Federal Clock, State Report

The federal rule first. 45 CFR 164.404(b) requires notice to affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." A breach involving 500 or more individuals goes to HHS "contemporaneously" with the individual notice (164.408(b)); smaller breaches are logged and reported "not later than 60 days after the end of each calendar year" (164.408(c)); a breach involving "more than 500 residents of a State or jurisdiction" also goes to prominent media serving that state (164.406(a)). A business associate has the same 60-day ceiling to notify the covered entity (164.410(b)).

Now N.C.G.S. 75-65. Any business that owns or licenses "personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach." Five features matter to a practice:

  • Paper counts. The parenthetical is in the statute. A stolen box of charts, a misdirected fax with Social Security numbers, or a lost binder is a state breach.
  • Timing. Notice "shall be made without unreasonable delay," allowing for law enforcement needs and for "any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system." No fixed day count, and no 60-day ceiling to lean on.
  • Attorney General report, every time. Subsection (e1): "In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General's Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice." There is no threshold. The Attorney General accepts the report through an online security breach form.
  • Credit bureaus at 1,000. Under (f), notice to "more than 1,000 persons at one time" also requires notice to the nationwide consumer reporting agencies "of the timing, distribution, and content of the notice."
  • Vendors notify immediately. A business that holds records it does not own "shall notify the owner or licensee of the information of any security breach immediately following discovery," faster than the federal 60-day business associate ceiling.

The notice itself has seven required elements under 75-65(d), including "the toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General's Office." Draft one letter that satisfies both lists.

ObligationFederal HIPAANorth Carolina (N.C.G.S. 75-65)
TriggerBreach of unsecured P.H.I. (164.402)Security breach of unencrypted, unredacted personal information, in any form including paper
Individual notice deadlineNo later than 60 calendar days after discoveryWithout unreasonable delay; no fixed day count
Government noticeHHS: contemporaneous if 500 or more; annual log if fewerAttorney General Consumer Protection Division, every notifiable breach
MediaProminent outlets if more than 500 residents of a stateOnly as substitute notice when direct notice is impractical
Credit bureausNot requiredNationwide agencies if more than 1,000 persons
Vendor to clientNo later than 60 days (164.410)Immediately following discovery
Letter contentFive elements, plain language (164.404(c))Seven elements including FTC and Attorney General contacts (75-65(d))

The working rule: run the federal process from the breach notification guide, use a letter template that carries the North Carolina elements, and file the Attorney General report as soon as the letters go out. North Carolina has no HIPAA deemed-compliance clause; following the federal rule does not excuse the state filing.

HIPAA Penalties in North Carolina

Federal OCR Penalty Tiers

45 CFR 160.404 sets four culpability tiers, and the amounts are inflation-adjusted each year at 45 CFR 102.3. Under the 2025 adjustment, the per-violation ranges are: $145 to $73,011 where the entity did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect not corrected. The calendar-year cap for identical violations is $2,190,294. OCR has applied a Notice of Enforcement Discretion with lower annual caps for the first three tiers; those figures are not quoted here. The penalty amounts post tracks the numbers.

North Carolina Attorney General Enforcement

Under 75-65(i), "A violation of this section is a violation of G.S. 75-1.1," the state's unfair and deceptive trade practices statute. That gives the Attorney General the Chapter 75 toolkit, including a civil penalty under 75-15.2 "of up to five thousand dollars ($5,000) for each violation" where the conduct was "knowingly violative of a statute." The same subsection limits private suits: "No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation." The Attorney General's office reports that more than 20,000 security breaches have been reported to it since December 2005. Any waiver of the article "is contrary to public policy and is void and unenforceable" (75-65(g)), so a vendor contract cannot sign the duty away.

HIPAA Compliance for North Carolina Healthcare Providers

North Carolina Hospitals and Health Systems

Systems already run federal programs. The state overlay lands in the incident response plan (the Attorney General report step and the seven-element letter), the disposal policy required by 75-64, and vendor contracts, which should carry the state's "immediately following discovery" notice term. Infectious disease and behavioral health units operate under 130A-143 and 122C-52.

North Carolina Dental Practices

A dental office becomes a covered entity with its first electronic claim; the dental compliance page covers the federal program. The state additions are concrete: a written shredding policy under 75-64, a breach letter template with the Attorney General and FTC contacts, and awareness that paper counts. The OCR settlement with a dental practice over social media disclosures of patients' P.H.I. ($10,000, October 2, 2019) is a reminder that dental enforcement usually starts with a review reply, not a hacker.

North Carolina Behavioral Health Providers

Section 122C-52 applies to facilities under Chapter 122C, and 42 CFR Part 2 may apply to substance use disorder records. Federal enforcement in this sector has centered on patient access: OCR imposed a $100,000 penalty against a mental health center for failure to provide timely access to patient records (November 19, 2024). The 30-day deadline in 45 CFR 164.524(b)(2) applies to a counseling practice exactly as it applies to a hospital. The behavioral health compliance page covers the program.

North Carolina Home Health and Long-Term Care

Home health agencies and nursing facilities move P.H.I. on phones and paper in cars. The $3 million OCR settlement over failure to encrypt mobile devices (November 5, 2019) is the sector's warning. Encryption keeps a lost device out of the federal breach definition and out of the state one, because both exempt secured data. Every vendor on the agency's list needs a B.A.A. with the state's immediate-notice term.

North Carolina HIPAA Compliance Checklist

RequirementSourceTimingEvidence to keep
Security risk analysis and risk management planFederal, 164.308(a)(1)Documented; reviewed at least annually in practiceRisk analysis report, remediation plan
Workforce trainingFederal, 164.530(b), 164.308(a)(5)New hires; when policies change; annual in practiceTraining log with dates and names
Signed B.A.A. with every P.H.I. vendorFederal, 164.504(e), 164.314(a)Before access; add the state "immediately" notice termExecuted agreement per vendor
Breach procedure with an Attorney General report stepFederal 164.404 to 164.410; N.C.G.S. 75-65(e1)Letters without unreasonable delay; report to the Attorney General when notice is givenIncident log, online report confirmation, notice copies
Breach letter template with the seven state elementsN.C.G.S. 75-65(d); federal 164.404(c)Ready before an incidentApproved template on file
Written disposal policy (paper and electronic)N.C.G.S. 75-64; federal 164.310(d)OngoingWritten policy, shredding vendor contract and certificates
Communicable disease and mental health release proceduresN.C.G.S. 130A-143, 122C-52Before any non-treatment disclosureConsent forms, release log

One note on timing. The proposed update to the HIPAA Security Rule, published in January 2025, would add express requirements such as encryption and multifactor authentication. It is a proposal, not current law, and OCR is not enforcing it. Nothing in this guide depends on it.

---

FAQ

Does HIPAA compliance satisfy North Carolina's breach notification law?

No. North Carolina's Identity Theft Protection Act has no HIPAA deemed-compliance clause. A practice that follows the federal 60-day rule still owes residents notice without unreasonable delay, a letter that carries the state's seven required elements, and a report to the Attorney General's Consumer Protection Division for every breach that triggers notice.

Does North Carolina require notice to the Attorney General for small breaches?

Yes. N.C.G.S. 75-65(e1) requires the Attorney General report whenever a business provides notice to an affected person, with no minimum number of people. The 1,000-person threshold in subsection (f) adds the nationwide consumer reporting agencies; it does not remove the Attorney General report for smaller breaches.

Does North Carolina's breach law cover paper records?

Yes. The statute applies to personal information 'in any form (whether computerized, paper, or otherwise).' A lost box of charts containing Social Security numbers is a state breach as well as a federal one.

Are mental health and HIV records treated differently in North Carolina?

Yes. N.C.G.S. 122C-52 restricts disclosure of mental health facility records to the circumstances in 122C-53 through 122C-56, and 130A-143 makes reportable communicable disease records strictly confidential. Both statutes permit treatment, payment, and operations disclosures to the extent 45 CFR 164.506 allows, so they add consent requirements only outside those purposes.

Who enforces HIPAA in North Carolina?

OCR enforces the federal rules. The North Carolina Attorney General enforces the Identity Theft Protection Act as an unfair trade practice under G.S. 75-1.1, with civil penalties of up to $5,000 per knowing violation under 75-15.2, and receives every breach report filed under 75-65(e1).

Conclusion

The federal program comes first: risk analysis, written policies, workforce training, and signed B.A.A.s. The North Carolina layer is an Attorney General report step in the breach procedure, a written disposal policy, and a few state consent checks. One Guy Consulting's Full-Scope plan builds the federal program and documents the state overlay alongside it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading