HIPAA Compliance in Ohio: What State Law Adds and Where It Steps Aside

Practical guidance for healthcare teams and business associates

On July 29, 2026, the HHS Office for Civil Rights announced a $552,250 settlement of a ransomware investigation with OSF HealthCare System. The resolution agreement cites a risk analysis failure, an impermissible disclosure affecting 53,907 individuals, and late notification to the affected individuals and to HHS. Two of the three findings are about a document and a calendar, not the attack.

An Ohio practice reading that would reasonably ask what Ohio adds. Ohio's breach statute exempts HIPAA covered entities outright. Its records access and fee statute, its mental health confidentiality sections, and its HIV disclosure statute apply in full, and its Data Protection Act offers a litigation defense to a practice with a real Security Rule program. This guide covers all of it, from the covered entity test to a closing checklist.

HIPAA Compliance Ohio: How the Federal and State Rules Interact

HIPAA is a federal floor. The preemption rule at 45 CFR 160.203 says a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," except in listed cases. The case that matters here is paragraph (b): state law survives when it "relates to the privacy of individually identifiable health information and is more stringent than" the Privacy Rule. Under 160.202, "more stringent" includes a state law that "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted," or that "permits greater rights of access or amendment."

Ohio's statutes lean on HIPAA rather than fight it: the fee statute defers to federal limits for a patient's own copies, the breach statute exempts a "covered entity as defined in 45 C.F.R. 160.103," and the Data Protection Act names the Security Rule as a qualifying framework. Where Ohio is more protective, as with mental health and HIV records, Ohio controls; the general framework is in state privacy laws vs HIPAA.

Who Is a Covered Entity in Ohio

The federal definition does not change at the state line. 45 CFR 160.103 defines a covered entity as "a health plan," "a health care clearinghouse," or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." In Ohio that captures hospitals, physician practices, dental offices, behavioral health providers, home health agencies, pharmacies, nursing facilities, and health plans. The test is electronic billing, not size.

Ohio's own statutes use a broader term. ORC 3701.74 defines "health care provider" to include hospitals, "ambulatory care facilities" (home health agencies, urgent care, imaging centers), long-term care facilities, pharmacies, and licensed practitioners from dentists to counselors. That definition drives the access and fee rules below whether or not the provider bills electronically.

Who Is a Business Associate in Ohio

A business associate under 160.103 is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including "billing" and "practice management," or who provides legal, accounting, consulting, or administrative services involving P.H.I. (Protected Health Information). Subcontractors count too, and each one needs a signed B.A.A. (Business Associate Agreement).

The breach statute's exemption at ORC 1349.19(F)(2) names covered entities only. A vendor that "owns or licenses" computerized personal information about Ohio residents is subject to the state's 45-day rule in its own right, and one that "is the custodian of or stores computerized data" for another must notify that party "in an expeditious manner" under 1349.19(C). A BAA with an Ohio vendor should state the vendor's notification clock in days, inside the 60-day HIPAA outer limit under 164.410.

Ohio Statutes That Stack on HIPAA

Patient Access to Medical Records (ORC 3701.74 and 3701.741)

ORC 3701.74(B) requires "a written request signed by the patient" and "dated not more than one year before the date on which it is submitted." The provider must, "within a reasonable time," let the patient "examine the record during regular business hours without charge or, on request, shall provide a copy." Under 3701.74(C), a patient who is refused "may bring a civil action to enforce the patient's right of access."

HIPAA's own deadline at 164.524(b)(2) is 30 days after receipt, with one 30-day extension. Both apply; an Ohio provider should never let a request sit on the theory that HIPAA allows 30 days. Fees under 3701.741 split by who is asking. For the patient, a personal representative, or a power of attorney, copies are "reasonable, cost-based amounts permitted to be charged to the patient under federal laws and regulations," and electronic access is capped at $50. For anyone else, the statute sets a base search fee of $16.84 plus $1.11 per page for the first 10 pages, $0.57 for pages 11 through 50, $0.23 for pages 51 and up, and $1.87 per page for imaging, all adjusted yearly by the Director of Health under 3701.742. The federal side is in the right of access guide.

One carve-out: 3701.74(D) says the section "does not apply to medical records whose release is covered by" ORC Chapters 5119 or 5122, or by 42 CFR Part 2.

Mental Health Records (ORC 5119.28 and 5122.31)

ORC 5119.28(A) says "all records, and reports" that identify a person and pertain to "the person's mental health condition, assessment, provision of care, treatment, or recovery supports" and are maintained in connection with services the department of behavioral health approves or with its licensed facilities "shall be kept confidential and shall not be disclosed by any person except" in listed cases. The list includes consent, disclosures another law provides for, releases to insurers for payment, a court order, and the person's own access unless "restricted in a person's treatment plan for clear treatment reasons." ORC 5122.31 runs the same list for hospitalization records under Chapter 5122.

Two details set Ohio apart. Under 5119.28(B) and 5122.31(B), before records go to a payer or move under the continuity-of-care exceptions, "the custodian of the records shall attempt to obtain the person's consent"; HIPAA requires no such attempt. And both sections say records of a person "deceased for fifty years or more are no longer considered confidential," the same 50-year line HIPAA draws at 164.502(f), explained in HIPAA and deceased patients.

HIV Test Results (ORC 3701.243)

ORC 3701.243(A) forbids anyone who "acquires the information while providing any health care service" from disclosing the identity of a person tested for HIV, identifiable results, or an AIDS diagnosis, except as the section allows. The list at (B)(1) includes the individual, a person named in "a written release" that specifies "to whom disclosure of the test results or diagnosis is authorized and the time period during which the release is to be effective," treating clinicians, and the health department. Under (B)(2), a provider participating in the individual's care may receive the information on "a medical need to know."

Under 3701.243(E), "any disclosure pursuant to this section shall be in writing" and must carry a statement ending: "A general authorization for the release of medical or other information is not sufficient for the purpose of the release of HIV test results or diagnoses." An Ohio release covering HIV results therefore needs a named recipient and an expiration, and the disclosure goes out in writing with the statement attached. The current version took effect March 20, 2025.

The Ohio Data Protection Act (ORC Chapter 1354)

Effective November 2, 2018, ORC 1354.02 gives a business with "a written cybersecurity program" that "reasonably conforms to an industry recognized cybersecurity framework" an affirmative defense to any tort claim alleging "that the failure to implement reasonable information security controls resulted in a data breach." ORC 1354.03(B)(1)(a) lists, as a qualifying framework, "the security requirements of the Health Insurance Portability and Accountability Act of 1996, as set forth in 45 CFR Part 164 Subpart C." When a framework is amended, 1354.03(B)(2) allows one year from the effective date to conform.

This is not immunity. It is a defense the practice has to prove, and the proof is the written program 164.316 already requires. The one-year clause also matters for the Security Rule update HHS proposed in January 2025, which is proposed, not final, and not being enforced; if finalized, the Ohio conformance clock would start on its effective date. Its status is tracked in the Security Rule delay post.

Records Retention: No Single Ohio Number

The Revised Code sections reviewed for this article do not set a general retention period for a physician or dental office's charts. Retention comes from licensure rules, boards, payer contracts, and malpractice exposure, so a practice has to adopt a written schedule and confirm the number for its license type with counsel. HIPAA's own six-year rule at 164.316(b)(2)(i) and 164.530(j)(2) covers compliance documentation, not charts.

Ohio Breach Notification Requirements

The Federal Clock

Under 45 CFR 164.404(b), a covered entity notifies each affected individual "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." Under 164.408, a breach involving 500 or more individuals is reported to HHS "contemporaneously" with the individual notices; a smaller breach is logged and reported "not later than 60 days after the end of each calendar year." A disclosure is presumed to be a breach unless the four-factor assessment under 164.402 shows "a low probability that the protected health information has been compromised." The process is in the breach notification rule guide.

Ohio's 45-Day Statute and the Covered Entity Exemption

ORC 1349.19(B)(2) requires a person that owns or licenses computerized personal information to notify affected Ohio residents "in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach." Under (A)(1)(a), a breach is "unauthorized access to and acquisition of computerized data" creating "a material risk of identity theft or other fraud," and "personal information" under (A)(7) is a name combined with an unencrypted Social Security number, driver's license or state ID number, or financial account number with its access code. Medical information is not on the list.

Older guides miss ORC 1349.19(F)(2): "This section does not apply to any person or entity that is a covered entity as defined in 45 C.F.R. 160.103, as amended." For an Ohio hospital, practice, or health plan, the state's 45-day clock does not run at all; the HIPAA clocks are the only breach clocks. The section has no Attorney General notice requirement; paragraph (I) lets the Attorney General investigate and sue. Its one remaining duty, (G), notice to the nationwide consumer reporting agencies when an incident requires notice to more than 1,000 Ohio residents, falls on non-exempt business associates rather than on the practice.

ItemHIPAA (federal)Ohio ORC 1349.19
Applies to a HIPAA covered entityYesNo: (F)(2) exempts covered entities as defined in 45 CFR 160.103
Applies to a business associateYes, notify the CE within 60 days (164.410)Yes, if it owns or licenses personal information (45 days) or stores it for another (expeditiously, (C))
Individual notice deadlineWithout unreasonable delay, no later than 60 calendar days after discovery (164.404)Most expedient time possible, no later than 45 days after discovery ((B)(2))
Regulator noticeHHS, contemporaneously if 500 or more; annual log if fewer (164.408)None required; Attorney General may investigate and sue ((I))

HIPAA Penalties in Ohio

Federal OCR Penalties

OCR's civil money penalties follow the four culpability tiers at 45 CFR 160.404, with amounts inflation-adjusted at 45 CFR 102.3. The 2025 figures per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect corrected within 30 days, $14,602 to $73,011; willful neglect not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. The lower enforcement-discretion caps OCR has applied since 2019 are tracked in the penalty amounts post.

Recent actions show the range: a $600,000 phishing attack settlement with a health care network (April 23, 2025), a $1,500,000 civil money penalty against Warby Parker in a hacking investigation (February 20, 2025), and the OSF HealthCare settlement above, which turned on a missing risk analysis and late notification as much as on the ransomware.

State Enforcement

Three Ohio paths exist alongside OCR. First, HITECH lets a state attorney general sue in federal court for HIPAA violations affecting state residents; under 42 U.S.C. 1320d-5(d), statutory damages run "up to $100" per violation, capped at $25,000 per calendar year for identical violations, plus attorney fees. Second, for a non-exempt business that violates ORC 1349.19, ORC 1349.192 allows civil penalties of up to $1,000 per day, rising to $5,000 per day after 60 days and $10,000 per day after 90 days of intentional or reckless noncompliance. Third, a patient denied access may sue under 3701.74(C), and 5119.28(C) says "no person shall reveal the content of a medical record" made confidential by that section "except as authorized by law." Licensing boards can discipline on top of all three.

Ohio HIPAA Rules by Provider Type

Hospitals and Health Systems

Hospitals carry the 3701.74 access, fee, and civil-action provisions in full, and psychiatric units fall under 5122.31. Under 3701.243(B)(3), each health care facility must have "a protocol to be followed by employees" for need-to-know HIV disclosures, and staff who follow it are immune from civil damages. A hospital breach almost always tops 500 residents of the state, which triggers the federal media notice under 164.406.

Dental Practices

Dentists and dental hygienists are named "health care practitioners" in 3701.74, so the written-request rule, the reasonable-time standard, and the 3701.741 fee schedule apply to every dental office. The federal side is the enforcement priority: OCR imposed a $70,000 civil monetary penalty against Gums Dental Care for failure to provide timely access to patient records (October 17, 2024).

Behavioral Health Providers

Community behavioral health records are under 5119.28, hospitalization records under 5122.31, and federally assisted substance use programs add 42 CFR Part 2. Because 3701.74(D) carves those records out of the general access statute, a patient's access request is handled under 5119.28(A)(5), with the treatment-plan restriction as the only basis to limit it. The consent-attempt rule before payer disclosures needs a line in the intake workflow, and the release-of-information procedure has to ask which statute governs each record before a form is chosen.

Home Health Agencies

3701.74(A)(1) lists "home health agency" inside "ambulatory care facility," so the same access and fee rules apply. Scheduling, electronic visit verification, and telehealth platforms each need a BAA, and each vendor that is not itself a covered entity sits outside the 1349.19 exemption with its own Ohio breach duties.

Ohio HIPAA Compliance Checklist

RequirementFederal or stateDeadline or frequencyDocumentation
Risk analysis and written Security Rule programFederal (164.308(a)(1), 164.316); Ohio Data Protection Act defense (1354.02)Current; conform within one year of any framework amendmentSigned risk analysis, policies, implementation records
BAA with every PHI vendorFederal (164.504(e), 164.314(a)); Ohio vendor duties (1349.19(C))Before access; reviewed yearlySigned BAA per vendor with notification clock
Breach notice to individuals and HHSFederal (164.404, 164.408)60 days; HHS contemporaneously if 500 or moreFour-factor assessment, letters, portal receipt
Ohio breach statuteState (1349.19)Not applicable to covered entities ((F)(2)); 45 days for non-exempt vendorsNote in the incident plan; vendor clause
Patient access and copy feesFederal (164.524) + state (3701.74, 3701.741)30 days (HIPAA); reasonable time (Ohio); $50 electronic capRequest log; posted fee schedule, current year
Mental health releasesState (5119.28, 5122.31) + Part 2 where applicableBefore disclosure; consent attempt before payer releaseConsent on file, attempt documented
HIV information releasesState (3701.243)Before each disclosureRelease naming recipient and period; written disclosure with statement

---

FAQ

Does Ohio's 45-day breach notification law apply to HIPAA-covered providers?

No. ORC 1349.19(F)(2) states that the section does not apply to any person or entity that is a covered entity as defined in 45 CFR 160.103. A HIPAA-covered hospital, practice, or health plan follows the federal breach rule only: individual notice within 60 days of discovery and HHS notice contemporaneously for 500 or more individuals. Business associates that are not themselves covered entities are not exempt.

Does Ohio require breach notice to the Attorney General?

ORC 1349.19 contains no Attorney General notice requirement. It authorizes the Attorney General to investigate and sue for noncompliance, and it requires notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are notified in a single incident. HIPAA's own notice to HHS still applies to covered entities.

How much can an Ohio provider charge for copies of medical records?

For the patient, a personal representative, or a power of attorney, ORC 3701.741 limits charges to the reasonable, cost-based amounts HIPAA permits, with electronic access capped at $50. For other requesters, the statute sets a search fee plus per-page charges that the Ohio Department of Health adjusts each year. Patients may also examine their records in person without charge.

Are mental health and HIV records treated differently in Ohio?

Yes. ORC 5119.28 and 5122.31 keep mental health records confidential except in listed cases and require the custodian to attempt to obtain consent before releasing records to payers. ORC 3701.243 limits HIV test result disclosures to listed recipients, requires a written release that names the recipient and a time period, and requires every disclosure to be in writing with a statutory statement attached.

What is the Ohio Data Protection Act and does HIPAA compliance count?

ORC Chapter 1354 gives a business an affirmative defense to tort claims alleging that a failure to implement reasonable security controls caused a data breach, if the business maintains a written cybersecurity program that reasonably conforms to a recognized framework. ORC 1354.03 lists the HIPAA Security Rule, 45 CFR Part 164 Subpart C, as a qualifying framework. The defense must be proven, so the written program is the evidence.

Conclusion

Ohio is a state where the federal program does most of the work. The breach statute steps aside for covered entities, the fee statute defers to HIPAA for a patient's own copies, and the Data Protection Act turns a documented Security Rule program into a defense in court. The state-only items are the access and fee rules, the mental health and HIV consent handling, and a retention schedule the practice has to set for itself.

One Guy Consulting's Full-Scope plan builds the written Security Rule program, the policies, the breach procedure, and the vendor agreements, with consulting time to layer in the Ohio pieces. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading