An imaging center in Knoxville learns from a security researcher that one of its servers has been reachable from the internet, unprotected, for months. Every study on it is exposed. The federal clock starts: 60 days to notify patients, HHS at the same time if 500 or more are affected, and the media if more than 500 Tennesseans are involved. The center then asks the state question and gets an answer that surprises most practices: Tennessee's breach statute does not apply to it at all.
That scenario is not invented. OCR (the HHS Office for Civil Rights) announced on May 6, 2019 that a Tennessee diagnostic medical imaging services company paid $3,000,000 to settle a breach exposing over 300,000 patients' protected health information. Federal enforcement is the enforcement that matters in Tennessee. This article covers how federal and state rules interact, who is a covered entity or business associate in Tennessee, the state statutes that touch health data and the ones that expressly do not, the breach rules, penalties, provider-type notes, and a checklist.
HIPAA Compliance Tennessee: How the Federal and State Rules Interact
HIPAA (Health Insurance Portability and Accountability Act) is the floor everywhere. Under 45 CFR 160.203, a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. 45 CFR 160.202 defines more stringent to include a state law that "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted" or "provides for the retention or reporting of more detailed information or for a longer duration."
Tennessee took a different route from states like Illinois or California. Instead of writing stricter health privacy rules, its legislature carved HIPAA-regulated entities out of the two general data statutes that would otherwise overlap: the breach notification section of the Identity Theft Deterrence Act and the 2024 Tennessee Information Protection Act. The result is a state where, for a covered entity, the federal program is close to the whole program. The general framework is in state privacy laws vs federal HIPAA.
Who Qualifies as a Covered Entity in Tennessee
The definition is federal. 45 CFR 160.103 covers a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Hospitals and health systems in Nashville, Memphis, Knoxville, and Chattanooga, physician groups, dental offices, behavioral health providers, home health agencies, and nursing facilities that bill electronically all qualify. The test is walked through in what is a covered entity under HIPAA.
The federal definition also decides the state question. Tennessee's breach statute exempts "any information holder that is subject to" HIPAA as expanded by HITECH. A practice that is a covered entity is outside the state breach statute; a cash-only practice that never files an electronic claim is not a covered entity and is inside it.
Who Qualifies as a Business Associate in Tennessee
Also federal. 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, and any subcontractor "that creates, receives, maintains, or transmits protected health information on behalf of the business associate." Each one signs a business associate agreement, and each one is directly bound by the Security Rule and the Breach Notification Rule. Business associates are "subject to" HIPAA in their own right, so the state exemption reaches them too. Their duty to tell the practice about a breach comes from 45 CFR 164.410: "without unreasonable delay and in no case later than 60 calendar days after discovery."
Tennessee Laws That Touch Health Data
T.C.A. 47-18-2107: Breach Notification, and Its HIPAA Exemption
Tennessee's breach section was rewritten twice in two years. Public Chapter 692 of 2016 set the deadline at 45 days and added the HIPAA exemption; Public Chapter 91 of 2017 restated the whole section. As enacted, a "breach of system security" is the acquisition by an unauthorized person of unencrypted computerized data, or encrypted data together with the key, "that materially compromises the security, confidentiality, or integrity of personal information." Personal information is a name plus a Social Security number, a driver license number, or an account or card number with its access code. Medical information is not on the list.
The operative sentence for health care is subsection (i): "This section does not apply to any information holder that is subject to: (1) Title V of the Gramm-Leach-Bliley Act of 1999; or (2) The Health Insurance Portability and Accountability Act of 1996, as expanded by the Health Information Technology for Clinical and Economic Health Act." A covered entity or business associate follows the federal Breach Notification Rule and does not owe a separate Tennessee notice. The exemption is written at the entity level, so it applies to the whole information holder, not only to its PHI. Where a breach also involves employee payroll data, counsel should confirm how the exemption reads on those facts.
The Tennessee Information Protection Act (T.C.A. 47-18-3201 and Following)
Public Chapter 408 of 2024, the Tennessee Information Protection Act (TIPA), took effect July 1, 2025. It applies to businesses that exceed $25,000,000 in revenue and either control or process personal information of at least 25,000 consumers while deriving more than half their revenue from selling it, or process personal information of at least 175,000 consumers in a year. Section 47-18-3210(a)(4) exempts "a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States department of health and human services, 45 CFR Parts 160 and 164," and the act separately exempts protected health information, information used for public health activities, and information intermingled with HIPAA-exempt data held by a covered entity or business associate. A HIPAA-covered practice can set TIPA aside.
Medical Records and Mental Health Statutes
Tennessee does have state statutes on patient access to medical records (Title 63, Chapter 2), hospital records (Title 68, Chapter 11), and confidentiality of mental health and substance use records (Title 33). The deadlines, fee schedules, and retention periods in those sections could not be confirmed against the official code for this article, so they are not stated here. A practice should treat them as real, ask counsel for the current text, and remember that where they are stricter about privacy or give patients more, they control under 160.203(b). The federal access deadline, 30 days under 45 CFR 164.524(b)(2), applies regardless; see the right of access guide, and for retention, how long to keep medical records.
Tennessee Breach Notification Requirements
For a covered entity in Tennessee, the breach rules are the federal ones. 45 CFR 164.402 defines a breach as "the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information," presumed to be a breach "unless the covered entity or business associate ... demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment" of four factors: the nature and extent of the PHI, the unauthorized person, whether the PHI was actually acquired or viewed, and the extent of mitigation.
The deadlines. 164.404(b): individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." 164.408(b): for breaches of 500 or more individuals, notice to HHS "contemporaneously with the notice required by 164.404(a)." 164.408(c): for smaller breaches, keep a log and report "not later than 60 days after the end of each calendar year." 164.406(a): for a breach involving "more than 500 residents of a State or jurisdiction," notify "prominent media outlets serving the State." The letter contents are set at 164.404(c): what happened and when, the types of PHI involved, steps individuals should take, what the practice is doing, and contact procedures including a toll-free number, email, website, or postal address. The full process is in the Breach Notification Rule guide.
What Tennessee Would Require of a Non-Exempt Practice
A practice outside HIPAA, such as a cash-only wellness clinic that never bills electronically, is an information holder under 47-18-2107. Its deadline is 45 days from discovery. Notice may be written, electronic, or, when the cost would exceed $250,000 or more than 500,000 persons are affected, substitute notice by email, website posting, and statewide media. If more than 1,000 persons are notified at once, the nationwide consumer reporting agencies must be told "of the timing, distribution, and content of the notices." The statute as enacted contains no requirement to notify the Tennessee Attorney General.
| Item | Federal HIPAA (applies to covered entities and BAs) | Tennessee 47-18-2107 (non-HIPAA information holders only) |
|---|---|---|
| Trigger | Breach of unsecured PHI, presumed unless a four-factor risk assessment shows a low probability of compromise | Unauthorized acquisition of unencrypted personal information, or encrypted data with the key, that materially compromises it |
| Data covered | Any P.H.I. (Protected Health Information) | Name plus SSN, driver license number, or account number with access code |
| Individual notice | Without unreasonable delay, no later than 60 calendar days after discovery | No later than 45 days from discovery or notification |
| Regulator notice | HHS, with individual notice if 500 or more; annual log if fewer | None in the statute |
| Other notices | Media if more than 500 residents of a state | Consumer reporting agencies if more than 1,000 persons |
| Who is covered | Covered entities and business associates | Everyone else; HIPAA and GLBA entities exempt |
HIPAA Penalties in Tennessee
Federal OCR Enforcement
Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted for inflation at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. The history is in the 2026 penalty amounts post, and what starts an investigation is in HIPAA violations: what triggers an investigation.
Tennessee State Enforcement
For a covered entity, there is no state breach penalty to add, because the state breach statute does not apply. For a non-exempt information holder, 47-18-2107(h) gives any injured customer the right to "institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section." The Tennessee Attorney General enforces the state's consumer protection laws generally; the specific civil penalty amounts under those laws were not confirmed from a primary source for this article and are not stated. Licensing boards, including the Board of Medical Examiners and the Board of Dentistry, can discipline licensees for records violations under their own rules.
HIPAA Compliance for Tennessee Healthcare Providers
Tennessee Hospitals and Health Systems
Large systems in Middle and East Tennessee run the full federal program, and at their scale nearly every breach clears the 500-individual line, which means contemporaneous HHS notice and media notice. The 2019 imaging settlement is the local reminder that an exposed server is a Security Rule case as much as a breach case: the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) has to be "accurate and thorough." Vendor counts are high; see BAA management.
Tennessee Dental Practices
A dental office is a covered entity from its first electronic claim, and from that moment the state breach statute steps aside. That is not a reason to relax. Dental billing files carry Social Security numbers and dates of birth, and a lost unencrypted laptop is a reportable federal breach with a 60-day clock. Encryption that meets HHS guidance takes the device out of the "unsecured PHI" definition; see the HIPAA encryption requirements post. Program basics are at HIPAA for dental practices.
Tennessee Behavioral Health Providers
Tennessee's Title 33 confidentiality provisions sit alongside HIPAA for mental health and substance use records, and programs holding substance use disorder treatment records also answer to 42 CFR Part 2, covered in 42 CFR Part 2 vs HIPAA. Where the state rule restricts a disclosure HIPAA would permit, the state rule controls. The federal program is at HIPAA for behavioral health.
Tennessee Home Health and Long-Term Care
Field devices and vendor sprawl are the exposures. Every scheduling, visit verification, and telehealth vendor is a business associate that needs a signed agreement and that owes the agency its own 60-day breach notice under 164.410. Full-disk encryption on phones and laptops is the control that turns a stolen device into a documented non-event.
Tennessee HIPAA Compliance Checklist
| Requirement | Federal or State | Deadline or Frequency | Documentation |
|---|---|---|---|
| Security risk analysis and risk management | Federal, 164.308(a)(1) | Ongoing; review at least annually | Signed risk analysis, remediation plan |
| Written policies and procedures | Federal, 164.316 and 164.530(i) | In place; retain 6 years | Policy set with revision dates |
| Workforce training | Federal, 164.530(b) and 164.308(a)(5) | New hires, material changes, annual refresh | Completion records |
| BAA with every PHI vendor | Federal, 164.308(b) and 164.504(e) | Before access; review annually | Signed BAA per vendor |
| Device and transmission encryption | Federal, 164.312 (addressable) | Every device that holds ePHI | Encryption inventory |
| Breach risk assessment | Federal, 164.402 | Every incident | Four-factor memo, dated |
| Breach notice to individuals and HHS | Federal, 164.404 and 164.408 | 60 days; HHS at the same time if 500 or more; annual log if fewer | Letters, HHS portal confirmation, breach log |
| Media notice | Federal, 164.406 | More than 500 residents of Tennessee | Press notice copy |
| State breach notice | State, 47-18-2107 | Not applicable to HIPAA-covered entities; 45 days for others | Counsel memo confirming exemption |
| Records access | Federal, 164.524; state Title 63 (confirm text) | 30 days federal | Request log |
| Notice of privacy practices | Federal, 164.520 | First service; post and publish | Acknowledgments |
A Note on the Proposed Security Rule Update
HHS published a proposed rule in January 2025 that would make encryption, multifactor authentication, and asset inventories explicit Security Rule requirements. It is proposed, not final, and OCR is not enforcing it; the timeline is in the Security Rule 2027 delay post. Tennessee practices have no state statute pushing them to encrypt, which makes the federal safe harbor for encrypted PHI the reason to do it now. This article is educational information, not legal advice; a Tennessee practice facing an incident should involve counsel early.
---
FAQ
Does Tennessee have its own HIPAA law?
No. Tennessee's breach notification statute, T.C.A. 47-18-2107, expressly does not apply to information holders subject to HIPAA and HITECH, and the Tennessee Information Protection Act exempts HIPAA covered entities and business associates. State statutes on medical records, hospital records, and mental health confidentiality still exist and control where they are stricter.
How quickly must a Tennessee practice report a data breach?
A HIPAA covered entity follows the federal rule: individual notice without unreasonable delay and no later than 60 calendar days after discovery, HHS notice at the same time when 500 or more individuals are affected, and media notice when more than 500 Tennessee residents are involved. The state's 45-day deadline applies only to information holders that are not subject to HIPAA.
Does Tennessee require notice to the Attorney General after a breach?
The breach statute as enacted in 2017 contains no Attorney General notice requirement, and HIPAA-covered entities are exempt from the statute anyway. HHS receives federal notice through its breach portal.
Does the Tennessee Information Protection Act apply to medical practices?
Not to HIPAA covered entities or business associates, which section 47-18-3210 exempts, and not to protected health information. The act, effective July 1, 2025, applies to businesses over $25,000,000 in revenue that meet consumer-count thresholds.
Who enforces health privacy law in Tennessee?
OCR enforces federal HIPAA, which is the operative law for covered entities. For non-exempt information holders, the state breach statute gives injured customers a private civil action, and the Tennessee Attorney General enforces consumer protection law generally. Licensing boards discipline licensees for records violations.
Conclusion
In Tennessee the state mostly steps aside, which means the federal program has to be complete on its own: risk analysis, policies, training, BAAs, and a breach process that runs without a state backstop. One Guy Consulting's Full-Scope plan builds exactly that. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.203 (preemption of state law)
- 45 CFR 160.202 (definition of more stringent)
- 45 CFR 160.103 (definitions)
- 45 CFR 164.402 (breach definitions)
- 45 CFR 164.404 (breach notification to individuals)
- 45 CFR 164.408 (breach notification to the Secretary)
- 45 CFR 164.308 (administrative safeguards, risk analysis)
- 45 CFR 160.404 (civil money penalty tiers)
- 45 CFR 102.3 (adjusted penalty amounts)
- Tennessee General Assembly, SB 2005 (2016) bill page: breach notification amendment
- Public Chapter 692 (2016): 45-day deadline and HIPAA exemption, enacted text
- Public Chapter 91 (2017): T.C.A. 47-18-2107 restated, enacted text
- Tennessee General Assembly, SB 73 / HB 1181 (2024) bill page: Tennessee Information Protection Act
- Public Chapter 408 (2024): Tennessee Information Protection Act, enacted text
Related Reading