HIPAA Compliance in Tennessee: What the State Adds, and What It Leaves to HIPAA

Practical guidance for healthcare teams and business associates

An imaging center in Knoxville learns from a security researcher that one of its servers has been reachable from the internet, unprotected, for months. Every study on it is exposed. The federal clock starts: 60 days to notify patients, HHS at the same time if 500 or more are affected, and the media if more than 500 Tennesseans are involved. The center then asks the state question and gets an answer that surprises most practices: Tennessee's breach statute does not apply to it at all.

That scenario is not invented. OCR (the HHS Office for Civil Rights) announced on May 6, 2019 that a Tennessee diagnostic medical imaging services company paid $3,000,000 to settle a breach exposing over 300,000 patients' protected health information. Federal enforcement is the enforcement that matters in Tennessee. This article covers how federal and state rules interact, who is a covered entity or business associate in Tennessee, the state statutes that touch health data and the ones that expressly do not, the breach rules, penalties, provider-type notes, and a checklist.

HIPAA Compliance Tennessee: How the Federal and State Rules Interact

HIPAA (Health Insurance Portability and Accountability Act) is the floor everywhere. Under 45 CFR 160.203, a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. 45 CFR 160.202 defines more stringent to include a state law that "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted" or "provides for the retention or reporting of more detailed information or for a longer duration."

Tennessee took a different route from states like Illinois or California. Instead of writing stricter health privacy rules, its legislature carved HIPAA-regulated entities out of the two general data statutes that would otherwise overlap: the breach notification section of the Identity Theft Deterrence Act and the 2024 Tennessee Information Protection Act. The result is a state where, for a covered entity, the federal program is close to the whole program. The general framework is in state privacy laws vs federal HIPAA.

Who Qualifies as a Covered Entity in Tennessee

The definition is federal. 45 CFR 160.103 covers a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Hospitals and health systems in Nashville, Memphis, Knoxville, and Chattanooga, physician groups, dental offices, behavioral health providers, home health agencies, and nursing facilities that bill electronically all qualify. The test is walked through in what is a covered entity under HIPAA.

The federal definition also decides the state question. Tennessee's breach statute exempts "any information holder that is subject to" HIPAA as expanded by HITECH. A practice that is a covered entity is outside the state breach statute; a cash-only practice that never files an electronic claim is not a covered entity and is inside it.

Who Qualifies as a Business Associate in Tennessee

Also federal. 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, and any subcontractor "that creates, receives, maintains, or transmits protected health information on behalf of the business associate." Each one signs a business associate agreement, and each one is directly bound by the Security Rule and the Breach Notification Rule. Business associates are "subject to" HIPAA in their own right, so the state exemption reaches them too. Their duty to tell the practice about a breach comes from 45 CFR 164.410: "without unreasonable delay and in no case later than 60 calendar days after discovery."

Tennessee Laws That Touch Health Data

T.C.A. 47-18-2107: Breach Notification, and Its HIPAA Exemption

Tennessee's breach section was rewritten twice in two years. Public Chapter 692 of 2016 set the deadline at 45 days and added the HIPAA exemption; Public Chapter 91 of 2017 restated the whole section. As enacted, a "breach of system security" is the acquisition by an unauthorized person of unencrypted computerized data, or encrypted data together with the key, "that materially compromises the security, confidentiality, or integrity of personal information." Personal information is a name plus a Social Security number, a driver license number, or an account or card number with its access code. Medical information is not on the list.

The operative sentence for health care is subsection (i): "This section does not apply to any information holder that is subject to: (1) Title V of the Gramm-Leach-Bliley Act of 1999; or (2) The Health Insurance Portability and Accountability Act of 1996, as expanded by the Health Information Technology for Clinical and Economic Health Act." A covered entity or business associate follows the federal Breach Notification Rule and does not owe a separate Tennessee notice. The exemption is written at the entity level, so it applies to the whole information holder, not only to its PHI. Where a breach also involves employee payroll data, counsel should confirm how the exemption reads on those facts.

The Tennessee Information Protection Act (T.C.A. 47-18-3201 and Following)

Public Chapter 408 of 2024, the Tennessee Information Protection Act (TIPA), took effect July 1, 2025. It applies to businesses that exceed $25,000,000 in revenue and either control or process personal information of at least 25,000 consumers while deriving more than half their revenue from selling it, or process personal information of at least 175,000 consumers in a year. Section 47-18-3210(a)(4) exempts "a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States department of health and human services, 45 CFR Parts 160 and 164," and the act separately exempts protected health information, information used for public health activities, and information intermingled with HIPAA-exempt data held by a covered entity or business associate. A HIPAA-covered practice can set TIPA aside.

Medical Records and Mental Health Statutes

Tennessee does have state statutes on patient access to medical records (Title 63, Chapter 2), hospital records (Title 68, Chapter 11), and confidentiality of mental health and substance use records (Title 33). The deadlines, fee schedules, and retention periods in those sections could not be confirmed against the official code for this article, so they are not stated here. A practice should treat them as real, ask counsel for the current text, and remember that where they are stricter about privacy or give patients more, they control under 160.203(b). The federal access deadline, 30 days under 45 CFR 164.524(b)(2), applies regardless; see the right of access guide, and for retention, how long to keep medical records.

Tennessee Breach Notification Requirements

For a covered entity in Tennessee, the breach rules are the federal ones. 45 CFR 164.402 defines a breach as "the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information," presumed to be a breach "unless the covered entity or business associate ... demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment" of four factors: the nature and extent of the PHI, the unauthorized person, whether the PHI was actually acquired or viewed, and the extent of mitigation.

The deadlines. 164.404(b): individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." 164.408(b): for breaches of 500 or more individuals, notice to HHS "contemporaneously with the notice required by 164.404(a)." 164.408(c): for smaller breaches, keep a log and report "not later than 60 days after the end of each calendar year." 164.406(a): for a breach involving "more than 500 residents of a State or jurisdiction," notify "prominent media outlets serving the State." The letter contents are set at 164.404(c): what happened and when, the types of PHI involved, steps individuals should take, what the practice is doing, and contact procedures including a toll-free number, email, website, or postal address. The full process is in the Breach Notification Rule guide.

What Tennessee Would Require of a Non-Exempt Practice

A practice outside HIPAA, such as a cash-only wellness clinic that never bills electronically, is an information holder under 47-18-2107. Its deadline is 45 days from discovery. Notice may be written, electronic, or, when the cost would exceed $250,000 or more than 500,000 persons are affected, substitute notice by email, website posting, and statewide media. If more than 1,000 persons are notified at once, the nationwide consumer reporting agencies must be told "of the timing, distribution, and content of the notices." The statute as enacted contains no requirement to notify the Tennessee Attorney General.

ItemFederal HIPAA (applies to covered entities and BAs)Tennessee 47-18-2107 (non-HIPAA information holders only)
TriggerBreach of unsecured PHI, presumed unless a four-factor risk assessment shows a low probability of compromiseUnauthorized acquisition of unencrypted personal information, or encrypted data with the key, that materially compromises it
Data coveredAny P.H.I. (Protected Health Information)Name plus SSN, driver license number, or account number with access code
Individual noticeWithout unreasonable delay, no later than 60 calendar days after discoveryNo later than 45 days from discovery or notification
Regulator noticeHHS, with individual notice if 500 or more; annual log if fewerNone in the statute
Other noticesMedia if more than 500 residents of a stateConsumer reporting agencies if more than 1,000 persons
Who is coveredCovered entities and business associatesEveryone else; HIPAA and GLBA entities exempt

HIPAA Penalties in Tennessee

Federal OCR Enforcement

Civil money penalties follow the four culpability tiers in 45 CFR 160.404, adjusted for inflation at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. The history is in the 2026 penalty amounts post, and what starts an investigation is in HIPAA violations: what triggers an investigation.

Tennessee State Enforcement

For a covered entity, there is no state breach penalty to add, because the state breach statute does not apply. For a non-exempt information holder, 47-18-2107(h) gives any injured customer the right to "institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section." The Tennessee Attorney General enforces the state's consumer protection laws generally; the specific civil penalty amounts under those laws were not confirmed from a primary source for this article and are not stated. Licensing boards, including the Board of Medical Examiners and the Board of Dentistry, can discipline licensees for records violations under their own rules.

HIPAA Compliance for Tennessee Healthcare Providers

Tennessee Hospitals and Health Systems

Large systems in Middle and East Tennessee run the full federal program, and at their scale nearly every breach clears the 500-individual line, which means contemporaneous HHS notice and media notice. The 2019 imaging settlement is the local reminder that an exposed server is a Security Rule case as much as a breach case: the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) has to be "accurate and thorough." Vendor counts are high; see BAA management.

Tennessee Dental Practices

A dental office is a covered entity from its first electronic claim, and from that moment the state breach statute steps aside. That is not a reason to relax. Dental billing files carry Social Security numbers and dates of birth, and a lost unencrypted laptop is a reportable federal breach with a 60-day clock. Encryption that meets HHS guidance takes the device out of the "unsecured PHI" definition; see the HIPAA encryption requirements post. Program basics are at HIPAA for dental practices.

Tennessee Behavioral Health Providers

Tennessee's Title 33 confidentiality provisions sit alongside HIPAA for mental health and substance use records, and programs holding substance use disorder treatment records also answer to 42 CFR Part 2, covered in 42 CFR Part 2 vs HIPAA. Where the state rule restricts a disclosure HIPAA would permit, the state rule controls. The federal program is at HIPAA for behavioral health.

Tennessee Home Health and Long-Term Care

Field devices and vendor sprawl are the exposures. Every scheduling, visit verification, and telehealth vendor is a business associate that needs a signed agreement and that owes the agency its own 60-day breach notice under 164.410. Full-disk encryption on phones and laptops is the control that turns a stolen device into a documented non-event.

Tennessee HIPAA Compliance Checklist

RequirementFederal or StateDeadline or FrequencyDocumentation
Security risk analysis and risk managementFederal, 164.308(a)(1)Ongoing; review at least annuallySigned risk analysis, remediation plan
Written policies and proceduresFederal, 164.316 and 164.530(i)In place; retain 6 yearsPolicy set with revision dates
Workforce trainingFederal, 164.530(b) and 164.308(a)(5)New hires, material changes, annual refreshCompletion records
BAA with every PHI vendorFederal, 164.308(b) and 164.504(e)Before access; review annuallySigned BAA per vendor
Device and transmission encryptionFederal, 164.312 (addressable)Every device that holds ePHIEncryption inventory
Breach risk assessmentFederal, 164.402Every incidentFour-factor memo, dated
Breach notice to individuals and HHSFederal, 164.404 and 164.40860 days; HHS at the same time if 500 or more; annual log if fewerLetters, HHS portal confirmation, breach log
Media noticeFederal, 164.406More than 500 residents of TennesseePress notice copy
State breach noticeState, 47-18-2107Not applicable to HIPAA-covered entities; 45 days for othersCounsel memo confirming exemption
Records accessFederal, 164.524; state Title 63 (confirm text)30 days federalRequest log
Notice of privacy practicesFederal, 164.520First service; post and publishAcknowledgments

A Note on the Proposed Security Rule Update

HHS published a proposed rule in January 2025 that would make encryption, multifactor authentication, and asset inventories explicit Security Rule requirements. It is proposed, not final, and OCR is not enforcing it; the timeline is in the Security Rule 2027 delay post. Tennessee practices have no state statute pushing them to encrypt, which makes the federal safe harbor for encrypted PHI the reason to do it now. This article is educational information, not legal advice; a Tennessee practice facing an incident should involve counsel early.

---

FAQ

Does Tennessee have its own HIPAA law?

No. Tennessee's breach notification statute, T.C.A. 47-18-2107, expressly does not apply to information holders subject to HIPAA and HITECH, and the Tennessee Information Protection Act exempts HIPAA covered entities and business associates. State statutes on medical records, hospital records, and mental health confidentiality still exist and control where they are stricter.

How quickly must a Tennessee practice report a data breach?

A HIPAA covered entity follows the federal rule: individual notice without unreasonable delay and no later than 60 calendar days after discovery, HHS notice at the same time when 500 or more individuals are affected, and media notice when more than 500 Tennessee residents are involved. The state's 45-day deadline applies only to information holders that are not subject to HIPAA.

Does Tennessee require notice to the Attorney General after a breach?

The breach statute as enacted in 2017 contains no Attorney General notice requirement, and HIPAA-covered entities are exempt from the statute anyway. HHS receives federal notice through its breach portal.

Does the Tennessee Information Protection Act apply to medical practices?

Not to HIPAA covered entities or business associates, which section 47-18-3210 exempts, and not to protected health information. The act, effective July 1, 2025, applies to businesses over $25,000,000 in revenue that meet consumer-count thresholds.

Who enforces health privacy law in Tennessee?

OCR enforces federal HIPAA, which is the operative law for covered entities. For non-exempt information holders, the state breach statute gives injured customers a private civil action, and the Tennessee Attorney General enforces consumer protection law generally. Licensing boards discipline licensees for records violations.

Conclusion

In Tennessee the state mostly steps aside, which means the federal program has to be complete on its own: risk analysis, policies, training, BAAs, and a breach process that runs without a state backstop. One Guy Consulting's Full-Scope plan builds exactly that. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading