HIPAA Compliance in Virginia: The Health Records Privacy Statute and the Breach Law

Practical guidance for healthcare teams and business associates

A billing manager at a family practice in Chesterfield County clicks a link in an email that looks like it came from the clearinghouse. By the time anyone notices, the mailbox has been forwarding claim attachments to an outside address for three weeks. The practice knows the federal clock: 60 days to notify patients. Virginia adds a second question the same afternoon: does the Office of the Attorney General need to hear about this, and when?

Phishing is not a hypothetical. OCR (the HHS Office for Civil Rights) settled a HIPAA phishing cybersecurity investigation with Solara Medical Supplies for $3,000,000, announced January 14, 2025. Federal enforcement reaches Virginia the same as any other state; what changes is the state layer sitting on top. This article covers how the two layers interact, who is a covered entity or business associate in Virginia, the state statutes that stack on HIPAA, the breach rules, the penalties, provider-type notes, and a checklist.

HIPAA Compliance Virginia: How the Federal and State Rules Interact

HIPAA (Health Insurance Portability and Accountability Act) is the floor. The preemption rule at 45 CFR 160.203 says a federal standard "that is contrary to a provision of State law preempts the provision of State law," except, under 160.203(b), where the state law "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule. 45 CFR 160.202 defines "more stringent" to include a state law that "prohibits or restricts a use or disclosure in circumstances under which such use or disclosure otherwise would be permitted," one that "permits greater rights of access or amendment," and one that "provides for the retention or reporting of more detailed information or for a longer duration."

Virginia's main health privacy statute, Va. Code 32.1-127.1:03, was written with HIPAA in view. It borrows the federal definitions of health plan and clearinghouse from 45 CFR 160.103, cross-references 45 CFR 164.501 for health care operations, and ties its electronic access rules to HITECH and HIPAA. Where the two overlap, a practice that follows HIPAA is most of the way there. Where Virginia goes further, Virginia controls. The general framework is in state privacy laws vs federal HIPAA.

Who Qualifies as a Covered Entity in Virginia

Federally, 45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." In Virginia that is every hospital and health system, physician group, dental practice, behavioral health provider, home health agency, and nursing facility that bills electronically. The federal test is explained in what is a covered entity under HIPAA.

Virginia's statute reaches wider. 32.1-127.1:03(B) defines a "health care entity" as any health care provider, health plan, or clearinghouse, and "health care provider" includes "all persons who are licensed, certified, registered or permitted or who hold a multistate licensure privilege issued by any of the health regulatory boards within the Department of Health Professions" (funeral directors and veterinarians excepted). A cash-only counselor who never files an electronic claim may sit outside HIPAA and still owe every duty in the Virginia statute.

Who Qualifies as a Business Associate in Virginia

The business associate definition is federal. 160.103 covers a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, and data analysis, and any subcontractor "that creates, receives, maintains, or transmits protected health information on behalf of the business associate." Each one signs a business associate agreement.

Virginia's breach statute adds a parallel state duty. Va. Code 18.2-186.6(D) requires an entity that "maintains computerized data that includes personal information that the individual or entity does not own or license" to notify the owner "without unreasonable delay following discovery" of a breach. A vendor holding a Virginia practice's data has that state obligation alongside the federal one at 45 CFR 164.410.

Virginia Privacy Laws That Stack on Top of HIPAA

Va. Code 32.1-127.1:03: Health Records Privacy

Subsection A opens with a sentence HIPAA never wrote: "There is hereby recognized an individual's right of privacy in the content of his health records." Records are the property of the entity that maintains them, but "no health care entity, or other person working in a health care setting, may disclose an individual's health records" except as the statute or other state law permits. Three features matter most for a practice.

Redisclosure. Subdivision A.3: "No person to whom health records are disclosed shall redisclose or otherwise reveal the health records of an individual, beyond the purpose for which such disclosure was made, without first obtaining the individual's specific authorization." Health care entities may make subsequent disclosures the statute and the federal Privacy Rule allow, but the default for everyone else is a stop sign.

Access within 30 days. Subsection E requires a written, dated, signed request, and then "within 30 days of receipt" the entity must furnish the copies or electronic access, tell the requester the information does not exist or cannot be found, redirect the requester to the entity that holds the record, or deny the request on a ground the statute allows. That matches the federal 30-day deadline at 45 CFR 164.524(b)(2); the difference is that Virginia lists exactly four acceptable responses. The federal side is in the right of access guide.

Denials and psychotherapy notes. Subsection F permits a denial only when a treating physician, psychologist, clinical social worker, or licensed professional counselor has written in the record that access "would be reasonably likely to endanger the life or physical safety of the individual or another person," with a right to a reviewing professional, and psychotherapy notes require written authorization for nearly every disclosure.

Va. Code 18.2-186.6: Breach of Personal Information

Virginia's general breach law defines personal information as a resident's first name or initial and last name combined with a Social Security number, a driver's license or state ID number, a financial account or card number with the code that opens it, a passport number, or a military identification number, when the data is neither encrypted nor redacted. Medical information is not on the list. The statute is covered in detail below.

Va. Code 32.1-127.1:05: Breach of Medical Information

This section adds medical information, but only for public "entities": state agencies, political subdivisions, and organizations "supported wholly or principally by public funds." A public hospital or health district that suffers a breach of unencrypted medical information must notify the Office of the Attorney General, the Commissioner of Health, the subject, and affected residents "without unreasonable delay." Private practices are outside it.

Va. Code 32.1-36.1: HIV Test Results

"The results of every test to determine infection with human immunodeficiency virus shall be confidential." Release is limited to persons "permitted or authorized to obtain protected health information under any applicable federal or state law." A willful or grossly negligent unauthorized disclosure exposes the discloser to a civil penalty of up to $5,000 per violation, and the patient may sue for actual damages or $100, whichever is greater, plus attorney's fees.

18VAC85-20-26: Board of Medicine Records Rule

The Board of Medicine's regulation requires practitioners to keep patient records "for a minimum of six years following the last patient encounter," and for minors "until the child reaches 18 years of age or becomes emancipated," with the six-year floor still applying. Practitioners must post or otherwise tell patients the retention timeframe, and may destroy records only "in a manner that protects patient confidentiality, such as by incineration or shredding." HIPAA's own six-year rule at 45 CFR 164.316(b)(2)(i) and 164.530(j)(2) covers policies and compliance documentation, not the chart. Other boards set their own periods; see how long to keep medical records.

Va. Code 59.1-575 and Following: The Consumer Data Protection Act

Virginia's consumer privacy act applies to businesses that control or process the personal data of at least 100,000 consumers a year, or at least 25,000 consumers while earning more than half their revenue from selling personal data. Under 59.1-576(B), it does not apply to any "covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164," and 59.1-576(C) exempts protected health information, Title 32.1 health records, and 42 CFR Part 2 records outright.

Virginia Breach Notification Requirements

The federal rule first: 45 CFR 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," 164.408 requires HHS notice at the same time for breaches of 500 or more individuals and an annual log for smaller ones, and 164.406 requires media notice for breaches involving "more than 500 residents of a State or jurisdiction." The walkthrough is in the Breach Notification Rule guide.

The Virginia Trigger and Clock

Under 18.2-186.6(A), a "breach of the security of the system" is "the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information ... and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth."

Subsection B sets the clock: the entity "shall disclose any breach of the security of the system following discovery or notification of the breach ... to the Office of the Attorney General and any affected resident of the Commonwealth without unreasonable delay." No day count, but the Attorney General is on the list for every qualifying breach, not only large ones. Notice may be delayed to determine scope and restore the system, or at the request of law enforcement. If more than 1,000 persons are notified at once, subsection E adds notice to the nationwide consumer reporting agencies "of the timing, distribution, and content of the notice."

What the Virginia Notice Must Say

The statute requires a description of the incident in general terms, the type of personal information involved, the steps taken to protect it, a telephone number if one exists, and advice to review account statements and monitor credit reports, which maps onto the federal content list at 164.404(c), so one letter can carry both. Substitute notice is allowed only when notice would cost more than $50,000, would reach more than 100,000 residents, or contact information is missing.

Whether Following HIPAA Satisfies the Virginia Statute

Subsection H says an entity "that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity's primary or functional state or federal regulator shall be in compliance with this section." For a covered entity, that regulator is HHS, and the procedures are the Breach Notification Rule. Read plainly, a practice that follows 164.404 has satisfied 18.2-186.6. The safe harbor depends on actually following the federal procedure, on time and in full. Whether to send the Attorney General a notice anyway is a judgment call for counsel, not a rule in the text.

ItemFederal HIPAAVirginia 18.2-186.6
TriggerBreach of unsecured PHI under 164.402, presumed unless a four-factor risk assessment shows low probability of compromiseUnauthorized access and acquisition of unencrypted, unredacted personal information that causes or is reasonably believed to cause identity theft or fraud
Data coveredAny P.H.I. (Protected Health Information)Name plus SSN, license or state ID, financial account with code, passport, or military ID
Individual noticeWithout unreasonable delay, no later than 60 calendar daysWithout unreasonable delay; no day count
Regulator noticeHHS, with individual notice if 500 or more; annual log if fewerOffice of the Attorney General, every qualifying breach
Safe harborNoneCompliance with the primary federal regulator's procedures satisfies the section (subsection H)

HIPAA Penalties in Virginia

Federal OCR Enforcement

Civil money penalties follow the four tiers in 45 CFR 160.404, with inflation-adjusted amounts at 45 CFR 102.3. Under the 2025 adjustment, per violation: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. The calendar-year cap for identical violations is $2,190,294. Background is in the 2026 penalty amounts post.

Virginia Attorney General Enforcement

Under 18.2-186.6(I), the Attorney General "may bring an action to address violations of this section" and "may impose a civil penalty not to exceed $150,000 per breach of the security of the system or a series of breaches of a similar nature that are discovered in a single investigation." The same subsection preserves an individual's right to recover "direct economic damages." Unauthorized HIV disclosures carry the separate $5,000 civil penalty and $100 minimum private recovery under 32.1-36.1. Licensing boards may discipline practitioners who mishandle records under their own regulations.

HIPAA Compliance for Virginia Healthcare Providers

Virginia Hospitals and Health Systems

Health systems in Northern Virginia, Richmond, and Hampton Roads carry the full federal program plus the 32.1-127.1:03 access, denial, and redisclosure rules for every department. Publicly funded hospitals also sit inside 32.1-127.1:05, which adds the Commissioner of Health to the breach notice list. Review the BAA list at least annually.

Virginia Dental Practices

A dental office is a covered entity from its first electronic claim, and because dentists are licensed by a Department of Health Professions board, the state health records statute applies either way. The 30-day response window for records requests is both federal and state law.

Virginia Behavioral Health Providers

Counselors, psychologists, and clinical social workers appear by name in the statute's denial and psychotherapy notes provisions, providers treating patients in civil commitment proceedings have disclosure duties under Va. Code 37.2-804.2, and programs holding substance use disorder records also answer to 42 CFR Part 2.

Virginia Home Health and Long-Term Care

Field staff carry laptops and phones, and 18.2-186.6 turns on whether the data on them is encrypted. Full-disk encryption keeps a stolen device out of the state statute, and every scheduling, visit verification, and telehealth vendor needs a BAA and has its own state duty to notify the agency after a breach.

Virginia HIPAA Compliance Checklist

RequirementFederal or StateDeadline or FrequencyDocumentation
Security risk analysis and risk managementFederal, 164.308(a)(1)Ongoing; review at least annuallySigned risk analysis, remediation plan
BAA with every PHI vendorFederal, 164.308(b) and 164.504(e)Before access; review annuallySigned BAA per vendor
Records request responseFederal, 164.524; state, 32.1-127.1:03(E)30 days; one of four permitted responsesRequest log with dates
Redisclosure controlsState, 32.1-127.1:03(A)(3)Every outbound disclosureAuthorization on file, disclosure log
Access denial procedureState, 32.1-127.1:03(F); federal, 164.524(d)Each denialTreating provider's written statement, review offer
Record retentionState, 18VAC85-20-26 (physicians)6 years after last encounter; minors to 18Retention schedule, posted notice
Breach notice to individualsFederal and state60 days federal; without unreasonable delay stateLetters, mailing proof
Breach notice to the Attorney GeneralState, 18.2-186.6(B)Without unreasonable delay (subsection H safe harbor if HIPAA procedures followed)Filed notice or counsel memo on safe harbor

A Note on the Proposed Security Rule Update

The January 2025 proposed Security Rule update (explicit encryption, multifactor authentication, asset inventories) is proposed, not final, and OCR is not enforcing it. Virginia gives a practice its own reason to encrypt today: under 18.2-186.6, encrypted data with the key intact is not a breach. This article is educational information, not legal advice; a practice facing a real incident should involve counsel early.

---

FAQ

Does Virginia have its own HIPAA law?

Virginia's health records privacy statute, Va. Code 32.1-127.1:03, recognizes a right of privacy in the content of health records, restricts redisclosure, and sets a 30-day response window for records requests. It applies to every licensed provider, not only those that bill electronically. Federal HIPAA still applies in full.

How quickly must a Virginia practice report a data breach?

Federal HIPAA requires individual notice without unreasonable delay and no later than 60 calendar days after discovery. Va. Code 18.2-186.6 requires notice to the Office of the Attorney General and affected residents without unreasonable delay when unencrypted personal information such as Social Security numbers is acquired; if more than 1,000 persons are notified, consumer reporting agencies must be told as well.

Does following HIPAA satisfy Virginia's breach statute?

Subsection H of 18.2-186.6 deems an entity that complies with its primary federal regulator's notification procedures to be in compliance with the section. For a covered entity that regulator is HHS. The safe harbor depends on following the federal procedure fully and on time; many practices still notify the Attorney General when Social Security numbers are involved, on counsel's advice.

How long must Virginia physicians keep patient records?

The Board of Medicine regulation, 18VAC85-20-26, requires a minimum of six years after the last patient encounter, and records of minors until the child turns 18 or is emancipated, with the six-year floor still applying. Other health regulatory boards set their own periods.

Who enforces health privacy law in Virginia?

OCR enforces federal HIPAA. The Virginia Attorney General enforces the breach statute, with a civil penalty of up to $150,000 per breach or series of similar breaches. Health regulatory boards discipline licensees, and patients have private remedies under the HIV confidentiality statute and for direct economic damages after a breach.

Conclusion

Virginia rewards a practice that already runs a real federal program: the state statute borrows HIPAA's definitions, and the breach law defers to HIPAA procedures. One Guy Consulting's Full-Scope plan builds that program and layers the Virginia access, redisclosure, and retention rules onto it. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading