For years, many organizations treated HIPAA as the primary—sometimes only—privacy framework worth worrying about. That’s no longer sufficient. A growing patchwork of state privacy laws, led by California’s CCPA and CPRA, now applies to companies far outside healthcare, and the compliance obligations don’t overlap neatly with HIPAA requirements.
Why HIPAA Alone Isn’t Enough Anymore
HIPAA governs protected health information within specific covered entities and business associates. But most organizations collect far more than health data—customer names, browsing behavior, purchase history, location data, and employee information all fall outside HIPAA’s scope. State privacy laws were created specifically to address this broader category of personal information, and they apply regardless of industry.
What CCPA and CPRA Actually Require
California’s Consumer Privacy Act, expanded by the California Privacy Rights Act, gives consumers specific rights over their personal data, including the right to:
- Know what personal information is being collected and how it’s used
- Delete personal information held by a business
- Opt out of the sale or sharing of personal information
- Correct inaccurate personal information
- Limit use of sensitive personal information
Businesses meeting certain revenue or data-volume thresholds must comply, even if they’re not physically located in California, as long as they collect data from California residents.
The Patchwork Problem
California isn’t alone. Virginia, Colorado, Connecticut, Utah, and a growing list of other states have passed their own privacy laws, each with slightly different requirements around consent, data minimization, breach notification, and consumer rights. This creates a compliance challenge: a single national privacy program has to account for variations across every state where an organization does business, rather than meeting one uniform standard.
Where Organizations Typically Fall Short
Common gaps include:
- No formal data inventory documenting what personal information is collected and where it’s stored
- Privacy policies that haven’t been updated to reflect current data practices or new state requirements
- No process for handling consumer rights requests within required timeframes
- Vendor contracts that don’t address data-sharing obligations under newer state laws
- Confusion about which state laws actually apply based on customer geography and revenue thresholds
Building a Scalable Privacy Program
Rather than chasing compliance state by state, organizations benefit from building a privacy program based on the strictest applicable requirements, then layering in state-specific nuances. This typically involves:
- Conducting a data mapping exercise to understand what’s collected, why, and where it flows
- Establishing a consumer rights request process that can scale across jurisdictions
- Updating privacy notices and consent mechanisms to meet current standards
- Reviewing vendor and third-party contracts for adequate data protection language
- Creating a monitoring process to track new state legislation as it’s enacted
Why This Matters Beyond Legal Risk
Privacy compliance failures carry real consequences—regulatory fines, private right of action exposure in some states, and reputational damage. But a mature privacy program also builds customer trust and increasingly factors into enterprise sales cycles, where buyers expect vendors to demonstrate responsible data handling as part of security due diligence.
How Steadfast Partners Can Help
Steadfast Partners helps organizations build privacy compliance programs that scale across state requirements without duplicating effort—from data mapping through policy updates and ongoing monitoring. If your compliance program was built around HIPAA and hasn’t caught up to broader privacy obligations, call 737-210-5503 to discuss where the gaps might be.

