HIPAA is a floor, and a floor is not a ceiling.
HIPAA expressly does not preempt state law that is more protective, and several states are. Washington has a consumer health data act with a private right of action, a health care information statute that predates HIPAA and is stricter in places, and a breach clock half the length of the federal one. An assessment that only checks the federal boxes will pass and still leave the exposure in place.
Four provisions that outrank or outrun HIPAA.
These four are Washington's, cited to statute. They are the worked example because they are the set I have read most closely. The pattern generalizes: a consumer health data law, an older disclosure statute, a shorter breach clock, and a behavioral health layer.
My Health My Data Act
Washington's consumer health data law, RCW 19.373. It reaches health data that HIPAA does not: data held by organizations that are not covered entities, and data about health that never touched a clinical system. It requires a separate consumer health data privacy policy, and it carries a private right of action, which is the part that changes the risk calculation. A program that is fully HIPAA-compliant can still sit squarely inside this law's reach.
Uniform Health Care Information Act
RCW 70.02, a state health care information disclosure statute that predates HIPAA, still applies, and in several places is stricter, which means HIPAA does not preempt it. Disclosure without authorization, patient access, and record retention all have state answers that differ from the federal floor.
Data breach notification
Under RCW 19.255, notice to affected consumers and, above 500 residents, to the Attorney General, within 30 days. HIPAA allows 60. If you plan your incident response to the federal clock, you are already late under the state one.
Behavioral health and SUD records
Programs holding substance use disorder records carry 42 CFR Part 2 on top of HIPAA, and the 2024 final rule moved the notice and consent requirements. States layer their own involuntary treatment and disclosure provisions on top of that.
This is a practitioner's summary, not legal advice, and statutes change. Where you need an opinion on your own facts, retain counsel. See the terms.
The state layer is inside the assessment, not a separate invoice.
A risk analysis scoped only to 45 CFR 164.308(a)(1)(ii)(A) produces a document that is correct and incomplete. The assessment reads the federal requirement and the state provisions that sit above it together, because that is the combination you are actually held to. Where a provision has no federal analogue, the finding says so and cites the statute.
Part of the assessment happens on site. 45 CFR 164.310 is about a physical environment, and a questionnaire cannot see one: it cannot tell you what is visible on an unattended screen at the front desk, or which door does not latch. The on-site walkthrough is in scope at the published price, and travel is settled in the intake conversation rather than billed as a surprise.
Two ways in.
The Security Risk Assessment at starting at $3,500, including the on-site walkthrough and a read on 45 CFR 164.308(a)(1)(ii)(A) plus the state provisions above. Or the compliance officer retainer from $2,500/mo if the program needs an owner rather than a report.