Enforcement
HIPAA establishes civil and criminal penalties for violation of HIPAA. Criminal penalties include up to $250,000 for each violation and up to 10 years in prison.
Preemption
The HIPAA Privacy Rule establishes a uniform minimum for protecting the privacy of PHI. The HIPAA Privacy Rule preempts, or overrides, state laws that are contrary to, and that are less protective than the HIPAA Privacy Rule. State laws related to the privacy of health information that are more protective than the federal rule will remain in effect.