Tennessee HIPAA Laws: Records, Breaches, and Penalties

Health information in Tennessee is governed by federal HIPAA rules and a set of Tennessee statutes that go further on several points. The Tennessee HIPAA laws that matter most to patients and providers include the Patient’s Privacy Protection Act, the mental health confidentiality statute at Tenn. Code Ann. 33-3-103, the medical records access statute, and the state breach notification law. Where federal and state rules overlap, the stricter one controls, which is why Tennessee providers face shorter deadlines for records requests and breach notices than HIPAA alone would require.

Who Has to Follow HIPAA in Tennessee

HIPAA covers three types of organizations: healthcare providers that transmit health information electronically, health plans, and healthcare clearinghouses. In practice that means hospitals, physician practices, dentists, pharmacies, and insurers including TennCare. Third-party vendors that handle protected health information for those entities, called business associates, are directly liable under HIPAA too. Billing companies, IT providers, cloud storage firms, and law firms handling medical records during litigation all fall in that category, and the Office for Civil Rights can penalize them the same way it penalizes covered entities.1Office of the Law Revision Counsel. 42 USC 17934 – Application of Privacy Provisions and Penalties to Business Associates of Covered Entities

What HIPAA Does Not Cover

Not every organization holding health information is covered. Employers are not covered entities just because they keep employee health records. Sick notes, workers’ compensation paperwork, fitness-for-duty reports, and drug test results held in HR files are employment records, and HIPAA does not reach them. An employer-sponsored group health plan is a covered entity, but the employer itself is not, and organizations that sponsor plans have to wall off plan administration staff from staff who make hiring and disciplinary decisions.

How Tennessee Law Goes Further Than HIPAA

HIPAA’s Privacy Rule is a national floor. Tennessee raises it in several places.

The Patient’s Privacy Protection Act

Starting at Tenn. Code Ann. 68-11-1501, the Patient’s Privacy Protection Act restricts how identifying patient information can be shared.2Justia. Tennessee Code 68-11-1501 – Short Title Section 68-11-1503 prohibits disclosure of names, addresses, and other identifying details except in limited situations: when a statute requires it (such as public health reporting), when a third-party payer needs it for utilization review or case management, when it goes to other providers involved in the patient’s care, or when the patient did not object to basic directory information after being told they could. Selling patient identifying information is flatly prohibited.3FindLaw. Tennessee Code 68-11-1503 – Patient Privacy Protections

Mental Health Records

Tennessee Code 33-3-103 requires that any record identifying someone as a recipient of mental health services stay confidential unless disclosure is specifically authorized.4Justia. Tennessee Code 33-3-103 – Confidentiality of Mental Health Records Section 33-3-104 lists who can consent to release: the patient (if 16 or older), a conservator, an attorney-in-fact under a power of attorney, a parent or legal guardian of a minor, a guardian ad litem for litigation, a treatment review committee for an involuntarily committed patient, or an executor or personal representative for a deceased patient.5Justia. Tennessee Code 33-3-104 – Persons Who May Consent to Disclosure Without consent from one of those people, mental health records generally stay put.

Substance Use Disorder Records

Substance use records live under a separate federal regulation, 42 CFR Part 2, which historically ran stricter than HIPAA.6eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records A recent final rule partially aligned Part 2 with HIPAA by allowing a single patient consent covering all future treatment, payment, and healthcare operations disclosures. A HIPAA-covered entity that receives records under that consent can then redisclose them under standard HIPAA rules. Part 2 still bars using these records against patients in civil, criminal, or administrative proceedings without separate consent or a court order.7U.S. Department of Health & Human Services. Fact Sheet 42 CFR Part 2 Final Rule

Getting Your Medical Records in Tennessee

HIPAA gives you the right to see, copy, and request corrections to your records. Tennessee tightens the response deadlines and caps what a provider can charge.

Response Time

HIPAA gives a provider 30 days to respond, with a possible 30-day extension. Tennessee cuts that: providers must furnish copies within 10 working days of a written request from the patient or authorized representative. A provider may offer a summary, but a summary does not replace the full record if you asked for one.8Justia. Tennessee Code 63-2-101 – Release of Medical Records

Copy Fees

For paper records, Tennessee caps the charge at $25 for the first five pages and $0.50 per page after that, plus actual mailing costs. Electronic records requested by someone other than the patient follow a separate schedule: up to $25 for the first 10 pages, then $0.25 per page up to $90. Radiology images on disc or USB run no more than $25 per request, or $15 if sent electronically. When you request your own records, HIPAA’s cost-based standard applies rather than the state per-page caps.9Justia. Tennessee Code 63-2-102 – Costs of Reproduction, Copying

Amendments

If your records contain an error, you can ask the provider to correct them. A denial has to come with a written explanation, and you can submit a statement of disagreement that becomes part of the permanent record.

Records After a Patient’s Death

HIPAA continues to protect health information for 50 years after death. During that window, a personal representative such as an executor or estate administrator has the same access rights the patient would have had.10U.S. Department of Health and Human Services. Health Information of Deceased Individuals

How Long Hospitals Keep Records

Tennessee hospitals must retain patient care and treatment records for at least 10 years after discharge or death. For minors or patients with a mental disability, the clock runs 10 years after discharge or one year after the disability or minority ends, whichever is longer.11Justia. Tennessee Code 68-11-305 – Preservation of Records

When Providers Can Share Your Information Without Asking

HIPAA permits several categories of disclosure without patient authorization, subject to sharing only the minimum necessary.

  • Treatment, payment, and operations. Providers can share with specialists, pharmacists, and labs; insurers and billing staff can use records to process claims.
  • Public health reporting. Tennessee law requires reporting of certain infectious diseases to the Department of Health, and HIPAA permits it.
  • Law enforcement and court proceedings. Providers must respond to court orders, subpoenas, and warrants, and must report suspected abuse, neglect, or domestic violence to agencies such as the Department of Children’s Services or Adult Protective Services.
  • Family and friends involved in your care. A provider can share relevant information with people you identify as involved in your care or payment as long as you do not object, and a pharmacist may use professional judgment to let someone pick up a prescription for you.12U.S. Department of Health and Human Services. Disclosures to Family and Friends

Hospital directory information (name, general condition, location) can be shared with visitors and callers under the Patient’s Privacy Protection Act, but only if you were told at admission that you could object and did not. If you are incapacitated with no next of kin available to object, directory information may be included by default.3FindLaw. Tennessee Code 68-11-1503 – Patient Privacy Protections

Data Breach Notification

HIPAA requires covered entities to notify affected individuals no later than 60 days after discovering a breach of unsecured protected health information, with written notice by first-class mail or by email if the patient previously agreed to electronic communication. When contact information is outdated and 10 or more people are affected, the entity has to post a conspicuous notice on its website for 90 days and publish in major print or broadcast media, plus keep a toll-free number active for at least 90 days.13U.S. Department of Health and Human Services. Breach Notification Rule

Tennessee cuts that window. Under Tenn. Code Ann. 47-18-2107, notification must go out within 45 days of discovery. Law enforcement can request a delay to protect a criminal investigation, but notice still has to go out within 45 days after law enforcement clears it. Any breach affecting more than 1,000 people also triggers notice to all nationwide consumer reporting agencies. Someone injured by a notification violation can sue for damages and seek an injunction.14Justia. Tennessee Code 47-18-2107 – Release of Personal Information

Penalties

OCR imposes civil monetary penalties on a four-tier scale that runs from unknowing violations at the low end to uncorrected willful neglect at the top. The 2025 inflation-adjusted figures range from $145 per violation for the lowest tier up to $2,190,294 per violation and per year for the most serious. Because each affected record can count as its own violation, exposure from a single breach can multiply quickly.15Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

Criminal penalties apply to anyone who knowingly obtains or discloses individually identifiable health information in violation of HIPAA. A basic offense carries up to $50,000 and one year in prison. Obtaining information under false pretenses raises that to $100,000 and five years. Intent to sell, transfer, or use the information for commercial advantage or malicious harm carries up to $250,000 and 10 years. These penalties reach any person, not just covered entities and business associates, and the Department of Justice handles the prosecutions.16Office of the Law Revision Counsel. 42 US Code 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

On the state side, Tennessee’s Consumer Protection Act and Identity Theft Deterrence Act can both apply when health information is mishandled. The Attorney General can pursue entities that violate state privacy rules, and affected individuals may have civil claims for identity theft or deceptive practices. State claims can stack on federal HIPAA penalties.

How to File a Complaint

The Office for Civil Rights within HHS handles federal HIPAA complaints and investigates possible Privacy, Security, and Breach Notification Rule violations. Complaints must be filed within 180 days of when you knew about the violation, though OCR can extend that deadline for good cause. Serious cases may go to the Department of Justice for criminal prosecution.17U.S. Department of Health and Human Services. How to File a Health Information Privacy or Security Complaint

For state-specific medical privacy laws, the Tennessee Department of Health takes reports about violations of the Patient’s Privacy Protection Act and related statutes. For identity theft, deceptive practices, or consumer harm tied to a privacy breach, the Tennessee Attorney General’s Office is the right contact. Tennessee residents can also file civil lawsuits for financial losses or emotional distress caused by unauthorized disclosure of medical information.