HIPAA laws in Illinois combine the federal HIPAA Privacy, Security, and Breach Notification Rules with a set of state statutes that go further than federal law in several important areas. Illinois organizations that handle health data have to satisfy both layers, and where the state rule is stricter, the state rule wins. The three Illinois laws that most often add obligations beyond HIPAA are the Personal Information Protection Act (PIPA), the Mental Health and Developmental Disabilities Confidentiality Act, and the Biometric Information Privacy Act (BIPA).
How Federal HIPAA and Illinois Law Fit Together
HIPAA sets a federal floor for health information privacy. It does not preempt state laws that offer stronger protection, and Illinois has several. The practical rule is simple: when an Illinois statute is more protective of patient privacy than HIPAA, the Illinois statute controls.
PIPA is the clearest example of the overlap. It protects personal information, including medical information and health insurance data, held by any “data collector” in the state. That definition reaches beyond HIPAA’s covered entities and business associates to include businesses, universities, and state agencies handling personal data of Illinois residents. PIPA’s breach notification and data disposal rules apply whether or not the organization is HIPAA-covered.
The result is that a single incident at an Illinois healthcare organization often triggers multiple compliance tracks at once: federal HIPAA duties to OCR, PIPA duties to the Illinois Attorney General, and potentially BIPA exposure through private lawsuits.
Mental Health Records Have Stricter Consent Rules
The Mental Health and Developmental Disabilities Confidentiality Act (740 ILCS 110) imposes consent requirements well beyond HIPAA’s general authorization framework. All records and communications created during mental health or developmental disabilities services are confidential and cannot be disclosed except as the Act specifically allows.
When a patient does consent, the written consent form must include:
- The specific person or agency who will receive the information
- The purpose of the disclosure
- The nature of the information being disclosed
- The patient’s right to inspect and copy the information before it goes out
- A calendar expiration date (without one, the information can only be released on the day the form is received)
- The patient’s right to revoke consent at any time in writing
Blanket consents authorizing disclosure of unspecified information are invalid. Only information relevant to the stated purpose can be released. Anyone who receives disclosed mental health records cannot share them further unless the patient specifically consents to that redisclosure, and these restrictions survive the patient’s death. Organizations that handle both general medical and mental health records need two consent workflows, not one.
BIPA in Healthcare Settings
BIPA regulates the collection, storage, and use of biometric identifiers such as fingerprints, retina scans, voiceprints, and facial geometry scans. Before collecting biometric data, an organization must obtain written informed consent and publish a written policy establishing a retention schedule and destruction guidelines.
BIPA carves out biometric information captured from a patient in a healthcare setting, as well as biometric information collected, used, or stored for treatment, payment, or operations under HIPAA. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court confirmed that the exemption covers both patient-sourced data and data used for HIPAA-defined purposes regardless of the source.
The exemption does not extend to everything a hospital or clinic collects. An employee fingerprint scan used for clocking in and out is not patient information and is not being used for treatment, payment, or operations, so it falls squarely under BIPA. Violations carry liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney fees and costs. BIPA provides a private right of action, meaning any aggrieved individual can sue directly. For a healthcare employer with hundreds of employees on a fingerprint clock, the aggregate exposure from a consent gap can be substantial.
Security and Privacy Obligations
The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic protected health information (ePHI). On the administrative side, every organization must conduct a risk analysis assessing threats to the confidentiality, integrity, and availability of ePHI, then implement risk management measures that reduce those vulnerabilities to a reasonable level. This is not a one-time exercise; the analysis needs updating as systems, threats, and workflows change.
Technical safeguards include access controls, audit logs, integrity controls, and transmission security. Encryption is currently an “addressable” specification, meaning organizations must implement it or document why an equivalent alternative is reasonable. Regulators generally expect encryption for data in transit and at rest.
PIPA adds a parallel state duty. Data collectors must implement and maintain “reasonable security measures” to protect personal information. PIPA does not prescribe specific technical controls, but the reasonableness standard requires organizations to keep pace with evolving threats. An organization that suffers a breach after ignoring known vulnerabilities will struggle to argue its measures were reasonable.
Proposed 2026 Security Rule Changes
HHS published a proposed rule in January 2025 that would tighten the Security Rule considerably. The proposal would make encryption mandatory for nearly all ePHI, with limited exceptions for certain medical devices. Multi-factor authentication would shift from an addressable control to a required one for any system or user accessing ePHI. Organizations would have to document security actions and assessments and update the documentation at least every 12 months. As of early 2026, the rule remains a proposal and has not been finalized.
Patient Rights: Access and Amendments
HIPAA gives patients a right to access and obtain copies of their health information. A covered entity must respond within 30 days and may take a single 30-day extension if it gives the patient a written explanation and a date by which it will act. Fees for copies must be reasonable and cost-based, limited to labor for copying, supplies for the medium, and postage when the patient requests mailing.
Patients can also request amendments to inaccurate information. The organization has 60 days to act, with one possible 30-day extension. If it accepts the amendment, it must make reasonable efforts to share the corrected information with business associates and others known to have the inaccurate version. If it denies the request, it must provide a written explanation and let the patient file a statement of disagreement that gets attached to the disputed record for all future disclosures.
Business Associate Agreements
Any third party that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate and must sign a business associate agreement (BAA) before accessing PHI. Cloud storage providers, billing companies, IT support firms, medical transcription services, and health information exchanges are common examples.
Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for compliance with specific HIPAA requirements. OCR can take enforcement action against a business associate for failing to comply with the Security Rule, failing to report a breach to the covered entity, making impermissible uses or disclosures of PHI, failing to provide ePHI to a patient who requests it, and failing to enter into downstream BAAs with subcontractors. Any subcontractor that will handle PHI needs its own BAA.
Under the proposed 2026 changes, business associates would have to report activation of their contingency plans to the covered entity within 24 hours. BAA management is best treated as an ongoing task. A BAA signed five years ago that does not reflect current data flows or subcontractors creates real liability exposure.
When PHI Can Be Shared Without Authorization
HIPAA permits disclosures without patient authorization in several defined circumstances.
Public Health
Covered entities can share PHI with public health authorities legally authorized to receive reports for preventing or controlling disease, injury, or disability. This includes reporting births, deaths, diseases, and injuries, along with public health surveillance and investigations. PHI can also be disclosed to report known or suspected child abuse or neglect to authorized government agencies, and to report adverse events and product defects to entities regulated by the FDA.
Law Enforcement
PHI can be disclosed to law enforcement without a warrant under narrow conditions. A covered entity may respond to an administrative subpoena or investigative demand if the information is relevant to a legitimate inquiry, the request is limited in scope, and de-identified information could not reasonably serve the same purpose. To help identify or locate a suspect, fugitive, or missing person, an entity may share basic identifiers like name, address, date of birth, and physical description, but not DNA, dental records, or body fluid analyses.
A covered entity that believes criminal conduct occurred on its premises may disclose relevant PHI in good faith. During off-premises emergency care, limited disclosures are permitted to alert law enforcement about the nature and location of a crime and the identity of a perpetrator. These exceptions are narrowly drawn, and disclosing more than the specific exception allows carries the same penalties as any other unauthorized disclosure.
Research
PHI can be used for research without individual authorization if an Institutional Review Board or a privacy board approves a waiver. The waiver requires documentation showing minimal privacy risk, adequate plans to protect and destroy identifiers, and that the research could not practicably be conducted without the waiver.
Breach Notification Timelines
When a breach of unsecured PHI occurs, federal and Illinois law both impose notification duties, and the timelines are not identical.
Under the federal HIPAA Breach Notification Rule, a covered entity must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovering the breach. A breach is “discovered” on the first day the entity knows about it or, through reasonable diligence, should have known. Notification goes out by first-class mail or email if the individual has agreed to electronic notice. When contact information is insufficient for 10 or more people, the entity must post a conspicuous notice on its website for 90 days or issue notice through major media outlets.
PIPA applies to any data collector holding personal information about Illinois residents. For private entities, it requires notification “in the most expedient time possible and without unreasonable delay,” but sets no specific day count. A separate 45-day deadline applies only to state agencies notifying the Attorney General, not to private organizations notifying affected individuals. PIPA also requires data collectors to notify the Attorney General when a breach occurs, and the AG may then publish the name of the breached organization, the types of personal information compromised, and the date range of the breach. Illinois organizations should plan to meet whichever deadline is shortest for each obligation.
Penalties for Non-Compliance
Federal HIPAA civil penalties fall into four tiers based on culpability. The dollar amounts are adjusted annually for inflation; the figures below reflect the 2026 adjustments effective January 28, 2026.
- Tier 1, Did not know: the entity was unaware of the violation and could not reasonably have known. $145 to $73,011 per violation.
- Tier 2, Reasonable cause: the violation resulted from reasonable cause rather than willful neglect. $1,461 to $73,011 per violation.
- Tier 3, Willful neglect, corrected: willful neglect corrected within 30 days of when the entity knew or should have known. $14,602 to $73,011 per violation.
- Tier 4, Willful neglect, not corrected: willful neglect not corrected within 30 days. $73,011 to $2,190,294 per violation.
The calendar-year cap for all violations of the same provision is $2,190,294. These penalties apply to both covered entities and business associates.
Criminal Penalties
A person who knowingly obtains or discloses individually identifiable health information in violation of HIPAA faces criminal prosecution on three levels:
- Basic violation: a fine up to $50,000 and up to one year in prison.
- False pretenses: a fine up to $100,000 and up to five years in prison.
- Commercial or malicious intent: a fine up to $250,000 and up to 10 years in prison when the offense is committed with intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm.
Illinois State Penalties
A PIPA violation constitutes an unlawful practice under the Illinois Consumer Fraud and Deceptive Business Practices Act, giving the Attorney General broad enforcement authority. For improper disposal of personal information, PIPA authorizes civil penalties of up to $100 per affected individual, capped at $50,000 per disposal incident. The AG can also seek injunctive relief.
BIPA damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation are recoverable through private lawsuits, individually or as class actions. For a healthcare employer that collected biometric data from a large workforce without proper consent, aggregate exposure can climb quickly.
Who Enforces These Laws
At the federal level, the HHS Office for Civil Rights is the primary HIPAA enforcement body. OCR investigates complaints, conducts compliance audits, and imposes civil monetary penalties. The HITECH Act requires HHS to periodically audit covered entities and business associates for compliance with the Privacy, Security, and Breach Notification Rules.
HITECH also gave state attorneys general authority to bring civil actions on behalf of state residents for HIPAA Privacy and Security Rule violations. Illinois healthcare organizations therefore face potential enforcement from both OCR and the Illinois Attorney General.
For Illinois-specific privacy laws, the Attorney General’s office handles PIPA enforcement directly, including breach investigations and improper disposal penalties. BIPA enforcement runs primarily through private litigation because the statute creates an individual right of action. One incident can produce an OCR investigation, an AG enforcement action under HITECH and PIPA, and a private BIPA lawsuit from employees, all at the same time.