HIPAA Compliance in Vermont: State‑Specific Requirements for Providers and Business Associates
Adhering to HIPAA Privacy and Security Rules
Vermont follows HIPAA’s baseline requirements for safeguarding Protected Health Information (PHI), including the Minimum Necessary Standard, workforce training, ongoing risk analysis, and incident response. When you serve Vermont patients, remember HIPAA’s preemption rule: state laws that are more protective of patient privacy are not preempted and must also be followed.
Vermont overlays you must follow in addition to HIPAA include: strict confidentiality for HIV-related public health records and mandatory pre‑test notice that a positive test will be reported to the Department of Health; special consent rules for mental health information; limits on disclosure of genetic test results; and tight access controls and non‑redisclosure limits for Vermont’s Prescription Monitoring System (VPMS). If your practice is subject to 42 CFR Part 2 (substance use disorder records), those federal rules apply on top of HIPAA and Vermont law. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/021/01001?utm_source=openai))
If you are a health plan, TPA, or other required “reporter,” also account for Healthcare Claims Reporting (VHCURES). Vermont’s all‑payer claims database requires submission of eligibility and claims data under 18 V.S.A. § 9410 and Green Mountain Care Board rules, with confidentiality protections and sanctions for misuse. Build HIPAA and state‑law controls into your data pipelines and vendor contracts. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/221/09410?utm_source=openai))
- Do a Vermont‑aware risk assessment that maps PHI, VPMS data, and any consumer data outside HIPAA (see S.71 below).
- Apply role‑based access and the Minimum Necessary Standard across EHR, HIE, telehealth, and claims systems.
- Document state‑specific release‑of‑information workflows for HIV, mental health, genetic, and VPMS data.
Managing Business Associate Agreements
Business Associate Agreements (BAAs) must set HIPAA‑required safeguards, breach reporting, and termination rights and must flow down the same privacy and security duties to each subcontractor that handles PHI. In Vermont, strengthen BAAs to address state overlays: HIV and communicable‑disease confidentiality, mental health disclosures, VPMS non‑redisclosure, and any reporting obligations that touch Vermont systems (for example, VHCURES for payers). ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/021/01001?utm_source=openai))
Watch for data outside HIPAA. Vermont’s new Data Privacy and Online Surveillance Act (S.71, Act 145, signed June 16, 2026; effective January 1, 2028) largely exempts PHI and HIPAA‑regulated entities, but it regulates “consumer health data” and other personal data that your websites, apps, or analytics tools may collect. Add data‑processing terms and purpose limits to vendor contracts where S.71 applies. ([legislature.vermont.gov](https://legislature.vermont.gov/bill/status/2026/S.71?wpmobileexternal=true&utm_source=openai))
- Subcontractors: require written assurances that HIPAA and Vermont confidentiality laws are met; prohibit onward disclosure of VPMS data; and specify Vermont breach‑notification coordination.
- VHCURES (for payers): align reporting specifications, access controls, and retention with GMCB Rule 8.000 and 18 V.S.A. § 9410. ([law.cornell.edu](https://www.law.cornell.edu/regulations/vermont/80-006-Code-Vt-R-80-280-006-X?utm_source=openai))
Complying with Vermont Disclosure Restrictions
Vermont imposes additional, topic‑specific limits on disclosure that you must integrate into your release‑of‑information workflow:
- HIV and communicable diseases: Public health HIV records are confidential; unauthorized disclosures carry civil penalties. Providers must give pre‑test notice that a positive test will be reported; anonymous testing options exist. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/021/01001?utm_source=openai))
- Mental health records: Disclosures generally require the patient’s (or authorized representative’s) written consent, with narrow statutory exceptions. ([codes.findlaw.com](https://codes.findlaw.com/vt/title-18-health/vt-st-tit-18-sect-7103/?utm_source=openai))
- Genetic testing: Vermont regulates consent and restricts certain uses and disclosures of genetic information. Build clear consent language and data‑segregation practices. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/217/09332?utm_source=openai))
- VPMS (prescription monitoring): Access is limited to statutorily authorized users and purposes; non‑redisclosure is mandatory. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/084A/04284?utm_source=openai))
- Substance use disorder records: If 42 CFR Part 2 applies, its stricter consent requirements control even where HIPAA would otherwise permit disclosure. ([govregs.com](https://www.govregs.com/regulations/42/2?utm_source=openai))
Also consider minors’ consent in areas where Vermont allows it (for example, certain outpatient mental health services), which can affect who is authorized to receive information. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/196/08350?utm_source=openai))
Implementing Telehealth Service Regulations
Vermont defines “telehealth” to include telemedicine (live audio‑video), store‑and‑forward, and audio‑only telephone. Out‑of‑state clinicians must obtain either a Telehealth License (up to 20 unique Vermont patients per two‑year term) or a short‑term Telehealth Registration (120 days, up to 10 unique patients). These provisions, effective July 1, 2023, also require you to document telehealth encounters to the same standard as in‑person care, and they reference Vermont’s prescribing and informed‑consent rules. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/fullchapter/26/056))
Consult‑only exception: a clinician licensed elsewhere may consult with a Vermont‑licensed professional without a telehealth license if there is no direct patient contact. Align your Telemedicine Licensing Requirements, informed‑consent scripts, and documentation with 18 V.S.A. §§ 9361–9362 and 26 V.S.A. ch. 56. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/219/09361?utm_source=openai))
If you bill Vermont Medicaid for telehealth, ensure applicable provider enrollment and maintain complete records consistent with state law and program rules. ([law.cornell.edu](https://www.law.cornell.edu/regulations/vermont/13-003-Code-Vt-R-13-174-003-X?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Following Medical Records Retention Policies
Set Medical Records Retention Periods to meet both HIPAA and Vermont requirements. HIPAA requires you to retain required compliance documentation (for example, policies, risk analyses, and notices) for at least six years; state law sets clinical‑record timelines by setting and license type.
- Hospitals: retain medical records for at least 10 years (licensure requirement). ([healthinfolaw.org](https://www.healthinfolaw.org/state-law/vt-stat-ann-tit-18-%C2%A7-1905-license-requirements-under-health-law?utm_source=openai))
- Home health agencies: retain patient records for 10 years after discharge or longer if other law requires. ([dail.vermont.gov](https://dail.vermont.gov/sites/dail/files//documents/Regulations_Designations_operations_Home_Health_Agencies.pdf?utm_source=openai))
- OPR‑regulated professions (for example, many non‑physician clinicians): failure to retain client records for seven years is unprofessional conduct unless a profession‑specific rule allows a shorter period. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/03/005/00129a?utm_source=openai))
- Pharmacy records: generally three years under Board of Pharmacy rules. ([law.cornell.edu](https://www.law.cornell.edu/regulations/vermont/04-230-Code-Vt-R-04-030-230-X?utm_source=openai))
- Adverse‑event investigation materials (hospitals): retain at least seven years under Patient Safety rules. ([law.cornell.edu](https://www.law.cornell.edu/regulations/vermont/13-068-Code-Vt-R-13-140-068-X?utm_source=openai))
Tip: build a defensible retention schedule that applies the longest applicable rule across your service lines, and ensure secure destruction workflows once retention expires.
Navigating Vermont Consumer Privacy Exemptions
Vermont’s Data Privacy and Online Surveillance Act (S.71, Act 145) was signed June 16, 2026 and takes effect January 1, 2028. The Act largely exempts PHI processed by HIPAA covered entities and business associates and exempts health care providers and facilities to the extent they maintain PHI in compliance with HIPAA and Vermont law. However, it regulates other personal data—particularly “consumer health data”—that you or your vendors might collect outside HIPAA (for example, from websites, apps, or marketing tools). ([legislature.vermont.gov](https://legislature.vermont.gov/bill/status/2026/S.71?wpmobileexternal=true&utm_source=openai))
The Act also bans geofencing within 1,850 feet of health care, mental health, and reproductive or sexual health facilities for purposes such as tracking or targeting consumers based on health‑related visits. Update your privacy notices, consent flows, and vendor contracts accordingly. ([legiscan.com](https://legiscan.com/VT/text/S0071/id/3449610/Vermont-2025-S0071-Chaptered.pdf))
Utilizing Vermont Health Data Utility Support
Vermont legislatively designates Vermont Information Technology Leaders (VITL) to operate the statewide Vermont Health Information Exchange (VHIE)—now matured into a “health data utility” model to support care coordination, public health, and analytics. Using VHIE can help you exchange data securely under HIPAA’s TPO framework while meeting Health Data Utility Compliance expectations in state planning documents. ([vitl.net](https://vitl.net/about-vitl/?utm_source=openai))
Consent model: since March 1, 2020, the VHIE uses an opt‑out consent policy adopted under Act 53 of 2019, greatly improving availability of data for treatment while preserving a patient’s right to opt out. Ensure your Notice of Privacy Practices and front‑desk scripts explain the VHIE and opt‑out rights; build flags in your EHR to honor opt‑out status. Note: 42 CFR Part 2 data still requires express patient consent before exchange. ([vitl.net](https://vitl.net/resources/vhie-consent/?utm_source=openai))
Conclusion
To stay compliant in Vermont, apply HIPAA rigorously and layer in state‑specific rules for disclosures, telehealth, record retention, claims reporting, and consumer privacy. Use BAAs and vendor controls to operationalize these duties, and leverage the VHIE health data utility to share the right data with the right people—securely and lawfully.
FAQs.
What are Vermont’s specific HIPAA disclosure restrictions?
In addition to HIPAA, Vermont restricts disclosures for HIV‑related public health records (pre‑test notice, confidentiality, and penalties for unauthorized disclosure), mental health information (written consent required except for narrow exceptions), genetic testing results (consent and use limits), and VPMS prescription data (strict access and non‑redisclosure). If 42 CFR Part 2 applies, it imposes stricter consent rules than HIPAA. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/021/01001?utm_source=openai))
How must business associates manage subcontractor agreements in Vermont?
Subcontractors must receive the same HIPAA duties as the primary business associate, in writing. In Vermont, flow down state‑law limits (for example, HIV, mental health, VPMS) and, if you or your vendors process non‑HIPAA consumer data, add S.71‑compliant terms (purpose limitation, confidentiality, and processor obligations). Payers should also ensure vendors that touch Healthcare Claims Reporting (VHCURES) follow 18 V.S.A. § 9410 and Green Mountain Care Board Rule 8.000. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/section/18/021/01001?utm_source=openai))
What are the medical records retention requirements in Vermont?
Hospitals must retain records for at least 10 years. Many OPR‑regulated professions treat failure to retain client records for seven years as unprofessional conduct unless a shorter profession‑specific rule applies. Pharmacies generally retain records three years. Home health agencies retain for 10 years, and hospitals must keep adverse‑event investigation materials at least seven years. Keep HIPAA compliance documentation for a minimum of six years. ([healthinfolaw.org](https://www.healthinfolaw.org/state-law/vt-stat-ann-tit-18-%C2%A7-1905-license-requirements-under-health-law?utm_source=openai))
How is telehealth regulated under Vermont HIPAA laws?
Vermont defines telehealth to include telemedicine, store‑and‑forward, and audio‑only care. Out‑of‑state clinicians need a Telehealth License (up to 20 unique patients over two years) or a Telehealth Registration (120 days, up to 10 patients). Telehealth encounters must be documented to the same standard as in‑person care, and Vermont’s telehealth statutes cross‑reference prescribing and informed‑consent rules in 18 V.S.A. §§ 9361–9362. ([legislature.vermont.gov](https://legislature.vermont.gov/statutes/fullchapter/26/056))
Table of Contents
- Adhering to HIPAA Privacy and Security Rules
- Managing Business Associate Agreements
- Complying with Vermont Disclosure Restrictions
- Implementing Telehealth Service Regulations
- Following Medical Records Retention Policies
- Navigating Vermont Consumer Privacy Exemptions
- Utilizing Vermont Health Data Utility Support
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.