New Hampshire PACE Privacy Laws: Sharing Interdisciplinary Notes with Contracted Vendors

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

New Hampshire PACE Privacy Laws: Sharing Interdisciplinary Notes with Contracted Vendors

Kevin Henry

Data Privacy

September 04, 2026

8 minutes read
Share this article
New Hampshire PACE Privacy Laws: Sharing Interdisciplinary Notes with Contracted Vendors

Overview of New Hampshire Privacy Act Compliance

If you operate a PACE program in New Hampshire, “RSA 507-H compliance” under the New Hampshire Privacy Act (often called the NHPA) sits alongside HIPAA and, where applicable, 42 CFR Part 2. RSA 507-H defines “controllers” and “processors,” sets consumer rights, and requires “reasonable security measures.” It also exempts certain entities and data, including protected health information and many HIPAA contexts.

Key scoping points for PACE organizations: interdisciplinary notes are typically protected health information and, when handled by covered entities or business associates, are generally outside NHPA’s scope. Nonprofit organizations are also excluded. Still, the NHPA can reach non-PHI personal data (for example, website analytics, marketing, or call-center metadata) and may apply to for‑profit vendors that process consumer data outside HIPAA pathways.

Practically, your program should map where NHPA applies, where HIPAA/Part 2 governs, and where both inform due diligence. That mapping drives contract strategy, notice and consent language, and vendor risk management for “third-party data processing contracts.”

Requirements for Interdisciplinary Notes Sharing

Identify whether each element of the interdisciplinary team (IDT) note is PHI, Part 2 data, de-identified data, or other consumer data. Most IDT notes are PHI; substance use disorder entries may be Part 2. Non-PHI operational metadata (for instance, scheduling logs) can trigger NHPA duties.

Confirm roles and purposes

Document whether your organization is acting as a HIPAA covered entity and the vendor as a business associate, and whether any processing also makes you a “controller/processor” under the NHPA. Limit disclosures to treatment, payment, or health care operations if you rely on HIPAA pathways, and apply the “minimum necessary” standard to maintain “interdisciplinary notes confidentiality.”

Apply data minimization and need-to-know

Share only the specific IDT fields a vendor needs to perform the contracted service. Redact free-text where feasible, split identifiers from clinical narratives, and use role-based access so staff and subcontractors see only what’s necessary.

Assess heightened-risk processing

If a vendor uses sensitive data for profiling, advanced analytics, or other high-impact processing outside HIPAA, conduct and retain a written data protection assessment under NHPA. Address benefits versus risks, mitigations, de-identification, and consumer expectations.

Document disclosures and retention

Maintain an auditable record of each disclosure, the lawful basis, the receiving party, and the retention schedule. Align retention and destruction timelines across your program, vendor, and any subcontractors.

Contractual Obligations with Vendors

Combine the BAA and the NHPA processor terms

Where the vendor is a HIPAA business associate, a BAA is mandatory. If any non-PHI consumer data is processed under the NHPA, incorporate processor obligations too. Your agreement should state that vendor processing is strictly limited to your documented instructions.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Core NHPA processor requirements to include

  • Confidentiality: everyone who processes data is bound by a duty of confidentiality.
  • Deletion/return: delete or return personal data at end of services unless law requires retention.
  • Transparency to you: on reasonable request, make available information needed to demonstrate compliance.
  • Subprocessor control: require your prior opportunity to object and flow down equal obligations in any subcontract.
  • Assessments and audits: allow reasonable assessments or provide an independent assessment report on security and organizational controls.
  • Cooperation: assist you with security obligations, breach notifications, and consumer rights requests where applicable.

PACE-specific prohibitions and guardrails

  • No sale, targeted advertising, or unrelated analytics using PACE data.
  • No combining IDT notes with external datasets except as expressly permitted and risk-assessed.
  • No training of general-purpose AI models on PACE data; use is restricted to your documented purposes.

Outside HIPAA/Part 2 pathways, “consumer consent under NHPA” may be required—especially for “sensitive data” (health, biometrics, precise geolocation, or data from children). Obtain consent before such processing, unless another NHPA-permitted basis applies.

  • Clear affirmative action: present concise, intelligible language; avoid bundled or pre-checked boxes and any deceptive design.
  • Specificity: tie consent to defined purposes, data categories, and vendors. Separate optional uses (e.g., product improvements) from operational necessities.
  • Representative authority: accept consent from a lawfully authorized representative (e.g., guardian, health care proxy) when appropriate for PACE participants.
  • Easy revocation: provide a simple, at-least-as-easy mechanism to withdraw consent and stop processing promptly thereafter; keep an audit trail of each change.

Synchronize notices

Align your HIPAA Notice of Privacy Practices with NHPA privacy notices for non-PHI data. State how consumers exercise their rights, what you share with third parties, and the categories of recipients.

Data Sharing Agreement Essentials

What to capture in the DSA

  • Parties, roles, and lawful bases: identify covered entity/BA status and any NHPA controller/processor roles.
  • Data inventory: list the specific IDT note elements, identifiers, and any sensitive fields; flag Part 2 data with additional handling rules.
  • Purpose limitation: describe permitted uses; prohibit secondary use, sale, or targeted advertising.
  • Retention and destruction: define timelines, secure disposal methods, and documentation of completion.
  • Access and accountability: role-based access, least privilege, workforce training, background checks, and logging.
  • Subprocessing: approval process, flow-down obligations, and transparency to you.
  • Security and incident response: “reasonable security measures,” encryption, monitoring, and prompt notice of incidents that implicate your obligations.
  • Data subject rights assistance: procedures for intake, verification, and response when NHPA rights apply.
  • De-identification and aggregation: conditions, methods, and prohibitions on re-identification.
  • Exit plan: return/transfer of data, certification of deletion, and continuing confidentiality after termination.

Keep documents consistent

Ensure the DSA, BAA, SOWs, and security exhibits do not conflict. State the order of precedence and how updates will be negotiated and recorded.

Security Measures for Data Protection

Administrative controls

  • Governance: assign accountable owners, approve vendor risk assessments, and track remediation.
  • Policies and training: minimum necessary access, acceptable use, secure communications, and incident response drills tailored to IDT workflows.
  • Third-party oversight: due diligence, security questionnaires, SOC 2/HITRUST reports where appropriate, and periodic reassessments.

Technical controls

  • Encryption: TLS in transit and strong encryption at rest for notes and backups.
  • Identity and access: MFA, just-in-time access, session timeouts, and prompt deprovisioning.
  • Network and endpoint: segmentation, EDR, vulnerability scanning, timely patching, and secure mobile device management.
  • Data loss prevention: prevent exfiltration via email, chat, or file sharing; watermark reports where feasible.
  • Monitoring and logging: immutable logs for access to IDT notes; alerting on anomalous activity; regular log review.

Physical and operational controls

  • Secure facilities: badge access, visitor controls, and clean-desk for printed notes.
  • Resilience: tested backups, recovery time objectives, and tabletop exercises simulating vendor outages.
  • Secure disposal: cryptographic erasure, certified destruction of media, and verified shredding for paper artifacts.

Enforcement and Penalties Overview

“New Hampshire Attorney General enforcement” is exclusive under the NHPA. There is no private right of action. The AG may require production of your data protection assessments relevant to an investigation and can seek injunctive relief and civil penalties for violations treated as unfair or deceptive acts under state law.

There is a statutory cure period early in the law’s lifecycle; after that, the AG has discretion whether to offer an opportunity to cure based on factors like number of violations, processing scope, and risk of harm. Weak vendor governance, inadequate “reasonable security measures,” or gaps in “data sharing agreement terms” are common enforcement triggers.

Conclusion

For PACE programs, the safest path is to treat IDT notes primarily through HIPAA/Part 2 rules while hardening contracts and workflows to satisfy RSA 507-H where it applies. Map your data, tighten vendor terms, obtain NHPA-grade consent when needed, and prove “reasonable security measures” in practice. Doing so protects participants, reduces enforcement risk, and ensures compliant, patient-centered care delivery.

FAQs.

What are the NHPA requirements for sharing PACE data with vendors?

Most IDT notes are PHI shared under HIPAA with a business associate agreement. When vendors handle non-PHI consumer data, the NHPA may apply and requires a controller–processor contract with instruction-bound processing, confidentiality, deletion/return at end of services, subprocessor controls, cooperation on security and consumer rights, and support for assessments. Always apply data minimization, need-to-know access, and maintain audit trails.

HIPAA typically allows IDT note sharing for treatment, payment, and operations without separate consent. If you process sensitive personal data outside HIPAA (for example, optional analytics not tied to operations), obtain NHPA-compliant consent: a clear, specific affirmative action; no pre-checked boxes or bundled terms; easy revocation; and records of who consented, to what, and when. Accept consent from a legally authorized representative when appropriate.

What contractual terms are necessary for compliance?

Use a BAA for PHI and add NHPA processor clauses for any non-PHI consumer data. Required elements include purpose limitation; confidentiality; deletion/return; subprocessor approval and flow-down; cooperation with audits and assessments; breach support; and assistance with consumer rights requests. Add PACE-specific prohibitions against sale, targeted advertising, unrelated analytics, and training of general-purpose AI on PACE data.

What penalties exist for NHPA violations in PACE programs?

The New Hampshire Attorney General exclusively enforces the NHPA. Violations are treated as unfair or deceptive acts under state law and can result in investigations, required remediation, injunctive relief, and civil penalties. Early on, there is a statutory opportunity to cure; afterward, cure is discretionary and depends on factors like violation count, processing scope, and risk of harm. Robust vendor management and documented security controls materially reduce enforcement risk.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles