Tennessee Health Data Protection Requirements: HIPAA, TIPA, and State Breach Rules Explained

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Tennessee Health Data Protection Requirements: HIPAA, TIPA, and State Breach Rules Explained

Kevin Henry

Data Protection

December 05, 2025

7 minutes read
Share this article
Tennessee Health Data Protection Requirements: HIPAA, TIPA, and State Breach Rules Explained

HIPAA Privacy Rule Overview

The HIPAA Privacy Rule governs how covered entities and business associates use and disclose Protected Health Information (PHI). Covered entities include health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions; business associates handle PHI for covered entities under written agreements. Key principles include permitted uses for treatment, payment, and health care operations (TPO), the “minimum necessary” standard, and robust individual rights. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?Channel=Google_PPC&field_insight_category_target_id=2&utm_source=openai))

You must give patients a clear Notice of Privacy Practices and honor rights to access, receive an accounting of disclosures, request amendments, and restrict or confidentially communicate PHI. Employment records and FERPA-protected education records are outside HIPAA’s PHI scope. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?Channel=ms-solution-banner&LDNsummitHB1=&WHB=2&field_insight_category_target_id=3&field_insight_category_target_id=All&utm_source=openai))

HIPAA Security Rule Safeguards

The Security Rule applies to electronic PHI and requires you to implement administrative, physical, and technical safeguards proportionate to your risks. Practically, that means performing and documenting a risk analysis, managing risks, training your workforce, controlling facility and device access, and enforcing access controls, audit controls, integrity protections, authentication, and transmission security in your EHR and connected systems. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/index.html?obref=obinsite&utm_source=openai))

Because Electronic Health Records (EHR) Security hinges on accurate risk analysis and continuous improvement, build a living security program: reassess when technologies, threats, or workflows change, and confirm that “addressable” measures (such as encryption) are implemented where reasonable and effective. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=openai))

HIPAA Breach Notification Procedures

First decide whether an incident is a reportable breach. HIPAA presumes an impermissible use or disclosure of PHI is a breach unless your documented four-factor assessment shows a low probability of compromise, considering: the nature and extent of PHI; the unauthorized recipient; whether PHI was actually acquired/viewed; and mitigation. Narrow exceptions (e.g., certain internal misdirected disclosures) may apply. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.402?utm_source=openai))

When notification is required, you must notify affected individuals without unreasonable delay and no later than 60 days after discovery; include what happened, the PHI types, steps individuals should take, what you are doing to investigate and mitigate, and your contact information. For breaches involving 500+ individuals, also notify HHS within 60 days and prominent media in the affected state; breaches under 500 require reporting to HHS within 60 days after the calendar year ends. Business associates must notify the covered entity within 60 days of discovery. Law enforcement may request a limited delay. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))

Tennessee Information Protection Act Compliance

The Tennessee Information Protection Act (TIPA) took effect July 1, 2025. It applies to businesses that conduct business in Tennessee (or target residents), exceed $25 million in revenue, and either process data on at least 175,000 consumers during a calendar year or process data on at least 25,000 consumers while deriving over 50% of gross revenue from selling personal information. These Consumer Personal Data Processing Thresholds determine whether you are a “controller” under TIPA. ([cliclaw.com](https://www.cliclaw.com/legal_compliance/tennessee-information/))

Controllers must honor consumer rights to access, correct, delete, and obtain a portable copy of personal information, as well as to opt out of sales, targeted advertising, and certain profiling. You have 45 days to respond (with one 45-day extension when reasonably necessary) and must maintain transparent notices, limit collection to what’s necessary, secure data, and avoid processing sensitive data without consent. ([cliclaw.com](https://www.cliclaw.com/legal_compliance/tennessee-information/))

Exemptions matter: HIPAA-covered entities and business associates, HIPAA PHI, GLBA financial institutions, and Tennessee-licensed insurance companies are outside TIPA’s scope. Enforcement is exclusively by the State Attorney General, with a 60-day cure period; civil penalties can reach $7,500 per violation, and courts may award treble damages for willful or knowing violations. An affirmative defense exists for businesses maintaining a NIST-conforming privacy program. ([cliclaw.com](https://www.cliclaw.com/legal_compliance/tennessee-information/))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Tennessee Data Breach Notification Obligations

Under Tennessee’s general breach law (Tenn. Code Ann. § 47-18-2107), information holders must notify affected residents “immediately, but no later than 45 days” after discovering or being notified of a breach of system security involving personal information. Notification may be delayed if law enforcement determines notice would impede an investigation. ([codes.findlaw.com](https://codes.findlaw.com/tn/title-47-commercial-instruments-and-transactions/tn-code-sect-47-18-2107/?utm_source=openai))

A “breach of system security” generally means unauthorized acquisition of unencrypted computerized personal information—or encrypted data plus the key—that materially compromises security, confidentiality, or integrity. If you notify more than 1,000 residents, you must also notify nationwide consumer reporting agencies; the statute does not require notice to the Tennessee Attorney General. ([omm.com](https://www.omm.com/media/5toj1tkf/a_guide_to_us_breach_notification_laws.pdf?utm_source=openai))

HIPAA- and GLBA-regulated entities are exempt from Tennessee’s general breach statute. However, if both HIPAA and state law apply to your incident, follow the stricter Breach Notification Timelines—practically, that means meeting Tennessee’s 45-day clock for resident notice while satisfying HIPAA’s federal content and reporting rules. ([dwt.com](https://www.dwt.com/gcp/states/tennessee?utm_source=openai))

Tennessee Medical Records Retention Requirements

Physicians must retain medical records for at least 10 years from the last professional contact. For minors, retain the record for at least one year after the patient reaches the age of majority or 10 years from the last contact—whichever is longer. ([law.cornell.edu](https://www.law.cornell.edu/regulations/tennessee/Tenn-Comp-R-Regs-0880-02-.15?utm_source=openai))

Hospitals must preserve records directly related to patient care for 10 years following discharge or death during treatment; mammography records follow the same period. Align your retention schedule with these Medical Records Retention Periods and ensure secure destruction at end-of-life. ([law.justia.com](https://law.justia.com/codes/tennessee/2023/title-68/health/chapter-11/part-3/section-68-11-305/?utm_source=openai))

Tennessee Insurance Data Security Regulations

Tennessee has adopted the NAIC Insurance Data Security framework. Insurance “licensees” must maintain a written Insurance Data Security Program based on risk assessments; implement administrative, technical, and physical safeguards; oversee third-party service providers; keep an incident response plan; and document remediation when material improvements are needed. ([codes.findlaw.com](https://codes.findlaw.com/tn/title-56-insurance/tn-code-sect-56-2-1004/?utm_source=openai))

After determining a qualifying cybersecurity event, a licensee must notify the Commissioner within three business days (subject to statutory triggers and nuances for assuming insurers and producers). Preserve cybersecurity event records for at least five years and, if domiciled in Tennessee, submit an annual April 15 compliance certification to the Department of Commerce & Insurance. ([law.justia.com](https://law.justia.com/codes/tennessee/title-56/chapter-2/part-10/section-56-2-1006/?utm_source=openai))

Conclusion

In practice, you will likely operate under overlapping regimes: HIPAA for PHI, TIPA for broader consumer data (unless exempt), Tennessee’s 45-day breach rule for personal information, rigorous medical-records retention schedules, and specialized insurance cybersecurity duties. Map your data, decide which laws apply, and build procedures that meet the most protective standard across timelines, security controls, and consumer rights. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?Channel=Google_PPC&field_insight_category_target_id=2&utm_source=openai))

FAQs

What entities are covered by HIPAA in Tennessee?

HIPAA is federal and applies in Tennessee to health plans, health care clearinghouses, and health care providers that transmit health information electronically in standard transactions, plus their business associates that handle PHI on their behalf. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?Channel=Google_PPC&field_insight_category_target_id=2&utm_source=openai))

When must a breach be reported under Tennessee law?

You must notify affected Tennessee residents immediately, but no later than 45 days after discovery or notification of a qualifying breach; law enforcement can request a reasonable delay. If more than 1,000 residents are notified, also notify the nationwide consumer reporting agencies; Tennessee does not require notice to the Attorney General for private-sector breaches. ([codes.findlaw.com](https://codes.findlaw.com/tn/title-47-commercial-instruments-and-transactions/tn-code-sect-47-18-2107/?utm_source=openai))

How long must medical records be retained in Tennessee?

Physicians must retain records for at least 10 years from last professional contact (longer for minors: at least one year after majority or 10 years, whichever is longer). Hospitals must retain patient care records for 10 years after discharge or death during treatment. ([law.cornell.edu](https://www.law.cornell.edu/regulations/tennessee/Tenn-Comp-R-Regs-0880-02-.15?utm_source=openai))

What are the key protections under TIPA?

TIPA grants rights to access, correct, delete, and obtain a portable copy of personal information, and to opt out of sales, targeted ads, and certain profiling. It imposes transparency, data-minimization, and security duties on controllers; responses to verified requests are due within 45 days (with a possible 45-day extension). Enforcement is by the State Attorney General, with a 60-day cure period and penalties up to $7,500 per violation (trebled for willful or knowing violations). ([cliclaw.com](https://www.cliclaw.com/legal_compliance/tennessee-information/))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles