Services › U.S. Privacy & HIPAA
U.S. Privacy & HIPAA

Protect patient and HCP data — and prove it.

Comprehensive state privacy laws carry HIPAA carve-outs, research exemptions, and employee-data provisions that generalist firms miss — so we scope per data stream, not per company.

A bright life-sciences laboratory with data and molecular network overlays representing protected health data

Comprehensive state privacy laws include HIPAA carve-outs, research exemptions, and employee-data provisions that generalist firms often miss. We scope per data stream, not per company — the same organization may have PHI-governed clinical-trial data and non-PHI consumer-health or patient-services data, each treated differently under HIPAA, MHMDA, MODPA, CMIA, and the twenty state comprehensive laws.

What we do

Right-sized programs for pharma, biotech & patient services

  • HIPAA risk assessments & Business Associate Agreements
  • State comprehensive privacy laws — CCPA/CPRA, MHMDA, MODPA, CMIA, and 20+ others
  • Per-data-stream scoping (PHI, PII, employee, patient services, RWD)
  • Data Subject Request (DSR) workflows and vendor DPAs
  • Breach response planning, tabletops & readiness testing
  • Privacy-by-design for data, vendors, and AI systems
  • Board-level privacy reporting and accountability
TRESTLE Regulatory Radar™

The live reference every tier includes.

63tracked requirements
9regulatory categories
28jurisdictions with active requirements
Aug 2026last verified
Showing 63 of 63 requirements
Status
Category
Function
Federal requirements
HIPAA Security Rule NPRM (2025 Proposed Update)
FederalPendingHIPAA / 42 CFR Part 2
EU AI Act (Extraterritorial)
FederalUpcomingAI Governance
FTC Health Breach Notification Rule (2024)
FederalEffectiveFTC Enforcement / Adtech
HIPAA Reproductive Health Privacy Rule (2024)
FederalVacatedHIPAA / 42 CFR Part 2

Plain-English summaries, per-function action items, and reusable client conversation notes — refreshed monthly. Walk through it before we meet, filtered to your state footprint.

Open the Radar™
Next Step

Map your data and state footprint.

We’ll start with the data streams and business activities that matter, then identify the obligations and evidence your program actually needs.