- HIPAA is only a floor. Other state and federal laws—including California's CCPA/CPRA, Illinois' BIPA, and the EU's GDPR and AI Act—often apply to healthcare-adjacent data or reach beyond traditional ...