KS AG Opinion 2025-17 August 12, 2025

Does HIPAA let a Kansas hospital refuse a law enforcement subpoena for medical records?

Short answer: No. The Attorney General concluded that once a law enforcement subpoena or court order meets HIPAA's procedural requirements, Kansas healthcare providers are legally obligated to disclose the protected health information. HIPAA's "may disclose" wording does not give providers a right to refuse, providers cannot demand that law enforcement sign a separate HIPAA compliance agreement first, and an out-of-state privacy law that is stricter than HIPAA does not excuse noncompliance with a Kansas subpoena or order.

Apply this to your situation

This page answers the general question as of 2025. Ezel answers yours: what it means for your facts, under current Kansas law, with citations.

Disclaimer: This is an official Kansas Attorney General opinion. AG opinions are persuasive authority in Kansas but are not binding precedent like a court ruling. This summary is for informational purposes only and is not legal advice. Consult a licensed Kansas attorney for advice on your specific situation.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official AG opinion. The original opinion (linked on this page as a PDF) is the authoritative source for any reliance.
View original AG opinion (PDF)

Plain-English summary

A district attorney asked the Attorney General about healthcare providers who were refusing to hand over protected health information (PHI) in response to lawful subpoenas and court orders, pointing to the "may disclose" language in HIPAA's Privacy Rule. The provider's theory was that because the federal regulation says a covered entity "may" disclose PHI to law enforcement rather than "must," HIPAA gives them a right to say no.

The Attorney General rejected that reading. HIPAA sets a floor of privacy protections and lays out the conditions under which disclosure to law enforcement is permitted, but it does not create a shield against separately existing state-law duties to comply with a subpoena or court order. When a subpoena or warrant satisfies the procedural conditions in the federal regulation, the underlying Kansas legal obligation to comply still applies, and a provider that refuses can face the normal consequences for disobeying a subpoena or court order, including contempt. The opinion also concluded that a provider cannot condition its compliance on law enforcement first signing an agreement to abide by HIPAA, since law enforcement agencies are not "covered entities" under HIPAA in the first place. Finally, an out-of-state medical privacy law that happens to be stricter than HIPAA has no bearing on whether a Kansas subpoena or order must be obeyed, because that stricter law was never made applicable in Kansas.

What this means for you

Healthcare providers and hospital compliance staff: the opinion holds that HIPAA does not authorize you to withhold PHI once a subpoena, court order, or court-ordered warrant meets the procedural requirements in 45 C.F.R. § 164.512(f)(1); withholding required disclosures can expose the provider to contempt or other adverse action.

Prosecutors and law enforcement agencies: the opinion confirms you are not a "covered entity" under HIPAA and cannot lawfully be required to sign a HIPAA compliance agreement as a precondition to receiving PHI you are otherwise entitled to under a subpoena or order.

Providers weighing an out-of-state privacy rule against a Kansas order: the opinion holds that a stricter privacy law from another state does not excuse noncompliance with a Kansas subpoena or court order, absent some separate out-of-state connection to the case.

Common questions

Can a hospital refuse to release medical records to police without a court order?
The opinion addresses subpoenas and court-ordered warrants, not informal requests. When law enforcement presents a subpoena, court order, or court-ordered warrant that meets HIPAA's procedural conditions, the provider is legally required to disclose, according to the opinion.

Does the word "may" in HIPAA's disclosure rule mean providers have a choice?
No, according to the opinion. HIPAA's "may disclose" language describes what HIPAA permits without violating federal law; it does not override a separate state-law duty to comply with a validly issued Kansas subpoena or court order.

Can a hospital make law enforcement sign a HIPAA agreement before it will turn over records?
No. The opinion concludes that law enforcement agencies are not "covered entities" or "business associates" under HIPAA, so nothing in HIPAA conditions disclosure on such an agreement.

Background and statutory framework

HIPAA's Privacy Rule, found at 45 C.F.R. Part 164, governs how "covered entities" such as hospitals and other healthcare providers may use or disclose PHI. Under 45 C.F.R. § 164.512(f), a covered entity may disclose PHI to law enforcement officials in several circumstances, including when required by law through a court order, court-ordered warrant, subpoena, or summons issued by a judicial officer. The opinion traces how courts have interpreted this provision as a set of required procedures for disclosure, not an independent source of privilege that a provider can invoke to withhold records otherwise required by Kansas law.

The opinion also relies on K.S.A. 60-245 and K.S.A. 20-1204a, which govern subpoenas and civil contempt in Kansas, to explain that a provider's failure to comply with a subpoena or order that satisfies HIPAA's procedural safeguards can result in contempt proceedings just as noncompliance with any other lawful subpoena would. On preemption, the opinion explains that HIPAA permits states to enact medical privacy protections stricter than the federal floor, but that permission does not reach across state lines: a stricter privacy statute from another state has no application to a Kansas subpoena or order unless some other legal basis ties that out-of-state law to the Kansas proceeding.

Citations and references

Statutes and regulations:
- K.S.A. 60-245; K.S.A. 20-1204a
- 42 U.S.C. §§ 1320d-5, 1320d-6, 1395x
- 45 C.F.R. §§ 160.103, 160.202, 160.203, 164.103, 164.104, 164.502, 164.512

Selected cases:
- United States v. Zamora, 408 F. Supp. 2d 295 (S.D. Tex. 2006)
- Northwestern Memorial Hosp. v. Ashcroft, 362 F.3d 923 (7th Cir. 2004)
- In re Estate of Broderick, 34 Kan. App. 2d 695, 125 P.3d 564 (2005)
- Sebelius v. LaFaver, 269 Kan. 918, 9 P.3d 1260 (2000)
- Kansas/Iowa ex rel. Sec'y of Soc. & Rehab. Servs. v. Bohrer, 286 Kan. 898, 189 P.3d 1157 (2008)

Source

Original opinion text

August 12, 2025

ATTORNEY GENERAL OPINION NO. 2025-17

Michael Kagay
District Attorney
Third Judicial District of Kansas
200 SE 7th Street, Suite 214
Topeka, Kansas 66603

Re: Procedure, Civil—Rules of Civil Procedure—Subpoenas

         Procedure, Civil—Rules of Civil Procedure—Subpoenas of nonparty
         records

         Courts—Contempts of Court—Indirect contempt; procedure

Synopsis: Law enforcement subpoenas and warrants that comply with
regulations regarding disclosure of protected health information (PHI)
promulgated under the Health Insurance Portability and
Accountability Act (HIPAA) create a legal obligation on Kansas
healthcare providers to disclose such information. A healthcare
provider may not require a law enforcement agency to sign an
agreement to be bound by HIPAA's disclosure requirements before the
provider discloses PHI to law enforcement as required by law.
Withholding PHI that is required to be disclosed based on such a
contingency may subject the healthcare provider to adverse action,
such as contempt. Moreover, a healthcare provider may not rely on
inapplicable out-of-state disclosure restrictions that are more stringent
than HIPAA to avoid compliance with Kansas subpoenas and court
orders requiring disclosure of PHI. Cited herein: K.S.A. 60-245; K.S.A.
20-1204a; 42 U.S.C. §§ 1320d-5, 1320d-6, 1395x; 45 C.F.R. §§ 160.103,
160.202, 160.203, 164.103, 164.104, 164.502, 164.512.

                                *               *    *

Dear Mr. Kagay:

As the District Attorney for the Third Judicial District of Kansas, you ask:

(1) Whether Kansas healthcare providers can lawfully refuse to disclose
    protected health information (PHI) despite a properly issued subpoena or
    court order for such PHI.

(2) Whether law enforcement subpoenas and warrants create a legal obligation
    to disclose PHI, notwithstanding the "may disclose" language in the Health
    Insurance Portability and Accountability Act (HIPAA) regulations.

(3) Whether prosecuting agencies could incur liability or waive immunity by
    signing agreements to comply with HIPAA when HIPAA does not apply to
    them.

(4) Whether Kansas law preempts any attempts by healthcare providers to
    comply with out-of-state disclosure restrictions that contradict Kansas
    subpoenas and court orders.

In your request for opinion, you note that healthcare providers in Kansas have been
refusing to disclose PHI pursuant to lawful subpoenas and court orders based on the
providers' interpretation of HIPAA and regulations promulgated under that act.

                             HIPAA and the Privacy Rule

Under the authority granted by HIPAA, the United States Department of Health
and Human Services (HHS) has issued final regulations related to the security and
privacy of certain healthcare information.1 The Standards for Privacy of
Individually Identifiable Health Information, commonly referred to as the "Privacy
Rule," address the use and disclosure of individuals' identifiable health information
(called "protected health information") by organizations subject to the Privacy Rule
(called "covered entities").2

Covered entities are defined as health plans, health case clearinghouses, and
healthcare providers who transmit health information in electronic form in

1 42 C.F.R. § 160 et seq. and 45 C.F.R. § 164 et seq.
2 45 C.F.R. § 164 et seq.

connection with certain transactions.3 A healthcare provider includes all "providers
of services" (institutional providers such as hospitals and nursing facilities),
"providers of medical or health services" (non-institutional providers such as
physicians, dentists, and other practitioners), and any other person or organization
that furnishes, bills, or is paid for health care in the normal course of business.4

Under the Privacy Rule, a covered entity may not use or disclose PHI, except as
permitted or required by the Privacy Rule.5 Relevant to this opinion, a covered
entity may disclose PHI as permitted in 45 C.F.R. § 164.512.6 Subsection (a) of 45
C.F.R. § 164.512 provides:

    (1) A covered entity may use or disclose protected health information to
    the extent that such use or disclosure is required by law and the use or
    disclosure complies with and is limited to the relevant requirements of
    such law.

    (2) A covered entity must meet the requirements described in
    paragraph (c), (e), or (f) of this section for uses or disclosures required
    by law.7

The Privacy Rule specifically defines the phrase "required by law" as "a mandate
contained in law that compels an entity to make a use or disclosure of protected
health information and that is enforceable in a court of law."8 This definition of
"required by law" goes on to provide a non-exclusive list of examples:

    [C]ourt orders and court-ordered warrants; subpoenas or summons
    issued by a court, grand jury, a governmental or tribal inspector
    general, or an administrative body authorized to require the
    production of information; a civil or an authorized investigative
    demand; Medicare conditions of participation with respect to health
    care providers participating in the program; and statutes or
    regulations that require the production of information, including
    statutes or regulations that require such information if payment is
    sought under a government program providing public benefits.9

Subsection (e) of 45 C.F.R. § 164.512 governs disclosures for judicial and
administrative proceedings, which distinguishes disclosures in response to a court

3 45 C.F.R. § 164.104.
4 45 C.F.R. § 160.103; 42 U.S.C. § 1395x.
5 45 C.F.R. § 164.502.
6 45 C.F.R. § 164.502(a)(1)(vi)(B).
7 Emphasis added.
8 45 C.F.R. § 164.103.
9 45 C.F.R. § 164.103.

order from disclosures in response to a subpoena or discovery order not
accompanied by a court order. Covered entities may disclose PHI in a judicial or
administrative proceeding if the request for the information is through an order
from a court or administrative tribunal.10 A covered entity may also disclose PHI in
response to a subpoena, discovery request, or other lawful process, that is not
accompanied by an order of a court or administrative tribunal only if certain
"satisfactory assurances" regarding notice to the individual or a protective order are
provided.11 The provisions of subsection (e) do not supersede other provisions of 45
C.F.R. § 164.512 that otherwise permit or restrict uses or disclosures of protected
health information.12

Most pertinent to your inquiry, subsection (f) of 45 C.F.R. § 164.512 applies to
disclosures of PHI to law enforcement officials for law enforcement purposes. A law
enforcement official is:

    [A]n officer or employee of any agency or authority of the United
    States, a State, a territory, a political subdivision of a State or
    territory, or an Indian tribe, who is empowered by law to:

    (1) Investigate or conduct an official inquiry into a potential violation
    of law; or

    (2) Prosecute or otherwise conduct a criminal, civil, or administrative
    proceeding arising from an alleged violation of law.13

Under 45 C.F.R. § 164.512(f), covered entities may disclose PHI to law enforcement
officials for law enforcement purposes under the following six circumstances, and
subject to specified conditions: (1) as required by law (including mandatory
reporting, court orders, court-ordered warrants, subpoenas) and administrative
requests; (2) to identify or locate a suspect, fugitive, material witness, or missing
person; (3) to provide information about a victim or suspected victim of a crime; (4)
to alert law enforcement of a person's death, if the covered entity suspects that
criminal activity caused the death; (5) when a covered entity believes that PHI is
evidence of a crime that occurred on its premises; and (6) in a medical emergency
not occurring on the covered entity's premises, when necessary to inform law
enforcement about the commission and nature of a crime, the location of the crime
or crime victims, and the perpetrator of the crime. The inquiry here deals with
disclosures required by law under 45 C.F.R. § 164.512(f)(1).

10 45 C.F.R. § 164.512(e)(1)(i).
11 45 C.F.R. § 164.512(e)(1)(ii)-(v).
12 45 C.F.R. § 164.512(e)(2).
13 45 C.F.R. § 164.103.

45 C.F.R. § 164.512(f)(1) provides that a covered entity "may disclose" protected
health information:

     (i) As required by law including laws that require the reporting of
    certain types of wounds or other physical injuries, except for laws
    subject to paragraph (b)(1)(ii) or (c)(1)(i) of this section; or
    (ii) In compliance with and as limited by the relevant requirements of:
            (A) A court order or court-ordered warrant, or a subpoena or
            summons issued by a judicial officer;
            (B) A grand jury subpoena; or
            (C) An administrative request for which response is required by
            law, including an administrative subpoena or summons, a civil
            or an authorized investigative demand, or similar process
            authorized under law, provided that:
                   (1) The information sought is relevant and material to a
                   legitimate law enforcement inquiry;
                   (2) The request is specific and limited in scope to the
                   extent reasonably practicable in light of the purpose for
                   which the information is sought; and
                   (3) De-identified information could not reasonably be
                   used.

Importantly, unlike required disclosures not accompanied by a court order in
judicial proceedings under subsection (e), no required disclosures to law
enforcement are predicated on the covered entity obtaining "satisfactory
assurances" regarding notice or protective orders before they release PHI.14

Your inquiry suggests that healthcare providers claim the discretionary language of
"may disclose" contained in the relevant portions of 45 C.F.R. § 164.512 means they
need not comply with subpoenas or court orders requiring disclosure. While
healthcare providers do not violate HIPAA by refusing disclosure, they violate
Kansas law and court orders requiring disclosure.

As explained below, HIPAA sets out a federally mandated floor of procedural
requirements before disclosing PHI to law enforcement. While states may provide
more stringent standards before PHI may be disclosed, HIPAA is more stringent
than any of Kansas's privilege statutes.15 So if Kansas law or a court order requires
disclosure of PHI, and HIPAA's procedural requirements are satisfied, then a
covered entity is required to disclose such information.16

14 Compare 45 C.F.R. § 164.512(f)(1), with 45 C.F.R. § 164.512(e)(1)(ii)-(v).
15 Kan. Att'y Gen. Op. No. 2004-21 (July 7, 2004).
16 As a policy matter, the "'HIPAA Privacy Rule strives to balance the interest of individuals in

maintaining the confidentiality of their health information with the interests of society in obtaining,
using, and disclosing health information to carry out a variety of public and private activities.'"

Law enforcement subpoenas and warrants that comply with HIPAA

regulations create a legal obligation on Kansas healthcare providers to
disclose PHI.

In response to your first two questions, we believe that (1) Kansas healthcare
providers cannot rely on HIPAA or the Privacy Rule to refuse to disclose PHI
pursuant to a properly issued subpoena or court order and (2) law enforcement
subpoenas and warrants create a legal obligation to disclose PHI, notwithstanding
the "may disclose" language in HIPAA regulations.

"HIPAA was passed to ensure an individual's right to privacy over medical records,
it was not intended to be a means for evading prosecution in criminal
proceedings."17 And considering 45 C.F.R. § 164.512(f)(1), it is "evidently denudate"
that a purpose of HIPAA and the Privacy Rule is that health information that
would otherwise be protected is to be provided to law enforcement when required by
law, or when a covered entity is provided a lawful court order or subpoena.18

Courts interpreting the disclosure procedures under 45 C.F.R. § 164.512 have long
held that they merely provide the required procedures for disclosure.19 As a result,
they "do not create a privilege or govern disclosure in court actions."20 And
ultimately, "'HIPAA regulations do not trump the rules of civil procedure with
respect to discovery obligations or questions of relevance.'"21 As a result, when a
subpoena or court order meets the procedural requirements in the HIPAA
regulations, a covered entity is required to provide the relevant PHI.22 Failure to

Menorah Park Center for Senior Living v. Rolston, 164 Ohio St. 3d 400, 406, 173 N.E.3d 432, 438
(Ohio 2020) (quoting Tovino, A Timely Right to Privacy, 104 Iowa L. Rev. 1361, 1367 (2019)). In
enacting the Privacy Rule, the HHS determined that an individual's privacy interest in their health
information givens way when law enforcement meets the procedural requirements of 45 C.F.R. §
164.512(f)(1). And allowing the "may disclose" language in the Privacy Rule to supersede Kansas law
requiring disclosure would thwart the HHS's intent allowing PHI to be obtained and used in
carrying out law enforcement functions.
17 United States v. Zamora, 408 F. Supp. 2d 295, 298 (S.D. Tex. 2006).
18 Bayne v. Provost, 359 F. Supp. 2d 234, 237 (N.D.N.Y. 2005). The court in Bayne addressed

subpoenas issued in civil judicial proceedings and noted that, under 45 C.F.R. § 164.512(e), "it is
evidently denudate that a purpose of HIPAA was that health information, that may eventually be
used in litigation or court proceedings, should be made available during the discovery phase." Id. at
237. See also In re Grand Jury Subpoena John Doe No. A01-209, 197 F. Supp. 2d 512, 515 (E.D. Va.
2002) ("the HIP[A]A regulations themselves make clear that any privacy interest patients have in
their medical records is trumped by a grand jury subpoena . . . .").
19 See, e.g., Northwestern Memorial Hosp. v. Ashcroft, 362 F.3d 923, 925-26 (7th Cir. 2004); In re

Estate of Broderick, 34 Kan. App. 2d 695, 702, 125 P.3d 564 (2005).
20 Loyning v. Potter, 2024 WY 82, ¶ 26, 553 P.3d 128 (Wyo. 2024).
21 Id. (quoting Polk v. Swift, 339 F.R.D. 189, 195-96 (D. Wyo. 2021)).
22 Chapman v. Health and Hospitals Corps., 7 Misc. 3d 933, 939, 796 N.Y.S.2d 876, 880 (Sup. Ct.

2005) (noting that "[t]he present order is a qualified protective order that satisfies HIPAA and its
regulations, so the Hospital now must provide the relevant medical records.")

comply with the subpoena or court order may result in adverse action to the covered
entity, such as contempt of the court in which an action is pending.23

Without knowing the terms of agreements to abide by HIPAA, we are
unable to opine on whether a prosecuting agency could incur liability by
signing such agreements. However, covered entities may not require that
law enforcement agencies sign an agreement to be bound HIPAA's
disclosure requirements before disclosing PHI as required by law.

HIPAA provides both civil and criminal penalties for improper disclosures of
medical information.24 Congress has provided for the administrative enforcement of
its provisions by HHS, as well as by state attorneys general.25 However, law
enforcement agencies, including prosecuting attorney offices, are not covered
entities under HIPAA and are not subject to its restraints on the use or receipt of
protected medial information.26

Your inquiry suggests that healthcare providers have been asking or demanding
your office to sign agreements to comply with HIPAA before disclosing PHI.
However, we are unaware of the terms or language of these agreements. As a result,
we cannot accurately opine on the extent the prosecuting agency could incur
liability by signing such an agreement. That said, such agreements are not required
under HIPAA or its regulations before a covered entity must disclose PHI to law
enforcement pursuant to a HIPAA-complaint subpoena or court order.

In some circumstances, HIPAA regulations require that covered entities obtain
certain guarantees from recipients of PHI that the information will not be
unlawfully disclosed. For example, as previously noted, before PHI may be disclosed
in a judicial proceeding pursuant to a non-court ordered discovery request, the
covered entity must obtain "satisfactory assurances" from the party requesting the
information that such party either (1) gave notice to the individual or (2) is securing
a qualified protection order.27 And, more akin to the proposed agreements you
described, before disclosing PHI to business associates, HIPAA regulations require
that covered entities enter into written agreements with the business associate that
obligates that associate to abide by HIPAA's restriction on PHI disclosures.28 But a
law enforcement agency is not a business associate where such agreement is

23 K.S.A. 60-245(e); K.S.A. 20-1204a; see also Sebelius v. LaFaver, 269 Kan. 918, 924, 9 P.3d 1260

(2000).
24 42 U.S.C. §§ 1320d-5, d-6.
25 Id. Notably, HIPAA does not provide a private cause of action. Bonney v. Stephens Memorial

Hospital, 2011 ME 46, ¶ 20, 17 A.3d 123, 128 (2011).
26 United States v. Elliott, 676 F. Supp. 2d 431, 440 (D. Md. 2009).
27 45 C.F.R. § 164.512(e)(1).
28 45 C.F.R. § 164.502(e); 45 C.F.R. §164.504(e); Monarch Fire Protection District of St. Louis County,

Missouri v. Freedom Consulting & Auditing Services, Inc., 678 F. Supp. 2d 927, 932 (E.D. Mo. 2009),
aff'd, 644 F.3d 633 (8th Cir. 2011).

required before disclosure.29 If the HIPAA-regulation drafters desired disclosure to
law enforcement to be contingent on their agreement to comply with HIPAA, they
certainly knew how to do so. This shows the drafters did not intend to require the
procedure for disclosing PHI to law enforcement under 45 C.F.R. § 164.512(f)(1) to
include an agreement by law enforcement to comply with HIPAA regulations.30 And
refusal to disclose PHI as required by court order or subpoena that otherwise
satisfies 45 C.F.R. § 164.512(f)(1) based on such additional requirement with no
basis in HIPAA would subject the healthcare facility to potential adverse action.

Inapplicable out-of-state disclosure restrictions have no bearing on
whether a healthcare provider complies with Kansas subpoenas or court
orders.31

HIPAA and its regulations expressly preempt state medical privacy laws except
when those laws are more stringent than the standards promulgated by the HHS.32
As a result, HIPAA permits more stringent state laws to remain in effect. A state
law is more stringent than HIPAA if the state law increases the privacy protections
afforded, provides the patient access to more information than HIPAA requires,
increases an individual's right to access or amend health information, or restricts
the use or disclosure of information that HIPAA would otherwise permit.33

Several states have laws that provide more restrictions on disclosure of PHI than
HIPAA and its regulations.34 However, neither HIPAA nor its regulations make
these more stringent restrictions applicable in Kansas.35 And a healthcare provider

29 See 45 C.F.R. § 160.103 (definition of "[b]usiness associate").
30 See Kansas/Iowa ex rel. Sec'y of Soc. & Rehab. Servs. v. Bohrer, 286 Kan. 898, 915, 189 P.3d 1157

(2008).
31 This section assumes no out-of-state nexus. In the event there is some connection to another state,

the analysis depends on the facts. See, e.g., State v. Heaney, 689 N.W.2d 168, 176 (Minn. 2004)
(finding that, in a Minnesota criminal case, Wisconsin's laws governing physician-patient privilege
applied to medical records and a blood sample located at Wisconsin hospital); Inghram v. Mutual of
Omaha Ins. Co., 170 F. Supp. 2d 907, 909-10 (W.D. Mo. 2001) (finding that Missouri law, not Kansas
law, governed Missouri insured's claim against Nebraska health insurer for producing her medical
records in Kansas court without moving to quash subpoena issued by Kansas court for use in third-
party proceeding in Kansas).
32 45 C.F.R. § 160.203.
33 45 C.F.R. § 160.202.
34 See, e.g., Wade v. Vabnick-Wener, 922 F. Supp. 2d 679, 691 (W.D. Tenn. 2010) (finding that

Tennessee law was more stringent than HIPAA's privacy rules concerning ex parte communications
with health care providers); Isidore Steiner, DPM, PC v. Bonanni, 292 Mich. App. 265, 274, 807
N.W.2d 902 (2011) (Michigan law regarding disclosures was more stringent than HIPAA).
35 See Standards for Privacy of Individually Identifiable Health Information, 64 Fed. Reg. 59918,

60000 (Nov. 3, 1999) ("[W]e do not believe that it is the intent of [section 264(c)(2) of Public Law 104-
191] to give an effect to State law that it would not otherwise have in the absence of section
264(c)(2)."); In re Grand Jury Proceedings, 450 F. Supp. 2d 115, 119 (D. Me. 2006) (noting that state
medical-privacy law, even if more stringent, is inapposite when dealing with a federal grand-jury
subpoena).

cannot rely on inapplicable out-of-state medical privacy laws to avoid compliance
with a Kansas subpoena or court order that complies with HIPAA.36 As a result,
healthcare providers must comply with HIPAA compliant subpoenas and court
orders even if compliance would violate inapplicable out-of-state disclosure
restrictions.

                                      Conclusion

Kansas healthcare providers are legally required to comply with subpoenas and
court orders requiring disclosure of PHI that satisfy the procedural requirements of
45 C.F.R. § 164.512(f)(1). Failure to comply with such subpoena or order may
subject the provider to contempt proceedings. A healthcare provider may not
demand a law enforcement agency to subject themselves to HIPAA's requirements
before releasing the required PHI. And, finally, a healthcare provider may not rely
on inapplicable out-of-state disclosure restrictions as a basis to refuse complying
with a lawful Kansas subpoena or court order.

                                          Sincerely,

                                          /s/ Kris W. Kobach

                                          Kris W. Kobach
                                          Attorney General

                                          /s/ Andrew J. Lohmann

                                          Andrew J. Lohmann
                                          Assistant Solicitor General

36 Grand Jury Proceedings, 450 F. Supp. 2d at 119 (denying hospital's motion to quash subpoena

because state medical-privacy law did not apply to a federal grand-jury subpoena).

Get today's answer for your situation

You just read a 2025 opinion on this question. Ezel checks the current Kansas statutes and case law and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the law it relies on.