No: HIPAA does not apply to veterinarians, because the federal Privacy Rule protects health information about people, and your patients are animals.
The word has become shorthand for any medical-records privacy rule, so clients invoke it and practice owners assume it.
The laws that actually govern veterinary records are state practice acts, and they bite in ordinary marketing moments: review replies, testimonials, and client texts.
This page is the records-privacy companion to veterinary advertising rules, which covers what you may say in ads; this one covers what you may repeat, and about whom.
Usual caveat for a topic like this: it is a plain-English summary of published rules, not legal advice, so confirm specifics with your state veterinary board or an attorney.
Why HIPAA does not cover veterinary practices
HIPAA's Privacy Rule protects "protected health information", and its definitions are built entirely around people.
Under 45 CFR 160.103, an "individual" is "the person who is the subject of protected health information", and "health care" means "care, services, or supplies related to the health of an individual" (eCFR).
"Person", in the rule's own definition, means a natural person: a human being who is born alive.
Animals are not persons in that sense, so animal records are not protected health information under HIPAA, and a veterinary practice is not a covered entity because it treats animals.
A 2019 JAVMA review of veterinary record confidentiality puts it flatly: "the federal Health Insurance Portability and Accountability Act does not apply to animals" (JAVMA).
Because the rule never reaches your practice, there are no HIPAA risk assessments to run, no HIPAA breach notifications to send, and no HIPAA fines for any veterinary practice.
Client expectations still matter: owners who say "HIPAA" mean "keep my information private", and your state's confidentiality law plus ordinary professionalism is what delivers that.
In human medicine
- The patient is an "individual": a person.
- Records about human patients are protected health information.
- Providers handling them operate as covered entities.
In your practice
- Patients are animals, so records are not PHI under HIPAA.
- Treating animals never makes a practice a covered entity.
- State practice acts fill the gap.
HIPAA still matters to a practice owner in one indirect way: some federal texting exemptions are written for covered entities, and that trap is covered further down this page.
Veterinary client confidentiality: what actually applies
No HIPAA does not mean no confidentiality law.
No national law governs the confidentiality of veterinary records: state laws range from strict to limited, so your duties depend on your own state practice act (the same JAVMA review).
The AVMA's Principles of Veterinary Medical Ethics add a profession-level norm: veterinary medical records are confidential and may be released only as the law requires or allows, or with client consent (AVMA).
The practical upshot is that a records habit imported from human medicine does not transfer: the federal rulebook is out, and your state's rulebook is in.
Veterinary records privacy laws, state by state
California has the sharpest edges: Business and Professions Code 4857 bars disclosing information about an animal patient, the client, or the care provided outside listed exceptions, violations carry criminal penalties, and a negligent release creates civil liability for damages (California statute).
The exceptions include client consent (written, witnessed verbal, or electronic), a court order or subpoena, legal compliance, and sharing situations such as with peace or humane officers and treating facilities.
Texas writes the duty into its practice act too: a veterinarian may not violate the confidential vet-client relationship, and release requires the client's written authorization or waiver, or a court order or subpoena (Texas statute).
Florida treats information a client discloses during an animal's care as confidential, disclosable only to other vets involved in the care, with the client's written authorization, or under subpoena (Fla. Stat. 474.2165).
Illinois veterinarians need not disclose records without the client's written authorization or waiver, or a court order or subpoena, and records must be kept at least five years (225 ILCS 115/25.17).
Pennsylvania requires vets and their staff to protect clients' personal privacy, expressly including Social Security numbers, sensitive financial information, and confidential health information about the client, with release to the general public only on written consent, a subpoena, or a court order (49 Pa. Code 31.21).
New York lists revealing a client's personally identifiable information without consent as unprofessional conduct, "except as authorized or required by law" (8 NYCRR 29.1).
Different statutes, one pattern: the client is the protected party, and consent is the master key.
Where this actually bites: review replies and testimonials
The most common collision is emotional rather than technical: a client posts a one-star review that gets the facts wrong, and the record-correcting instinct takes over.
Resist the urge to annotate: the safe default in every state is a short, professional reply with no pet names, no visit dates, no diagnosis, and no payment details.
Texas is the one documented exception, and it is narrow: when a client publishes false information about the vet in a public forum, the law allows a reply limited to facts that directly refute the false statements, with no personally identifiable information beyond the client's full name, and all three conditions must hold.
California is the cautionary case in the other direction: the same statute that makes records confidential attaches criminal penalties to violations and civil liability to a negligent release.
Full scripts, platform reporting steps, and the escalation path live in responding to negative veterinary reviews.
Testimonials sit in the same zone: New York requires written client authorization before one runs, and the AVMA ethics treat testimonials as advertising limited to verifiable claims, which veterinary testimonial rules covers in depth.
HIPAA and veterinary texting: the exemptions that do not fit
Client texting is where "we are not covered by HIPAA" turns dangerous in the other direction.
The TCPA's exemptions for "health care" messages apply only to messages sent by or for a HIPAA covered entity or its business associate, and a veterinary practice is neither, so those exemptions are not yours to rely on.
The workable habits are simple: collect consent to text at intake, and get prior express written consent before any promotional texts, which is what the TCPA requires for marketing texts (47 CFR 64.1200).
The hinge is the reminder-versus-promotion line: a vaccine reminder and a dental-month special live in different consent worlds, so label your campaigns accordingly.
Consent language, revocation handling, and the reminder-versus-promotion line are laid out in veterinary texting consent.
A confidentiality-safe marketing checklist
None of this blocks marketing; it just shapes the mechanics.
- Drop "HIPAA-compliant" from your marketing vocabulary: no law requires it for veterinary practices, and HIPAA-grade vendors are a best practice, not a legal one.
- Treat client identities and contact details as sensitive, because rules like California's cover information about the client, not only the animal.
- Reply to every review with zero pet, client, or visit details, in every state.
- Get written client authorization before publishing any testimonial or client story.
- Record texting consent at intake, and written consent before promotional texts.
- Confirm your own state's rules with your state veterinary board or an attorney, since state laws range from strict to limited.
The reframe worth keeping: confidentiality rules are not an obstacle between your practice and growth, they are a constraint on how you talk about the work.
Every tactic in local SEO for veterinarians, from review generation to your Google Business Profile, runs comfortably inside those constraints.
Frequently asked questions
Does HIPAA apply to veterinarians?
No. HIPAA's Privacy Rule protects health information about people, and animal records are not protected health information, so a veterinary practice is not a covered entity because it treats animals (45 CFR 160.103; JAVMA, 2019).
Do veterinarians have confidentiality rules?
Yes, but they come from state practice acts and AVMA ethics, not HIPAA. No national law governs veterinary record confidentiality, so your duties depend on your own state practice act.
Can I reply to a negative review without breaking confidentiality?
The safe default in every state is a short, professional reply with no pet, client, or visit details. Texas law allows a narrow factual reply to a false public post, limited to refuting facts and no personal information beyond the client's full name.
What law protects veterinary records if HIPAA does not?
State practice acts and board rules. California's, for example, bars disclosure of patient, client, and care information outside listed exceptions and attaches criminal and civil penalties, while Illinois requires records to be kept at least five years.
Do I need HIPAA-compliant software for my veterinary practice?
No law requires it, because HIPAA does not cover veterinary records. Some practices choose HIPAA-grade vendors anyway as a best practice, which is fine, just not a legal requirement.