HIPAA is federal law and applies nation-wide in every US State. But individual States like Vermont have begun to enact their own health-data privacy and security laws which overlap with HIPAA. Entities doing business in each state must comply with both HI