If HIPAA rules are stricter than state law, which standard should you follow and why? What if the state law was stricter?

You have to follow the most restricive law.