State Law

Does a Medical Practice Need a Do Not Sell or Share Link?

Almost every practice answers this with "we don't sell patient data," which is true and is not the question the statute asks. The definition is much wider than money changing hands.

Consential Research is the editorial desk at Consential.io. Articles are drafted against primary sources, listed at the end of every piece, and reviewed by Joe Garraffo before publication. Legal-topic articles describe published guidance and filings and are not legal advice.

Article title card reading Does a Practice Need a Do Not Sell Link, from Consential Research

Ask a practice owner whether their site needs a Do Not Sell link and the answer arrives before the question finishes: we do not sell patient data. That statement is almost always true, it is said in good faith, and it does not answer the question, because the statutes did not define the word the way ordinary usage does.

This is one of the few places in privacy law where the everyday meaning of a term and its legal meaning diverge far enough to produce confident, sincere errors. Working through the definition takes ten minutes and changes what a practice concludes about its own website.

What the Do Not Sell link actually signals

The link is not a promise. It is a mechanism, and its presence is an admission that something within the definition is happening. That is why adding one defensively is not costless, and why omitting one when it is required is a visible, externally checkable failure.

California's framework, described by the California Attorney General, requires businesses that sell or share personal information to provide a clear and conspicuous link enabling consumers to opt out. The obligation attaches to the activity, not to the industry. A business that neither sells nor shares does not need the link and should not have one.

Sale, as defined rather than as understood

Disclosing personal information to a third party for monetary or other valuable consideration. The second half is where practices land unexpectedly. No invoice needs to exist. Receiving analytics, audience-building capability or improved ad targeting in return for data can be consideration.

California then adds a second, separately defined activity: sharing, meaning disclosure to a third party for cross-context behavioural advertising. Sharing is regulated whether or not anything of value comes back at all. This is precisely why the required link reads "Do Not Sell or Share My Personal Information" rather than referring to sales alone.

Why "we do not sell data" is usually the wrong test

Set the definitions against what a typical practice website does.

An advertising pixel on a treatment page passes a persistent identifier, the page address and the visitor's IP address to a platform, which uses them to build and target audiences including audiences the practice will later advertise to. Nobody sent an invoice. Personal information was disclosed to a third party, and it was disclosed for cross-context behavioural advertising, which is the definition of sharing almost verbatim.

THE QUESTION PRACTICES ASK VS THE QUESTION THE STATUTE ASKS "Did we sell patient data?" Did money change hands for records? Almost always: no "Did we sell OR share?" Disclosed for valuable consideration, or for cross-context advertising? WHAT AN AD PIXEL ON A TREATMENT PAGE ACTUALLY DOES Passes a persistent id + page address + IP to a platform, which builds audiences from it. No invoice exists. It still meets the sharing definition, and may meet the sale definition.
Two separately defined activities. A practice can be entirely correct that it never sold anything and still be sharing.

The other common defence is that the data is anonymous. It is worth being precise here, because the argument fails on a technicality that is not really a technicality: a persistent identifier is personal information when it is reasonably linkable to a person, and a large advertising platform receiving it generally holds what is needed to link it. The reasoning is worked through in what counts as PHI on a website, and it applies with equal force outside HIPAA.

A third defence deserves a mention because it is the most technically sophisticated and still does not land. Practices sometimes point out that they have signed the advertising platform's data processing terms, which designate the platform as a service provider acting on their instructions rather than as an independent third party. That designation genuinely matters, and it is the correct structure where it holds. It holds only while the platform actually confines itself to your instructions. A platform that also uses what it receives to improve its own models or to build audiences usable by other advertisers is not behaving as a service provider on that data, whatever the contract is called, and the analysis reverts.

The useful question to put to a vendor is therefore narrower than whether they will sign something. It is whether the specific data flow from your site is confined to your purposes, in writing, with the setting that enforces it identified by name. Vendors who can answer that will answer it quickly.

Where the HIPAA exemption leaves you

Every state privacy law contains a HIPAA-related exemption, and this is where practices reasonably expect to be released. Whether they are depends on which shape their state wrote.

An entity-level exemption excludes the covered entity itself, and where one applies the analysis genuinely ends. A data-level exemption excludes only protected health information as 45 CFR 160.103 defines it, and leaves everything else in scope.

The practical consequence is uncomfortable, because the population a data-level exemption fails to protect is exactly the population a website generates. People who browsed and never became patients are not patients, so nothing about them is PHI, so nothing about them is exempt. A practice with excellent digital marketing has a large number of these people, and they are the ones an advertising audience is built from.

Not patients The individuals most affected by website sharing are usually the ones a HIPAA-based exemption does nothing for, because they never became patients in the first place.

Which shape applies is set state by state, and it is recorded per state in our California breakdown and its companions. This is the single most useful thing to check before concluding that being a covered entity settles the matter.

So does your practice need a Do Not Sell link?

Three questions, in order, and the first two dispose of most cases.

Does a state privacy law apply to you at all? Comprehensive privacy laws generally have thresholds based on revenue, records processed, or share of revenue derived from selling data. Many single-location practices fall below all of them. Note that the health data statutes discussed in consumer health data under state law largely do not have such thresholds, so a practice can be below the comprehensive-law floor and squarely inside a health data statute.

Are you selling or sharing as defined? Not as understood. If advertising tags on your pages pass identifiers to platforms for audience building, assume yes until someone demonstrates otherwise from a network log.

Does your state's HIPAA exemption reach the data in question? Entity-level, and you are likely done. Data-level, and your non-patient website data is still in scope.

If the answers put you in scope, the link is the visible part and not the hard part. The harder requirement in California is honouring a recognised opt-out preference signal such as Global Privacy Control, which arrives in the browser request itself. A visitor who has enabled it has opted out before your page rendered, without clicking anything, and a link cannot satisfy an obligation to respect a signal that was already sent.

1. Does a state privacy law apply to you at all? Revenue, record count, or share of revenue from selling data No: stop 2. Are you selling or sharing as those terms are defined? Read from a network log, not from intentions No: stop 3. Does your state's HIPAA exemption reach this data? Entity-level ends it. Data-level leaves non-patient data in scope. Data-level: link required Question 2 is the one nobody can answer from memory, and the one that decides most cases.
Ordered so the cheap disqualifiers come first. Most practices never reach question three.

What to do instead of guessing

The reason this question stays unresolved in most practices is that it is being answered from memory rather than from evidence. Nobody knows what the tags are doing, so the discussion stays at the level of intentions, and intentions are genuinely good.

Start from the network log. Get the list of third parties receiving data from your pages, then ask what each receives and why. That list is the input every one of the three questions above needs, and it is usually the first time anyone has seen it.

Then consider what a default of nothing does to the analysis. If non-essential tags are held until a visitor agrees, the sharing that triggers these obligations does not happen by default, the opt-out signal is honoured by construction because nothing was going to fire anyway, and the record of what each visitor chose exists if anyone asks. That is what consent gating produces, and combined with state privacy detection it means the right notice reaches the right visitor without maintaining a decision tree per state.

One caution to close on. Do not add a Do Not Sell link defensively because it seems safer. The link asserts that you sell or share, and it commits you to honouring requests made through it. Publishing one you cannot service is worse than not publishing it, and it is the kind of inconsistency that reads badly precisely when someone is looking.

The mirror image of that caution is worth stating too, because practices tend to make one error or the other. A privacy policy that flatly declares you never sell or share personal information, published on a site whose pages pass identifiers to three advertising platforms, is a statement that can be checked against observable behaviour by anyone in about two minutes. Under most state regimes an inaccurate privacy disclosure is independently actionable as a deceptive practice, entirely separately from whatever the underlying sharing rules require. That means the policy language can create exposure that the sharing itself would not have.

The uncomfortable conclusion is that the safest position is not the most reassuring language. It is language that matches what a network log shows, which requires knowing what the log shows before writing the policy. Practices almost always do it in the opposite order.

Key takeaways

  • Sale means disclosure for monetary or other valuable consideration. No invoice is needed for the definition to be met.
  • Sharing is separately defined as disclosure for cross-context behavioural advertising, and is regulated whether or not anything comes back.
  • An advertising pixel passing identifiers to a platform for audience building is the fact pattern these definitions describe.
  • A data-level HIPAA exemption protects patient records and leaves non-patient website data exposed, which is most of what a site generates.
  • In California, honouring an opt-out preference signal like Global Privacy Control is a harder requirement than displaying a link, because it arrives before the page renders.
  • Do not add the link defensively. It asserts that you sell or share, and commits you to servicing requests made through it.

Common questions

Does a medical practice need a Do Not Sell or Share My Personal Information link?

It depends on whether a state privacy law applies to the practice and whether the practice sells or shares personal information as those terms are defined. The definitions are broader than a cash transaction, and the HIPAA exemption in many states is data-level, covering protected health information only and leaving website and marketing data in scope.

We don't sell patient data. Does that settle it?

Usually not. Under California law, sharing personal information with a third party for cross-context behavioural advertising is regulated even without payment, and a disclosure in exchange for other valuable consideration can constitute a sale. Running advertising tags that pass identifiers to a platform is the fact pattern these definitions were written for.

What is the Global Privacy Control?

A browser-level signal that communicates an opt-out preference automatically. California treats a recognised opt-out preference signal as a valid request, meaning a site may need to honour it even though the visitor never clicked anything on the page. A link alone does not satisfy a requirement to respect the signal.

Editorial note. This article describes what published guidance, statutes and court filings say as of its publication date. It is general information, not legal advice, and it is not a statement about any particular practice's obligations. Consential.io is not a law firm. Regulations and case law change. Confirm your own position with healthcare counsel licensed in your state before acting on anything here.

Sources

  1. California Consumer Privacy Act, California Attorney General Including the definitions of sale and sharing and the HIPAA-related exemptions
  2. 45 CFR 160.103, definitions of covered entity and protected health information For the boundary a data-level exemption draws
  3. Chapter 19.373 RCW, Washington My Health My Data Act For the separate authorisation a sale of consumer health data requires

Find out what your pages are already sharing

The free scan names every third party receiving data from your site before a visitor consents, which is the input this question needs.