Most summaries of state privacy law treat it as one subject with fifty variations. For a medical practice that framing hides the thing that matters, because two genuinely different families of statute reach a practice website, and consumer health data laws are the family almost nobody explains properly.
The distinction is not academic. It decides whether the reassuring sentence a practice usually hears, that HIPAA-covered entities are exempt, does any work at all. Frequently it does not, and the reason is structural rather than a matter of interpretation.
Two different families of state law
The first family is the comprehensive consumer privacy law. Twenty states now have one in effect. These cover personal data broadly, grant rights to access and delete, and typically treat health information as one category of sensitive data among several alongside biometrics, precise geolocation and immigration status. California's is the best known, and our state-by-state breakdown covers each of the twenty individually.
The second family is much smaller and much sharper: dedicated statutes regulating health information specifically, written after the 2022 shift in reproductive privacy and aimed squarely at the gap where health data sits outside HIPAA. They are not general privacy laws with a health chapter. They are health statutes with their own definitions, their own consent architecture and, in one case, their own private right of action.
What consumer health data laws actually cover
The definitional move that makes these statutes powerful is that they do not ask whether you are a healthcare provider. They ask whether information identifies a consumer and relates to their physical or mental health status, and they read that relationship broadly.
Why the breadth matters on a website
Under a definition of that shape, an inference about health status can qualify. A visit to a page about a specific treatment, associated with an identifier, is the kind of linkage these statutes were written to reach, which is precisely the theory a federal court removed from the HIPAA analysis in 2024. Removing it from one framework does not remove it from the other.
That is the single most important thing for a practice to understand. The 2024 ruling narrowed HIPAA's reach over public marketing pages, and it said nothing whatsoever about state law. A practice that read the ruling and reinstated everything has improved its HIPAA position and left its state position untouched, which for a Washington visitor is the position with a private right of action attached.
The second structural feature is separate consent. These statutes generally require affirmative consent to collect, and a further separate consent to share, with sale requiring a distinct written authorisation. Bundling all of that into one accept button does not satisfy a requirement built specifically to prevent bundling.
A third feature gets less attention and is worth knowing about because it is not a website matter at all: geofencing restrictions. Several of these statutes prohibit establishing a virtual boundary around a healthcare facility for the purpose of identifying or advertising to people near it. A practice would rarely do that to itself, but an agency running proximity-targeted campaigns around competitor locations, or around a hospital, may be doing exactly the thing the provision names. That belongs on the list of questions to ask a media buyer, not a web developer.
The fourth is that these laws generally attach rights to deletion that are broader than practices expect, and require a mechanism for exercising them. A consumer asking a practice to delete their consumer health data is not necessarily a patient, and the request may reach data held by vendors rather than by the practice. Being able to answer that request depends on knowing which vendors received what, which is an inventory problem before it is a legal one.
The states with dedicated consumer health data laws
Three matter, and they behave differently enough that treating them as one group causes errors. Note that the list is short today and was zero four years ago, which is the more useful thing to know about it.
| State | Instrument | Distinguishing feature |
|---|---|---|
| Washington | My Health My Data Act, RCW 19.373 | Private right of action through the Consumer Protection Act. The reason this family gets attention. |
| Nevada | Senate Bill 370 (2023) | Structurally similar to Washington, enforced only by the attorney general. No private suits. |
| Connecticut | Amendments to its comprehensive act | Health provisions added to a general privacy law rather than a standalone statute. |
Notice what is absent from that table: Washington and Nevada do not appear among the twenty states with comprehensive privacy laws, because health data is the route they took instead. A practice working from a list of comprehensive-law states will not see either of them, and those two are the ones with the health-specific obligations.
Washington's is the one to understand first, both because of the private right of action and because it applies based on where the consumer is rather than where the business is. Full treatment is in what My Health My Data means for a practice website, and the state-by-state comparison against Nevada is in Nevada and Washington side by side.
How the HIPAA exemption works, and where it stops
Every one of these laws contains a HIPAA-related exemption, which is where the false comfort comes from. The exemptions are not all the same shape, and the shape is what decides the outcome.
An entity-level exemption excludes a covered entity itself from the statute. Where one applies, the analysis genuinely does end there.
A data-level exemption excludes only protected health information as HIPAA defines it, and leaves everything else the business holds inside the state law. This is the common case and it is far narrower than practices assume, because a practice website is full of data that is not PHI: prospective patients who never became patients, marketing analytics, newsletter subscribers, ad campaign audiences. All of that sits outside HIPAA's definition and therefore outside a data-level exemption's protection.
The distinction between the two is set state by state, and it is recorded per state in our state-by-state breakdown. The practical guidance is simple: never accept "we are a covered entity, so state law does not apply" without checking which kind of exemption the relevant state wrote.
There is a further trap for practices that concluded they sit outside HIPAA altogether, a possibility examined elsewhere in this series. Being outside HIPAA removes access to the exemption entirely. A cash-pay aesthetics practice with no electronic billing is exactly the entity these health data statutes were written to capture, and it has no HIPAA shelter to claim.
That asymmetry is worth stating directly, because it inverts what most practices expect. The information a data-level exemption fails to protect is precisely the information a website generates: people who browsed and left, people who filled in a form and never booked, audiences assembled for advertising. Those individuals are not patients, so nothing about them is protected health information, so nothing about them is exempt. The better a practice is at digital marketing, the larger that unprotected population is.
What this means for a practice website
Three conclusions carry across every state in both families.
First, the applicable framework is decided by where your visitor is, not where you are. A practice in one state routinely has visitors from many, and rights attach to the consumer. This is why detecting the visitor's state and showing the right notice is an operational requirement rather than a nicety, and it is what state privacy detection does.
Second, consent has to be capable of being separated. A single accept button cannot express separate agreement to collect and to share, and it certainly cannot carry a written authorisation to sell. Architecture that assumes one binary decision will not satisfy a statute built around several.
Third, and least discussed, these statutes reward being able to show what happened. Where a private right of action exists, the question in dispute becomes what a specific visitor was shown and what they chose on a specific date. An append-only record of that answers it. A policy describing what the site is configured to do does not. That is the entire reason consent gating writes a durable record rather than simply setting a cookie.
A closing note on how to keep up with this without reading legislatures. The number of states in each family changes every session, and any article naming a count is accurate for a while and then quietly is not. What does not change nearly as fast is the structure: two families, a coverage test that follows the consumer, exemptions that come in two shapes, and consent that has to be separable. A practice that builds around the structure rather than around a list of state names does not have to redo the work each time another state joins. That is the argument for treating this as an architecture decision rather than as a compliance checklist to be refreshed annually.
Key takeaways
- Two separate families: twenty comprehensive privacy laws, and a small number of dedicated consumer health data statutes with their own definitions and consent rules.
- Washington and Nevada are not among the twenty comprehensive-law states, so a list of those states omits the two with health-specific obligations.
- The 2024 federal ruling narrowed HIPAA's reach over public pages and changed nothing about state law.
- HIPAA exemptions come in two shapes. Entity-level ends the analysis; data-level protects only PHI and leaves marketing and prospect data exposed.
- Health data statutes largely lack the size thresholds that exempt small businesses from comprehensive privacy laws.
- Coverage follows the visitor, not the practice, and separate consent to collect and to share cannot be expressed by a single accept button.
Common questions
Are consumer health data laws the same as state privacy laws?
No. They are two separate families. Comprehensive consumer privacy laws, of the kind now in effect in twenty states, cover personal data broadly and usually treat health information as one sensitive category. Consumer health data laws are dedicated statutes covering health information specifically, with their own definitions, consent requirements and enforcement.
Does being outside HIPAA mean state health data laws do not apply?
It generally means the opposite. Consumer health data statutes were written substantially to cover information that HIPAA does not reach, so a practice or product outside HIPAA is more likely to be squarely inside them, not less.
Does the HIPAA exemption in a state privacy law cover my whole practice?
It depends on whether the exemption is entity-level or data-level, and states differ. An entity-level exemption can exclude a covered entity altogether. A data-level exemption excludes only the protected health information itself, leaving marketing data, website analytics and non-patient contacts inside the law. Check the specific state.
Editorial note. This article describes what published guidance, statutes and court filings say as of its publication date. It is general information, not legal advice, and it is not a statement about any particular practice's obligations. Consential.io is not a law firm. Regulations and case law change. Confirm your own position with healthcare counsel licensed in your state before acting on anything here.
Sources
- Chapter 19.373 RCW, Washington My Health My Data Act Washington State Legislature
- California Consumer Privacy Act, California Attorney General Includes the CCPA HIPAA-related exemptions
- Nevada Senate Bill 370 (2023), consumer health data Cited without a link: the Nevada legislature record could not be verified from our environment, and a candidate URL resolved to a different bill.
- 45 CFR 160.103, definitions of covered entity and protected health information Electronic Code of Federal Regulations
See which framework applies to your visitors
Consential detects the state a visitor is in and shows the notice that state expects, recorded on an append-only trail.