California · CCPA/CPRA
California privacy law, explained for practice owners
The one where the threshold is the least of your problems
The short answer
California does not exempt your practice — it exempts your patient records. If your practice cleared more than $25 million in gross revenue last year, or touched the personal information of 100,000 California residents, the CCPA applies to everything you hold that isn't protected health information: your website analytics, your ad platform identifiers, your prospect lists, your staff records. And even if you fall under both thresholds, California's medical confidentiality law and its wiretapping statute both carry private rights of action that no privacy-law threshold protects you from.
or 100k consumers
per violation
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does CCPA/CPRA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Being a covered entity does not exempt you
California exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.
Do you cross the threshold?
$25M revenue or 100k consumers. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.
If you are near the line, get the number from your analytics rather than estimating from patient volume.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
California privacy law: the key facts
| Law | California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA) |
|---|---|
| Citation | Cal. Civ. Code § 1798.100 et seq. |
| Effective | January 1, 2020 CPRA amendments effective January 1, 2023; CPPA regulations on risk assessments, automated decisionmaking, and cybersecurity audits phase in from 2026. |
| Who enforces it | California Privacy Protection Agency and the Attorney General |
| Applicability | You are a covered business if, in the prior calendar year, you met any one of these:
The revenue test is the one that catches practices. It is total gross revenue, not California revenue, and it says nothing about how much data you hold. A multi-provider practice group clearing $25M in collections is a covered business even if it has three hundred California patients. |
| HIPAA exemption | Data-level only — PHI is exempt, the practice is not California carves out the data, not the entity. Protected health information handled under HIPAA is exempt, and so is patient information a provider maintains in the same manner as PHI. Medical information governed by California's own Confidentiality of Medical Information Act is exempt too. What is not exempt: everything else you hold. Website analytics on your public pages. Ad platform identifiers. Newsletter lists. Prospective-patient form fills before anyone becomes a patient. Employee and job-applicant records. California is the state where “we're a HIPAA covered entity” is the least useful sentence a practice can say. |
| Sensitive data | Sensitive personal information includes health data, precise geolocation, racial or ethnic origin, and biometric information. California's approach is a right to limit its use rather than an opt-in gate: a consumer can tell you to use their sensitive information only for the purposes the statute permits. |
| Definition of “sale” | Broad — monetary or other valuable consideration California defines “sell” and “share” broadly enough to capture disclosures where no money changes hands. Sharing personal information with a third party for cross-context behavioral advertising is a regulated “share” on its own terms. In practice that means a Meta Pixel or a Google Ads remarketing tag on your site is very likely a share, and it triggers a “Do Not Sell or Share My Personal Information” opt-out you must offer. |
| Universal opt-out / GPC | Yes. California requires businesses that sell or share personal information to treat an opt-out preference signal — in practice, Global Privacy Control — as a valid request from that consumer's browser. You cannot require the visitor to find your footer link if their browser already told you no. |
| Consumer rights |
|
| Cure period | There is no guaranteed right to cure. The CPRA removed the automatic 30-day cure the original CCPA gave businesses; the Attorney General and the California Privacy Protection Agency may consider a cure, but neither owes you one. Assume the first letter you receive is not a warning. |
| Penalties | Administrative and civil penalties run to $2,500 per violation, rising to $7,500 for an intentional violation or one involving a consumer the business knows is under 16. These statutory figures are adjusted for inflation. Critically, a “violation” is counted per consumer, per incident — not per website. |
| Private right of action | Yes, and this is where the real money is. California is the only state on this list whose comprehensive privacy law includes a private right of action, and it is limited to data breaches. But two other California statutes matter far more to a medical website:
|
What it means for you
The parts that actually change how you operate
The CIPA problem is bigger than the CCPA problem
If you own a practice in California and you are worried about the wrong statute, this is the paragraph to read twice.
The CCPA is enforced by regulators with finite bandwidth. The California Invasion of Privacy Act is enforced by plaintiffs' firms with software that crawls websites looking for third-party trackers, and it has no revenue threshold, no HIPAA carve-out worth relying on, and no cure period. The theory is straightforward: your page loaded a third-party script that read the visitor's activity, so a third party “eavesdropped” on a communication without consent.
California courts in 2026 have been notably unsympathetic to healthcare sites that let marketing pixels sit on pages where the URL or the page content reveals what a visitor is there for. A page path like /hair-transplant-consultation tells an ad platform something about the person who loaded it. That is the whole claim.
The defense is boring and it works: do not let third-party tags load until the visitor has agreed, and keep a record showing when they did.
CMIA: $1,000 per person, no harm required
The Confidentiality of Medical Information Act predates HIPAA in California and it is stricter in one specific way that matters to your website. It gives the individual a direct claim, and § 56.36 provides nominal damages of $1,000 per violation without requiring proof that anything bad happened.
Multiply that by the number of people who filled out a form on a page where a tracker was running. That is not a regulatory risk model, that is a class action arithmetic problem, and it is the reason California health systems settled tracking cases rather than litigate them.
What the CPPA regulations added for 2026
The California Privacy Protection Agency finalized regulations that go beyond notice-and-choice into documented process. Depending on your size and what you do with data, they can require:
- Risk assessments for processing that presents significant risk to privacy, including selling or sharing personal information and processing sensitive information;
- Cybersecurity audits for larger businesses, on a phased schedule;
- Disclosures and opt-outs for automated decisionmaking technology when it is used for significant decisions.
The through-line is that California has stopped asking whether you have a banner and started asking whether you can produce documentation. A consent record with timestamps is documentation. A screenshot of your cookie notice is not.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in California
Administrative and civil penalties run to $2,500 per violation, rising to $7,500 for an intentional violation or one involving a consumer the business knows is under 16. These statutory figures are adjusted for inflation. Critically, a “violation” is counted per consumer, per incident — not per website.
The arithmetic nobody puts in a proposal
Take a modest number. Two thousand California visitors reach your consult page in a quarter while a marketing pixel fires before anyone has consented. At the non-intentional rate that is 2,000 × $2,500 — a theoretical $5 million — before anyone argues intent. Nobody expects a regulator to bill the ceiling. The point is that the exposure scales with your traffic, and your traffic is the thing your marketing budget is designed to increase.
Your privacy policy says you don't sell data. Your pixel disagrees.
Almost every practice privacy policy in California contains a sentence like “we do not sell your personal information.” Almost every practice website simultaneously runs Meta and Google advertising tags that share identifiers for cross-context behavioral advertising, which California treats as a regulated “share” requiring an opt-out link.
That mismatch is worse than having no policy at all, because now the statement is affirmatively inaccurate and it is in writing, signed by you, published on your own domain. Regulators and plaintiffs both start there.
Do this
Your California action list
In order. Items one and two are the ones that change your answer to everything else.
- Establish whether you crossed $25M gross revenue or 100,000 California consumers last year — get this from your CPA, in writing, and re-check annually.
- Inventory every third-party script on your site. Not what your web team believes is there — what actually loads in a browser.
- Stop non-essential tags from firing before consent, especially on treatment, consult, and form pages.
- Honor Global Privacy Control as an opt-out, not as a suggestion.
- Add a working “Do Not Sell or Share My Personal Information” mechanism if any tag qualifies as a sale or share.
- Reconcile your privacy policy with what your site actually does, then keep them reconciled.
- Keep an append-only record of consent events, so you can answer “what did this visitor agree to, and when?” a year from now.
- Have healthcare counsel review CMIA and CIPA exposure specifically. These are not covered by a CCPA compliance checklist.
Questions
California privacy law FAQ
Does the CCPA apply to a HIPAA covered entity in California?
Partly. California exempts protected health information and medical information governed by HIPAA or the CMIA, but it does not exempt the covered entity. Your non-PHI data — website analytics, advertising identifiers, prospect and marketing lists, employee records — remains subject to the CCPA if your practice meets any applicability threshold.
Is a Meta Pixel a “sale” of personal information under California law?
California's definitions of “sell” and “share” reach disclosures made for monetary or other valuable consideration, and separately reach sharing for cross-context behavioral advertising. Advertising pixels commonly meet the “share” definition even when no money changes hands, which triggers an opt-out obligation.
What is the fine for a CCPA violation?
Up to $2,500 per violation, or $7,500 for an intentional violation or one involving a consumer under 16, adjusted for inflation. Violations are counted per consumer, so exposure scales with site traffic rather than with the number of pages at issue.
Do I get a chance to fix a problem before being fined in California?
Not as a matter of right. The CPRA eliminated the automatic 30-day cure period. Regulators may take remediation into account, but no statutory cure period protects you.
Why do California practices get sued over trackers when HIPAA covers them?
Because the suits are not brought under HIPAA, which has no private right of action. They are brought under the Confidentiality of Medical Information Act and the California Invasion of Privacy Act, both of which let individuals sue directly and neither of which is defeated by being a HIPAA covered entity.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in California and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing