Colorado · CPA
Colorado privacy law, explained for practice owners
Opt-in for health data, $20,000 a violation, no cure period
The short answer
Colorado does not let a medical practice out of its privacy law. It exempts protected health information, not covered entities, so your practice is a regulated controller for all the data on your website that isn't a patient record. Two Colorado specifics make this sharper than most states: health data is sensitive data requiring opt-in consent before processing, and Colorado formally requires you to honor Global Privacy Control as a recognized universal opt-out signal. The 60-day cure period expired in January 2025, and penalties run to $20,000 per violation — the steepest per-violation figure in the country.
or 25k + data revenue
per violation
Jan 1, 2025
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does CPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Being a covered entity does not exempt you
Colorado exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.
Do you cross the threshold?
100k consumers or 25k + data revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.
If you are near the line, get the number from your analytics rather than estimating from patient volume.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
Colorado privacy law: the key facts
| Law | Colorado Privacy Act (CPA) |
|---|---|
| Citation | Colo. Rev. Stat. § 6-1-1301 et seq. |
| Effective | July 1, 2023 Universal opt-out mechanism recognition required since July 1, 2024. Cure period expired January 1, 2025. |
| Who enforces it | Attorney General and district attorneys |
| Applicability | The CPA reaches controllers that conduct business in Colorado or target Colorado residents and, in a calendar year, either:
Note what is absent: any revenue threshold at all. Colorado does not care how big you are, only how many Coloradans' data you touch. Website visitors are consumers. |
| HIPAA exemption | Data-level only — PHI is exempt, the practice is not Colorado exempts protected health information and several categories of health-related data, but it does not exempt HIPAA covered entities as entities. Your practice stays inside the statute for every piece of personal data that is not PHI. For a Colorado practice, the exposed surface is the public website: analytics identifiers, advertising cookies, IP addresses, and form data captured before anyone becomes a patient. |
| Sensitive data | Sensitive data — including data revealing a physical or mental health condition or diagnosis — requires opt-in consent before you process it. This is the reverse of California's model. In Colorado, silence is a no. Read that against a practice website. If a tracker on a treatment page transmits something that reveals a health interest, the question is not whether you gave the visitor a way to object. It is whether you obtained consent first. |
| Definition of “sale” | Broad — monetary or other valuable consideration Colorado defines a sale as an exchange for monetary or other valuable consideration. Handing visitor identifiers to an advertising platform in exchange for better ad targeting is the textbook example of other valuable consideration. Colorado also gives consumers a separate opt-out of targeted advertising and of profiling in furtherance of significant decisions, so even a narrow reading of “sale” does not get you out of the opt-out obligation. |
| Universal opt-out / GPC | Colorado went first and went furthest. The Colorado Department of Law maintains an official public list of recognized universal opt-out mechanisms, and Global Privacy Control is on it. This is not a best practice you can defer. It is a named signal, on a state-published list, that you are required to honor. |
| Consumer rights |
|
| Cure period | Gone. The CPA's 60-day right to cure sunset on January 1, 2025. Colorado enforcement no longer comes with a built-in grace period. |
| Penalties | CPA violations are deceptive trade practices under the Colorado Consumer Protection Act, which carries civil penalties of up to $20,000 per violation. That is the highest per-violation figure of any state on this list — four times the Connecticut number and nearly three times the common $7,500 ceiling. |
| Private right of action | No private right of action under the CPA. Enforcement sits with the Attorney General and Colorado's district attorneys. The absence of private suits is genuine relief compared to California, but it also means enforcement arrives as a government inquiry rather than a demand letter you can settle quietly. |
What it means for you
The parts that actually change how you operate
Colorado's universal opt-out list is not optional and not vague
Most state privacy laws say something abstract about honoring “an opt-out preference signal.” Colorado did the unusual thing and published a list. The Department of Law ran an application and public comment process, and Global Privacy Control became the first recognized universal opt-out mechanism under the CPA.
That specificity cuts both ways. It removes any argument about which signal you were supposed to honor — and it removes any argument that you did not know. A regulator can test your site with a GPC-enabled browser in about fifteen seconds and see whether your trackers stopped.
The practical failure mode we see constantly: a practice installs a consent banner, the banner renders correctly, and the site ignores GPC entirely because nobody wired the signal to the tag-blocking logic. The banner is theater; the signal is the test.
Opt-in for health data changes the default on your own website
Colorado treats data revealing a physical or mental health condition or diagnosis as sensitive data requiring consent before processing. Most practices read that and think about patient charts, which are PHI and exempt.
Now read it about the part that isn't exempt. A visitor lands on your hair restoration page. An advertising tag records the visit against a persistent identifier. That transmission carries an inference about a health interest attached to a specific device.
Whether any given tag crosses the line is a question for your counsel, and it depends on what the tag actually sends. But the structure of the risk is clear, and the mitigation is the same either way: nothing non-essential fires until the visitor says yes, and you keep the record that they did.
What Colorado asks you to write down
The CPA requires data protection assessments for processing that presents a heightened risk of harm — which expressly includes processing sensitive data and processing for targeted advertising. An assessment is a document. It has to exist before the processing, and it has to be producible on request.
Colorado also requires contracts with your processors, meaningful privacy notice content, and a working appeals process for denied consumer requests. None of it is exotic. All of it is the kind of thing that either exists in a file or does not.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in Colorado
CPA violations are deceptive trade practices under the Colorado Consumer Protection Act, which carries civil penalties of up to $20,000 per violation. That is the highest per-violation figure of any state on this list — four times the Connecticut number and nearly three times the common $7,500 ceiling.
The arithmetic nobody puts in a proposal
Colorado's number is the one to put in front of a skeptical partner. At $20,000 per violation, a single quarter of unconsented tracking across a few thousand Colorado visitors produces a number with more zeros than the practice's annual marketing budget. Enforcement discretion is real and no regulator seeks the ceiling — but the ceiling is what defines the negotiating position you would be starting from.
The cure period you are counting on expired in January 2025
A lot of practice owners absorbed the 2023 version of this law, in which a Colorado inquiry came with 60 days to fix the problem. That provision sunset on January 1, 2025.
The operational consequence is that the compliance work has to be done before contact, not after it. There is no longer a mechanism that converts “we hadn't gotten to it” into “we fixed it within the statutory window.”
Do this
Your Colorado action list
In order. Items one and two are the ones that change your answer to everything else.
- Count your Colorado consumers honestly, including website visitors — the 25,000 and 100,000 thresholds have no revenue floor beneath them.
- Test your own site in a browser with Global Privacy Control enabled and confirm trackers actually stop.
- Treat anything that reveals a health condition or diagnosis as requiring consent first, not objection later.
- Block non-essential tags on treatment and consult pages until consent is captured.
- Write the data protection assessment for targeted advertising and sensitive-data processing before the processing starts.
- Put processor contracts in place with every vendor that touches visitor data.
- Build the appeal path for denied consumer requests, and document who owns it.
- Keep an append-only consent log. With the cure period gone, contemporaneous records are the only retroactive defense you have.
Questions
Colorado privacy law FAQ
Does the Colorado Privacy Act apply to healthcare providers?
Yes, to the extent they process data that is not protected health information. Colorado provides a data-level exemption for PHI and certain health data, not an entity-level exemption for HIPAA covered entities, so a provider's website analytics, advertising data, and marketing lists remain in scope if the provider meets an applicability threshold.
Is Global Privacy Control required in Colorado?
Colorado requires controllers to honor a recognized universal opt-out mechanism, and the Colorado Department of Law has recognized Global Privacy Control as a valid mechanism. Honoring the GPC signal is therefore a specific, testable obligation rather than a general best practice.
What is the penalty under the Colorado Privacy Act?
Violations are deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation — the highest per-violation ceiling among the state comprehensive privacy laws.
Does Colorado still give a 60-day cure period?
No. The Colorado Privacy Act's right to cure expired on January 1, 2025. Enforcement no longer includes a statutory grace period.
Do I need consent before processing health data in Colorado?
Yes. Data revealing a physical or mental health condition or diagnosis is sensitive data under the CPA and requires the consumer's opt-in consent before processing. This differs from California, which uses a right to limit rather than an opt-in gate.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Colorado and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing