Connecticut · CTDPA

Connecticut privacy law, explained for practice owners

Rewritten July 2026. Sensitive data is now a trigger, not a threshold.

Hinges on covered-entity status In effect since July 1, 2023 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Connecticut still exempts HIPAA covered entities and business associates at the entity level, so a true covered entity is outside the CTDPA. The catch is what happened on July 1, 2026: the threshold dropped to 35,000 consumers and gained a new trigger that has no volume floor at all — processing any sensitive data, which includes health information. For a practice that is not actually a HIPAA covered entity, and many cash-pay aesthetic and elective practices are not, Connecticut is now one of the easiest state privacy laws in the country to fall under.

In effect sinceJuly 1, 2023
Applies at35k consumers —
or any sensitive data
Max penaltyUp to $5,000
per willful violation
Cure periodExpired
Dec 31, 2024

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does CTDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, CTDPA does not apply to you at all — Connecticut exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 35k consumers — or any sensitive data.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Connecticut privacy law: the key facts

Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq., as amended by Public Act 25-113. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawConnecticut Data Privacy Act (CTDPA)
CitationConn. Gen. Stat. § 42-515 et seq., as amended by Public Act 25-113
EffectiveJuly 1, 2023
Substantially rewritten by SB 1295 / Public Act 25-113, effective July 1, 2026. Profiling impact assessments apply to activity generated on or after August 1, 2026.
Who enforces itAttorney General
Applicability

As of July 1, 2026, Connecticut applies to any entity doing business in the state or targeting Connecticut residents that, in the prior year, met any one of these:

  • controlled or processed the personal data of 35,000 or more consumers (down from 100,000), excluding data processed solely to complete a payment transaction;
  • controlled or processed any sensitive data at all, regardless of volume; or
  • offered consumers' personal data for sale in trade or commerce, regardless of volume.

The old test that required 25% of revenue from selling data is gone. Read the second bullet again: volume no longer protects you if you touch sensitive data, and Connecticut's definition of sensitive data expressly covers physical and mental health information.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Connecticut keeps an entity-level exemption for HIPAA covered entities and business associates. If your practice is genuinely a covered entity, the CTDPA's controller and processor obligations do not apply to you — and Public Act 25-113 did not change that. What it did change was the Gramm-Leach-Bliley exemption, which dropped from entity-level to data-level. Financial institutions lost their blanket carve-out; healthcare providers did not.

That makes one question decisive in Connecticut, and most practices have never actually answered it: are you a HIPAA covered entity? See below.

Sensitive data

Sensitive data requires opt-in consent, and Public Act 25-113 widened the category. It now expressly reaches mental and physical health information — with the definition expanded from condition and diagnosis to include disability or treatment — as well as transgender or nonbinary status, genetic and biometric data, neural data, financial account information, and government identifiers.

Because processing any sensitive data is now itself an applicability trigger, the sensitive data definition and the scope question are the same question in Connecticut.

Definition of “sale”

Broad — monetary or other valuable consideration

Connecticut's definition of sale reaches exchanges for monetary or other valuable consideration, so advertising data flows can qualify. Consumers also get a standalone opt-out of targeted advertising, which does not depend on whether a transfer was a “sale” at all.

Universal opt-out / GPC

Yes. Connecticut has required controllers to recognize a universal opt-out signal since January 1, 2025. Global Privacy Control is the mechanism in practical use.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and profiling in furtherance of significant decisions
  • Consent required before processing sensitive data
  • Appeal a denied request
  • From August 1, 2026: profiling impact assessments for consequential automated decisions
Cure period

Expired. The CTDPA's 60-day cure period ran out at the end of 2024. The Attorney General may still offer an opportunity to cure at his discretion, but you are not entitled to one.

Penalties

CTDPA violations are enforced as unfair trade practices under the Connecticut Unfair Trade Practices Act, which carries civil penalties of up to $5,000 per willful violation, plus restitution, injunctive relief, and the state's costs and fees. The headline number is the lowest on this list — but CUTPA remedies are not limited to the per-violation figure, and injunctive relief that forces you to change how your website works can cost more than the fine.

Private right of action

No private right of action under the CTDPA. Enforcement runs through the Attorney General's office, which has been among the more active state privacy enforcers and has published its own findings on the industries it reviewed.

What it means for you

The parts that actually change how you operate

Are you actually a HIPAA covered entity? In Connecticut this is the whole question

Connecticut's entity-level exemption is generous, which makes it dangerous to assume. A HIPAA covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a HIPAA standard transaction — claims, eligibility checks, remittance advice, and the like.

The word doing the work is transactions. A provider who never bills insurance electronically, never checks eligibility electronically, and never submits a standard transaction may not be a covered entity at all. That describes a meaningful slice of the aesthetic, elective, and cash-pay market: hair restoration practices that do not bill insurance, med spas, cosmetic-only providers, wellness and weight-management clinics operating outside insurance entirely.

If that is your practice, the exemption you have been relying on may not exist — in Connecticut or anywhere. And Connecticut's new sensitive-data trigger means the volume threshold will not save you either.

This is a determination for your counsel or compliance advisor, made in writing, kept in a file. It is one of the highest-value legal questions a practice owner can pay to have answered properly, because the answer sets your posture in every state on this list at once.

The new trigger, in one sentence

Before July 1, 2026, a small Connecticut practice could reason: we're nowhere near 100,000 consumers, so the CTDPA is not our problem. After July 1, 2026, that reasoning does not survive contact with the statute — because if you process any sensitive data at all, you are in scope regardless of how few people you serve.

Health information is sensitive data. A practice that is not entity-exempt and that collects health-related information from a hundred people is inside the law on the same terms as a company with a hundred thousand.

The exemption attaches to the entity — check which entity

Practices are rarely one legal entity. There is often a professional corporation that provides care, a management or marketing company that owns the website and runs the advertising, and sometimes a separate entity for a retail or product line.

If the entity that operates the website and buys the media is not a covered entity or a business associate, the CTDPA exemption does not travel to it. The obligation follows the entity that controls the data, and on a marketing site that is frequently not the clinical entity at all.

Profiling impact assessments arrive August 1, 2026

Public Act 25-113 added a profiling impact assessment requirement for automated processing that produces legal or similarly significant effects, applying to activity created or generated on or after August 1, 2026. For most practices this is not yet a live issue — but if you deploy automated screening, eligibility, or triage logic that affects who gets an appointment or an offer, it is worth knowing that Connecticut now expects that decision to be documented before it is made.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Connecticut

CTDPA violations are enforced as unfair trade practices under the Connecticut Unfair Trade Practices Act, which carries civil penalties of up to $5,000 per willful violation, plus restitution, injunctive relief, and the state's costs and fees. The headline number is the lowest on this list — but CUTPA remedies are not limited to the per-violation figure, and injunctive relief that forces you to change how your website works can cost more than the fine.

The arithmetic nobody puts in a proposal

Connecticut's dollar ceiling is comparatively mild. Its real cost is process. A CUTPA action brings restitution and injunctive relief into play, which means the outcome is not a check you write once but a court-supervised change to your operations, on a schedule you do not set, with your name attached to it in the public record.

“We're too small for Connecticut” stopped being true on July 1, 2026

The 100,000-consumer threshold was the sentence every small practice used to skip this law. It is now 35,000 — and next to it sits a trigger with no number attached at all.

If you are not a HIPAA covered entity and you handle health information, you are in scope in Connecticut at any size. The only reliable way out is the entity-level exemption, and the only way to rely on that is to have confirmed it in writing.

Do this

Your Connecticut action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Get a written determination of whether each of your legal entities is a HIPAA covered entity or business associate. This is the single highest-leverage step in Connecticut.
  2. Identify which entity actually owns the website and the ad accounts — the exemption follows the entity, not the brand.
  3. If you are not entity-exempt, assume you are in scope: the sensitive-data trigger has no volume floor.
  4. Honor Global Privacy Control; it has been required since January 1, 2025.
  5. Get opt-in consent before processing sensitive data, now expanded to include disability and treatment information.
  6. Stop non-essential tags on treatment and consult pages until consent is recorded.
  7. Document any automated profiling that drives significant decisions, ahead of the August 1, 2026 assessment requirement.
  8. Do not plan around a cure period. Connecticut's expired at the end of 2024.

Questions

Connecticut privacy law FAQ

Are HIPAA covered entities exempt from the Connecticut Data Privacy Act?

Yes. Connecticut provides an entity-level exemption for HIPAA covered entities and business associates, and the July 2026 amendments did not remove it. The amendments narrowed the Gramm-Leach-Bliley exemption from entity-level to data-level, which affects financial institutions rather than healthcare providers.

What changed in the CTDPA on July 1, 2026?

SB 1295 (Public Act 25-113) lowered the applicability threshold from 100,000 to 35,000 consumers, removed the 25%-of-revenue test, added processing any sensitive data and offering personal data for sale as standalone triggers with no volume floor, expanded the sensitive data definition to include disability and treatment information, and added profiling impact assessments for activity from August 1, 2026.

Does the Connecticut privacy law apply to a small medical practice?

If the practice is a HIPAA covered entity, no. If it is not — which can be the case for cash-pay aesthetic, elective, or wellness practices that never transmit HIPAA standard transactions electronically — then yes, potentially at any size, because processing sensitive data is now an applicability trigger without a volume threshold.

What are the penalties under the CTDPA?

Violations are enforced as unfair trade practices under CUTPA, with civil penalties up to $5,000 per willful violation plus restitution, injunctive relief, and the state's costs. The cure period expired December 31, 2024.

Is Global Privacy Control required in Connecticut?

Yes. Connecticut has required controllers to recognize a universal opt-out mechanism since January 1, 2025, and Global Privacy Control is the signal in practical use.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Connecticut and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing