Website privacy law by state

Website privacy law in District of Columbia for medical practices

No comprehensive privacy law District of Columbia has no comprehensive consumer privacy law in effect. That does not mean a practice website in District of Columbia is unregulated: the state wiretapping statute, federal rules, and the law of every state your visitors sit in all still apply.

Attorney review pending. Every statute reference on this page is reproduced from its citation and has not been reviewed by counsel for Consential. It is a description of what exists, not advice about what to do, and it is not a legal opinion about your practice.

What actually applies: the recording and interception statute

This is the statute that most often reaches a website. Session recording, chat transcripts, form-field capture and analytics that replay a visit have all been argued as interception of a communication.

Citation
D.C. Code ยง 23-554
Consent regime
One-party consent
Private lawsuits
Yes. A private party can sue.
Damages named
Greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees
Observed filing volume
Low

Your state is not the only one that applies

Wiretap exposure follows the visitor, not the practice. A District of Columbia practice whose website is read by someone sitting in an all-party-consent state can be answering to that state's statute, not this one. Twenty states also have a comprehensive consumer privacy law in effect, and those reach your visitors from District of Columbia wherever your servers are.

Start with California, Colorado, Connecticut, Delaware, Florida, Indiana, or see the full list of jurisdictions.

The federal floor

HIPAA applies to a covered entity in every state. Civil money penalties were last adjusted January 28, 2026; the highest tier reaches $2,190,294 per violation with an annual cap of $2,190,294 for the same requirement.

Neighbouring states

Maryland · Virginia

Sources

Figures last reviewed July 25, 2026.