Florida · FDBR

Florida privacy law, explained for practice owners

The narrowest privacy law in the country, and the risk that isn't it

FDBR almost certainly does not apply In effect since July 1, 2024 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

The Florida Digital Bill of Rights almost certainly does not apply to your practice. It requires more than $1 billion in global revenue plus an additional technology criterion, and it exempts HIPAA covered entities at the entity level on top of that. What does reach your Florida practice website is HIPAA itself, Florida's data breach statute, and — the one to actually worry about — the Florida Security of Communications Act, a wiretapping law with a private right of action that plaintiffs are using against websites running third-party trackers without consent.

In effect sinceJuly 1, 2024
Applies at$1B+ revenue
(almost nobody)
Max penaltyUp to $50,000
per violation
Cure period45 days

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does FDBR actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, FDBR does not apply to you at all — Florida exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. $1B+ revenue (almost nobody).

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Florida privacy law: the key facts

Florida Digital Bill of Rights (FDBR), Fla. Stat. § 501.701 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawFlorida Digital Bill of Rights (FDBR)
CitationFla. Stat. § 501.701 et seq.
EffectiveJuly 1, 2024
The core controller obligations reach only very large businesses. Other Florida statutes reach everyone.
Who enforces itDepartment of Legal Affairs (Attorney General)
Applicability

Florida wrote the narrowest comprehensive privacy law in the country. The controller obligations apply to a business that makes more than $1 billion in global gross annual revenue and meets an additional criterion tied to online advertising, an app store, or a smart speaker with a virtual assistant.

Your practice is not that. We are not going to pretend otherwise to sell you something. But do not close the tab, because the honest answer to “what regulates my Florida practice's website” is not “nothing” — it is “three other things,” and one of them has a private right of action.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

The FDBR exempts HIPAA covered entities and business associates at the entity level, and it exempts PHI as data. Between that and the $1 billion revenue test, the Florida Digital Bill of Rights is effectively irrelevant to a medical practice.

This is the rare page where the state comprehensive privacy law is the least important thing on it.

Sensitive data

The FDBR treats health data as sensitive and requires consent for its processing by covered controllers. Given the revenue threshold, the practical sensitive-data rule for a Florida practice comes from HIPAA, not from the FDBR.

Definition of “sale”

Broad — monetary or other valuable consideration

The FDBR's sale definition reaches monetary or other valuable consideration and includes specific provisions on the sale of sensitive data and on voice and facial recognition data collected through smart devices. For practices, the operative Florida risk around advertising data is not the FDBR. It is the Florida Security of Communications Act.

Universal opt-out / GPC

Florida does not mandate recognition of a universal opt-out mechanism. That said, if your site serves visitors from Colorado, Connecticut, Texas, Montana, Nebraska, New Hampshire, New Jersey, Delaware, Oregon, Minnesota, Maryland, or California, you are honoring one anyway — a website does not get to be a different website for each visitor's home state.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale and targeted advertising
  • Consent for sensitive data processing
  • Appeal a denied request
  • All of it limited to controllers above the $1B revenue threshold
Cure period

The FDBR provides a 45-day cure period — the longest of any state except Iowa's 90 days. Academic for most practices, given the revenue threshold.

Penalties

Up to $50,000 per violation, with trebling available for certain violations involving known minors or failures to honor a consumer's deletion or opt-out request. This is by far the highest per-violation figure in the country. It is also attached to the highest applicability threshold in the country, which is the trade Florida chose to make.

Private right of action

The FDBR has no private right of action. Florida's wiretapping statute does. The Florida Security of Communications Act (Fla. Stat. ch. 934) has become a favored vehicle for website tracking claims, on the same theory driving California's CIPA suits: a third-party script intercepted the visitor's communications with your site without consent. There is no HIPAA exemption to hide behind, no revenue threshold to fall under, and no cure period.

Florida's Telephone Solicitation Act is the parallel exposure on the outbound side, and it has generated a substantial volume of litigation against practices running SMS marketing without properly documented consent.

What it means for you

The parts that actually change how you operate

What actually regulates your Florida practice website

Here is the honest map, in order of how likely each is to cost you money.

1. The Florida Security of Communications Act. Chapter 934 makes it unlawful to intercept a wire or electronic communication without consent, and it gives the aggrieved person a civil cause of action with statutory damages. Applied to a website, the argument is that a third-party marketing script read the visitor's interaction with your pages, and the visitor never agreed. No threshold, no HIPAA carve-out, no cure period. Consent — real, recorded, before the script runs — is the defense.

2. HIPAA and the OCR tracking-technology guidance. The federal floor never moved. Discussed below.

3. The Florida Telephone Solicitation Act. If you send marketing texts, FTSA consent documentation is a live litigation risk independent of anything on your website.

4. Florida's data breach statute, Fla. Stat. § 501.171, which applies to essentially every business holding personal information and sets notification duties and timelines. Unlike the FDBR, this one has no revenue threshold.

5. The FDBR, which applies to you only if your practice makes a billion dollars a year.

Why “we're exempt” is the wrong lesson to take from this page

A practice owner who reads that the FDBR does not apply and concludes that Florida practices have no website privacy obligation has drawn exactly the wrong inference. The comprehensive privacy statute is the one piece of the picture that doesn't reach you. The wiretapping statute, the federal HIPAA framework, and the breach law all do.

And the mitigation for all three is the same piece of infrastructure: don't let third-party scripts run until the visitor agrees, and be able to prove when they agreed. That is one control that answers a Chapter 934 claim, an OCR inquiry, and the “what was disclosed” question in a breach investigation.

If you operate in more than one state, Florida sets your floor, not your ceiling

Most Florida practices with real ad spend draw patients across state lines, and a website has one configuration for every visitor. Once your traffic includes Colorado, Texas, Maryland, or California residents, you are building to those states' requirements regardless of what Florida asks — which means the practical answer in Florida is to build the stricter thing once.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Florida

Up to $50,000 per violation, with trebling available for certain violations involving known minors or failures to honor a consumer's deletion or opt-out request. This is by far the highest per-violation figure in the country. It is also attached to the highest applicability threshold in the country, which is the trade Florida chose to make.

The arithmetic nobody puts in a proposal

Florida's $50,000 is a headline number that will almost certainly never be aimed at a practice, because a practice will almost never be a covered controller. The number worth modeling in Florida is a class action under the Security of Communications Act, where statutory damages are assessed per plaintiff and the class is defined by your traffic.

The state with the weakest privacy law has one of the sharpest tracking-litigation risks

It is easy to read the $1 billion threshold as a statement that Florida is relaxed about privacy. Chapter 934 says otherwise. Wiretapping statutes were written decades before pixels existed, they carry private rights of action and statutory damages, and they do not care how large you are or whether you are a HIPAA covered entity.

The practices getting hurt in Florida are not being fined by the Attorney General under the FDBR. They are receiving demand letters over the trackers on their consult pages.

Do this

Your Florida action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Do not build your Florida website posture around the FDBR. It almost certainly does not apply to you.
  2. Treat the Florida Security of Communications Act as the operative risk: no third-party tracker fires before consent.
  3. Keep an auditable consent record — under a wiretapping theory, documented prior consent is the defense.
  4. Review SMS marketing consent documentation against the Florida Telephone Solicitation Act.
  5. Confirm your breach notification procedure under Fla. Stat. § 501.171, which does apply to you regardless of size.
  6. Follow HHS OCR's tracking-technology guidance on authenticated pages and patient portals, where the federal analysis is strongest.
  7. If you serve patients from other states, build to the strictest state your traffic includes.
  8. Have counsel review chat widgets and session-replay tools specifically. They are the most-litigated category.

Questions

Florida privacy law FAQ

Does the Florida Digital Bill of Rights apply to medical practices?

Almost never. The FDBR's controller obligations require more than $1 billion in global gross annual revenue plus an additional criterion involving online advertising, an app store, or a smart speaker. It also exempts HIPAA covered entities and business associates at the entity level.

What privacy law applies to a Florida medical practice website?

HIPAA and HHS OCR's tracking-technology guidance set the federal floor. Florida's data breach statute (Fla. Stat. § 501.171) applies regardless of size. The Florida Security of Communications Act (ch. 934) is the most active litigation risk, because it has a private right of action and is being used against websites running third-party trackers without consent.

What is the penalty under the Florida Digital Bill of Rights?

Up to $50,000 per violation, with trebling available for certain violations involving known minors or failures to honor deletion and opt-out requests. It is the highest per-violation figure of any state law, paired with the highest applicability threshold.

Does Florida require honoring Global Privacy Control?

No. Florida does not mandate universal opt-out mechanism recognition. In practice, any site with out-of-state traffic honors it anyway to meet the requirements of the twelve states that do.

Is there a cure period under the FDBR?

Yes, 45 days — the second-longest of any state after Iowa's 90 days. It is academic for practices given the revenue threshold.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Florida and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing