Indiana · INCDPA
Indiana privacy law, explained for practice owners
New for 2026, and one of the friendlier ones
The short answer
If your practice is a HIPAA covered entity, Indiana's new privacy law does not apply to you — it exempts covered entities and business associates at the entity level, not just their patient records. And even without that exemption, most practices sit well under the 100,000-Indiana-consumer threshold. Indiana also keeps a permanent 30-day cure period, making it one of the gentler states. The two things worth your attention: confirming in writing that you really are a covered entity, and remembering that HIPAA's own rules about website trackers were never affected by any of this.
or 25k + 50% revenue
per violation
(no sunset)
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does INCDPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Are you a HIPAA covered entity?
If yes, INCDPA does not apply to you at all — Indiana exempts covered entities and business associates at the entity level, not just their patient records.
If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.
If not, do you cross the threshold?
Without the entity-level exemption, the applicability test is the only thing between you and the statute. 100k consumers or 25k + 50% revenue.
Count website visitors, not just patients. Personal data includes the identifiers your site collects.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
Indiana privacy law: the key facts
| Law | Indiana Consumer Data Protection Act (INCDPA) |
|---|---|
| Citation | Ind. Code § 24-15 et seq. |
| Effective | January 1, 2026 Passed in 2023 with an unusually long runway — nearly three years between enactment and effect. |
| Who enforces it | Attorney General (exclusive) |
| Applicability | Indiana follows the Virginia template. You are in scope if, during a calendar year, you either:
The second prong is effectively a data-broker test. A medical practice does not derive half its revenue from selling data, so for practices Indiana comes down to a single question: 100,000 Indiana residents, or not. |
| HIPAA exemption | Entity-level — a HIPAA covered entity is outside the statute Indiana exempts HIPAA covered entities and business associates at the entity level. A practice that is genuinely a covered entity is outside the INCDPA entirely — not merely exempt as to its patient records. That is real relief, and it is also the reason this page spends most of its time on the two questions that survive it: whether you are actually a covered entity, and what still binds you if you are. |
| Sensitive data | Sensitive data requires opt-in consent, and the definition includes personal data revealing mental or physical health diagnosis, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and data from a known child. |
| Definition of “sale” | Narrow — monetary consideration only Indiana defines a sale as an exchange of personal data for monetary consideration only. That is the narrow definition, and it means the ordinary operation of advertising pixels — where value flows but money does not — generally is not a “sale” in Indiana. Do not over-read that. Indiana grants a separate, standalone right to opt out of targeted advertising, which does not depend on the sale definition at all. The narrow “sale” language changes which label applies; it does not remove the opt-out. |
| Universal opt-out / GPC | Indiana does not require recognition of a universal opt-out mechanism. It does require a clear and conspicuous way to exercise the targeted-advertising opt-out. |
| Consumer rights |
|
| Cure period | Indiana provides a 30-day cure period with no expiration date. The Attorney General must give written notice and thirty days to fix the problem before bringing an action. Among the twenty states, this is one of the more forgiving enforcement postures still standing. |
| Penalties | Up to $7,500 per violation, plus the Attorney General's reasonable expenses and attorney fees, and injunctive relief. Only reachable after the 30-day notice-and-cure window closes. |
| Private right of action | No private right of action. The INCDPA expressly gives exclusive enforcement authority to the Attorney General. |
What it means for you
The parts that actually change how you operate
Confirm the exemption instead of assuming it
Indiana's entity-level exemption is the good outcome, and it is worth exactly as much as your ability to demonstrate it. A HIPAA covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a HIPAA standard transaction.
The last clause is where practices fall out. A provider who bills only cash, never submits electronic claims, never runs electronic eligibility checks, and never transmits a standard transaction may not be a covered entity. That is common in aesthetics, elective procedures, hair restoration, weight management, and wellness.
If that is your practice, no state on this list exempts you as an entity, and Indiana's 100,000-consumer threshold becomes the only thing standing between you and the statute.
Get the determination in writing from counsel. Then file it where you can find it in two years, because that is roughly when someone will ask.
Indiana's narrow “sale” definition is not the free pass it looks like
Indiana is one of six states — with Iowa, Kentucky, Tennessee, Utah, and Virginia — that define a sale as requiring monetary consideration. In those states, the argument that a Meta Pixel constitutes a “sale” is weak, because no money moves.
Two reasons not to build a strategy on that. First, Indiana separately gives consumers the right to opt out of targeted advertising, and that right does not route through the sale definition. Second, your website serves visitors from states with the broad definition, where the same tag is treated very differently. You cannot configure a site to be narrow-definition for Hoosiers and broad-definition for everyone else.
The summary-instead-of-copy quirk
Indiana included a provision found almost nowhere else: a controller may satisfy the portability right by providing a representative summary rather than a full copy of the personal data. If you ever do handle Indiana consumer requests, this materially reduces the operational burden of a data access response. It is a small kindness in an otherwise standard statute.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in Indiana
Up to $7,500 per violation, plus the Attorney General's reasonable expenses and attorney fees, and injunctive relief. Only reachable after the 30-day notice-and-cure window closes.
The arithmetic nobody puts in a proposal
The permanent cure period changes the arithmetic more than the dollar figure does. In Indiana, a good-faith operator who responds to a notice inside thirty days effectively caps exposure at the cost of the fix. The failure mode is not being wrong; it is being unreachable, disorganized, or unable to demonstrate what changed and when.
The exemption covers the entity — check which entity owns the website
A practice is often several companies. The professional corporation delivers care and is the covered entity. A management company or marketing LLC frequently owns the domain, runs the ad accounts, and controls the visitor data.
The entity-level exemption follows the covered entity. It does not automatically extend to an affiliate that is neither a covered entity nor a business associate. If your marketing entity is the controller of your website data, its status is the one that matters — and nobody has usually asked that question.
Do this
Your Indiana action list
In order. Items one and two are the ones that change your answer to everything else.
- Get a written determination that each of your entities is or is not a HIPAA covered entity or business associate.
- Identify which legal entity controls the website and the advertising accounts.
- If you are entity-exempt, document it once and stop rebuilding the analysis every year.
- If you are not, count Indiana consumers — including website visitors — against the 100,000 threshold.
- Provide a clear opt-out of targeted advertising regardless of Indiana's narrow “sale” definition.
- Get opt-in consent before processing sensitive data, including health diagnosis data.
- Keep the 30-day cure period usable: make sure a legal notice reaches a human who can act on it.
- Apply HIPAA's own tracking-technology analysis to your site. The Indiana exemption does nothing about that.
Questions
Indiana privacy law FAQ
When did Indiana's privacy law take effect?
January 1, 2026. The Indiana Consumer Data Protection Act was enacted in 2023 with an unusually long runway of nearly three years.
Are medical practices exempt from the Indiana Consumer Data Protection Act?
HIPAA covered entities and business associates are exempt at the entity level, meaning the whole statute does not apply to them. A practice that is not a covered entity — for example, a cash-pay provider that never transmits HIPAA standard transactions electronically — does not get that exemption and is in scope if it meets the 100,000-consumer threshold.
Is a tracking pixel a “sale” under Indiana law?
Probably not. Indiana defines a sale as an exchange for monetary consideration only, so advertising data sharing generally falls outside it. Indiana still provides a separate right to opt out of targeted advertising, which applies regardless.
Does Indiana have a cure period?
Yes, and it does not expire. The Attorney General must provide written notice and 30 days to cure before bringing an enforcement action.
What are the penalties under the INCDPA?
Up to $7,500 per violation, plus the Attorney General's reasonable expenses and attorney fees, available only after the 30-day cure window closes. There is no private right of action.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Indiana and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing