Iowa · ICDPA

Iowa privacy law, explained for practice owners

The lightest-touch privacy law in America

Very unlikely to apply In effect since January 1, 2025 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Iowa's privacy law is the weakest in the country and it very likely does not touch your practice. HIPAA covered entities are exempt at the entity level, the threshold is 100,000 Iowa residents in a state of 3.2 million, there is no right to opt out of targeted advertising at all, sensitive data needs only notice and an opt-out rather than consent, and the cure period is a full 90 days. If you are looking for the thing that actually governs an Iowa practice website, it is HIPAA and the federal tracking-technology analysis — not the ICDPA.

In effect sinceJanuary 1, 2025
Applies at100k consumers
or 25k + 50% revenue
Max penaltyUp to $7,500
per violation
Cure period90 days
(longest in US)

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does ICDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, ICDPA does not apply to you at all — Iowa exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 100k consumers or 25k + 50% revenue.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Iowa privacy law: the key facts

Iowa Consumer Data Protection Act (ICDPA), Iowa Code § 715D.1 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawIowa Consumer Data Protection Act (ICDPA)
CitationIowa Code § 715D.1 et seq.
EffectiveJanuary 1, 2025
The most business-friendly comprehensive privacy law in the country, by a clear margin.
Who enforces itAttorney General (exclusive)
Applicability

Iowa applies to controllers or processors that conduct business in Iowa or target Iowa residents and, during a calendar year, either:

  • control or process the personal data of 100,000 or more Iowa consumers; or
  • control or process the personal data of 25,000 or more Iowa consumers and derive over 50% of gross revenue from the sale of personal data.

Iowa's population is about 3.2 million. Reaching 100,000 Iowa residents means touching roughly one in thirty people in the state. For a practice, that is not a realistic number on patient volume, and it is a stretch even on web traffic.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Iowa exempts HIPAA covered entities and business associates at the entity level, and separately exempts PHI, HIPAA de-identified data, and information used for public health activities and research.

Between the entity-level exemption and the threshold, the ICDPA is very unlikely to reach an Iowa medical practice.

Sensitive data

Iowa requires sensitive data processing to be disclosed with a clear notice and an opportunity to opt out, rather than requiring opt-in consent as most states do. For data concerning a known child, Iowa defers to COPPA. This is a notably lighter standard than the opt-in gate in Colorado, Virginia, Connecticut, and the rest.

Definition of “sale”

Narrow — monetary consideration only

Iowa uses the narrow definition — a sale requires monetary consideration. Combined with Iowa's biggest omission, described below, this means Iowa asks less about your advertising stack than any other state with a privacy law.

Universal opt-out / GPC

No universal opt-out mechanism requirement.

Consumer rights
  • Confirm processing and access
  • Delete
  • Portability
  • Opt out of the sale of personal data
  • Appeal a denied request
  • No right to correct inaccurate data
  • No right to opt out of targeted advertising
  • No right to opt out of profiling
Cure period

Iowa gives 90 days to cure after written notice from the Attorney General — the longest cure period of any state privacy law, with no sunset. Iowa built its statute to be difficult to be punished under.

Penalties

Up to $7,500 per violation, reachable only after the 90-day cure window closes without a fix.

Private right of action

No private right of action. Exclusive enforcement by the Iowa Attorney General.

What it means for you

The parts that actually change how you operate

What Iowa left out, and why it matters to your website

Most state privacy laws converge on six consumer rights. Iowa deliberately omitted three of them, and the omissions are the ones aimed at advertising technology:

  • No right to opt out of targeted advertising. Every other state on this list grants it. Iowa does not.
  • No right to opt out of profiling.
  • No right to correct inaccurate personal data.

Add the monetary-only sale definition and the absence of a universal opt-out requirement, and Iowa is the one state where the comprehensive privacy law genuinely has little to say about the trackers on your site.

Which is exactly why the honest version of this page has to spend its remaining space on the rules that do apply.

The federal floor did not move

Iowa's leniency has no effect on HIPAA. If your practice is a covered entity, the Privacy Rule still governs disclosures of protected health information to third parties, and a marketing vendor receiving identifiable information about a patient's care still needs a business associate agreement or an authorization.

The HHS Office for Civil Rights issued guidance in December 2022 on tracking technologies and revised it in March 2024. A federal court vacated portions of that guidance in American Hospital Association v. Becerra in June 2024, and HHS withdrew its appeal — so the specific theory that IP addresses on unauthenticated public pages are automatically individually identifiable health information no longer stands.

What survived is significant: authenticated environments and patient portals remain squarely within the analysis, and the underlying Privacy Rule obligations were never touched by the case. An Iowa practice that reads the vacated bulletin as permission to put a Meta Pixel behind a patient login has misread it.

Where an Iowa practice's real exposure sits

In rough order:

  1. HIPAA, especially on authenticated pages, patient portals, and anything where a specific individual's care can be inferred.
  2. Out-of-state visitors. If your ad spend brings in patients from Illinois, Minnesota, Colorado, or anywhere else with stricter rules, your one website has to satisfy those rules. Iowa's leniency does not follow the visitor home.
  3. Iowa's data breach notification law, which applies regardless of the ICDPA's thresholds.
  4. The ICDPA, last, and only if you cross 100,000 Iowa consumers while not being a covered entity.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Iowa

Up to $7,500 per violation, reachable only after the 90-day cure window closes without a fix.

The arithmetic nobody puts in a proposal

Practically speaking, Iowa's enforcement model is a warning letter with a three-month runway. That is not a reason to ignore the law, but it is a reason to spend your compliance attention on the states that will actually generate an event, and on the federal rules that apply to you no matter what Iowa says.

Building to Iowa's standard means failing everywhere else

The trap in a lenient state is architectural. A practice that configures its website to Iowa's requirements has built something that does not honor Global Privacy Control, does not gate sensitive data behind consent, and does not offer a targeted-advertising opt-out — and that site is out of compliance the moment a Colorado, Connecticut, or Maryland resident loads it.

Since a website has exactly one configuration, the correct baseline is not your own state. It is the strictest state your traffic includes.

Do this

Your Iowa action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm your HIPAA covered-entity status in writing — it is what actually exempts you here.
  2. Do not use Iowa's standard as your website's design target if you have any out-of-state traffic.
  3. Apply HIPAA's tracking-technology analysis on authenticated pages and patient portals, where it is strongest.
  4. Keep third-party tags off pages where an individual's care can be inferred.
  5. Confirm your Iowa breach notification procedure, which applies regardless of ICDPA thresholds.
  6. If you approach 100,000 Iowa consumers, revisit this — the exemption question then becomes load-bearing.
  7. Capture and retain consent records anyway. They are the evidence that answers HIPAA questions, not just state-law ones.
  8. Review vendor agreements for marketing platforms that may receive identifiable patient information.

Questions

Iowa privacy law FAQ

Does Iowa's privacy law apply to medical practices?

Very unlikely. Iowa exempts HIPAA covered entities and business associates at the entity level, and the threshold requires controlling or processing the personal data of 100,000 or more Iowa consumers in a state of roughly 3.2 million people.

Does Iowa require an opt-out of targeted advertising?

No. Iowa is the only state with a comprehensive privacy law that does not grant a right to opt out of targeted advertising. It also omits the rights to correct data and to opt out of profiling.

What is Iowa's cure period?

90 days after written notice from the Attorney General — the longest of any state privacy law, with no sunset date.

Does Iowa require consent before processing sensitive data?

No. Iowa requires a clear notice and an opportunity to opt out, rather than the opt-in consent most other states require. Data concerning a known child is handled under COPPA.

If Iowa's law is so light, what actually governs my practice website?

HIPAA and the federal tracking-technology analysis, your obligations to visitors from stricter states, and Iowa's data breach notification law. The ICDPA is the least of the four for most practices.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Iowa and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing