Kentucky · KCDPA

Kentucky privacy law, explained for practice owners

New for 2026, broadened for healthcare before it started

Likely exempt if you are a covered entity In effect since January 1, 2026 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Kentucky's privacy law took effect January 1, 2026, and it is one of the friendliest in the country to healthcare. HIPAA covered entities and business associates are exempt at the entity level, HB 473 broadened those healthcare carve-outs in 2025, the threshold is 100,000 Kentucky residents, and the 30-day cure period never expires. If you are a covered entity, the KCDPA is genuinely not your exposure. What remains is HIPAA's own analysis of the trackers on your website, and the requirements of the stricter states your out-of-state patients come from.

In effect sinceJanuary 1, 2026
Applies at100k consumers
or 25k + 50% revenue
Max penaltyUp to $7,500
per violation
Cure period30 days
(no sunset)

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does KCDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, KCDPA does not apply to you at all — Kentucky exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 100k consumers or 25k + 50% revenue.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Kentucky privacy law: the key facts

Kentucky Consumer Data Protection Act (KCDPA), KRS § 367.3611 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawKentucky Consumer Data Protection Act (KCDPA)
CitationKRS § 367.3611 et seq.
EffectiveJanuary 1, 2026
Amended before it ever took effect by HB 473 (2025), which broadened the healthcare-related exemptions.
Who enforces itAttorney General (exclusive)
Applicability

Kentucky is a close copy of Virginia. In scope if, during a calendar year, you either:

  • control or process the personal data of 100,000 or more Kentucky consumers; or
  • control or process the personal data of 25,000 or more Kentucky consumers and derive over 50% of gross revenue from the sale of personal data.

Kentucky's population is roughly 4.5 million, so the 100,000 threshold means reaching about one in forty-five residents. Practices rarely get there.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Kentucky exempts HIPAA covered entities and business associates at the entity level, and HB 473 in 2025 widened the healthcare-related carve-outs before the law even took effect. It also exempts PHI, HIPAA de-identified data, and information processed for research under federal human-subjects rules.

Of the twenty states, Kentucky is among the most explicitly accommodating to healthcare. If you are a covered entity, the KCDPA is not your problem.

Sensitive data

Sensitive data requires opt-in consent. The category includes data revealing mental or physical health diagnosis, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and personal data of a known child.

Definition of “sale”

Narrow — monetary consideration only

Narrow definition: a sale requires monetary consideration. Advertising data flows generally are not sales in Kentucky. The targeted-advertising opt-out still applies independently.

Universal opt-out / GPC

No universal opt-out mechanism requirement. A clear and conspicuous opt-out method for targeted advertising and sale is still required.

Consumer rights
  • Confirm processing and access
  • Correct inaccuracies
  • Delete
  • Portability
  • Opt out of sale, targeted advertising, and profiling in furtherance of significant decisions
  • Appeal a denied request within a specified window
Cure period

Kentucky provides a permanent 30-day cure period. The Attorney General must give written notice and thirty days before filing suit, and there is no expiration on that requirement.

Penalties

Up to $7,500 per violation, plus reasonable expenses and attorney fees, after the cure window closes. Kentucky also directs penalties to a dedicated consumer privacy fund.

Private right of action

No private right of action. Exclusive enforcement by the Kentucky Attorney General.

What it means for you

The parts that actually change how you operate

Kentucky amended the law for healthcare before it took effect

The KCDPA passed in 2024 and was scheduled for January 1, 2026. Before that date arrived, the 2025 session passed HB 473, which broadened the healthcare-related exemptions and clarified how the profiling assessment obligations apply.

That sequence tells you something useful about the enforcement climate. A legislature that widens carve-outs during the runway is not building toward aggressive early enforcement against regulated healthcare providers. It does not change the text of any obligation that still applies to you, but it is a reasonable input into where you spend attention.

The exemption is only as good as your covered-entity status

Same caveat that applies in every entity-level state, and it is the most valuable paragraph on this page for a certain kind of practice.

HIPAA covered entity means a health plan, a healthcare clearinghouse, or a provider that transmits health information electronically in connection with a HIPAA standard transaction. A cash-pay practice that never submits an electronic claim or eligibility check may not meet that definition — which is common in aesthetics, hair restoration, elective and cosmetic procedures, and wellness.

If you are not a covered entity, Kentucky's generous carve-out does not reach you and the 100,000-consumer threshold is your only shelter. Get the determination in writing.

What Kentucky still expects if you are in scope

For a non-exempt controller, Kentucky is a standard Virginia-model statute: a privacy notice with specific required content, opt-in consent before processing sensitive data, opt-outs for sale, targeted advertising, and consequential profiling, data protection assessments for higher-risk processing, processor contracts, and a documented appeals process for denied requests.

None of that is unusual. All of it is the kind of thing that exists as a document or does not.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Kentucky

Up to $7,500 per violation, plus reasonable expenses and attorney fees, after the cure window closes. Kentucky also directs penalties to a dedicated consumer privacy fund.

The arithmetic nobody puts in a proposal

With a permanent cure period and an entity-level healthcare exemption, the realistic Kentucky exposure for a covered-entity practice is close to zero. That is a legitimate finding, and pretending otherwise would be the sort of manufactured urgency this page exists to avoid.

A permanent cure period only helps if the notice reaches someone

Kentucky's 30-day cure period is one of the last unqualified ones left, and it is genuinely protective — but it starts running when the Attorney General sends written notice, not when you read it.

Practices lose this protection in unglamorous ways: the notice goes to a registered agent address nobody monitors, or to an office manager who left, or to an info@ inbox. Thirty days is plenty of time to fix a tracking configuration. It is not plenty of time to discover a letter.

Do this

Your Kentucky action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm in writing whether each entity is a HIPAA covered entity or business associate.
  2. Make sure your registered agent address and legal-notice inbox reach a human weekly — the cure period depends on it.
  3. If not exempt, count Kentucky consumers including website visitors against the 100,000 threshold.
  4. Provide opt-outs for sale, targeted advertising, and consequential profiling.
  5. Get opt-in consent before processing sensitive data, including health diagnosis data.
  6. Write data protection assessments for higher-risk processing before you start it.
  7. Apply HIPAA's tracking-technology analysis to your site regardless of the KCDPA exemption.
  8. Build your website to the strictest state in your traffic mix, not to Kentucky's baseline.

Questions

Kentucky privacy law FAQ

When did Kentucky's consumer data privacy law take effect?

January 1, 2026. It was amended by HB 473 during the 2025 session, before ever taking effect, to broaden healthcare-related exemptions and clarify profiling assessment obligations.

Are HIPAA covered entities exempt from the Kentucky Consumer Data Protection Act?

Yes, at the entity level. Kentucky exempts HIPAA covered entities and business associates from the statute as a whole, not merely their protected health information, and HB 473 broadened those healthcare carve-outs further.

What are the Kentucky KCDPA thresholds?

Controlling or processing the personal data of 100,000 or more Kentucky consumers in a calendar year, or 25,000 or more while deriving over 50% of gross revenue from the sale of personal data.

Does Kentucky have a cure period?

Yes, 30 days after written notice from the Attorney General, with no sunset date. Enforcement cannot proceed until that window closes without a fix.

Is a marketing pixel a “sale” in Kentucky?

Generally no — Kentucky defines a sale as requiring monetary consideration. The separate right to opt out of targeted advertising applies regardless of whether a transfer is a sale.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Kentucky and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing