Maryland · MODPA

Maryland privacy law, explained for practice owners

Strictest in the country. Lowest threshold. Health data is sensitive data.

Highest-risk state on this list In effect since October 1, 2025 HIPAA exemption: data-level only Reviewed July 25, 2026

The short answer

Maryland is the state to worry about. MODPA exempts protected health information but not covered entities, so your non-PHI data is fully in scope. Its threshold is the lowest in the country at 35,000 consumers with no revenue floor. It caps data collection at what is reasonably necessary and proportionate to the specific service a consumer requested — which invalidates most “collect it in case we need it” analytics. And it bans the sale of sensitive data outright, with no consent option, at the same time as defining “sale” broadly enough to reach advertising data sharing. Health data is sensitive data. Do the arithmetic.

In effect sinceOctober 1, 2025
Applies at35k consumers
or 10k + 20% revenue
Max penalty$10,000 / $25,000
per violation
Cure period60 days
until Apr 1, 2027

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does MODPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Being a covered entity does not exempt you

Maryland exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.

2

Do you cross the threshold?

35k consumers or 10k + 20% revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.

If you are near the line, get the number from your analytics rather than estimating from patient volume.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Maryland privacy law: the key facts

Maryland Online Data Privacy Act (MODPA), Md. Code, Com. Law § 14-4601 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawMaryland Online Data Privacy Act (MODPA)
CitationMd. Code, Com. Law § 14-4601 et seq.
EffectiveOctober 1, 2025
Widely regarded as the strictest comprehensive state privacy law in the country. The 60-day cure period sunsets April 1, 2027.
Who enforces itAttorney General, Consumer Protection Division
Applicability

Maryland reaches controllers that conduct business in the state or target Maryland residents and, in the prior calendar year, either:

  • controlled or processed the personal data of 35,000 or more Maryland consumers, excluding data used solely to complete a payment transaction; or
  • controlled or processed the personal data of 10,000 or more Maryland consumers and derived more than 20% of gross revenue from the sale of personal data.

No revenue floor. Tied with Rhode Island for the lowest primary threshold in the country. A practice group with several locations, a busy website, and Baltimore-Washington market reach can plausibly cross 35,000 Marylanders in a year.

HIPAA exemption

Data-level only — PHI is exempt, the practice is not

Maryland exempts protected health information processed in compliance with HIPAA. It does not exempt HIPAA covered entities as entities. Your practice stays inside MODPA for all its non-PHI data — website analytics, advertising identifiers, app telemetry, marketing lists, prospective-patient data captured before anyone is a patient.

Maryland is the worst possible combination for a practice: a data-level exemption, the lowest threshold in the country, and the strictest substantive obligations anywhere. If you rank the twenty states by how much attention a medical practice should give them, Maryland is first.

Sensitive data

Maryland is categorically different here, and this is the single most important paragraph on the page.

  • Selling sensitive data is flatly prohibited. Not gated behind consent. Not subject to an opt-out. Banned. There is no consent a consumer can give that makes it lawful.
  • Processing sensitive data is limited to what is strictly necessary to provide or maintain a specific product or service the consumer requested.

Sensitive data includes data revealing physical or mental health condition or diagnosis. Now put that next to a practice website that shares consult-page visitor data with an advertising platform under a broad “sale” definition. That is the exact fact pattern Maryland made unlawful outright.

Definition of “sale”

Broad — monetary or other valuable consideration

Broad definition: monetary or other valuable consideration. And then Maryland goes further than any other state — see the sensitive-data ban below, which is not an opt-out or a consent requirement but a flat prohibition.

Universal opt-out / GPC

Yes, from the day the law took effect. Maryland controllers must recognize a universal opt-out mechanism, which in practice means honoring Global Privacy Control.

Consumer rights
  • Access, correction, deletion, and portability
  • Obtain a list of the categories of third parties to which the controller has disclosed personal data
  • Opt out of sale, targeted advertising, and profiling in furtherance of consequential decisions
  • Strict data minimization as a controller duty, independent of any consumer request
  • Appeal a denied request
Cure period

Maryland provides a 60-day cure period, at the Attorney General's discretion, that sunsets April 1, 2027. You have a limited window in which good-faith remediation still has a statutory path.

Penalties

MODPA violations are unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act: up to $10,000 per violation, and up to $25,000 for each repeat violation of the same provision.

Private right of action

No private right of action under MODPA. Enforcement runs through the Attorney General's Consumer Protection Division.

What it means for you

The parts that actually change how you operate

Data minimization: the provision that breaks the default analytics setup

Every other state asks you to disclose what you collect. Maryland limits what you are allowed to collect at all. Collection must be reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer.

Read that against how a practice website is actually built. A visitor requested a page about a procedure. Under Maryland's standard, what is reasonably necessary and proportionate to deliver that page? Serving the HTML. Perhaps error monitoring and security. It is difficult to argue that building a cross-site advertising profile of that visitor is necessary to deliver the page they asked for.

Maryland moved the question from “did you tell them” to “did you need it.” Most marketing stacks were not designed to answer the second question, because until October 2025 nobody in the United States asked it.

The sensitive-data sale ban has no consent workaround

Practices are used to a compliance world where consent solves everything. Get the checkbox, keep the record, proceed. Maryland removed that option for one category.

You may not sell sensitive data. Period. Not with consent, not with a granular preference center, not with a signed acknowledgment. And Maryland's “sale” reaches transfers for other valuable consideration, which is how advertising data sharing is usually characterized.

If any tag on your site transmits something that reveals a health condition or diagnosis to a third party in exchange for advertising value, the Maryland question is not whether you obtained consent. It is whether that transfer happens at all.

The practical control is architectural, not procedural: the tag must not fire on those pages, or must not receive that data. A consent banner cannot fix a prohibition.

A practice can cross 35,000 Marylanders without noticing

Thirty-five thousand sounds large until you count the way the statute counts. “Consumer” means a Maryland resident. “Control or process personal data” includes the IP addresses, device identifiers, and cookies your website collects. Payment-transaction-only data is excluded; nothing else is.

A practice group running paid search across the Baltimore-Washington corridor, with several locations and a content library that ranks, can see 35,000 unique Maryland visitors in twelve months without any of that traffic converting. Your marketing team is measured on making that number go up.

Which means the threshold question in Maryland is not a patient-volume question. It is an analytics question, and the answer is sitting in your traffic reports.

You have until April 1, 2027 to use the cure period

Maryland's 60-day cure window is discretionary and temporary. After April 1, 2027 it disappears and Maryland joins the growing list of states where the first contact is not a warning.

There is a narrow, real opportunity here: for the moment, a Maryland practice that discovers and fixes a problem still has a statutory mechanism to point at. That mechanism has an expiration date on it.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Maryland

MODPA violations are unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act: up to $10,000 per violation, and up to $25,000 for each repeat violation of the same provision.

The arithmetic nobody puts in a proposal

Maryland's escalation clause is the part to notice. The first finding is expensive; the second finding of the same failure costs two and a half times as much. That structure rewards fixing a problem completely and punishes fixing it cosmetically — which is precisely the difference between installing a banner and actually blocking the scripts.

Consent is not a defense to a prohibition

The instinct built by a decade of cookie banners is that privacy compliance means asking permission. Maryland is the state where that instinct produces the wrong answer.

For the sale of sensitive data, there is no permission to ask. A perfectly implemented consent banner, a flawless audit trail, a signed patient acknowledgment — none of them make a prohibited transfer lawful. The only compliant configuration is one where the transfer does not occur.

Consent infrastructure is still essential in Maryland, for everything else and for proving what you did and did not do. It just cannot be the whole answer here.

Do this

Your Maryland action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Pull your Maryland traffic numbers. If unique Maryland visitors approach 35,000 a year, assume you are in scope.
  2. Audit every third-party tag for whether it could transmit anything revealing a health condition. That transfer may be prohibited, not merely consent-gated.
  3. Remove advertising and analytics tags from treatment, consult, and symptom pages rather than gating them.
  4. Test your data collection against “reasonably necessary and proportionate to the requested service” and turn off what fails.
  5. Honor Global Privacy Control — required since October 1, 2025.
  6. Be able to produce the categories of third parties you disclosed personal data to.
  7. Use the cure period while it exists. It sunsets April 1, 2027.
  8. Get healthcare counsel to review whether your ad-tech transfers constitute a sale of sensitive data under Maryland's definitions. This is the highest-stakes question on this page.

Questions

Maryland privacy law FAQ

Does MODPA apply to HIPAA covered entities?

Yes, in part. Maryland exempts protected health information processed in compliance with HIPAA, but it does not exempt the covered entity. Non-PHI data such as website analytics, advertising identifiers, and marketing lists remains fully subject to MODPA.

What makes the Maryland Online Data Privacy Act the strictest state privacy law?

Two provisions. First, data collection is capped at what is reasonably necessary and proportionate to provide the specific product or service the consumer requested — a substantive limit, not a disclosure duty. Second, the sale of sensitive data is prohibited outright, with no consent exception.

Can I sell sensitive data in Maryland with consent?

No. MODPA bans the sale of sensitive data entirely. Unlike every other state, there is no consent mechanism that makes it lawful, and Maryland's definition of “sale” includes exchanges for other valuable consideration, not just money.

What are MODPA's applicability thresholds?

35,000 or more Maryland consumers in the prior calendar year, excluding data used solely to complete a payment transaction, or 10,000 or more while deriving over 20% of gross revenue from selling personal data. There is no revenue-only threshold.

What are the penalties under MODPA?

Violations are unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act, carrying up to $10,000 per violation and up to $25,000 for each repeat violation of the same provision. The 60-day cure period sunsets April 1, 2027.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Maryland and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing