Minnesota · MCDPA

Minnesota privacy law, explained for practice owners

The only state that makes you keep a data inventory

In scope for everything but PHI In effect since July 31, 2025 HIPAA exemption: data-level only Reviewed July 25, 2026

The short answer

Minnesota exempts protected health information but not covered entities, so your practice is a regulated controller for its website and marketing data. Two things make Minnesota unusual. It is the only state that requires you to maintain a documented data inventory — a written map of what personal data you hold and where. And it gives consumers a right to question the result of profiling: to ask why an automated decision went the way it did and what they could have changed. The 30-day cure period expired January 31, 2026.

In effect sinceJuly 31, 2025
Applies at100k consumers
or 25k + 25% revenue
Max penaltyUp to $7,500
per violation
Cure periodSunset
Jan 31, 2026

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does MCDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Being a covered entity does not exempt you

Minnesota exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.

2

Do you cross the threshold?

100k consumers or 25k + 25% revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.

If you are near the line, get the number from your analytics rather than estimating from patient volume.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Minnesota privacy law: the key facts

Minnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. §§ 325M.10 to 325M.21. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawMinnesota Consumer Data Privacy Act (MCDPA)
CitationMinn. Stat. §§ 325M.10 to 325M.21
EffectiveJuly 31, 2025
The 30-day cure period sunset January 31, 2026.
Who enforces itAttorney General
Applicability

Minnesota reaches controllers that conduct business in the state or target Minnesota residents and, during a calendar year, either:

  • control or process the personal data of 100,000 or more Minnesota consumers, excluding data processed solely to complete a payment transaction; or
  • control or process the personal data of 25,000 or more Minnesota consumers and derive more than 25% of gross revenue from the sale of personal data.

Minnesota also exempts small businesses as defined by the US Small Business Administration — with one carve-out that matters enormously to a medical website. See below.

HIPAA exemption

Data-level only — PHI is exempt, the practice is not

Minnesota exempts protected health information and other HIPAA-governed data, but not HIPAA covered entities as entities. Like Colorado, Oregon, Delaware, New Jersey, Maryland, and California, Minnesota takes the data-level approach: your patient records are out, your website data is in.

Minnesota also declined to write a broad nonprofit exemption, so nonprofit and foundation-structured practices should not assume relief.

Sensitive data

Sensitive data requires opt-in consent. Minnesota's list is broad, expressly including data revealing physical or mental health condition or diagnosis, gender identity and transgender or nonbinary status, precise geolocation, racial or ethnic origin, citizenship or immigration status, and genetic or biometric data.

Definition of “sale”

Broad — monetary or other valuable consideration

Broad definition — monetary or other valuable consideration. Advertising data sharing can qualify, and Minnesota separately grants opt-outs for targeted advertising and profiling.

Universal opt-out / GPC

Yes, from the effective date. Minnesota requires controllers to recognize a universal opt-out mechanism.

Consumer rights
  • Access, correction, deletion, and portability
  • Obtain a list of specific third parties to which personal data has been disclosed
  • Opt out of sale, targeted advertising, and profiling
  • Question the result of profiling — a right unique to Minnesota, covering the reason for the decision, the data used, and what the consumer could change
  • Appeal a denied request
Cure period

Expired. Minnesota's 30-day cure period was written to sunset six months after the effective date and ran out on January 31, 2026.

Penalties

Up to $7,500 per violation, plus injunctive relief, enforced by the Attorney General.

Private right of action

No private right of action. Enforcement by the Minnesota Attorney General.

What it means for you

The parts that actually change how you operate

The small-business exemption that does not exempt the thing that matters

Minnesota exempts small businesses as defined by the US Small Business Administration — a definition that varies by industry but commonly sits at fewer than 500 employees, which describes essentially every independent medical practice in the state.

Then Minnesota did what Texas and Nebraska also did, and left one obligation standing: a small business may not sell a consumer's sensitive data without the consumer's consent.

Read the sequence carefully, because it is the opposite of intuitive. The exemption removes almost everything from a small practice's obligations, and keeps the single provision that is most likely to be triggered by a medical website. Sensitive data includes health condition and diagnosis data. Minnesota's “sale” definition includes exchanges for other valuable consideration. Advertising tags on treatment pages are the fact pattern.

So the practical Minnesota posture for a small practice is narrow and specific: you probably owe very little, and the one thing you owe is consent before any transfer of health-revealing data to a third party for advertising value.

The data inventory requirement is unique, and it is a document

Minnesota requires controllers to maintain a data inventory as part of a documented privacy program. No other state privacy law says this outright.

It is not an onerous document. It is a map: what categories of personal data you collect, where it lives, who you share it with, and why. Most practices could produce a defensible version in an afternoon with their web developer and their marketing agency in the room.

Almost none have. And with the cure period expired, an inventory that does not exist on the day of an inquiry cannot be created retroactively in any way that helps you — the whole value of an inventory is that it was contemporaneous.

The right to question a profiling result

Minnesota gives consumers something no other state does: when profiling produced a decision, the consumer can ask what the reason was, what data was used, and what they could have done differently.

For most practices this is dormant. It stops being dormant if you deploy automated lead scoring, eligibility screening, insurance-based triage, or any tool that decides who gets an appointment slot or an offer. If a system is making that call, Minnesota says the person on the other end can ask it to explain itself, and you have to be able to.

List the specific third parties, not the categories

Minnesota, like Oregon, gives consumers a right to a list of the specific third parties to which their personal data has been disclosed — not merely the categories most states allow.

Practically, that means being able to name every vendor: the analytics provider, each ad platform, the chat widget vendor, the call-tracking service, the scheduling tool, the CRM. Practices are routinely unable to produce this list, not because it is secret but because nobody has ever assembled it. The tag inventory that answers this question is the same one that answers every other question on this page.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Minnesota

Up to $7,500 per violation, plus injunctive relief, enforced by the Attorney General.

The arithmetic nobody puts in a proposal

The dollar figure is standard. Minnesota's distinctive cost is documentary: it is the one state that requires you to maintain a data inventory, and an inventory is the kind of obligation you either satisfied before the inquiry or cannot satisfy afterward. You cannot reconstruct last year's data map in the thirty days you no longer have.

Being a small business is not the shield it appears to be

An owner who reads “small businesses are exempt” and stops reading has missed the only sentence in the Minnesota exemption that is likely to apply to them.

The carve-out keeps the sensitive-data sale prohibition in force for small businesses. For a medical practice — where the sensitive category is health data and the transfer at issue is a marketing tag — that surviving provision is the one aimed squarely at how your website works.

Do this

Your Minnesota action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Build the data inventory. Minnesota is the only state that requires it and it cannot be produced retroactively.
  2. If you are an SBA small business, focus on the one obligation that survives: consent before any sale of sensitive data.
  3. Treat health-revealing transfers to ad platforms as sales of sensitive data until counsel tells you otherwise.
  4. Assemble the list of specific third-party vendors receiving personal data — Minnesota consumers can demand it by name.
  5. Honor universal opt-out signals; required since July 31, 2025.
  6. Get opt-in consent before processing sensitive data.
  7. Document any automated profiling that produces decisions, and be able to explain a result.
  8. Do not plan around the cure period. It expired January 31, 2026.

Questions

Minnesota privacy law FAQ

Does the Minnesota Consumer Data Privacy Act apply to medical practices?

Minnesota exempts protected health information but not HIPAA covered entities, so a practice remains a controller for its non-PHI data. Minnesota also exempts SBA-defined small businesses, but that exemption expressly does not permit selling sensitive data without consent.

What is unique about Minnesota's privacy law?

Two things. It is the only state comprehensive privacy law that requires a controller to maintain a documented data inventory, and it is the only one granting consumers a right to question the result of profiling, including the reason for the decision and what they could have changed.

Are small businesses exempt from the Minnesota privacy law?

Largely, but not entirely. SBA-defined small businesses are exempt from most obligations, with one carve-out: they may not sell a consumer's sensitive data without consent. For medical practices that surviving provision is the most relevant one, because health data is sensitive data.

Is there still a cure period in Minnesota?

No. The 30-day cure period sunset on January 31, 2026, six months after the law took effect.

What are the penalties under the MCDPA?

Up to $7,500 per violation plus injunctive relief, enforced by the Minnesota Attorney General. There is no private right of action.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Minnesota and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing