Montana · MCDPA

Montana privacy law, explained for practice owners

Rewritten October 2025: lower threshold, no cure period, no nonprofit shield

Exempt if a covered entity — but check the entity In effect since October 1, 2024 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Montana still exempts HIPAA covered entities and business associates at the entity level, so a true covered entity sits outside the MCDPA. But Montana got materially tougher on October 1, 2025: the threshold fell to 25,000 consumers, the cure period was eliminated outright rather than sunset, the nonprofit exemption was gutted, and explicit $7,500-per-violation penalties were added with no aggregate cap. For any practice that is not a covered entity — cash-pay aesthetic and elective practices frequently are not — Montana is now a low-threshold, no-grace-period state.

In effect sinceOctober 1, 2024
Applies at25k consumers
or 15k + 25% revenue
Max penaltyUp to $7,500
per violation
Cure periodEliminated
Oct 1, 2025

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does MCDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, MCDPA does not apply to you at all — Montana exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 25k consumers or 15k + 25% revenue.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Montana privacy law: the key facts

Montana Consumer Data Privacy Act (MCDPA), Mont. Code Ann. § 30-14-2801 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawMontana Consumer Data Privacy Act (MCDPA)
CitationMont. Code Ann. § 30-14-2801 et seq.
EffectiveOctober 1, 2024
Substantially amended by SB 297, effective October 1, 2025: thresholds cut, cure period eliminated, nonprofit exemption gutted, minors' protections added.
Who enforces itAttorney General, Office of Consumer Protection
Applicability

Since SB 297 took effect on October 1, 2025, Montana reaches controllers that either:

  • control or process the personal data of 25,000 or more Montana consumers (down from 50,000); or
  • control or process the personal data of 15,000 or more Montana consumers and derive more than 25% of gross revenue from the sale of personal data.

Montana has roughly 1.1 million residents. A 25,000-consumer threshold is about one in forty-four Montanans — proportionally one of the most reachable thresholds in the country. A regional practice that advertises across the mountain west can cross it on web traffic alone.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Montana keeps its entity-level exemption for HIPAA covered entities and business associates. SB 297 removed the entity-level Gramm-Leach-Bliley exemption and replaced it with a data-level one, which hit financial institutions. Healthcare's entity-level carve-out survived that round.

What did not survive: the broad nonprofit exemption. SB 297 narrowed it to nonprofits established to detect and prevent insurance fraud. If your practice or clinic operates under a nonprofit structure and assumed that was a shield in Montana, it is not any more.

Sensitive data

Sensitive data requires opt-in consent, covering data revealing mental or physical health condition or diagnosis, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic and biometric data, and precise geolocation.

SB 297 added a separate duty of reasonable care to avoid a heightened risk of harm to minors for any controller offering an online service to someone it knows, or willfully disregards, is under 18.

Definition of “sale”

Broad — monetary or other valuable consideration

Broad definition — monetary or other valuable consideration. Montana also grants separate opt-outs for targeted advertising and for profiling in furtherance of consequential decisions.

Universal opt-out / GPC

Yes. Montana has required controllers to recognize a universal opt-out mechanism since January 1, 2025.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and consequential profiling
  • Consent required before processing sensitive data
  • Heightened protections for consumers under 18
  • Appeal a denied request
Cure period

Gone entirely. Montana originally provided a 60-day cure period. SB 297 eliminated it as of October 1, 2025 — not sunset on a future date, removed. Montana enforcement arrives without a statutory grace period.

Penalties

SB 297 introduced explicit civil penalties of up to $7,500 for each violation, with no statutory cap on the aggregate. Enforced by the Attorney General under Montana's unfair trade practices framework.

Private right of action

No private right of action. Enforcement by the Montana Attorney General's Office of Consumer Protection.

What it means for you

The parts that actually change how you operate

SB 297 changed four things at once, and three of them make it harder

Montana's original 2024 law was a mild, Connecticut-derived statute. The 2025 amendments turned it into one of the more demanding ones for anyone not entity-exempt:

  • Thresholds cut nearly in half — 50,000 to 25,000, and 25,000 to 15,000 on the data-revenue prong.
  • Cure period eliminated, effective immediately rather than on a future sunset date.
  • Nonprofit exemption gutted, narrowed to insurance-fraud-prevention nonprofits only.
  • Minors' protections added, with a reasonable-care duty and a willful-disregard standard that does not let you avoid the question by not asking.

The GLBA change went the other way for banks, but nothing in SB 297 loosened anything for a healthcare provider.

The nonprofit change is the one practices miss

Montana previously had a broad nonprofit exemption of the kind found in Virginia and several other states. SB 297 narrowed it to nonprofits organized to detect and prevent insurance fraud — which is to say, effectively eliminated it for everyone else.

Community clinics, foundation-affiliated practices, and nonprofit health organizations that were relying on that carve-out lost it on October 1, 2025. If your structure is nonprofit and not also a HIPAA covered entity, you went from clearly exempt to clearly in scope in a single amendment.

Small state, reachable threshold

Threshold numbers mean different things in different states. Twenty-five thousand consumers in Texas is a rounding error. In Montana, with 1.1 million residents, it is a meaningful share of the state — proportionally comparable to a 250,000-person threshold in a state of eleven million.

Practices that serve a regional footprint across Montana, Wyoming, Idaho, and the Dakotas should count Montana visitors specifically rather than assuming a low-population state implies a low-risk one.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Montana

SB 297 introduced explicit civil penalties of up to $7,500 for each violation, with no statutory cap on the aggregate. Enforced by the Attorney General under Montana's unfair trade practices framework.

The arithmetic nobody puts in a proposal

The absence of an aggregate cap is the detail worth reading twice. In states with a per-violation figure and a practical ceiling set by regulatory discretion, the negotiation has a natural stopping point. Montana wrote the per-violation number and declined to write a maximum.

“Eliminated” is different from “sunset”

Most states that removed their cure periods did it with a sunset date written into the original statute, which at least gave operators a calendar to plan against. Montana amended the law to delete the provision.

The distinction matters for anyone whose compliance plan was built around the original text. If your notes say Montana gives you 60 days, those notes are describing a statute that no longer exists.

Do this

Your Montana action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm in writing whether each entity is a HIPAA covered entity or business associate.
  2. If your structure is nonprofit, re-check your exemption — Montana narrowed it to insurance-fraud nonprofits on October 1, 2025.
  3. Count Montana consumers against 25,000, not the old 50,000.
  4. Honor universal opt-out signals; required since January 1, 2025.
  5. Get opt-in consent before processing sensitive data, including health condition data.
  6. Address the minors' reasonable-care duty — the willful-disregard standard means not asking is not a defense.
  7. Assume no cure period. It was eliminated, not scheduled to expire.
  8. Keep timestamped consent records; with no grace period, contemporaneous evidence is the only remedy available after the fact.

Questions

Montana privacy law FAQ

Are HIPAA covered entities exempt from Montana's privacy law?

Yes, at the entity level. SB 297 removed the entity-level Gramm-Leach-Bliley exemption for financial institutions but left the HIPAA entity-level exemption in place for covered entities and business associates.

What did Montana SB 297 change?

Effective October 1, 2025 it lowered thresholds to 25,000 consumers (or 15,000 with more than 25% of revenue from data sales), eliminated the cure period entirely, narrowed the nonprofit exemption to insurance-fraud-prevention nonprofits, added protections for consumers under 18, added explicit $7,500-per-violation penalties with no aggregate cap, and narrowed the GLBA exemption to data-level.

Does Montana still have a cure period?

No. SB 297 eliminated it as of October 1, 2025. This was a repeal, not a scheduled sunset.

Are nonprofits exempt from the Montana Consumer Data Privacy Act?

Generally no, not since October 1, 2025. The exemption was narrowed to nonprofits established to detect and prevent insurance fraud.

What are Montana's applicability thresholds now?

25,000 or more Montana consumers in a calendar year, or 15,000 or more while deriving more than 25% of gross revenue from the sale of personal data.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Montana and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing