New Hampshire · NHDPA
New Hampshire privacy law, explained for practice owners
Generous exemptions, and a dedicated enforcement unit to police the rest
The short answer
New Hampshire exempts HIPAA covered entities, nonprofits, and higher-education institutions at the entity level, so a covered-entity practice is outside the NHDPA. What makes New Hampshire worth reading anyway is enforcement posture: it is one of the few states to stand up a dedicated Data Privacy Unit inside its Department of Justice, its 60-day cure period expired at the end of 2025, penalties reach $10,000 per violation, and its 35,000-consumer threshold is proportionally low for a state of 1.4 million.
or 10k + 25% revenue
per violation
Dec 31, 2025
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does NHDPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Are you a HIPAA covered entity?
If yes, NHDPA does not apply to you at all — New Hampshire exempts covered entities and business associates at the entity level, not just their patient records.
If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.
If not, do you cross the threshold?
Without the entity-level exemption, the applicability test is the only thing between you and the statute. 35k consumers or 10k + 25% revenue.
Count website visitors, not just patients. Personal data includes the identifiers your site collects.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
New Hampshire privacy law: the key facts
| Law | New Hampshire Data Privacy Act (NHDPA) |
|---|---|
| Citation | N.H. Rev. Stat. Ann. ch. 507-H |
| Effective | January 1, 2025 The 60-day cure period sunset December 31, 2025. The state stood up a dedicated Data Privacy Unit inside the Department of Justice. |
| Who enforces it | Department of Justice, Consumer Protection and Antitrust Bureau — Data Privacy Unit |
| Applicability | New Hampshire reaches controllers that conduct business in the state or offer products or services to New Hampshire residents and, during a one-year period, either:
New Hampshire has about 1.4 million residents, so 35,000 is roughly one in forty. Proportionally, this is one of the more reachable thresholds in the country. |
| HIPAA exemption | Entity-level — a HIPAA covered entity is outside the statute New Hampshire includes entity-level exemptions for HIPAA covered entities, GLBA-regulated financial institutions, nonprofits, and institutions of higher education. A practice that is a covered entity is outside the NHDPA. New Hampshire is, on paper, one of the more generous states on exemptions. It is also one of the few that built an office specifically to enforce what remains. |
| Sensitive data | Sensitive data requires opt-in consent, including data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and personal data of a known child. |
| Definition of “sale” | Broad — monetary or other valuable consideration Broad definition — monetary or other valuable consideration. Separate opt-outs apply for targeted advertising and for profiling in furtherance of decisions with legal or similarly significant effects. |
| Universal opt-out / GPC | Yes, from the effective date. New Hampshire requires controllers to recognize a universal opt-out mechanism, and the Department of Justice has published business guidance on what that means in practice. |
| Consumer rights |
|
| Cure period | Expired. The 60-day cure period was time-limited by statute and ran out at the end of 2025. From January 1, 2026 the Attorney General may grant a cure opportunity at his discretion, but is no longer required to. |
| Penalties | Violations are enforced under New Hampshire's Consumer Protection Act, RSA 358-A, which provides civil penalties of up to $10,000 per violation along with injunctive relief. |
| Private right of action | No private right of action. Enforcement sits exclusively with the New Hampshire Department of Justice. |
What it means for you
The parts that actually change how you operate
New Hampshire built an office for this
Most states enforce privacy law out of a general consumer protection division that also handles auto dealers and home improvement contractors. New Hampshire created a Data Privacy Unit inside the Consumer Protection and Antitrust Bureau and published business-facing FAQ material about the new law.
That is a meaningful signal for a state this size. Dedicated units generate cases, because generating cases is what they are staffed to do. A general division triages privacy complaints against everything else on the desk; a specialist unit does not have anything else on the desk.
It also means the state has published its own reading of the statute — which is worth reading before your counsel writes their own memo, because it tells you what the enforcer thinks the law says.
The exemption is broad. Confirm you actually fall inside it.
New Hampshire's entity-level list is unusually generous: HIPAA covered entities, GLBA institutions, nonprofits, and higher education all get out. Two of those matter for practices, and both require an actual determination rather than an assumption.
Covered entity: a health plan, healthcare clearinghouse, or a provider that transmits health information electronically in connection with a HIPAA standard transaction. Cash-pay practices that never submit electronic claims may not qualify.
Nonprofit: straightforward if that is your structure — and worth noting that New Hampshire kept this exemption while Montana, Maryland, Minnesota, Delaware, New Jersey, and Oregon did not.
If neither applies to the entity that owns your website, the 35,000-consumer threshold is what stands between you and the statute, and in a state of 1.4 million that is a number a well-marketed regional practice can reach.
Two things expired or started on January 1
New Hampshire's timeline compressed two changes into the same date range. The universal opt-out recognition requirement began January 1, 2025, at the law's start. The cure period ended December 31, 2025, one year later.
So the first year of the NHDPA came with a built-in remediation path, and the second year does not. If your last review of New Hampshire was during 2025, the enforcement posture you assessed no longer exists.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in New Hampshire
Violations are enforced under New Hampshire's Consumer Protection Act, RSA 358-A, which provides civil penalties of up to $10,000 per violation along with injunctive relief.
The arithmetic nobody puts in a proposal
New Hampshire pairs an above-average per-violation figure with a proportionally low threshold and a purpose-built enforcement unit. The state is small; the enforcement apparatus is not proportionally small. That combination is unusual and worth taking seriously.
A small state with a specialist unit is not a low-risk state
Practice owners routinely rank state privacy risk by population, which puts New Hampshire near the bottom. That ranking ignores who is doing the enforcing.
New Hampshire has 1.4 million residents, a 35,000-consumer threshold that is proportionally low, a $10,000-per-violation ceiling that is above the national norm, no cure period since the end of 2025, and a Department of Justice unit whose specific job is this statute. On enforcement probability per dollar of your revenue, that is not the bottom of the list.
Do this
Your New Hampshire action list
In order. Items one and two are the ones that change your answer to everything else.
- Determine and document whether your entities are HIPAA covered entities, business associates, or qualifying nonprofits.
- Read the New Hampshire DOJ's own business guidance — the enforcer published its reading of the law.
- Identify which legal entity owns the website; the exemption follows the entity.
- Honor universal opt-out signals; required since January 1, 2025.
- Get opt-in consent before processing sensitive data, including health condition data.
- Provide opt-outs for sale, targeted advertising, and consequential profiling.
- Build the appeals path for denied consumer requests, including escalation to the Attorney General.
- Do not plan around the cure period. It expired December 31, 2025.
Questions
New Hampshire privacy law FAQ
Are HIPAA covered entities exempt from the New Hampshire Data Privacy Act?
Yes. New Hampshire provides entity-level exemptions for HIPAA covered entities, GLBA-regulated financial institutions, nonprofits, and institutions of higher education.
What are the New Hampshire privacy law thresholds?
Controlling or processing the personal data of 35,000 or more New Hampshire consumers during a one-year period, excluding payment-transaction-only data, or 10,000 or more while deriving more than 25% of gross revenue from selling personal data.
Is there still a cure period under the NHDPA?
No. The 60-day cure period was statutorily time-limited and expired December 31, 2025. From 2026 the Attorney General may offer a cure opportunity but is not required to.
Who enforces New Hampshire's privacy law?
The New Hampshire Department of Justice, through a dedicated Data Privacy Unit within the Consumer Protection and Antitrust Bureau. There is no private right of action.
What is the penalty for violating the New Hampshire Data Privacy Act?
Violations are enforced under RSA 358-A, the state Consumer Protection Act, with civil penalties up to $10,000 per violation plus injunctive relief.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in New Hampshire and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing