New Jersey · NJDPA
New Jersey privacy law, explained for practice owners
No percentage floor on the low threshold. Cure period expired weeks ago.
The short answer
New Jersey does not exempt HIPAA covered entities, only their protected health information — so your website and marketing data are in scope. Two features make New Jersey sharper than it looks. Its second applicability threshold triggers at just 25,000 consumers if you derive any revenue or benefit from selling data, with no percentage floor, and its sale definition is the broad one. Its sensitive data category expressly includes health treatment, not just condition or diagnosis. The 30-day cure period expired July 1, 2026, and penalties run $10,000 for a first violation and $20,000 for each one after.
or 25k + data revenue
per violation
Jul 1, 2026
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does NJDPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Being a covered entity does not exempt you
New Jersey exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.
Do you cross the threshold?
100k consumers or 25k + data revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.
If you are near the line, get the number from your analytics rather than estimating from patient volume.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
New Jersey privacy law: the key facts
| Law | New Jersey Data Privacy Act (NJDPA) |
|---|---|
| Citation | N.J.S.A. § 56:8-166.4 et seq. |
| Effective | January 15, 2025 Universal opt-out recognition required from July 2025. The 30-day cure period sunset July 1, 2026. Division of Consumer Affairs rulemaking is ongoing. |
| Who enforces it | Attorney General, Division of Consumer Affairs |
| Applicability | New Jersey reaches controllers that conduct business in the state or target New Jersey residents and, during a calendar year, either:
The second prong has no percentage floor — unlike Virginia's “over 50%” or Minnesota's “over 25%,” New Jersey only asks whether you derive any revenue or benefit from selling data. With a broad sale definition, that is a low bar for a practice running paid media. |
| HIPAA exemption | Data-level only — PHI is exempt, the practice is not New Jersey takes the data-level approach: PHI and HIPAA-governed data are exempt, the covered entity is not. New Jersey has expanded its HIPAA-based data carve-outs since enactment, but it did not convert them into an entity-level exemption. Your practice remains a controller for its non-PHI data. New Jersey also declined a broad nonprofit exemption. |
| Sensitive data | Sensitive data requires opt-in consent. New Jersey's list is one of the broadest in the country, expressly including data revealing racial or ethnic origin, religious beliefs, mental or physical health condition, treatment, or diagnosis, financial information including account numbers and credentials, sex life or sexual orientation, status as transgender or nonbinary, citizenship or immigration status, genetic or biometric data, and precise geolocation. Note “treatment” alongside “condition or diagnosis” — New Jersey wrote the wider phrasing from the start. |
| Definition of “sale” | Broad — monetary or other valuable consideration Broad definition — monetary or other valuable consideration. Read that together with the 25,000-consumer threshold prong, which triggers on deriving any revenue or benefit from selling data. In New Jersey the sale definition is not just a labeling question; it feeds directly into whether the law applies to you at all. |
| Universal opt-out / GPC | Yes. The NJDPA required controllers to recognize a universal opt-out mechanism within six months of the effective date, which landed in July 2025. |
| Consumer rights |
|
| Cure period | Expired. New Jersey's 30-day cure period was written to sunset eighteen months after the effective date and ran out on July 1, 2026 — three weeks before this page was last reviewed. |
| Penalties | Violations are unlawful practices under the New Jersey Consumer Fraud Act: up to $10,000 for a first violation and up to $20,000 for each subsequent violation, plus injunctive relief and the state's costs. |
| Private right of action | No private right of action under the NJDPA. That said, New Jersey plaintiffs' firms have been active under other theories, and the Consumer Fraud Act itself has a private right of action in other contexts — a distinction worth having your counsel map rather than assuming the NJDPA's silence closes the door on private litigation generally. |
What it means for you
The parts that actually change how you operate
The threshold prong with no percentage floor
Almost every state's second threshold requires that data sales be a meaningful share of your revenue. Virginia says over 50%. Minnesota says over 25%. Maryland and Delaware say over 20%. Those percentages are what keep ordinary businesses out of the second prong — nobody accidentally derives half their revenue from selling data.
New Jersey removed the percentage. Its second prong triggers at 25,000 consumers if the controller sells personal data or derives revenue or receives a discount from selling it. Any revenue. Any discount.
Now add the broad sale definition, where disclosure for other valuable consideration counts. A practice that shares visitor data with an advertising platform and receives better ad performance in return is at least arguably receiving a benefit from that disclosure. If it also touches 25,000 New Jersey residents in a year, the second prong is in play.
New Jersey is a dense state of over nine million people. Twenty-five thousand is not a difficult number to reach.
“Treatment” in the sensitive data definition
Connecticut had to amend its statute in 2026 to widen health-related sensitive data from “condition or diagnosis” to include disability and treatment. New Jersey wrote the wider language originally: sensitive data includes personal data revealing mental or physical health condition, treatment, or diagnosis.
For a practice website that is a broader net than it sounds. A page about a specific procedure is about treatment. A visitor's interest in that page, transmitted to a third party with a persistent identifier attached, is data that arguably reveals something about treatment.
The mitigation is the same as everywhere: nothing non-essential fires on those pages until consent is captured and recorded.
Rulemaking is still in motion
New Jersey gave its Division of Consumer Affairs rulemaking authority, and that process has been running since the law took effect. Practices should expect the operational detail — what a compliant opt-out looks like, how universal opt-out signals must be handled, what a data protection assessment has to contain — to be sharpened by regulation rather than settled by the statute alone.
The practical implication: build to the strict reading. Regulations issued after you have configured your site do not grandfather the configuration.
The cure period expired three weeks ago
As of the date this page was last reviewed, New Jersey's 30-day cure period has been gone for less than a month. It sunset on July 1, 2026, eighteen months after the effective date, exactly as the statute provided.
If your last New Jersey assessment was done in the first half of 2026, it was done under a materially different enforcement regime than the one you are operating in now.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in New Jersey
Violations are unlawful practices under the New Jersey Consumer Fraud Act: up to $10,000 for a first violation and up to $20,000 for each subsequent violation, plus injunctive relief and the state's costs.
The arithmetic nobody puts in a proposal
The Consumer Fraud Act is a powerful statute and New Jersey courts have interpreted it expansively. The doubling on subsequent violations follows the same logic as Maryland's escalation clause: a partial fix that leaves the underlying problem in place converts your next finding into a second violation at twice the price.
The percentage floor you are relying on is not in the New Jersey statute
Compliance summaries frequently describe the state privacy thresholds as a single pattern: 100,000 consumers, or 25,000 plus a large share of revenue from data sales. That summary is accurate for most states and wrong for New Jersey.
New Jersey's second prong has no share requirement at all. Any revenue or discount from selling data, at 25,000 consumers, is enough. In a state with nine million residents and a broad definition of “sale,” that is a genuinely different test — and it is the one most likely to catch a practice that assumed it was under the threshold.
Do this
Your New Jersey action list
In order. Items one and two are the ones that change your answer to everything else.
- Re-read the second threshold prong: 25,000 consumers plus any revenue or discount from selling data. There is no percentage floor.
- Count New Jersey consumers including website visitors — nine million residents makes 25,000 reachable.
- Have counsel assess whether your ad-tech data flows are a “sale” under the broad definition, since it feeds applicability, not just labeling.
- Treat pages about treatment as sensitive-data territory — New Jersey's definition names treatment explicitly.
- Get opt-in consent before processing sensitive data.
- Handle 13-to-17-year-old consumers' data with consent for sale, targeted advertising, and profiling.
- Honor universal opt-out signals; required since July 2025.
- Assume no cure period. It sunset July 1, 2026.
Questions
New Jersey privacy law FAQ
Does the New Jersey Data Privacy Act apply to HIPAA covered entities?
Yes, in part. New Jersey uses a data-level approach: PHI and HIPAA-governed data are exempt, but the covered entity remains a controller for personal data that is not PHI, including website analytics and advertising data.
What are the New Jersey Data Privacy Act thresholds?
100,000 or more New Jersey consumers in a calendar year excluding payment-transaction-only data, or 25,000 or more consumers where the controller sells personal data or derives revenue or receives a discount from selling it. The second prong has no revenue percentage floor, which distinguishes New Jersey from most other states.
Is there still a cure period under the NJDPA?
No. The 30-day cure period sunset on July 1, 2026, eighteen months after the effective date.
What are the penalties under the New Jersey Data Privacy Act?
Violations are unlawful practices under the New Jersey Consumer Fraud Act, carrying up to $10,000 for a first violation and up to $20,000 for each subsequent violation, plus injunctive relief and costs.
Does New Jersey require consent for health data?
Yes. Sensitive data requires opt-in consent, and New Jersey's definition expressly covers data revealing mental or physical health condition, treatment, or diagnosis — broader phrasing than several other states use.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in New Jersey and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing