Oregon · OCPA
Oregon privacy law, explained for practice owners
Name every vendor. Not the categories — the vendors.
The short answer
Oregon exempts protected health information but not covered entities, so your practice is a regulated controller for its website and marketing data. Oregon's signature requirement is the one most practices cannot satisfy today: a consumer can demand a list of the specific third parties you disclosed their personal data to — named vendors, not categories. Oregon also prohibits the sale of precise geolocation and of under-16 data outright, requires opt-in consent for a very broad sensitive-data category, and lost its cure period on January 1, 2026, the same day universal opt-out recognition became mandatory.
or 25k + 25% revenue
per violation
Jan 1, 2026
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does OCPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Being a covered entity does not exempt you
Oregon exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.
Do you cross the threshold?
100k consumers or 25k + 25% revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.
If you are near the line, get the number from your analytics rather than estimating from patient volume.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
Oregon privacy law: the key facts
| Law | Oregon Consumer Privacy Act (OCPA) |
|---|---|
| Citation | Or. Rev. Stat. § 646A.570 et seq. |
| Effective | July 1, 2024 Nonprofits came into scope July 1, 2025. The cure period sunset January 1, 2026, the same date universal opt-out recognition became mandatory. HB 2008 (2025) added sale prohibitions for precise geolocation and minors' data. |
| Who enforces it | Department of Justice, Attorney General |
| Applicability | Oregon reaches persons that conduct business in Oregon or provide products or services to Oregon residents and, during a calendar year, control or process:
Nonprofit organizations were phased in on July 1, 2025 — Oregon is one of the states that declined a permanent nonprofit exemption. |
| HIPAA exemption | Data-level only — PHI is exempt, the practice is not Oregon exempts protected health information and other HIPAA-governed data, but not HIPAA covered entities as entities. Oregon is squarely in the data-level camp with California, Colorado, Delaware, Maryland, Minnesota, and New Jersey. For an Oregon practice, that means the statute applies to your website, your advertising data, your marketing lists, and your prospective-patient data — everything short of the chart. |
| Sensitive data | Sensitive data requires opt-in consent, and Oregon's definition is among the broadest in the country. It expressly includes data revealing a consumer's status as transgender or nonbinary and status as a victim of crime, alongside racial or ethnic background, national origin, religious beliefs, mental or physical condition or diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, and precise geolocation. |
| Definition of “sale” | Broad — monetary or other valuable consideration Broad definition — monetary or other valuable consideration. HB 2008 (2025) went further and prohibited the sale of precise geolocation data and of the personal data of consumers under 16, regardless of consent. Oregon joined Maryland in deciding some categories are not for sale at any price. |
| Universal opt-out / GPC | Yes, as of January 1, 2026. Oregon controllers must recognize a universal opt-out mechanism. |
| Consumer rights |
|
| Cure period | Expired. Oregon's 30-day cure period ended January 1, 2026 — the same day the universal opt-out requirement began. The obligation got harder on the exact date the safety net disappeared. |
| Penalties | Up to $7,500 per violation, enforced by the Attorney General under the Unlawful Trade Practices Act, with injunctive relief available. |
| Private right of action | No private right of action. Enforcement by the Oregon Department of Justice. |
What it means for you
The parts that actually change how you operate
The specific-third-parties right is the hardest question on this page
Most state privacy laws let you answer a disclosure request with categories of recipients: “advertising partners,” “analytics providers,” “service vendors.” Oregon does not. An Oregon consumer can request a list of the specific third parties to which you have disclosed their personal data.
Try answering that for your own practice right now, from memory. A typical practice website discloses data to: an analytics platform, one or more ad networks, a tag manager, a chat or messaging widget, a call-tracking vendor, a scheduling tool, a review-collection service, a heatmap or session-recording tool nobody remembers installing, a CDN, and whatever a previous agency left behind.
Almost no practice can produce that list, and the reason is not secrecy. It is that nobody has ever assembled it — the tags accumulated over years, added by different agencies, and no single document records them.
Building that inventory is the single most useful compliance artifact a practice can create, because the same list answers Oregon's third-party right, Minnesota's data inventory requirement, Delaware's and Maryland's category lists, and the first question any regulator or plaintiff's lawyer asks.
Oregon publishes what it is enforcing
The Oregon Department of Justice has issued public enforcement reports on the OCPA, covering the complaints it received and the actions it took. Six-month and one-year reports have both been published.
The recurring themes in those reports have centered on opt-out mechanisms — consumers unable to exercise rights the statute grants them, and controllers whose privacy notices did not match the mechanisms actually available on their sites.
Two takeaways. First, this is a state where the enforcement priorities are documented rather than inferred. Second, the priority is the thing a regulator can verify from outside your building: does the opt-out on your website work.
Some data is not for sale at any price
HB 2008, passed in 2025, prohibited the sale of precise geolocation data and the personal data of consumers under 16 — outright, not gated behind consent. Oregon and Maryland are the two states that have crossed from consent-based regulation into flat prohibition for specific categories.
Practices with a paediatric, adolescent, or family-medicine component should note the under-16 provision specifically, and anyone using location-based advertising should assume precise geolocation is off the table in Oregon.
Two dates, one day
January 1, 2026 was a single-day pivot in Oregon: the cure period ended and universal opt-out recognition began. Before that date, an Oregon controller had thirty days to fix a problem and no obligation to honor a browser signal. After it, the reverse.
If your Oregon assessment predates 2026, both halves of it are out of date.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in Oregon
Up to $7,500 per violation, enforced by the Attorney General under the Unlawful Trade Practices Act, with injunctive relief available.
The arithmetic nobody puts in a proposal
Oregon's distinguishing feature is not the penalty size, it is transparency. The Department of Justice publishes enforcement reports describing what it received complaints about and what it did. That is unusual, useful, and slightly uncomfortable: it means the state has told you in writing what it is looking at, which removes any argument that you could not have known.
You cannot answer the question you have never been asked
The Oregon third-party right does not require you to do anything differently day to day. It requires you to know something — and the knowing has to precede the request, because a thirty-day response window is not enough time to audit years of accumulated tags across a site you did not build.
The practices that fail this requirement are not the ones doing something wrong with data. They are the ones who cannot say what they are doing with it.
Do this
Your Oregon action list
In order. Items one and two are the ones that change your answer to everything else.
- Build a named inventory of every third party receiving data from your site. Oregon requires names, not categories.
- Run a live scan of what actually loads in a browser, rather than trusting your tag manager's documentation.
- Honor universal opt-out signals; required since January 1, 2026.
- Get opt-in consent before processing sensitive data — Oregon's category is one of the broadest in the country.
- Stop any sale of precise geolocation data and of under-16 data. These are prohibited, not consent-gated.
- Test that the opt-out on your own website actually works. Oregon's enforcement reports say this is where complaints concentrate.
- Make sure your privacy notice describes the mechanisms your site actually offers.
- Assume no cure period. It sunset January 1, 2026.
Questions
Oregon privacy law FAQ
Does the Oregon Consumer Privacy Act apply to healthcare providers?
Yes, to the extent they process data that is not protected health information. Oregon uses a data-level HIPAA exemption rather than an entity-level one, so a provider's website analytics, advertising data, and marketing lists are in scope if the provider meets a threshold.
What is unique about the Oregon Consumer Privacy Act?
Oregon grants consumers the right to obtain a list of the specific third parties to which their personal data has been disclosed — named recipients rather than the categories most states permit. It also prohibits outright the sale of precise geolocation data and of the personal data of consumers under 16.
Is there still a cure period in Oregon?
No. The 30-day cure period sunset on January 1, 2026, the same date universal opt-out mechanism recognition became mandatory.
Are nonprofits exempt from Oregon's privacy law?
No. Oregon phased nonprofits into scope on July 1, 2025 rather than granting a permanent exemption.
What are the penalties under the OCPA?
Up to $7,500 per violation, enforced by the Oregon Department of Justice under the Unlawful Trade Practices Act, with injunctive relief available. There is no private right of action.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Oregon and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing