Rhode Island · RIDTPPA

Rhode Island privacy law, explained for practice owners

Name your buyers in public. No cure period, ever.

Exempt if a covered entity — verify it In effect since January 1, 2026 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Rhode Island exempts HIPAA covered entities and business associates at the entity level, so a covered-entity practice is outside its new privacy law. Two things make it worth reading anyway. Rhode Island's privacy notice requirement is the strictest in the country: you must identify the third parties to whom you have sold or may sell personal data, which no other state requires in a public notice. And there is no cure period at all — not a sunsetting one, not a discretionary one. The law arrived on January 1, 2026 without a grace period.

In effect sinceJanuary 1, 2026
Applies at35k consumers
or 10k + 20% revenue
Max penaltyUp to $10,000
per violation
Cure periodNone

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does RIDTPPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, RIDTPPA does not apply to you at all — Rhode Island exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 35k consumers or 10k + 20% revenue.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Rhode Island privacy law: the key facts

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws § 6-48.1-1 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawRhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
CitationR.I. Gen. Laws § 6-48.1-1 et seq.
EffectiveJanuary 1, 2026
No cure period at any point. Tied with Maryland for the lowest threshold in the country.
Who enforces itAttorney General
Applicability

Rhode Island reaches for-profit entities that conduct business in the state or produce products or services targeted to Rhode Island residents and, during the preceding calendar year, either:

  • controlled or processed the personal data of 35,000 or more customers, excluding data controlled or processed solely to complete a payment transaction; or
  • controlled or processed the personal data of 10,000 or more customers and derived more than 20% of gross revenue from the sale of personal data.

Rhode Island has roughly 1.1 million residents. A 35,000-customer threshold is about one in thirty-one — the most reachable threshold in the country as a share of state population.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Rhode Island exempts HIPAA covered entities and business associates at the entity level, and separately exempts protected health information. A practice that is a covered entity is outside the RIDTPPA.

Which makes this a short page for most practices — with two exceptions worth reading, because Rhode Island's notice requirement is stricter than any other state's and its enforcement has no grace period at all.

Sensitive data

Sensitive data requires opt-in consent, covering data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and personal data of a known child.

Definition of “sale”

Broad — monetary or other valuable consideration

Broad definition — monetary or other valuable consideration. Rhode Island pairs it with the disclosure requirement described below, which is where the law gets its name: data transparency was the point.

Universal opt-out / GPC

Rhode Island does not mandate recognition of a universal opt-out mechanism. It does require a clear and conspicuous means of exercising the opt-out rights it grants.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and consequential profiling
  • Consent required before processing sensitive data
  • A privacy notice that identifies the third parties to whom the controller has sold or may sell personal data
  • Appeal a denied request
Cure period

None, at any point. Rhode Island did not write a cure period into its statute — not a permanent one like Indiana's, not a sunsetting one like Delaware's. The law took effect January 1, 2026 with no built-in grace period from day one.

Penalties

Violations are deceptive trade practices under the Rhode Island Deceptive Trade Practices Act, carrying civil penalties of up to $10,000 per violation. The statute also provides for penalties of $100 to $500 per disclosure for intentional disclosure of personal data in violation of the Act, alongside injunctive relief.

Private right of action

No private right of action. Enforcement by the Rhode Island Attorney General under the Deceptive Trade Practices Act.

What it means for you

The parts that actually change how you operate

The notice requirement no other state has

Every state privacy law requires a privacy notice. Rhode Island requires something categorically different: the notice must identify the third parties to whom the controller has sold or may sell customers' personally identifiable information.

Two words do the damage. Identify, rather than “describe the categories of.” And may sell, which is forward-looking — it reaches recipients you have not disclosed to yet but might.

Oregon requires naming specific third parties, but only in response to an individual consumer request. Rhode Island requires it in the public-facing notice, where competitors, plaintiffs' lawyers, and regulators can all read it without asking you for anything.

For a practice, that means the ad-tech stack on your website becomes a published fact. Which is a strong argument for making the list short.

No cure period from day one

Most states wrote a cure period and either kept it (Indiana, Kentucky, Nebraska, Texas, Virginia) or scheduled it to sunset (Delaware, Minnesota, New Jersey, Oregon, Maryland, Connecticut, Colorado). Rhode Island skipped the step.

The RIDTPPA took effect January 1, 2026 with no statutory notice-and-cure mechanism at all. Combined with the per-disclosure penalty structure, Rhode Island is the least forgiving new law of the 2026 cohort — which is a strange result for a small state whose law is otherwise fairly standard.

The most reachable threshold in the country, proportionally

Thirty-five thousand customers sounds like a lot until you set it against 1.1 million residents. That is roughly one Rhode Islander in thirty-one — the highest ratio of any state threshold in the country.

Rhode Island is also embedded in the Providence-Boston corridor, where practices routinely draw patients across state lines and run digital advertising that does not respect state boundaries. A practice serving southern New England can accumulate 35,000 Rhode Island visitors without ever thinking of itself as a Rhode Island business.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Rhode Island

Violations are deceptive trade practices under the Rhode Island Deceptive Trade Practices Act, carrying civil penalties of up to $10,000 per violation. The statute also provides for penalties of $100 to $500 per disclosure for intentional disclosure of personal data in violation of the Act, alongside injunctive relief.

The arithmetic nobody puts in a proposal

The per-disclosure penalty structure is the unusual part. A per-violation figure is typically argued about at the level of “the practice failed to provide an opt-out.” A per-disclosure figure counts events — and a tracking tag on a busy website generates disclosures continuously, without anyone touching it.

Your privacy notice becomes a public list of your vendors

Practices treat the privacy policy as a compliance artifact nobody reads. Rhode Island turns it into a disclosure document with specific, checkable content — the third parties you sell or may sell data to, named.

Which creates an uncomfortable but clarifying incentive. If publishing your recipient list would be embarrassing, the problem is not the notice requirement. It is the list.

Do this

Your Rhode Island action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm and document your HIPAA covered-entity status. It is the exemption that decides this page for you.
  2. If in scope, build the named list of third parties you have sold or may sell data to — it goes in the public notice.
  3. Count Rhode Island customers against 35,000; proportionally it is the most reachable threshold in the country.
  4. Get opt-in consent before processing sensitive data, including health condition data.
  5. Provide a clear, working opt-out for sale, targeted advertising, and consequential profiling.
  6. Assume enforcement without warning. Rhode Island has no cure period at all.
  7. Reduce the vendor list before you publish it — a shorter list is easier to defend and easier to maintain.
  8. Keep timestamped consent records; with no cure period, contemporaneous evidence is your only retroactive answer.

Questions

Rhode Island privacy law FAQ

When did Rhode Island's privacy law take effect?

January 1, 2026. The Data Transparency and Privacy Protection Act was enacted in 2024 with an eighteen-month runway.

Are HIPAA covered entities exempt from the Rhode Island privacy law?

Yes. The RIDTPPA does not apply to HIPAA covered entities or business associates, and it separately exempts protected health information.

What makes Rhode Island's privacy notice requirement unusual?

It requires the controller to identify the third parties to whom it has sold or may sell customers' personally identifiable information, in the public privacy notice. Other states allow disclosure by category, and Oregon's specific-recipient right applies only in response to an individual request.

Does Rhode Island have a cure period?

No. The RIDTPPA contains no notice-and-cure mechanism, and never did. It took effect January 1, 2026 without one.

What are the penalties under the RIDTPPA?

Violations are deceptive trade practices under Rhode Island's Deceptive Trade Practices Act, carrying up to $10,000 per violation, plus $100 to $500 per disclosure for intentional disclosures in violation of the Act, and injunctive relief.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Rhode Island and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing