Tennessee · TIPA

Tennessee privacy law, explained for practice owners

The only state where doing it right is a written legal defense

Almost certainly does not apply In effect since July 1, 2025 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

TIPA almost certainly does not reach your practice. It requires more than $25 million in revenue and 175,000 Tennessee consumers — the highest volume threshold in the country — and it exempts HIPAA covered entities at the entity level on top of that. But Tennessee contributed something no other state did, and it is worth your attention regardless of scope: TIPA gives you an affirmative defense if you maintain a written privacy program that reasonably conforms to the NIST Privacy Framework. It is the only state that turns documented diligence into an actual legal defense, and it is a useful template for what “defensible” means anywhere.

In effect sinceJuly 1, 2025
Applies at$25M revenue AND
175k consumers
Max penaltyUp to $7,500
per violation
Cure period60 days

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does TIPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, TIPA does not apply to you at all — Tennessee exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. $25M revenue AND 175k consumers.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Tennessee privacy law: the key facts

Tennessee Information Protection Act (TIPA), Tenn. Code Ann. § 47-18-3201 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawTennessee Information Protection Act (TIPA)
CitationTenn. Code Ann. § 47-18-3201 et seq.
EffectiveJuly 1, 2025
The only state privacy law that provides an affirmative defense for maintaining a written program conforming to the NIST Privacy Framework.
Who enforces itAttorney General and Reporter
Applicability

Tennessee set the highest bar of any state that isn't Florida. TIPA applies only to a person that exceeds $25 million in annual revenue and either:

  • controls or processes the personal information of 175,000 or more Tennessee consumers; or
  • controls or processes the personal information of 25,000 or more Tennessee consumers and derives more than 50% of gross revenue from the sale of personal information.

Both conditions must be true. The 175,000 figure is the highest consumer threshold in the country. Almost no medical practice will meet this test.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Tennessee exempts HIPAA covered entities and business associates at the entity level, along with PHI and HIPAA de-identified data.

Between an entity-level exemption, a $25 million revenue floor, and a 175,000-consumer threshold, TIPA is realistically out of reach for practices. Which is why the most useful part of this page is not the law's obligations — it is the one idea Tennessee contributed that every practice can use.

Sensitive data

Sensitive data requires opt-in consent, covering data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and personal information collected from a known child.

Definition of “sale”

Narrow — monetary consideration only

Narrow definition — a sale requires monetary consideration. Tennessee joins Indiana, Iowa, Kentucky, Utah, and Virginia here. The separate targeted-advertising opt-out applies regardless.

Universal opt-out / GPC

No universal opt-out mechanism requirement.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and consequential profiling
  • Consent required before processing sensitive data
  • Appeal a denied request
  • All contingent on the controller meeting both the revenue and volume tests
Cure period

Tennessee provides a 60-day cure period after written notice from the Attorney General, with no sunset.

Penalties

Up to $7,500 per violation, and a court may award treble damages for a willful or knowing violation. Enforced by the Attorney General; TIPA expressly provides no private right of action.

Private right of action

No private right of action. TIPA states this expressly.

What it means for you

The parts that actually change how you operate

The NIST affirmative defense, and why it matters even if TIPA doesn't apply to you

TIPA contains a provision that exists nowhere else in American privacy law. A controller or processor may assert an affirmative defense to a claim under the Act if it creates, maintains, and complies with a written privacy program that reasonably conforms to the NIST Privacy Framework, or to a comparable framework — and updates that program to conform to subsequent revisions within two years of publication.

Every other state treats a good compliance program as a soft mitigating factor: something a regulator may consider when deciding what to do about you. Tennessee wrote it into the statute as a defense you can plead.

Here is why that is useful to a practice in a state that isn't Tennessee. TIPA is the clearest statutory statement anywhere of what regulators consider a defensible privacy posture, and it has three parts:

  1. The program is written. Not intended, not understood, written.
  2. You comply with it. A policy you violate is worse than no policy, because now the gap is documented.
  3. You update it as the standard evolves, on a defined schedule.

That is a good description of what your practice should be able to produce in any state, in front of any regulator, whether or not a statute promises you credit for it.

What actually governs a Tennessee practice website

Since TIPA does not reach you, the honest list:

  1. HIPAA and the federal tracking-technology analysis, strongest on authenticated pages and patient portals.
  2. Out-of-state visitors. One website, many states. If your traffic includes Colorado, Maryland, Texas, or California residents, their states' rules are the ones setting your configuration.
  3. Tennessee's data breach notification law, which applies without regard to TIPA's thresholds.
  4. The Tennessee Consumer Protection Act generally, under which a privacy notice that materially misdescribes what your website does is a potential deceptive-practice question independent of TIPA.

That last point is underappreciated. You do not need to be a covered controller under a privacy statute for “our website does not share your information with advertisers” to be a false statement in commerce.

The AG published guidance anyway

Before TIPA took effect, the Tennessee Attorney General's office issued tips and guidelines for businesses and consumers about the new law. Reading it costs nothing and tells you how the state frames its own statute — including how it thinks about the affirmative defense, which is the part of TIPA worth borrowing.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Tennessee

Up to $7,500 per violation, and a court may award treble damages for a willful or knowing violation. Enforced by the Attorney General; TIPA expressly provides no private right of action.

The arithmetic nobody puts in a proposal

Tennessee's numbers matter less than its structure. This is the one state where doing the work well is a documented legal defense rather than merely a mitigating factor — see below. In every other state, a good program helps you informally. In Tennessee it is written into the statute.

Writing the program and then not following it is worse than not writing one

The affirmative defense has a condition attached that practices skip: you must comply with the program you wrote. A privacy program that describes controls you do not actually operate is not a defense. It is a written admission that you knew what was required and did something else.

This is the most common failure we see in practice audits, in every state. The policy says non-essential cookies are blocked until consent. The site loads a Meta Pixel on page one. Both facts are documented, and only one of them is in your favor.

Do this

Your Tennessee action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm you are below TIPA's thresholds — it requires $25M revenue AND 175,000 Tennessee consumers, both.
  2. Confirm your HIPAA covered-entity status in writing regardless; it is your exemption in the states that do reach you.
  3. Write the privacy program. Tennessee's affirmative defense describes the standard worth meeting anywhere.
  4. Then actually operate it — a program you do not follow is evidence against you, not for you.
  5. Reconcile your privacy notice with what your site really does, to avoid a state consumer-protection problem independent of TIPA.
  6. Apply HIPAA's tracking analysis on authenticated pages and patient portals.
  7. Build your site to the strictest state in your traffic mix, not to Tennessee's.
  8. Review the Tennessee AG's published TIPA guidance; the enforcer has told you how it reads the law.

Questions

Tennessee privacy law FAQ

Does the Tennessee Information Protection Act apply to medical practices?

Almost never. TIPA requires both more than $25 million in annual revenue and either 175,000 Tennessee consumers or 25,000 consumers with over half of revenue from selling personal information. It also exempts HIPAA covered entities and business associates at the entity level.

What is TIPA's NIST affirmative defense?

TIPA lets a controller or processor assert an affirmative defense to a claim under the Act if it creates, maintains, and complies with a written privacy program that reasonably conforms to the NIST Privacy Framework or a comparable framework, and updates it to conform to subsequent revisions within two years. No other state privacy law provides this.

When did TIPA take effect?

July 1, 2025. It was signed in May 2023 with a long implementation runway.

Does Tennessee have a cure period?

Yes, 60 days after written notice from the Attorney General, with no sunset date.

What are TIPA's penalties?

Up to $7,500 per violation, with treble damages available for willful or knowing violations. TIPA expressly provides no private right of action.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Tennessee and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing