Utah · UCPA

Utah privacy law, explained for practice owners

The lightest of the Virginia-model laws

Very unlikely to apply In effect since December 31, 2023 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Utah's privacy law almost certainly does not apply to your practice. It requires both $25 million in annual revenue and 100,000 Utah consumers, and it exempts HIPAA covered entities at the entity level on top of that. Utah is also the lightest-touch of the Virginia-model laws: sensitive data needs only notice and an opt-out rather than consent, there is no right to correct data, no profiling opt-out, no universal opt-out requirement, and a permanent 30-day cure period. If you want to know what actually governs a Utah practice website, the answer is HIPAA and the requirements of your out-of-state visitors' home states.

In effect sinceDecember 31, 2023
Applies at$25M revenue AND
100k consumers
Max penaltyActual damages +
up to $7,500
Cure period30 days

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does UCPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, UCPA does not apply to you at all — Utah exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. $25M revenue AND 100k consumers.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Utah privacy law: the key facts

Utah Consumer Privacy Act (UCPA), Utah Code § 13-61-101 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawUtah Consumer Privacy Act (UCPA)
CitationUtah Code § 13-61-101 et seq.
EffectiveDecember 31, 2023
The most business-friendly of the Virginia-model laws. Enforcement runs through the Division of Consumer Protection before it reaches the Attorney General.
Who enforces itDivision of Consumer Protection, referring to the Attorney General
Applicability

Utah requires both a revenue test and a volume test. The UCPA applies to a controller or processor that has annual revenue of $25 million or more and either:

  • controls or processes the personal data of 100,000 or more Utah consumers; or
  • derives over 50% of gross revenue from the sale of personal data and controls or processes the personal data of 25,000 or more Utah consumers.

Both prongs must be satisfied. A practice under $25 million in revenue is out of scope regardless of how much data it touches.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Utah exempts HIPAA covered entities and business associates at the entity level, along with PHI and HIPAA de-identified data. Combined with the dual revenue-and-volume threshold, the UCPA is very unlikely to reach a medical practice.

Sensitive data

Utah is the outlier here. Sensitive data does not require opt-in consent — the controller must instead present the consumer with clear notice and an opportunity to opt out. Only Iowa takes a comparably light approach. Every other state on this list requires consent first.

Definition of “sale”

Narrow — monetary consideration only

Narrow definition — a sale requires monetary consideration. Utah is the least demanding state on advertising data, and it is the only Virginia-model state that does not grant an opt-out of profiling.

Universal opt-out / GPC

No universal opt-out mechanism requirement.

Consumer rights
  • Confirm processing and access
  • Delete
  • Portability
  • Opt out of sale and targeted advertising
  • No right to correct inaccurate data
  • No right to opt out of profiling
  • No appeal process requirement
Cure period

Utah provides a 30-day cure period with no sunset. Utah's process is also distinctive: the Division of Consumer Protection investigates and refers matters to the Attorney General, adding a step before enforcement escalates.

Penalties

The Attorney General may recover actual damages to the consumer plus up to $7,500 for each violation, after the cure period closes without a fix.

Private right of action

No private right of action.

What it means for you

The parts that actually change how you operate

What Utah asks that other states don't, and the reverse

Utah deliberately built the most controller-friendly version of the Virginia template. The omissions are the substance:

  • No opt-in consent for sensitive data. Notice plus an opportunity to opt out is sufficient. In Colorado, Connecticut, Virginia, Texas, and thirteen others, health data requires consent first.
  • No right to correct.
  • No profiling opt-out. Utah is the only Virginia-model state that omitted it.
  • No universal opt-out mechanism requirement.
  • No consumer appeal process requirement.
  • Monetary-only sale definition, so advertising data flows generally are not sales.

Stack those against a dual threshold requiring both $25 million and 100,000 consumers, and Utah is the least likely of the twenty laws to generate an obligation for a practice.

Which is exactly why Utah is the wrong design target

A website built to Utah's requirements has no opt-in gate on sensitive data, ignores Global Privacy Control, offers no profiling opt-out, and has no correction or appeal path. That site is non-compliant in Colorado the moment a Denver resident loads it, and in Maryland the moment a Baltimore resident does.

Your website has one configuration. The correct target is not your own state's floor — it is the ceiling set by the strictest state your traffic includes. For most practices with any paid media spend, that is Maryland or California, not Utah.

What actually governs a Utah practice website

  1. HIPAA and the federal tracking-technology analysis, strongest on authenticated pages and portals.
  2. Out-of-state visitors and their states' rules.
  3. Utah's breach notification law, which applies regardless of UCPA thresholds.
  4. The Utah Consumer Sales Practices Act, under which a privacy notice that materially misstates what your website does is a potential deceptive-practice issue independent of the UCPA.

The fourth one is the sleeper. Not being a covered controller under the privacy statute does not make an inaccurate published statement about your data practices safe.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Utah

The Attorney General may recover actual damages to the consumer plus up to $7,500 for each violation, after the cure period closes without a fix.

The arithmetic nobody puts in a proposal

Utah is the gentlest enforcement environment among the twenty states: a high dual threshold, an entity-level healthcare exemption, a two-step investigative process, a permanent cure period, and no profiling or universal-opt-out obligations. If you are ranking where to spend compliance attention, Utah is last.

A lenient state is a dangerous baseline

The risk in Utah is not enforcement. It is architecture. A practice that reads this page, concludes correctly that the UCPA does not apply, and configures its website accordingly has built something that fails in a dozen other states — and the visitors from those states are arriving through the same ad campaigns you are paying for.

Do this

Your Utah action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm you are below the dual threshold: the UCPA needs $25M revenue AND 100,000 Utah consumers.
  2. Confirm your HIPAA covered-entity status in writing anyway; it is your exemption in states that do reach you.
  3. Do not use Utah's standard as your website's design target.
  4. Identify the strictest state in your traffic mix and build to that.
  5. Apply HIPAA's tracking analysis on authenticated pages and patient portals.
  6. Reconcile your privacy notice with your site's actual behavior, to avoid a state consumer-protection issue independent of the UCPA.
  7. Confirm your Utah breach notification procedure, which applies regardless of thresholds.
  8. Capture consent records regardless. They are what answers a HIPAA question, not just a state-law one.

Questions

Utah privacy law FAQ

Does the Utah Consumer Privacy Act apply to medical practices?

Very unlikely. The UCPA requires both $25 million or more in annual revenue and either 100,000 Utah consumers or 25,000 consumers with over half of revenue from data sales. It also exempts HIPAA covered entities and business associates at the entity level.

Does Utah require consent before processing sensitive data?

No. Utah requires clear notice and an opportunity to opt out, rather than opt-in consent. Only Iowa takes a comparably light approach; every other state with a comprehensive privacy law requires consent.

What rights does the UCPA not include?

Utah omits the right to correct inaccurate data, the right to opt out of profiling, a required consumer appeals process, and any universal opt-out mechanism obligation. It also uses the narrow monetary-only definition of “sale.”

Who enforces Utah's privacy law?

The Utah Division of Consumer Protection investigates and refers matters to the Attorney General. There is a permanent 30-day cure period and no private right of action.

What are the penalties under the UCPA?

The Attorney General may recover actual damages to the consumer plus up to $7,500 for each violation, after the 30-day cure period closes without a fix.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Utah and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing