Virginia · VCDPA

Virginia privacy law, explained for practice owners

The original template — and a 2025 health-data law with no threshold and a private right of action

VCDPA likely exempt — SB 754 is not In effect since January 1, 2023 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Virginia's comprehensive privacy law exempts HIPAA covered entities at the entity level, so the VCDPA probably does not reach your practice. Virginia's other health-privacy law is the one to read. SB 754, effective July 1, 2025, amended the Virginia Consumer Protection Act to prohibit obtaining, disclosing, selling, or disseminating personally identifiable reproductive or sexual health information without consent. Because it sits in the consumer protection statute rather than the privacy statute, it carries a private right of action, applies with no data-volume or revenue threshold, and does not inherit the VCDPA's entity-level exemptions.

In effect sinceJanuary 1, 2023
Applies at100k consumers
or 25k + 50% revenue
Max penaltyUp to $7,500
per violation
Cure period30 days
(no sunset)

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does VCDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, VCDPA does not apply to you at all — Virginia exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. 100k consumers or 25k + 50% revenue.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Virginia privacy law: the key facts

Virginia Consumer Data Protection Act (VCDPA), Va. Code § 59.1-575 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawVirginia Consumer Data Protection Act (VCDPA)
CitationVa. Code § 59.1-575 et seq.
EffectiveJanuary 1, 2023
The template most other states copied. Separately, SB 754 (effective July 1, 2025) added a private right of action for reproductive and sexual health information under the Virginia Consumer Protection Act — with no thresholds at all.
Who enforces itAttorney General (exclusive, for the VCDPA)
Applicability

Virginia wrote the template. The VCDPA applies to persons that conduct business in Virginia or produce products or services targeted to Virginia residents and, during a calendar year, either:

  • control or process the personal data of 100,000 or more Virginia consumers; or
  • control or process the personal data of 25,000 or more Virginia consumers and derive over 50% of gross revenue from the sale of personal data.

Note that Virginia's definition of “consumer” excludes individuals acting in a commercial or employment context, so B2B and employee data are outside the statute entirely.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Virginia exempts HIPAA covered entities and business associates at the entity level. It also exempts PHI, HIPAA de-identified data, patient safety work product, and information used for public health activities and human-subjects research.

A covered-entity practice is outside the VCDPA. But Virginia is the state where stopping there would be a genuine mistake, because in 2025 Virginia added something with no exemption and no threshold at all.

Sensitive data

Under the VCDPA, sensitive data requires opt-in consent, covering data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and personal data of a known child.

Separately, and more consequentially for many practices, SB 754 requires consent for reproductive or sexual health information with no threshold and a private right of action attached.

Definition of “sale”

Narrow — monetary consideration only

Narrow definition — a sale requires monetary consideration. Virginia originated this approach, later copied by Indiana, Iowa, Kentucky, Tennessee, and Utah. The separate targeted-advertising opt-out applies regardless of the sale definition.

Universal opt-out / GPC

No universal opt-out mechanism requirement in the VCDPA. A clear and conspicuous opt-out method is still required.

Consumer rights
  • Confirm processing and access
  • Correct inaccuracies
  • Delete
  • Portability
  • Opt out of sale, targeted advertising, and profiling in furtherance of significant decisions
  • Appeal a denied request, with escalation to the Attorney General
Cure period

Virginia provides a 30-day cure period with no expiration. The Attorney General must give written notice and thirty days before bringing an action.

Penalties

Up to $7,500 per violation, plus reasonable expenses including attorney fees, after the cure window closes. Penalties are deposited into Virginia's Consumer Privacy Fund.

Private right of action

The VCDPA has no private right of action. Virginia's newer health-data law does.

SB 754, effective July 1, 2025, amended the Virginia Consumer Protection Act — not the VCDPA — to prohibit obtaining, disclosing, selling, or disseminating personally identifiable reproductive or sexual health information without consent, in connection with a consumer transaction. Because it sits in the VCPA, it carries the VCPA's private right of action, and because it is not part of the VCDPA it is not subject to any data-volume or revenue threshold and does not inherit the VCDPA's entity-level exemptions.

Its definition of reproductive or sexual health information is drawn broadly, in the mould of Washington's My Health My Data Act. Its consent standard is the VCDPA's: a clear, affirmative, specific, informed, and unambiguous opt-in.

What it means for you

The parts that actually change how you operate

SB 754 is the Virginia law that should worry you

Everything about the VCDPA is comfortable for a medical practice: entity-level exemption, high threshold, monetary-only sale definition, permanent cure period, no private right of action. If Virginia had stopped in 2023, this page would be short.

In 2025 Virginia passed SB 754, and it did something structurally different. Instead of amending the privacy statute, it amended the Virginia Consumer Protection Act to prohibit obtaining, disclosing, selling, or disseminating personally identifiable reproductive or sexual health information without the consumer's consent, in connection with a consumer transaction.

Three consequences follow from that placement, and each one removes a protection practices rely on:

  • Private right of action. The VCPA has one. Individuals can sue. The VCDPA's regulator-only enforcement does not apply here.
  • No thresholds. SB 754 is not tied to consumer counts or revenue, because the VCPA is not. Being small does not help.
  • No entity-level exemption. The VCDPA's HIPAA carve-out is in the VCDPA. It does not travel to the VCPA.

The definition of reproductive or sexual health information is drawn broadly, following the Washington My Health My Data model, and the consent standard is a clear, affirmative, specific, informed, and unambiguous opt-in.

For practices in women's health, fertility, urology, sexual wellness, hormone therapy, gender-affirming care, and related areas, this is the single most consequential state law on this entire site — and it applies to a practice of any size.

How SB 754 interacts with your website

The prohibition covers obtaining and disclosing, not just selling. A third-party script that collects information about a visitor's interaction with a page concerning reproductive or sexual health is a plausible target for both verbs.

The mitigation is the one this whole site is about, and here it carries unusual weight because the consent standard is explicit and the plaintiff is an individual: no third-party tag runs on those pages until the visitor has given clear, affirmative, specific, informed, unambiguous consent — and you can produce the record showing it.

A consent record is not a formality under SB 754. It is the evidence of the affirmative defense.

The VCDPA itself, for the practices it does reach

If you are not a covered entity and you cross 100,000 Virginia consumers, the VCDPA is a standard Virginia-model obligation set: privacy notice with required content, opt-in consent for sensitive data, opt-outs for sale, targeted advertising, and consequential profiling, data protection assessments for higher-risk processing, processor contracts, and an appeals process with escalation to the Attorney General.

Virginia's exclusion of employee and B2B data from the “consumer” definition is a meaningful narrowing that California does not offer.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Virginia

Up to $7,500 per violation, plus reasonable expenses including attorney fees, after the cure window closes. Penalties are deposited into Virginia's Consumer Privacy Fund.

The arithmetic nobody puts in a proposal

The VCDPA's own exposure for a covered-entity practice is close to zero. The number worth modeling in Virginia is a class action under SB 754, where the plaintiff is an individual, there is no threshold to fall under, and no entity-level exemption applies. Read the next section.

The exemption you are relying on lives in the wrong statute

Practices in Virginia have spent three years learning, correctly, that the VCDPA exempts HIPAA covered entities. That knowledge produces the wrong answer for SB 754, because SB 754 is not in the VCDPA.

An exemption written into one statute does not extend to a different one. SB 754 sits in the Virginia Consumer Protection Act, which has its own scope, its own remedies, and a private right of action — and no data-volume threshold to fall under.

Do this

Your Virginia action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Read SB 754 with counsel if your practice touches reproductive, sexual, hormonal, fertility, urologic, or gender-affirming care. It has no threshold and a private right of action.
  2. Get clear, affirmative, specific, informed, unambiguous consent before any tag runs on pages concerning those services.
  3. Keep an append-only consent record — under SB 754 it is your evidence, not paperwork.
  4. Confirm your HIPAA covered-entity status in writing; it exempts you from the VCDPA but not from SB 754.
  5. If not exempt and above 100,000 Virginia consumers, run the standard VCDPA program: notice, consent, opt-outs, assessments, processor contracts, appeals.
  6. Provide a targeted-advertising opt-out regardless of Virginia's narrow “sale” definition.
  7. Keep the 30-day cure period usable by monitoring where legal notice arrives.
  8. Have counsel map which of your legal entities is subject to which statute — the answers differ.

Questions

Virginia privacy law FAQ

Are HIPAA covered entities exempt from the Virginia Consumer Data Protection Act?

Yes, at the entity level. Virginia exempts HIPAA covered entities and business associates from the VCDPA entirely, along with PHI, HIPAA de-identified data, and patient safety work product.

What is Virginia SB 754 and does it apply to my practice?

SB 754, effective July 1, 2025, amended the Virginia Consumer Protection Act to prohibit obtaining, disclosing, selling, or disseminating personally identifiable reproductive or sexual health information without consent in connection with a consumer transaction. Because it sits in the VCPA rather than the VCDPA, it carries a private right of action, has no data-volume or revenue threshold, and does not inherit the VCDPA's entity-level HIPAA exemption.

What are the VCDPA thresholds?

Controlling or processing the personal data of 100,000 or more Virginia consumers in a calendar year, or 25,000 or more while deriving over 50% of gross revenue from the sale of personal data. Virginia's “consumer” definition excludes people acting in a commercial or employment context.

Does Virginia have a cure period?

Yes, 30 days after written notice from the Attorney General, with no sunset date, for VCDPA violations.

Is a tracking pixel a “sale” in Virginia?

Generally no. Virginia defines a sale as requiring monetary consideration. The separate right to opt out of targeted advertising applies regardless, and SB 754's prohibition covers obtaining and disclosing, not only selling.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Virginia and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing