Jurisdiction Awareness
Consent that adapts to your visitor's state
HIPAA is the floor. On top of it, roughly twenty US states now have their own consumer privacy laws — each with its own opt-out expectations. Consential recognizes which state framework applies to each visitor and shows the matching consent notice, without you managing any of it.
Coverage
One map, one system, every state
States shaded in teal have their own consumer privacy law layered on top of HIPAA. Consential detects which one applies to each visitor and shows the right notice. Everywhere else, the same widget holds to your HIPAA baseline — non-essential tracking stays blocked until a visitor agrees.
The states with a comprehensive consumer privacy law today:
Each state links to a full breakdown — thresholds, whether the HIPAA exemption is entity-level or data-level, penalties, cure periods, and the official statute. Written for practice owners.
State privacy law is a moving target — new states pass laws and existing ones take effect on a rolling basis. Consential's coverage list is maintained centrally, so a practice never has to track it. Click any state to read its full breakdown.
Your jurisdiction
What your state requires — and what your neighbors do
A comprehensive privacy law applies where your practice does business. The eavesdropping statutes behind the current wave of tracking-pixel suits do not — they follow the visitor. Every state you border is a state your paid media already reaches.
Choose your state above on the map to read its full breakdown, or browse the twenty state guides listed there.
How it works
Detected, shown, and recorded — automatically
Four steps, none of which your front desk ever touches.
Detected server-side
Consential resolves the visitor's US state from the connection itself — never from anything the browser claims. A visitor can't spoof their jurisdiction to weaken the record.
The right notice
A visitor in a state with a specific requirement sees the notice that matches it — a California visitor, for example, sees the "Do Not Sell or Share" choice. Everyone else sees the standard banner.
Recorded on the trail
The detected jurisdiction is written onto the same append-only consent event as every other choice, so a later review shows which framework applied to each visitor.
Deny-by-default
Non-essential tracking stays blocked until a visitor agrees, in every state, regardless of detection. A missed or unknown state can only add a notice — never quietly reduce protection.
Example
What a California visitor sees
California's CCPA/CPRA is the most recognized state law, with its statutory "Do Not Sell or Share My Personal Information" opt-out. When Consential detects a California visitor, that choice appears in the banner automatically — wired to deny all non-essential tracking. A visitor in a state without that requirement sees the standard banner instead.
Consent banner · California
Your Privacy Choices
We use cookies and similar technologies to run this site and, only with your permission, for analytics and marketing.
California residents may opt out of the sale or sharing of personal information. Do Not Sell or Share My Personal Information
Honest about the legal layer
Consential builds and operates the detection — the engine that reads the state and applies the right notice. The specific legal wording for each state is reviewed by healthcare counsel before it goes live for your practice, the same way our own policy documents are. Consential is compliance infrastructure; it is not a law firm, does not provide legal advice, and using it does not by itself guarantee compliance with any state or federal regulation. We pair the tooling with your counsel, not in place of it.
The guides
Twenty states, written out for practice owners
These are the states with a comprehensive consumer privacy law on the books. Each guide covers whether it reaches your practice, what the HIPAA carve-out does and does not exempt, what enforcement has actually cost, and what to do about your website. The other thirty-one states have no comprehensive law — your HIPAA baseline and the deny-by-default gate still apply there, and so do that state’s eavesdropping statutes, which follow the visitor rather than the practice.
- CaliforniaCCPA/CPRA · in effect January 1, 2020
- ColoradoCPA · in effect July 1, 2023
- ConnecticutCTDPA · in effect July 1, 2023
- DelawareDPDPA · in effect January 1, 2025
- FloridaFDBR · in effect July 1, 2024
- IndianaINCDPA · in effect January 1, 2026
- IowaICDPA · in effect January 1, 2025
- KentuckyKCDPA · in effect January 1, 2026
- MarylandMODPA · in effect October 1, 2025
- MinnesotaMCDPA · in effect July 31, 2025
- MontanaMCDPA · in effect October 1, 2024
- NebraskaNDPA · in effect January 1, 2025
- New HampshireNHDPA · in effect January 1, 2025
- New JerseyNJDPA · in effect January 15, 2025
- OregonOCPA · in effect July 1, 2024
- Rhode IslandRIDTPPA · in effect January 1, 2026
- TennesseeTIPA · in effect July 1, 2025
- TexasTDPSA · in effect July 1, 2024
- UtahUCPA · in effect December 31, 2023
- VirginiaVCDPA · in effect January 1, 2023
See it on your site
State detection is part of the same widget that already gates your tracking scripts — there's nothing extra to install. We'll show you what fires on your site today, and what a state-aware consent layer changes.
Scan Your Site Free