CCPA Risk Assessments in 2026: A Health Advertiser Guide
California now requires risk assessments before sharing data for ads or processing health data. What clinic and telehealth advertisers must document.
Since January 1, 2026, California's CCPA regulations require a documented risk assessment before a business shares personal information for cross-context behavioral advertising or processes sensitive personal information, which includes information collected and analyzed about a consumer's health. Clinics and telehealth brands running ad pixels can hit both triggers at once. Processing that was already running needs an assessment by December 31, 2027, and the first attestations are due to the California Privacy Protection Agency by April 1, 2028. Curve Compliance helps keep that assessment short by replacing browser pixels with server-side conversion tracking under a BAA on every plan.
Book a call. Curve Compliance sets up server-side conversion tracking with consent management for Meta, Google, TikTok, Microsoft and other ad platforms. Curve's team does the setup in about a week, and a BAA comes with every plan. Book a call with Curve.
This guide is general information, not legal advice.
What changed and when
The Agency's board adopted the regulations on July 24, 2025, and the Office of Administrative Law approved them on September 22, 2025, effective January 1, 2026. The package also covers cybersecurity audits and automated decisionmaking technology. This guide covers the risk-assessment rules and one opt-out display rule, quoted from the regulations text.
The two triggers ad tracking hits
Section 7150(b) lists processing that "presents significant risk to consumers' privacy." The first two items are:
- "Selling or sharing personal information."
- "Processing sensitive personal information."
In the CCPA statute, "sharing" means making personal information available to a third party "for cross-context behavioral advertising, whether or not for monetary or other valuable consideration." That covers retargeting pixels. "Sensitive personal information" includes "personal information collected and analyzed concerning a consumer's health." A Meta or Google pixel on a treatment page can touch both.
Does this apply to a HIPAA-covered clinic?
Partly. Civil Code section 1798.146 exempts protected health information collected by a covered entity or business associate. It also exempts a covered provider "to the extent the provider or covered entity maintains, uses, and discloses patient information in the same manner as" protected health information. Website and advertising data that is not handled as patient information, such as visitor data sent to ad platforms, is where the CCPA can still reach a clinic. The rules apply to businesses that meet at least one CCPA threshold: annual gross revenue above the inflation-adjusted limit; buying, selling or sharing the personal information of 100,000 or more consumers or households a year; or earning half or more of annual revenue from selling or sharing it.
What the assessment must document
Section 7152 requires a written risk assessment report covering:
- A specific purpose. Generic wording such as "to improve our services" is not allowed.
- The categories of personal information, including sensitive categories and "the minimum personal information that is necessary."
- How the data is collected, used, disclosed and retained, and where it comes from.
- How long each category is kept.
- How you interact with consumers, such as through your website.
- Roughly how many consumers are affected.
- What you have disclosed to consumers about the processing.
- The names or categories of the service providers, contractors and third parties who receive the data, and why. For ad tracking, that means every platform.
- The benefits, the negative impacts on privacy and their causes, and the safeguards you will use.
- Whether you will go ahead, who contributed, and who reviewed and approved it.
Section 7156 lets one assessment cover "a comparable set of processing activities," so similar ad platform setups can share one report.
Deadlines
- New processing: assess before you start (section 7155).
- Processing already running on January 1, 2026: assess by December 31, 2027.
- Reviews: at least every three years, and within 45 calendar days of a material change.
- Retention: for as long as the processing continues, or five years after the assessment, whichever is later.
- Submission: for assessments done in 2026 and 2027, a summary and an attestation under penalty of perjury, signed by a member of executive management, are due by April 1, 2028 (section 7157). The Agency or the Attorney General can demand full reports within 30 days.
Opt-out signals must be visible
Section 7025(c)(6) says a business "must display whether it has processed the consumer's opt-out preference signal as a valid request to opt-out of sale/sharing on its website," for example with the message "Opt-Out Request Honored." Your consent banner and your tracking have to agree, which our clinic consent banner guide covers.
How to keep the assessment short
The less your ad tracking shares, the less there is to assess and defend. In practice:
- take third-party pixels off treatment, condition and booking pages;
- send only the conversions you need, server-side, with neutral names;
- hash identifiers to each platform's requirements;
- limit the list of ad platforms that receive data;
- honor opt-out preference signals in every send.
Curve Compliance does this for Meta, Google, TikTok, Microsoft, Reddit, Amazon, ChatGPT Ads and others. It uses server-side conversion tracking in place of pixels, neutral event names, SHA-256 hashing, PHI-like pattern detection and consent management, and it keeps attribution through booking tools. Curve's team sets it up in about a week, with a BAA on every plan. For the wider California picture, see our California CMIA and CCPA guide and the state health privacy laws reference table.
Book a call. Bring your current pixel list, and Curve's team will show what your conversions look like sent server-side. Book a call with Curve.
Frequently Asked Questions
When do CCPA risk assessments start?
The rules took effect January 1, 2026. New covered processing needs an assessment before it starts, and processing already running on that date needs one by December 31, 2027.
Does running a Meta or Google pixel trigger a CCPA risk assessment?
It can. Sharing personal information for cross-context behavioral advertising is a listed trigger, and so is processing sensitive personal information such as health information.
Is health data sensitive personal information under the CCPA?
Yes. The statute includes "personal information collected and analyzed concerning a consumer's health."
Do HIPAA-covered clinics need CCPA risk assessments?
The CCPA exempts protected health information, and covered providers to the extent they handle patient information as HIPAA requires. Advertising and visitor data outside that, if the business meets a CCPA threshold, can still require an assessment.
What has to be submitted to the California Privacy Protection Agency?
For assessments done in 2026 and 2027, a summary and an attestation under penalty of perjury, signed by a member of executive management, by April 1, 2028. Full reports go to the Agency or the Attorney General within 30 days if requested.
Can one risk assessment cover several ad platforms?
Section 7156 allows a single assessment for a comparable set of processing activities that present similar risks.
Related articles
- GuideFertility Clinic Google Ads: Keyword Strategy for IVF, IUI, and Reproductive Endocrinology
- GuideCalifornia CMIA and CCPA: Healthcare Marketing Compliance for Golden State Practices
- GuideCurve Now Supports ChatGPT, Reddit, Amazon Ads, and Nextdoor
- GuideUrgent Care Facebook Ads: Meta Campaign Strategies for Walk-In Clinics and Multi-Location Groups
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit