Maryland Online Data Privacy Act for Health Advertisers
Maryland's MODPA bans selling health data and limits it to what is strictly necessary. What clinic and telehealth ad tracking should change.
Maryland's Online Data Privacy Act, in force since October 1, 2025, bans the sale of consumer health data outright. It allows health data to be collected, processed or shared only when strictly necessary to provide a product or service the consumer asked for, and it offers no consent route around either rule. For clinics and telehealth brands advertising to Maryland residents, the data that browser pixels send from service and booking pages deserves a hard look. Curve Compliance helps by replacing those pixels with server-side conversion tracking that sends neutral events, not health context, under a BAA on every plan.
Book a call. Curve Compliance sets up server-side conversion tracking with consent management for Meta, Google, TikTok, Microsoft and other ad platforms. Curve's team does the setup in about a week, and a BAA comes with every plan. Book a call with Curve.
This guide quotes the codified statute, Maryland Code, Commercial Law sections 14-4701 to 14-4714, and is general information, not legal advice.
Key dates
- May 9, 2024. The governor approves Senate Bill 541 as Chapter 455.
- October 1, 2025. The Act takes effect.
- April 1, 2026. According to the fiscal and policy note, certain controller and processor obligations do not apply to processing activities before this date.
- April 1, 2027. Until then, the Attorney General's Consumer Protection Division may issue a notice of violation with at least 60 days to cure before enforcing (section 14-4714).
Who it covers
The Act applies to a business that operates in Maryland or targets Maryland residents and, in the previous calendar year, handled the personal data of at least 35,000 consumers, not counting data used only to complete a payment. It also applies at 10,000 consumers if more than 20% of gross revenue came from selling personal data (section 14-4702).
For healthcare, the exemptions in section 14-4703 matter. The Act exempts "protected health information under HIPAA," and medical records held by a covered entity or business associate that applies HIPAA standards to them. It does not exempt a clinic as an organization. So data that is not PHI can still fall under the Act, including visitor and advertising data about people who are not yet patients.
The rules that matter for ad tracking
Consumer health data. "Personal data that a controller uses to identify a consumer's physical or mental health status," including data related to gender-affirming treatment or reproductive or sexual health care. It is one kind of "sensitive data," alongside precise geolocation and data about children (section 14-4701).
Strict necessity. A controller may not "collect, process, or share sensitive data concerning a consumer" except where that is "strictly necessary to provide or maintain a specific product or service requested by the consumer" (section 14-4707(a)(1)). Unlike most state privacy laws, there is no consent alternative.
No sale. A controller may not "sell sensitive data" (section 14-4707(a)(2)). A sale is an exchange of personal data with a third party "for monetary or other valuable consideration." Disclosures to a processor acting on your behalf are not a sale.
Minors. No targeted advertising to, and no sale of the data of, a consumer the controller knew or should have known is under 18.
Minimization. Collection of any personal data must be limited to what is "reasonably necessary and proportionate" to the product or service requested.
Opt-outs. Consumers can opt out of targeted advertising, sale and certain profiling, including through an authorized agent set by "a browser setting, browser extension, global device setting, or other similar technology" (sections 14-4705 and 14-4706).
Geofencing. No geofence within 1,750 feet of a mental health facility or a reproductive or sexual health facility to identify, track, collect data from or message consumers about their health data (section 14-4704).
Assessments. Targeted advertising, sale of personal data and processing of sensitive data each require a documented data protection assessment (section 14-4710).
Enforcement. A violation is an unfair, abusive or deceptive trade practice under the Maryland Consumer Protection Act, enforced by the Attorney General. The Act excludes the Consumer Protection Act's private damages provision, while leaving consumers any other remedy provided by law (section 14-4713).
What this means for pixels and conversions
A browser pixel on a page about a condition or service sends the page address and identifiers to the ad platform, which uses that data for its own purposes. That is the pattern where questions about sharing sensitive data, and about sales for "other valuable consideration," arise under Maryland law. Our state health privacy laws reference table sets Maryland beside Washington, Nevada, Connecticut and others, and our Washington My Health My Data Act guide covers the other strict regime.
Practical changes for Maryland traffic:
- Remove third-party pixels from condition, service, booking and intake pages.
- Send conversions server-side with neutral names, such as "Lead" or "Appointment Booked," and no condition, drug or service in any parameter.
- Honor opt-out preference signals and record opt-outs from targeted advertising.
- Stop radius targeting near mental health and reproductive or sexual health facilities.
- Put every vendor that processes data for you under a processor contract.
- Document a data protection assessment for your advertising and tracking.
How Curve Compliance helps
Curve replaces browser pixels with server-side conversion tracking for Meta, Google, TikTok, Microsoft, Reddit, Amazon, ChatGPT Ads and others. It sends neutral event names, hashes identifiers with SHA-256 to each platform's requirements and flags outgoing data that looks like PHI. Consent management honors visitors' choices, and attribution is kept through booking tools. Curve's team sets it up in about a week, with a BAA on every plan. Our guide on what to configure in a clinic consent banner covers the front end.
Book a call. Walk through your Maryland traffic, your pixels and your booking flow with Curve's team. Book a call with Curve.
Frequently Asked Questions
When did Maryland's Online Data Privacy Act take effect?
October 1, 2025. The fiscal and policy note says certain controller and processor obligations do not apply to processing activities before April 1, 2026, and a discretionary 60-day cure period runs for violations through April 1, 2027.
Does the Maryland Online Data Privacy Act apply to HIPAA-covered clinics?
It exempts protected health information and HIPAA-governed medical records, not the clinic as an organization. Personal data that is not PHI, such as advertising and visitor data about people who are not patients, can still be covered if the clinic meets the thresholds.
Can I get consent to share health data with Meta or Google under Maryland law?
The Act gives no consent route for sensitive data. Collection, processing and sharing are allowed only when strictly necessary to provide a product or service the consumer requested, and selling sensitive data is banned.
Is sending pixel data to an ad platform a sale under Maryland law?
It can be. A sale includes exchanges for "other valuable consideration," not only money, while disclosures to a processor acting for you are excluded. Ask counsel how your setup fits.
Is there a private right of action?
The Act is enforced by the Attorney General under the Maryland Consumer Protection Act and excludes that Act's private damages provision. It states that it does not prevent consumers from pursuing any other remedy provided by law.
What is Maryland's geofencing rule for health facilities?
No geofence within 1,750 feet of a mental health facility or a reproductive or sexual health facility to identify, track, collect data from or message consumers about their health data.
Related articles
- GuideFTC Health Privacy Actions: A Reference List
- GuideConnecticut Data Privacy Act for Healthcare Marketing: CT Provider Obligations in 2026
- GuideTherapy Practice Marketing: Balancing Privacy and Patient Acquisition
- GuideGoodRx to BetterHelp to Hims and Hers: The FTC's Health Privacy Enforcement Trajectory
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit