Skip to main content
Guide

State Privacy Law Bingo: Mapping 14 New Healthcare Marketing Restrictions in 2026

In February 2026, California's privacy regulator broke its own record with a $2.75 million settlement against a streaming company for opt-out failures, capping a year in which [1]Indiana, Kentucky,...

12 min read

In February 2026, California's privacy regulator broke its own record with a $2.75 million settlement against a streaming company for opt-out failures, capping a year in which [1]Indiana, Kentucky, and Rhode Island joined the ranks of states with effective comprehensive consumer privacy laws, bringing the total to 19. The state privacy laws 2026 healthcare marketers must navigate now span nearly half the country, and the federal government's retreat from HIPAA enforcement has accelerated state action rather than slowed it down.

This guide maps 14 distinct state healthcare marketing restrictions taking effect or intensifying in 2026, from Indiana's new opt-in sensitive data rules to Washington's geofencing ban with private right of action. You'll learn which states triggered enforcement first, what your real exposure looks like, and how to bring tracking infrastructure into compliance before a class action or AG investigation does it for you.

The Current Enforcement Landscape for State Privacy Laws 2026 Healthcare Marketers

As of January 1, 2026, [2]Indiana, Kentucky, and Rhode Island all activated comprehensive consumer privacy laws, each with penalties up to $7,500 per violation in Indiana and Kentucky and $10,000 per violation in Rhode Island. Add narrower consumer health data laws in Washington, Nevada, and Connecticut, plus reproductive health amendments in Virginia and California's geofencing rule near family planning centers, and the patchwork now imposes 14+ distinct healthcare marketing restrictions overlapping in unpredictable ways.

OCR Enforcement Trends

The Office for Civil Rights has continued to focus on browser-based tracking even after losing key portions of its tracking bulletin in court. [3]OCR's bulletin reminds regulated entities that they may only disclose PHI as expressly permitted or required by the HIPAA Privacy Rule, and that the agency is prioritizing compliance with the HIPAA Security Rule in investigations into online tracking technologies.

The legal landscape became more complicated in 2024, when [3]a federal court vacated OCR guidance to the extent it provided that HIPAA obligations were triggered when an online technology connects an individual's IP address with a visit to an unauthenticated public webpage addressing specific health conditions or healthcare providers. Other portions of the guidance, including obligations tied to authenticated patient portals and the requirement that [4]covered entities may only disclose health information to digital tracking vendors who first sign a business associate agreement, remain enforceable.

FTC Involvement

The FTC has filled gaps the court left in HIPAA enforcement. [5]In its first-ever Health Breach Notification Rule action, the FTC required GoodRx to pay a $1.5 million civil penalty for failing to notify consumers of unauthorized disclosures of personal health information to Facebook, Google, and other companies. One month later, the agency announced a $7.8 million settlement and consent order against BetterHelp for sharing customers' mental health data with third parties for advertising purposes. Both cases established that the FTC will pursue digital health companies regardless of HIPAA applicability. For multi-jurisdiction analysis, see our guide on managing compliance across overlapping state privacy laws.

Class-Action and State-Level Actions

State health privacy laws have unlocked private litigation in ways HIPAA never permitted. [6]Washington's My Health My Data Act applies to any entity that conducts business in Washington or produces products targeted at Washington consumers, and the law provides consumers with a private right of action under the state Consumer Protection Act. [1]Nine states with existing comprehensive privacy laws amended their statutes in 2025 to add new provisions, signaling that compliance review is not a one-time effort. Texas in particular has secured multi-billion-dollar privacy settlements under the Texas Data Privacy and Security Act, signaling aggressive AG enforcement that healthcare marketers should expect to face.

Specific Risks and Consequences Under State Privacy Laws 2026 Healthcare Enforcement

Financial Penalties

Penalty exposure now stacks across multiple regimes for a single tracking misconfiguration:

  • Indiana and Kentucky: [2]Up to $7,500 per violation, enforced by each state's Attorney General, with a 30-day cure period.
  • Rhode Island: Up to $10,000 per violation with no cure period.
  • Washington MHMDA: [6]Enforcement under the state Consumer Protection Act, plus a private right of action available to consumers.
  • Virginia VCDPA reproductive-health amendments: [7]Penalties for willful violations of reproductive and sexual health information rules, plus a private right of action.
  • FTC Health Breach Notification Rule: [5]Civil penalties with consumer redress, as in the $1.5 million GoodRx and $7.8 million BetterHelp actions.

Reputational Damage

OCR's public breach portal lists incidents affecting 500 or more individuals, and a single tracking pixel transmitting appointment data can require notifications to tens of thousands of patients at once. [5]The GoodRx order also included a permanent ban on sharing user health data with third parties for advertising, generating sustained press coverage that any healthcare brand would consider catastrophic.

Operational Disruption and Personal Liability

FTC consent decrees consistently impose long-tail obligations beyond the headline fine. [5]GoodRx was required to direct third parties to delete consumer health data, implement a comprehensive privacy program, and adhere to limits on use and retention. Similar 10- and 20-year monitoring regimes are common, diverting compliance resources for the better part of a decade. The FTC's enforcement record also signals direct scrutiny of marketing decision-making: boards that fail to govern marketing data practices increasingly face direct exposure under consent decrees that name officers.

How Violations Happen

Technical Configurations

Most violations originate in default tracking settings that marketers never inspected. [4]OCR's guidance reminds regulated entities that they may only disclose health information to digital tracking vendors who first sign a business associate agreement, and that cookies, pixels, and similar technologies on patient-facing pages can create impermissible disclosures.

Vendor Relationships

Washington MHMDA's structure makes vendors directly liable. [6]The Act applies broadly to any entity that conducts business in Washington or produces products or services targeted at Washington consumers, sweeping in marketing vendors who never previously considered themselves "healthcare" companies.

Staff Actions and Audit Triggers

[4]In July 2023, OCR and the FTC sent warning letters to 130 hospitals that use third-party tracking technology, and since that time numerous class action suits have been filed against providers alleging damages from tracking technologies. Each breach notification becomes a discovery document for plaintiffs' counsel. Marketing staff often interpret "we hashed the email" as compliant when the receiving platform can re-identify the user, a pattern central to the BetterHelp matter.

The 14 New 2026 Healthcare Marketing Restrictions to Map

Use this as your bingo card. Each row represents a distinct compliance obligation triggered by healthcare-adjacent marketing activity:

  1. Indiana Consumer Data Protection Act (Jan 1, 2026): [2]Opt-in consent required for sensitive data including mental or physical health condition; 30-day cure; $7,500 per violation.
  2. Kentucky Consumer Data Protection Act (Jan 1, 2026): Opt-in for sensitive data; HIPAA entity-level exemption; 30-day cure; $7,500 per violation enforced by the AG.
  3. Rhode Island Data Transparency and Privacy Protection Act (Jan 1, 2026): [1]Low applicability thresholds and a requirement to disclose specific third parties with whom personal data is shared, plus $10,000 per-violation penalties with no cure period.
  4. California AB 45 (Jan 1, 2026): Prohibits collection, use, sale, sharing, or retention of personal data from individuals at or near a family planning center, and bans geofencing around in-person healthcare facilities to track, collect data, send notifications, or advertise.
  5. California SB 361 data broker expansion (2026): Detailed disclosures including whether data is sold to generative AI developers, processed through the California Privacy Protection Agency's accessible deletion mechanism.
  6. California ADMT and risk-assessment regulations: 2026 effective dates for automated decision-making technology regulations, cybersecurity audit requirements, and risk assessment obligations create substantive operational requirements, not reporting formalities.
  7. Virginia VCDPA reproductive-health amendments: [7]Explicit consent required before collecting, disclosing, selling, or disseminating reproductive or sexual health information, with a private right of action plus AG penalties for willful violations.
  8. Washington MHMDA geofencing ban: Prohibits geofencing within a virtual boundary of any physical location providing in-person healthcare services for tracking, data collection, or related ads.
  9. Washington MHMDA inferred-data rule: [6]Consumer health data includes information derived or extrapolated from non-health data when used to associate or identify a consumer with health status.
  10. Connecticut CTDPA health-data amendments: "Consumer health data" added to sensitive data, with new prohibitions on geofence advertising and consent requirements for selling consumer health data aligned with MHMDA.
  11. Nevada Consumer Health Data Privacy Law: [7]Mirrors many MHMDA requirements (notice, consent, geofencing limits) but without a private right of action.
  12. Maryland Online Data Privacy Act: More stringent than peer laws, with data minimization at collection.
  13. Texas Data Privacy and Security Act enforcement intensification: The Texas AG has pursued major settlements alleging that embedded SDKs collected and sold sensitive data without proper notices or opt-outs, signaling aggressive enforcement that healthcare marketers should expect to face. For state-specific deep dives, see our Minnesota Consumer Data Privacy Act analysis.
  14. Nebraska Data Privacy Act and pediatric design code: New obligations apply when an online service has actual knowledge data is from a minor, creating new pediatric and adolescent healthcare marketing requirements.

Protection Strategies for State Privacy Laws 2026 Healthcare Marketing

Immediate Actions (This Week)

  1. Audit current tracking implementations across every patient-facing page, including unauthenticated marketing pages with condition information, appointment schedulers, symptom checkers, and patient portals.
  2. Review vendor BAA status for every analytics, advertising, and form-handling tool. [6]MHMDA reaches out-of-state processors, so contracts must reflect that allocation.
  3. Check for PHI in marketing data exports, including hashed identifiers that recipients can reverse.
  4. Document the current state so any subsequent change is provably an improvement, not an admission.

Short-Term Fixes (This Month)

  1. Remove or reconfigure tracking on pages where intent to seek care can be inferred, including condition pages, scheduling flows, and provider search.
  2. Implement server-side tracking with PHI stripping before any data reaches an advertising endpoint.
  3. Update privacy policies and publish the separate consumer health data privacy policy that MHMDA requires.
  4. Train marketing staff on the differing state-by-state definitions of consent, which generally require a clear affirmative act that cannot be obtained through a general terms-of-use acceptance.

Long-Term Compliance Infrastructure

Build a compliance technology stack that treats tracking as a regulated workflow rather than a marketing utility. [1]Because nine states amended their privacy laws in 2025 alone, compliance is an ongoing operational function, not a one-time legal exercise. That means recurring data protection impact assessments, signed BAAs with every processor, documented audit trails for every consent and opt-out request, and configuration drift monitoring on tags and pixels.

Vendor Evaluation Criteria

  • BAA availability and terms: Will the vendor sign? Will the BAA cover marketing-data flows specifically?
  • Technical compliance capabilities: Does the platform strip PHI server-side before transmission to ad networks?
  • Audit and SOC 2 certifications: Independent attestation of controls.
  • Healthcare-specific experience: General-purpose tag managers do not understand Facebook's healthcare ad policies or platform-specific restrictions.

How Curve Addresses Each Risk

Curve was built specifically for the dual-regulator, multi-state environment that healthcare marketers face under state privacy laws 2026 healthcare regimes. Each risk category mapped above has a corresponding Curve control:

  • Automated PHI stripping: Server-side filtering removes protected health information before any payload reaches Meta, Google, TikTok, or other ad endpoints, addressing the technical configuration risk that drove the GoodRx and BetterHelp settlements.
  • Signed BAAs included: Curve operates as a business associate by default, closing the vendor gap that MHMDA and state comprehensive laws now use to assign processor liability.
  • Audit trails: Every consent, opt-out, and data transmission is logged for the documentation that 30-day cure periods and FTC consent decrees demand.
  • Healthcare-specific design: Rules account for the inferred-data exposure under Washington's MHMDA and California's family planning rule, where ordinary location and behavior data become regulated health data by inference.
  • Rapid implementation: Most healthcare advertisers complete a Curve deployment within days, compressing the time during which non-compliant tags continue to fire and accumulate per-violation exposure.

Curve works alongside your existing CRM, EHR, and ad platforms. Practices running testosterone therapy campaigns on Google Ads or healthcare campaigns on TikTok use Curve to convert sensitive intent signals into compliant conversion events.

Don't Wait for Enforcement

Every day without compliant tracking is a day of risk exposure across 19 state privacy regimes, two federal regulators, and an active plaintiffs' bar. Schedule a Compliance Assessment with Curve to map your current exposure against the 14 restrictions above and close the gaps before an AG, the FTC, or a class-action filing forces you to.

Compliance Self-Assessment Checklist

  • We have inventoried every tracking pixel, tag, cookie, and SDK across patient-facing properties.
  • We have a signed BAA with every vendor that touches marketing or analytics data.
  • Our consent mechanism meets the MHMDA standard (clear, affirmative, specific, opt-in, not bundled in terms of use).
  • We have separately published a consumer health data privacy policy linked from the homepage where state law requires.
  • We do not geofence around healthcare facilities for ad delivery or data collection.
  • We do not collect, use, sell, share, or retain data from individuals at or near California family planning centers.
  • We have opt-in consent for processing sensitive data in Indiana, Kentucky, Rhode Island, Virginia, Connecticut, and other applicable states.
  • Hashed identifiers (emails, phone numbers) are not transmitted to ad platforms that can re-identify users.
  • We have documented data protection impact assessments for targeted advertising and profiling activities.
  • We can respond to access, deletion, and opt-out requests within statutory windows (often 45 days).
  • Our marketing staff has been trained on state-by-state consent and sensitive-data definitions.
  • We have an audit trail demonstrating compliance at any point in time.

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

HIPAA civil penalties scale by culpability tier and can reach into the millions per category per year. [2]State laws stack on top: up to $7,500 per violation in Indiana and Kentucky and $10,000 per violation in Rhode Island, plus FTC enforcement that has produced fines like the $1.5 million GoodRx and $7.8 million BetterHelp settlements.

Can healthcare practices be sued for using Meta Pixel?

Yes. [6]Washington's MHMDA grants consumers a private right of action under the state Consumer Protection Act, and Meta Pixel implementations on hospital websites have been a recurring target of class action litigation following OCR and FTC warning letters.

How do I know if my healthcare marketing is compliant?

Start with a tag audit on every patient-facing page. [6]Then check whether any of your data flows could be used to infer a consumer's health status from purchases or behavior, because MHMDA explicitly captures information derived or extrapolated from non-health data when used to associate a consumer with health status. For therapy practices specifically, see our piece on balancing privacy and patient acquisition.

What should I do if I discover a compliance violation?

Document the issue, remove or reconfigure the offending tracker immediately, and consult counsel about notification obligations. [3]OCR's guidance instructs regulated entities to provide breach notification of impermissible disclosures of PHI to tracking technology vendors when there is no Privacy Rule permission and no BAA, with a presumption of breach unless low probability of compromise can be demonstrated. In states with cure periods, prompt remediation can resolve AG enforcement before penalties attach.

Do HIPAA-covered entities need to worry about state consumer health laws?

Yes, partially. [2]Kentucky's KCDPA, for example, exempts organizations and data subject to HIPAA, but other state privacy laws 2026 healthcare marketers face (notably Washington's MHMDA) apply to data outside HIPAA's scope (such as marketing analytics, inferences from non-health data, and tracking on unauthenticated pages), which is precisely where most marketing-tech exposure lives.

Sources

  1. Smith Anderson, Data Privacy in 2026: State Enforcement Takes Center Stage
  2. Koley Jessen, New State Privacy Laws Effective January 1, 2026: Indiana, Kentucky, and Rhode Island
  3. HHS OCR, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
  4. Dentons, HHS-OCR Revises Its Guidance on Use of Online Tracking Technologies
  5. FTC Press Release, GoodRx Enforcement Action
  6. Washington Attorney General, Protecting Washingtonians' Personal Health Data and Privacy
  7. Jackson Lewis, States Move Forward with Privacy Protections to Close HIPAA Gaps

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit