Connecticut Data Privacy Act (CTDPA): Covered‑Entity Carve‑Outs for Patient Portals Explained

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Connecticut Data Privacy Act (CTDPA): Covered‑Entity Carve‑Outs for Patient Portals Explained

Kevin Henry

Data Privacy

September 01, 2026

5 minutes read
Share this article
Connecticut Data Privacy Act (CTDPA): Covered‑Entity Carve‑Outs for Patient Portals Explained

Connecticut’s CTDPA draws a bright line between HIPAA‑regulated patient portals and consumer apps that handle health information. If your portal is run by a HIPAA covered entity or its business associate, most CTDPA duties do not apply, and HIPAA remains your primary compliance regime. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

CTDPA Exemptions for Covered Entities

The statute exempts “covered entities” and “business associates” (as those terms are defined in 45 C.F.R. § 160.103) from CTDPA obligations. Practically, hospital and group‑practice patient portals fall under this Covered Entity Exemption, so CTDPA rights and duties generally do not attach to portal activity that is part of treatment, payment, or health care operations. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

CTDPA also excludes protected health information (PHI) and several research and patient‑safety categories from its scope. These data‑level exclusions further insulate HIPAA‑regulated portal content from CTDPA. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

HIPAA and Business Associate Exemptions

Patient portals commonly involve EHR vendors or other service providers acting as HIPAA business associates. Those business associates are likewise exempt under CTDPA when operating in that role for the covered entity. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

However, if a vendor that is merely a processor begins deciding the “purposes and means” of processing, it becomes a controller for that processing and can lose the protection of the business‑associate exemption for those activities. This is a key boundary for portal analytics, advertising, and secondary use. ([portal.ct.gov](https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act?utm_source=openai))

HIPAA still governs portal design and tracking technologies. HHS guidance treats data collected on user‑authenticated portal pages—even login or registration information—as PHI subject to HIPAA rules. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?utm_source=openai))

Consumer Health Data Controller Obligations

Entities that determine purposes and means for “consumer health data” but are not covered by HIPAA—think direct‑to‑consumer health apps—are Consumer Health Data Controllers under CTDPA. These obligations apply regardless of entity size. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

  • Access limits and confidentiality: You may not grant employees or contractors access to consumer health data unless they are bound by a statutory or contractual duty of confidentiality. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))
  • Processor contracts: You may not give processors access to such data without a compliant data processing agreement. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))
  • Clear disclosures and consumer rights: Controllers must provide meaningful privacy disclosures and honor CTDPA access and deletion rights. ([portal.ct.gov](https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act/?utm_source=openai))

Restrictions on Data Processing and Access

Beyond the CHD‑specific rules, CTDPA imposes baseline Data Processing Restrictions on controllers: limit collection to what is reasonably necessary; maintain reasonable security; obtain consent for sensitive data; and provide easy consent revocation. Additional protections apply to teens’ data for targeted ads and sale. ([cga.ct.gov](https://www.cga.ct.gov/2026/sup/chap_743jj.htm?utm_source=openai))

These duties do not apply to HIPAA covered entities or business associates when acting in that capacity, but they do bind non‑exempt Consumer Health Data Controllers offering health‑related portals or apps to Connecticut residents. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Prohibition on Sale of Consumer Health Data

CTDPA establishes a Data Sale Consent Requirement: you may not sell, or offer to sell, consumer health data without first obtaining the consumer’s consent. “Sale” broadly covers exchanges for monetary or other valuable consideration, subject to narrow exceptions. Obtain opt‑in consent with clear, conspicuous disclosures. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))

Geofencing Limitations in Health Contexts

CTDPA imposes a Geofencing Prohibition around mental health and reproductive or sexual health facilities. You may not use a geofence within 1,750 feet to identify, track, collect data from, or send notifications to consumers regarding their consumer health data. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))

Nonprofit Organization Exemptions

CTDPA’s general framework exempts nonprofits, but that Nonprofit Exemption Scope does not extend to Consumer Health Data obligations. Nonprofits that qualify as Consumer Health Data Controllers must still meet CHD rules unless they are separately exempt as HIPAA covered entities or business associates. ([cga.ct.gov](https://www.cga.ct.gov/2026/sup/chap_743jj.htm?utm_source=openai))

Bottom line: HIPAA‑regulated patient portals benefit from a clear carve‑out, while non‑HIPAA consumer‑facing portals and apps must implement CTDPA’s CHD safeguards, consent rules for sale, and the geofencing ban. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

FAQs

What entities are exempt under the CTDPA for patient portals?

HIPAA covered entities and their business associates are exempt from CTDPA, and PHI is excluded from CTDPA’s scope. Patient portals operated in those capacities generally fall outside CTDPA and remain governed by HIPAA. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

How does the CTDPA interact with HIPAA for covered entities?

CTDPA defers to HIPAA for covered entities and business associates. For example, HHS confirms that data collected on user‑authenticated portal pages—even logins—constitutes PHI governed by HIPAA’s Privacy and Security Rules. ([cga.ct.gov](https://www.cga.ct.gov/current/pub/chap_743jj.htm?utm_source=openai))

What restrictions apply to Consumer Health Data Controllers under the CTDPA?

They must bind staff to confidentiality, use processor contracts, honor disclosure and access rights, obtain opt‑in consent before any sale of consumer health data, and avoid prohibited geofencing near sensitive health facilities. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))

Are nonprofits fully exempt from CTDPA regulations?

No. While nonprofits are generally exempt from the CTDPA, they are not exempt from the law’s Consumer Health Data provisions and must comply if they act as Consumer Health Data Controllers, unless a separate exemption (e.g., HIPAA covered entity) applies. ([portal.ct.gov](https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act/?utm_source=openai))

What are the limitations on geofencing under the CTDPA?

A geofence may not be used within 1,750 feet of a mental health or a reproductive or sexual health facility to identify, track, collect data from, or send notifications to consumers regarding their consumer health data. ([cga.ct.gov](https://www.cga.ct.gov/2024/sup/chap_743jj.htm?utm_source=openai))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles