Connecticut Data Privacy Act (CTDPA): Health Data Exemptions for Healthcare Providers Explained

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Connecticut Data Privacy Act (CTDPA): Health Data Exemptions for Healthcare Providers Explained

Kevin Henry

Data Privacy

July 28, 2026

7 minutes read
Share this article
Connecticut Data Privacy Act (CTDPA): Health Data Exemptions for Healthcare Providers Explained

CTDPA Overview

The Connecticut Data Privacy Act establishes consumer rights and controller duties for personal data processed about Connecticut residents. As of July 1, 2023, the law applies to businesses that meet one or more applicability triggers, including controlling or processing personal data of at least 35,000 consumers, processing sensitive data, or offering consumers’ personal data for sale. In addition, Consumer Health Data controllers are covered regardless of business size or revenue.

For healthcare organizations, the CTDPA intersects with existing federal regimes like HIPAA. Understanding where the CTDPA applies—and where it does not—is essential to tailoring your compliance program, allocating resources efficiently, and avoiding conflicts between overlapping rules.

HIPAA Covered Entities Exemption

HIPAA Covered Entities and Business Associates are generally exempt from the CTDPA’s main controller and processor obligations. Separately, the CTDPA’s consumer health data section (Conn. Gen. Stat. § 42-526) expressly states that its requirements do not apply to Covered Entities or Business Associates. This means the CTDPA’s consumer health data–specific duties (including certain Geofencing Restrictions and sale limitations) typically do not reach HIPAA-regulated providers and their Business Associates.

Keep in mind that exemptions flow from your legal status and the data you handle. Affiliates that are not themselves HIPAA Covered Entities or Business Associates may still be subject to CTDPA obligations. Likewise, data categories expressly exempted by statute (for example, Protected Health Information) fall outside the CTDPA, while other information that is not PHI may still be governed by different rules depending on the entity and context.

Consumer Health Data Definition

Under the CTDPA, Consumer Health Data is personal data that you use to identify a consumer’s physical or mental health condition, diagnosis, or status. The definition is intentionally broad and explicitly includes gender-affirming health data and reproductive or sexual health data. In practice, this can encompass information gathered outside traditional clinical workflows—such as health-related website interactions, symptom checkers, fertility tracking, or mental health screening tools—when those uses identify a consumer’s health condition or status.

The CTDPA treats Consumer Health Data as Sensitive Data. Controllers must obtain Sensitive Data Consent—an opt-in, clear, affirmative, freely given, specific, informed, and unambiguous agreement—before processing Sensitive Data. Consent cannot be bundled into broad terms or obtained through dark patterns, and you must provide an easy way for consumers to revoke consent. When consent is revoked, you must stop processing within the statutory timeframe.

Two additional rules matter for health-centric operations: (1) you may not process Sensitive Data about a known child except in accordance with COPPA; and (2) selling Consumer Health Data requires prior, explicit consumer consent.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Specific Exemptions Under CTDPA

The CTDPA contains targeted Data Privacy Exemptions that are particularly relevant to healthcare. These carve-outs reduce overlap with federal requirements and clinical quality and safety programs:

Protected Health Information and De-Identification

  • Protected Health Information under HIPAA is exempt.
  • Data derived from HIPAA-regulated sources that has been de-identified in accordance with HIPAA is exempt.
  • Limited Data Sets are exempt to the extent used and maintained as required by 45 C.F.R. § 164.514(e).

Substance Use Disorder Confidentiality

  • Patient-identifying information regulated by 42 U.S.C. § 290dd-2 (42 C.F.R. Part 2) is exempt.

Human Subjects Research Compliance

  • Identifiable private information processed for human subjects research under the Common Rule (45 C.F.R. Part 46) is exempt.
  • Information collected as part of ICH Good Clinical Practice–compliant research is exempt.
  • Certain FDA human-subjects protections (21 C.F.R. Parts 6, 50, and 56) and HIPAA-defined research uses are exempt when conducted in accordance with applicable standards.

Quality, Safety, and Public Health

  • Information and documents created for purposes of the Health Care Quality Improvement Act are exempt.
  • Patient safety work product under the Patient Safety and Quality Improvement Act is exempt.
  • Uses for authorized public health, community health, and population health activities are exempt.

Operational Intermingling

  • Information originating from and intermingled with exempt HIPAA/Part 2 information, or treated in the same manner by a Covered Entity or Business Associate, is exempt.

Restrictions on Geofencing

The CTDPA imposes Geofencing Restrictions around sensitive health locations. No person may use a geofence within 1,750 feet of any mental health facility or reproductive or sexual health facility to identify, track, collect data from, or send notifications to a consumer regarding that consumer’s Consumer Health Data. “Geofence” includes technologies that establish a virtual boundary using GPS, Wi‑Fi, RFID, cell towers, or similar location-detection methods.

Important scope note: the CTDPA’s consumer health data section, which houses these Geofencing Restrictions, does not apply to HIPAA Covered Entities or Business Associates. Non-HIPAA health apps, adtech partners, and other Consumer Health Data controllers should evaluate and, if necessary, remove geofencing activities in the restricted zones.

Applicability to Nonprofit and Other Entities

Nonprofit organizations are generally exempt from the CTDPA’s main framework. However, that exemption does not extend to the law’s Consumer Health Data provisions—nonprofits that act as Consumer Health Data controllers must comply with those requirements. Government bodies and certain other categories (e.g., higher education institutions, GLBA-regulated financial institutions, national securities associations, tribal nation government organizations, and air carriers) also receive tailored exemptions in the consumer health data section.

For nonprofit healthcare providers, one additional nuance applies: if you are also a HIPAA Covered Entity or Business Associate, the CTDPA’s consumer health data section (including Geofencing Restrictions and sale limitations) does not apply to you by statute, even though nonprofit entities generally must follow that section.

Conclusion

  • HIPAA Covered Entities and Business Associates are broadly outside the CTDPA, and the consumer health data section expressly excludes them.
  • Consumer Health Data is treated as Sensitive Data, requiring explicit opt-in consent to process and to sell.
  • Robust healthcare-focused exemptions shield PHI, de-identified data, Limited Data Sets, Human Subjects Research, HCQIA materials, PSQIA work product, and authorized public health uses.
  • Geofencing within 1,750 feet of mental health and reproductive/sexual health facilities is prohibited for most non-HIPAA actors handling Consumer Health Data.

FAQs

What healthcare providers are exempt from the CTDPA?

Entities subject to HIPAA—namely HIPAA Covered Entities and Business Associates—are generally exempt from the CTDPA’s main framework, and the law’s consumer health data section also does not apply to them. Providers that are not HIPAA-regulated (for example, some digital health apps) must assess CTDPA coverage, including consumer health data duties.

How does HIPAA impact CTDPA applicability?

HIPAA narrows CTDPA reach in two ways. First, Protected Health Information and certain related categories (de-identified data, Limited Data Sets used as required, and patient safety work product) are exempt. Second, HIPAA Covered Entities and Business Associates are excluded from the CTDPA’s consumer health data section, which otherwise imposes Sensitive Data Consent and Geofencing Restrictions on non-HIPAA actors.

What types of health data are exempt under the CTDPA?

Exempt categories include: PHI under HIPAA; patient-identifying information under 42 U.S.C. § 290dd‑2 (42 C.F.R. Part 2); identifiable private information processed for Human Subjects Research Compliance (Common Rule/ICH/FDA frameworks); information and documents created for the Health Care Quality Improvement Act; patient safety work product (PSQIA); HIPAA-compliant de-identified data; Limited Data Sets used under 45 C.F.R. § 164.514(e); certain public health, community health, and population health uses; and information intermingled with, or treated the same as, exempt data by a Covered Entity or Business Associate.

Are nonprofit organizations subject to the CTDPA?

Nonprofits are generally exempt from the CTDPA’s main regime, but the nonprofit exemption does not apply to the consumer health data section—nonprofit Consumer Health Data controllers must comply. If a nonprofit is also a HIPAA Covered Entity or Business Associate, the consumer health data section does not apply to that organization by statute.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles