Does the Colorado Privacy Act Apply to a Denver Multispecialty Medical Group?
If you operate a multispecialty group practice in Denver, the Colorado Privacy Act (CPA) likely applies to some—but not all—of your data. Protected Health Information (PHI) under HIPAA is generally exempt, yet non-PHI personal data (such as marketing lists or website analytics) may fall under this State Privacy Regulation if CPA thresholds are met. The result: HIPAA Compliance remains essential, but the CPA can create additional duties for Patient Data Protection outside HIPAA.
Overview of the Colorado Privacy Act
The CPA is a statewide Healthcare Privacy Law that grants Colorado residents rights over their personal data and imposes duties on “controllers” and “processors.” It applies to organizations that conduct business in Colorado or target Colorado residents and that either: (1) control or process personal data of 100,000+ consumers in a calendar year, or (2) derive revenue or receive a discount from the sale of personal data and process 25,000+ consumers’ data in that year. Employees and B2B contacts are typically outside scope.
Key consumer rights and controller duties
- Rights: access, correction, deletion, and data portability; opt-out of targeted advertising, sale of personal data, and certain profiling.
- Consent: opt-in required for sensitive data (for example, precise geolocation, genetic/biometric identifiers, and in many contexts, health information when not PHI).
- Transparency: clear privacy notices describing categories, purposes, and how to exercise rights.
- Governance: data protection assessments for high-risk processing; reasonable security safeguards.
- Signals: honor a universal opt-out mechanism for targeted ads and sales as of July 1, 2024.
Timeline checkpoints
- Effective date: July 1, 2023.
- Universal opt-out mechanism: enforceable July 1, 2024.
- Right to cure: the automatic 60-day cure period ended January 1, 2025; remediation is now discretionary.
Definition of Multispecialty Medical Groups
Multispecialty Group Practices are integrated provider organizations that deliver care across several clinical specialties under one administrative and billing umbrella. They often include shared scheduling, centralized revenue cycle, and consolidated EHRs, and they routinely act as HIPAA covered entities (and sometimes business associates) when exchanging electronic health information.
Beyond PHI, these groups also handle non-clinical personal data: website analytics, patient education newsletter lists, event RSVPs, call-center recordings, visitor Wi‑Fi logs, and recruitment pipelines. That non-PHI is where the CPA most often enters the picture.
Interaction Between CPA and HIPAA
HIPAA Compliance is necessary but not sufficient
HIPAA governs PHI and imposes strict safeguards, but the CPA reaches personal data outside HIPAA’s PHI definition. The CPA does not create a full entity-level exemption for covered entities; instead, it largely exempts PHI itself. Practically, that means your clinical data flows remain under HIPAA, while your consumer-facing and marketing data may be subject to the CPA.
Scoping examples
- In scope for CPA: website cookies and trackers on appointment pages, newsletter sign-ups, call tracking for marketing campaigns, community event registrations.
- Out of scope for CPA (generally): PHI created or received in the course of care, payment, or operations, and de-identified data meeting HIPAA standards.
If the group processes 100,000+ Colorado consumers’ non-PHI personal data annually (or meets the 25,000/sale-of-data prong), the CPA applies to that non-PHI—even though the group already complies with HIPAA.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
CPA Exemptions for Healthcare
Data Privacy Exemptions most relevant to healthcare include:
- Protected Health Information under HIPAA, and HIPAA de-identified data.
- Information governed by human-subjects research rules (for example, research conducted under federal Common Rule oversight).
- Employment records about your workforce in an employment context.
- Publicly available information and truly de-identified or pseudonymous data as defined by the CPA.
Remember: these are generally data-level exemptions. Non-PHI personal data you handle—for instance, prospects who download a wellness guide—can remain subject to the CPA.
Compliance Requirements for Denver Medical Groups
1) Determine applicability and scope
- Quantify consumer counts for non-PHI data to evaluate the 100,000 and 25,000/sale thresholds.
- Inventory data systems to separate PHI from other personal data streams.
2) Update transparency
- Publish a CPA-compliant privacy notice covering categories, purposes, sharing, retention, and how to exercise rights.
- Disclose targeted advertising, profiling, and sale (if any), and provide opt-out methods, including universal opt-out signals.
3) Enable consumer rights
- Stand up intake and verification for access, correction, deletion, and portability requests.
- Respond within statutory timelines; document decisions and exceptions (for example, patient safety or security).
4) Manage sensitive data and consent
- Obtain opt-in consent before processing sensitive personal data that is not PHI.
- Avoid dark patterns; keep consent specific, informed, and revocable.
5) Data protection assessments (DPAs)
- Complete DPAs for high-risk processing like targeted advertising, sale of data, profiling with legal effects, or sensitive data.
- Record risk mitigations and revisit assessments upon material changes.
6) Vendor and processor management
- Execute CPA-required contracts with processors, distinct from HIPAA business associate agreements when the work involves non-PHI.
- Flow down security, subprocessor, and deletion obligations; monitor compliance.
7) Security, retention, and training
- Apply reasonable safeguards to non-PHI personal data; align technical controls with those used for PHI where feasible.
- Document retention schedules; delete or de-identify when no longer necessary.
- Train staff on differences between HIPAA and CPA obligations.
Impact of CPA on Patient Data Handling
The biggest impact is operational separation. You should clearly segment PHI systems (EHR, patient portals) from consumer-data systems (web analytics, CRM). Configure technology so that PHI does not leak into marketing or ad-tech pipelines. For example, avoid sending visit details, diagnosis pages, or appointment confirmations to third-party trackers unless a compliant basis exists and the data remains outside PHI scope.
Consent also matters. When you process sensitive non-PHI—such as precise location for clinic wayfinding apps—you need explicit opt-in. And because the CPA requires honoring a universal opt-out signal for targeted advertising and sales, your web stack must detect and respect those signals automatically.
Best Practices for Privacy Management in Medical Settings
- Build a unified data map distinguishing PHI, HIPAA de-identified data, and CPA-covered personal data.
- Default to data minimization for all Multispecialty Group Practices; collect only what you need, keep it only as long as necessary.
- Adopt privacy-by-design for new digital tools (online scheduling, telehealth add-ons, check-in kiosks).
- Use contractual and technical controls to keep third-party tools from combining your users’ data for cross-context behavioral advertising.
- Run tabletop exercises for consumer rights requests and opt-out signal handling.
- Align breach and incident playbooks across HIPAA and State Privacy Regulations to avoid gaps.
Conclusion
So, does the Colorado Privacy Act apply to a Denver multispecialty medical group? Often yes—at least for non-PHI personal data—if the CPA thresholds are met. Treat HIPAA as your foundation for clinical data, and layer CPA controls for marketing and other non-PHI contexts. With clear scoping, sensible governance, and well-tuned technology, you can meet both regimes and strengthen overall Patient Data Protection.
FAQs.
What types of data are exempt under the Colorado Privacy Act?
Key exemptions include Protected Health Information under HIPAA, HIPAA de-identified data, information processed under human-subjects research protocols, employment records in an employment context, publicly available information, and de-identified or pseudonymous data as defined by the CPA. These are largely data-level exemptions rather than blanket entity exemptions.
How does HIPAA affect the applicability of the CPA?
HIPAA removes PHI from the CPA’s scope, but it does not exempt the entire healthcare organization. A Denver medical group must still evaluate non-PHI data—such as website analytics, marketing programs, or event sign-ups—against CPA requirements, including transparency, opt-outs, consent for sensitive data, and data protection assessments.
Are Denver multispecialty groups required to comply with both HIPAA and CPA?
Yes, in many cases. You will comply with HIPAA for PHI, and you will comply with the CPA for personal data that is not PHI if you meet the CPA’s applicability thresholds. Think of HIPAA and the CPA as complementary: HIPAA for clinical data; CPA for broader consumer privacy rights and controls.
What are the penalties for non-compliance with the CPA in healthcare?
Enforcement is led by the Colorado Attorney General and district attorneys. There is no private right of action. Remedies can include civil penalties assessed per violation, injunctive relief, and mandated remediation. The automatic 60‑day cure period ended on January 1, 2025, so prompt compliance and documented good-faith efforts are critical to mitigate enforcement risk.
Table of Contents
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.