How the Colorado Privacy Act's Sensitive Data Rules Affect Telehealth Companies
Colorado Privacy Act Overview
The Colorado Privacy Act (CPA) applies to entities—including nonprofits—that do business in Colorado or target Colorado residents and meet specific thresholds. For telehealth organizations, that often means the CPA governs how you collect, use, share, and secure patient-facing data outside traditional medical records, alongside separate HIPAA obligations. The CPA establishes duties around transparency, data minimization, security, and honoring consumer rights. It also requires consent before certain Sensitive Data Processing and mandates Data Protection Assessments (DPAs) for high‑risk operations. ([coag.gov](https://coag.gov/resources/colorado-privacy-act/?utm_source=openai))
Telehealth companies typically handle information that triggers these heightened requirements. As you expand virtual care—video visits, remote patient monitoring, digital therapeutics, AI triage—you must inventory personal data, identify sensitive categories, and ensure compliant notices, controls, and records. When HIPAA governs a dataset (for example, protected health information processed by a covered entity or business associate), the CPA generally does not apply to that dataset; however, non‑PHI activities (such as website analytics or marketing) remain within CPA scope. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1304))
Sensitive Data Definition Under CPA
Under the CPA, “sensitive data” includes personal data revealing a mental or physical health condition or diagnosis; racial or ethnic origin; religious beliefs; sex life or sexual orientation; citizenship or citizenship status; genetic or biometric data processed for the purpose of uniquely identifying an individual; and personal data from a known child. These categories drive when consent is required and when a DPA is mandatory. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1303))
The definition was expanded in 2024 to cover “biological data” used for identification purposes, which explicitly includes “neural data” generated by measuring activity of the central or peripheral nervous system. In addition, Colorado’s rules clarify that sensitive‑data inferences (for example, an algorithm inferring a mental health condition from user behavior) are treated like sensitive data. ([leg.colorado.gov](https://www.leg.colorado.gov/bills/HB24-1058))
Telehealth Companies' Compliance Obligations
Telehealth controllers must implement a comprehensive program aligned to the CPA’s duties and the realities of virtual care. At a minimum, you should:
- Map data flows across apps, devices, call centers, EHR integrations, and ad/analytics tools, flagging Sensitive Data Processing and distinguishing HIPAA‑exempt PHI from CPA‑regulated non‑PHI. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1304))
- Publish clear notices explaining purposes, retention, consumer rights, and consent choices; minimize collection to what is adequate, relevant, and necessary for telehealth delivery. ([coag.gov](https://coag.gov/resources/colorado-privacy-act/?utm_source=openai))
- Operationalize Service Provider Compliance: execute processor agreements that bind vendors to your instructions, require confidentiality, enable audits, and mandate deletion or return of personal data at contract end. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1305?utm_source=openai))
- Be ready to honor opt‑outs and recognized universal opt‑out mechanisms for targeted advertising or sale across your web and mobile properties, if applicable to your operations. ([coag.gov](https://coag.gov/resources/colorado-privacy-act/?utm_source=openai))
Data Protection Assessments for Telehealth
You must complete a Data Protection Assessment before undertaking processing that presents a heightened risk of harm—including any processing of sensitive data, targeted advertising, certain profiling, or sale of personal data. DPAs apply to processing created or generated on or after July 1, 2023. Maintain each DPA and be prepared to provide it to the Colorado Attorney General upon request. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1309))
Effective DPAs for telehealth document: the processing purpose and context (for example, remote cardiac monitoring or mental‑health intake); categories and volumes of data; benefits to patients and the public; foreseeable risks (privacy, security, equity); and safeguards such as encryption, access controls, retention limits, de‑identification, and vendor oversight. Colorado’s rules also list specific DPA content elements you should address, including how you comply with consent requirements and data‑security duties. ([law.cornell.edu](https://www.law.cornell.edu/regulations/colorado/4-CCR-904-3-8.04?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Consumer Consent Requirements
Before processing sensitive data, you must obtain valid consent—a clear, affirmative act that is freely given, specific, informed, and unambiguous. Consent cannot be bundled in general terms of use, coerced through “take‑it‑or‑leave‑it” gating where unnecessary, or obtained via dark patterns. For known children’s data, you must obtain consent from a parent or lawful guardian. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1303))
Colorado’s rules reinforce these Consumer Consent Standards and address timing, refresh, and design integrity for consent experiences in apps and sites. Build consent prompts that are plain‑language, granular (by purpose), easy to withdraw, and logged for audit. ([law.cornell.edu](https://www.law.cornell.edu/regulations/colorado/4-CCR-904-3-7.02?utm_source=openai))
Neural Data and Telehealth
Neural data—signals derived from measuring brain or nervous‑system activity—often surface in tele‑neurology, neurofeedback, and emerging brain‑computer interface use cases. Colorado’s 2024 update classifies neural data as part of “biological data” when it is used or intended to be used to identify a person, which brings it squarely within the CPA’s sensitive data framework and consent requirements. ([leg.colorado.gov](https://www.leg.colorado.gov/bills/HB24-1058))
Even when neural data is not used for identification, its collection and analysis in clinical or wellness contexts frequently reveal a mental or physical health condition or diagnosis—another sensitive‑data trigger. For compliance, define your Neural Data Classification by use case (identification versus diagnosis), obtain consent before collection, complete a DPA, and ensure processor contracts cover sensor vendors, cloud inference services, and analytics tools end‑to‑end. ([colorado.public.law](https://colorado.public.law/statutes/crs_6-1-1303))
Enforcement and Compliance Considerations
Colorado Attorney General Enforcement is exclusive (along with district attorneys); there is no private right of action under the CPA. The AG can request and evaluate your DPAs and seek injunctive and civil remedies under the state’s consumer‑protection framework. ([law.justia.com](https://law.justia.com/codes/colorado/2022/title-6/article-1/part-13/section-6-1-1311/?utm_source=openai))
Colorado previously offered a limited right‑to‑cure notice for most CPA violations, but that provision sunset on January 1, 2025. A narrower cure opportunity continues for the CPA’s minors’ protections under recent amendments for a defined period, so teams handling teen‑oriented features should plan accordingly. ([privacyrights.org](https://privacyrights.org/resources-tools/law-overviews/colorado-privacy-act?utm_source=openai))
Practically, this means regulators may move more quickly when they identify deficiencies (for example, invalid consent, missing DPAs, or inadequate vendor controls). Keep documentation ready—processing inventories, DPAs, consent logs, and processor agreements—and ensure your systems honor recognized universal opt‑out signals where applicable. ([coag.gov](https://coag.gov/resources/colorado-privacy-act/?utm_source=openai))
FAQs
What types of sensitive data must telehealth companies protect under the CPA?
Telehealth companies must protect data revealing a mental or physical health condition or diagnosis, genetic or biometric data used for identification, personal data from a known child, and data revealing racial or ethnic origin, religious beliefs, sex life or sexual orientation, and citizenship or citizenship status. 2024 updates also bring “biological data” used for identification—including neural data—into sensitive scope.
How does the CPA define neural data for telehealth?
Colorado now treats neural data as a form of biological data when it is used or intended to be used for identification, making it sensitive data that requires consent and a DPA. Separately, neural signals used for clinical evaluation typically reveal health status, which is also sensitive under the CPA.
What are the consent requirements for processing sensitive data?
You must obtain prior, opt‑in consent that is specific, informed, and unambiguous. Avoid dark patterns and bundling consent with general terms. Provide clear choices by purpose, make withdrawal easy, and maintain records to prove valid consent.
Are telehealth companies exempt from CPA due to HIPAA?
No. The CPA contains HIPAA Exemptions for certain data, not for entire entities. PHI processed by covered entities and business associates is generally exempt from the CPA, but non‑PHI activities—such as marketing sites, analytics, or consumer apps operating outside HIPAA—remain subject to the CPA.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.