Iowa Consumer Data Protection Act (ICDPA): Carve-Outs for HIPAA-Covered Entities Operating Patient Portals

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Iowa Consumer Data Protection Act (ICDPA): Carve-Outs for HIPAA-Covered Entities Operating Patient Portals

Kevin Henry

Data Protection

August 07, 2026

7 minutes read
Share this article
Iowa Consumer Data Protection Act (ICDPA): Carve-Outs for HIPAA-Covered Entities Operating Patient Portals

ICDPA Overview and Scope

The Iowa Consumer Data Protection Act (ICDPA) establishes baseline privacy obligations for organizations that determine how and why personal data of Iowa residents is processed. It applies to “controllers” and their “processors,” focusing on transparency, security, and respecting consumer choices about data use.

Under the ICDPA, “personal data” means information linked or reasonably linkable to an identified or identifiable person. Publicly available information and properly de-identified data are out of scope. A “consumer” is an Iowa resident acting in an individual or household context, not in an employment or commercial role.

Because many healthcare organizations operate patient portals, understanding where the ICDPA stops and the Health Insurance Portability and Accountability Act (HIPAA) begins is essential. The law contains targeted carve-outs that significantly narrow ICDPA obligations when Protected Health Information (PHI) is involved.

HIPAA Exemptions under ICDPA

What is carved out

  • Protected Health Information (PHI) as defined by HIPAA is exempt from the ICDPA.
  • Activities by HIPAA-covered entities and their business associates that are regulated by HIPAA are exempt.
  • Data de-identified in accordance with HIPAA is outside the ICDPA’s definition of personal data.

In practice, these carve-outs mean the ICDPA generally does not apply to PHI handled within a patient portal operated by a HIPAA-covered entity or its business associate. HIPAA remains the primary compliance regime for that data.

Where HIPAA ends and the ICDPA begins

Not all data a covered entity touches is PHI. The ICDPA can apply to non-PHI collected around the portal experience—especially on unauthenticated pages or marketing properties. Distinguish clearly between HIPAA-regulated data and other personal data to determine which law governs each flow.

Common examples

  • Typically PHI (ICDPA-exempt): medical records displayed in the portal, messages with clinicians, lab results, care plans, insurance and billing details accessed after login.
  • Potentially non-PHI (ICDPA-in-scope): website analytics on public pages, advertising cookies, newsletter sign-ups, event registrations, satisfaction surveys not tied to care, and cross-site identifiers used for targeted advertising.

This boundary mapping is the foundation of Covered Entity Compliance under both laws: apply HIPAA to PHI, and apply ICDPA requirements to any personal data that falls outside HIPAA’s protections.

Patient Portal Data Handling

Segment PHI and non-PHI data flows

  • Inventory data collected across your portal ecosystem (authenticated portal, pre-login pages, apps, marketing tools). Label each flow as PHI, de-identified, or non-PHI personal data.
  • Route PHI exclusively through HIPAA-governed systems. Keep non-PHI personal data—such as analytics or advertising identifiers—in separate pipelines with ICDPA controls.

Vendor management: BAAs vs. DPAs

  • Maintain your HIPAA Notice of Privacy Practices for PHI.
  • Publish an ICDPA-compliant privacy notice for non-PHI personal data that explains processing purposes, categories of data and recipients, Consumer Data Access Rights, and Data Sale Opt-Out Provisions.
  • Configure cookie and tracking tools to respect consumer choices, especially for targeted advertising or data sales.

Security and minimization

Consumer Rights under ICDPA

What rights apply to non-PHI personal data

  • Right to confirm whether you process a consumer’s personal data and to access it (Consumer Data Access Rights).
  • Right to delete personal data the consumer provided to you.
  • Right to obtain a portable copy of personal data the consumer provided.
  • Right to opt out of the sale of personal data and of targeted advertising (Data Sale Opt-Out Provisions).

These rights do not apply to PHI processed under HIPAA. Build separate workflows so ICDPA requests do not inadvertently expose or alter PHI governed by HIPAA.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Operationalizing rights for patient portals

  • Offer clear request channels for non-PHI personal data (web form or portal setting). Verify identity without collecting excessive new data.
  • Respond within statutory timelines, track outcomes, and maintain records of requests and responses.
  • For opt-outs, ensure marketing and advertising tools propagate the choice across all processors that use identifiers for targeted ads or sales.

Enforcement and Compliance Requirements

Iowa Attorney General Enforcement

The ICDPA is enforced exclusively by the Iowa Attorney General. There is no private right of action. Before bringing an action, the Attorney General provides a cure period; failure to cure can lead to civil penalties, potentially assessed on a per-violation basis.

Core controller obligations

  • Maintain an accurate privacy notice covering non-PHI personal data, purposes, categories shared, and how consumers can exercise rights.
  • Implement reasonable administrative, technical, and physical security practices appropriate to the volume and sensitivity of personal data.
  • Execute processor contracts that specify processing instructions, confidentiality, security, and return/deletion of data.
  • Avoid discrimination against consumers who exercise their privacy rights.
  • Document your decisions to facilitate timely cures if the Iowa Attorney General Enforcement team raises concerns.

Thresholds for ICDPA Applicability

Personal Data Processing Thresholds determine whether you are a covered “controller.” Generally, the ICDPA applies if you conduct business in Iowa (or target Iowa residents) and, in a calendar year, either:

  • Control or process personal data of at least 100,000 consumers, or
  • Control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.

PHI processed under HIPAA is carved out; focus your threshold analysis on non-PHI personal data that falls under the ICDPA. Remember that “consumer” excludes individuals in an employment or B2B context.

Practical examples

  • A health system’s authenticated portal handling only PHI: generally outside ICDPA due to HIPAA exemptions.
  • A related marketing site collecting analytics and using targeted ads across 120,000 Iowa visitors: likely in scope for ICDPA with robust opt-out mechanisms required.
  • A small clinic’s newsletter list of 20,000 Iowa residents with no data sales: likely below ICDPA thresholds, but still wise to publish a clear notice and honor basic privacy practices.

Exempt Entities and Organizations

The ICDPA includes entity- and data-level exemptions. Commonly exempt categories include:

  • HIPAA-covered entities and business associates for activities regulated by HIPAA (including PHI and HIPAA-de-identified data).
  • Government entities and bodies performing governmental functions.
  • Nonprofit organizations.
  • Financial institutions and data subject to the Gramm-Leach-Bliley Act.
  • Data covered by sectoral laws (for example, certain education records or consumer reporting data) and publicly available information.

Exemptions are contextual. A HIPAA-covered entity operating a separate, consumer-facing app outside HIPAA’s scope may still have ICDPA obligations for that app’s non-PHI personal data. Map each line of business and data flow before concluding you are fully exempt.

Conclusion

For patient portals, HIPAA governs PHI while the ICDPA can apply to surrounding non-PHI data—especially analytics and advertising identifiers. By segmenting data flows, updating notices, honoring Consumer Data Access Rights and Data Sale Opt-Out Provisions, and aligning contracts and security controls, you can satisfy both regimes without confusion.

FAQs

What data is exempt from the ICDPA for patient portals?

PHI handled by HIPAA-covered entities or their business associates is exempt, as is data de-identified under HIPAA. Information displayed or exchanged within an authenticated patient portal for treatment, payment, or healthcare operations typically falls into this exempt category.

How does HIPAA exemption affect the ICDPA applicability?

HIPAA exemptions remove PHI from the ICDPA’s scope. However, the ICDPA can still apply to non-PHI personal data around the portal experience—such as analytics on unauthenticated pages or targeted advertising—if your organization meets the law’s applicability thresholds.

Who enforces the ICDPA in Iowa?

The Iowa Attorney General enforces the ICDPA. The office may offer an opportunity to cure alleged violations before pursuing penalties, and there is no private right of action.

What consumer rights does the ICDPA grant regarding health data?

The ICDPA grants rights for non-PHI personal data: to confirm and access data provided by the consumer, to request deletion of data the consumer provided, to obtain a portable copy, and to opt out of data sales and targeted advertising. These rights do not apply to PHI regulated by HIPAA.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles