The Virginia Consumer Data Protection Act and healthcare marketing
Virginia was the second US state, after California, to pass a comprehensive consumer privacy law. For most medical and dental practices, HIPAA remains the main privacy rule. But the VCDPA can still reach practices that are not HIPAA covered entities, larger groups, and the agencies and ad-tech tools that sit around a practice's marketing. This guide explains where the lines are.
- The Virginia Consumer Data Protection Act (VCDPA) took effect on January 1, 2023.
- It applies to businesses that process the personal data of at least 100,000 Virginia consumers a year, or 25,000 while earning over half their revenue from selling personal data.
- HIPAA covered entities and business associates are exempt, as is protected health information under HIPAA.
- Health diagnosis data is sensitive data: processing it generally requires consent.
- Consumers can opt out of targeted advertising. The Attorney General enforces the Act, with civil penalties of up to $7,500 per violation.
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
What the VCDPA is
The Virginia Consumer Data Protection Act is a state privacy law in Title 59.1 of the Code of Virginia. It was signed in March 2021 and took effect on January 1, 2023. It gives Virginia residents rights over their personal data and places duties on the businesses that collect and use it.
The Act uses two roles that matter for marketing. A controller decides why and how personal data is processed. A processor processes it on the controller's behalf. A practice running its own website and ads is usually the controller; its agency, analytics provider and CRM are usually processors.
A "consumer" under the Act is a Virginia resident acting in an individual or household context. People acting in a commercial or employment context are excluded, so a practice's staff data and B2B contacts are generally outside its scope.
Does it apply to your practice?
Work through three questions in order.
1. Are you exempt at the entity level?
The Act does not apply to HIPAA covered entities or business associates, among other exempt categories such as nonprofits and financial institutions covered by federal financial privacy law. Most medical and dental practices that bill insurance electronically are HIPAA covered entities. If that is you, the VCDPA generally does not apply to your practice as a whole.
2. If not, do you meet the thresholds?
Some healthcare businesses are not HIPAA covered entities, for example some cash-only aesthetic, wellness or direct-pay practices. Whether a particular business is a covered entity is a legal question, so confirm it with counsel. If you are not exempt, the Act applies only if, in a calendar year, you control or process the personal data of at least 100,000 Virginia consumers, or of at least 25,000 while deriving over 50% of gross revenue from selling personal data.
A single-location practice rarely reaches those numbers from patient records alone. But personal data includes information reasonably linkable to a person, which can include online identifiers collected by a busy website, so do not assume you are under the threshold without checking.
3. Are your vendors in scope?
Even when a practice is exempt, the marketing and ad-tech companies around it may be in scope for their own activities. That is one reason we recommend treating the VCDPA's standards as good practice, not just a box to check.
How it sits alongside HIPAA
HIPAA protects health information held by covered entities and their business associates. The VCDPA exempts both the entities and the protected health information they hold. So for a covered practice, the question is not "which law wins" but "is this data PHI?"
Where marketing gets tricky is the data that sits at the edge: a website visitor's browsing on a symptom page, a lead form filled in before anyone becomes a patient, or an audience list built in an ad platform. HHS has published guidance on the use of online tracking technologies by covered entities; a federal court in 2024 vacated part of that guidance as it applied to certain unauthenticated web pages. The law in this area is still moving, and we keep tracking conservative regardless.
- No advertising pixels on patient portals, booking flows or any page where someone enters health information.
- No form contents passed to ad or analytics platforms.
- A Business Associate Agreement with any vendor handling PHI. We are prepared to sign one where our work involves PHI.
Health data is sensitive data
The Act treats some categories of personal data as sensitive, including data revealing a mental or physical health diagnosis, genetic or biometric data used to identify a person, precise geolocation, and personal data collected from a known child. A controller generally may not process sensitive data without the consumer's consent; for a known child, processing must follow COPPA.
For businesses in scope, this has direct marketing consequences:
- Building ad audiences around a health condition (for example, people who viewed a diabetes page) processes health-related data and needs careful legal review.
- A lead form that asks about symptoms or diagnoses collects sensitive data and needs a clear consent step.
- Marketing aimed at children's services should be directed at parents, and data about children needs particular care. Virginia has amended the Act since 2023, including on children's data, so check the current text.
Consumer rights and targeted advertising
Consumers covered by the Act can ask a controller to:
- confirm whether it processes their personal data, and access it;
- correct inaccuracies;
- delete their personal data;
- get a portable copy of data they provided; and
- opt out of targeted advertising, the sale of their personal data, and certain profiling.
Controllers must respond within 45 days, extendable once by another 45 days where reasonably necessary, and must offer a way to appeal a refusal. They must also publish a clear privacy notice explaining what they collect, why, and how consumers can exercise their rights, including how to opt out of targeted advertising.
The Act also requires data protection assessments for higher-risk processing, which includes targeted advertising, the sale of personal data, certain profiling and any processing of sensitive data.
What it means for healthcare marketing
Whether or not the Act applies to you directly, these are the habits we build into every Virginia engagement:
- Collect less. Lead forms ask for what the front desk needs to call back, not medical history.
- Separate marketing pages from patient pages. Tracking lives on public marketing pages only, never on portals, booking confirmations or forms that capture health details.
- No condition-based retargeting. We do not build audiences from visits to condition or treatment pages.
- Honour opt-outs everywhere. An opt-out in email, text or advertising is applied across every system.
- Keep the privacy notice honest. It describes the tools actually in use and how to opt out.
- Measure without PHI. Calls and bookings are attributed to their source on Ichelon Agency OS without sending patient details to ad platforms.
These habits also make good marketing. Local search, Google Business Profile and clear service pages bring in most new patients for independent practices, and none of them depends on sensitive data.
Agencies and vendors as processors
Where the Act applies, it requires a written contract between a controller and each processor. The contract sets out the instructions for processing, the type of data and its duration, confidentiality duties, deletion or return of data at the end of the service, and cooperation with assessments and audits.
For a practice that is a HIPAA covered entity, the equivalent document for vendors handling PHI is the Business Associate Agreement. In both cases, ask your agency three questions: what data do you collect on our behalf, where does it go, and what happens to it when we stop working together?
Enforcement
The Virginia Attorney General has exclusive authority to enforce the Act; consumers cannot sue under it. As enacted, the Act requires the Attorney General to give written notice and a 30-day period to cure before bringing an action, and provides for civil penalties of up to $7,500 per violation, plus the possibility of injunctions and recovery of expenses.
Remember that other enforcement routes exist for healthcare marketing in Virginia: the Virginia Consumer Protection Act, the licensing boards (see our Board of Medicine and Board of Dentistry guides), HIPAA enforcement by HHS, and the FTC.
More: Healthcare marketing in Virginia · HIPAA marketing compliance · TCPA-safe patient outreach
VCDPA and healthcare marketing: common questions
Does the Virginia Consumer Data Protection Act apply to my medical or dental practice?
Often not directly. The Act exempts HIPAA covered entities and business associates, and it applies only to businesses that control or process the personal data of at least 100,000 Virginia consumers in a year, or at least 25,000 while deriving over half their gross revenue from selling personal data. It can still apply to practices that are not HIPAA covered entities, to larger groups, and to the marketing vendors they use. Confirm your status with counsel.
When did the VCDPA take effect?
The Virginia Consumer Data Protection Act took effect on January 1, 2023. It has been amended since, so check the current text of the Act in the Code of Virginia.
Is health information "sensitive data" under the VCDPA?
Yes. Personal data revealing a mental or physical health diagnosis is sensitive data under the Act, and a controller generally needs the consumer's consent before processing it. Data about a known child is also sensitive and must be handled in line with COPPA.
Can patients opt out of targeted advertising under the VCDPA?
Consumers covered by the Act have the right to opt out of targeted advertising, the sale of their personal data and certain profiling. Controllers must honour those requests and respond to rights requests within 45 days, which can be extended once by another 45 days where reasonably necessary.
Who enforces the VCDPA and what are the penalties?
The Virginia Attorney General has exclusive enforcement authority; there is no private right of action. The Act provides for civil penalties of up to $7,500 per violation, and as enacted it gives businesses notice and 30 days to cure a violation before an action is brought. Check the current text for any changes.
Is this guide legal advice?
No. It is general marketing guidance from a healthcare marketing agency. Check the current text of the Act and consult a privacy attorney before making decisions about your practice.