A Privacy Policy Is a Promise
Making a medical practice's website actually do what its California privacy notice says. The framework is the CCPA as amended by the CPRA; the enforcement examples are from 2025, the most active year the law has had. Confirm the operational specifics against current regulations before relying on them — this area is still moving.
The language a practice pastes into its website footer — the block that opens “Your California Privacy Rights” and recites the right to know, delete, correct, opt out — is not compliance. It is a set of promises. The moment it goes live, it becomes a representation the state can test against what the website actually does, and the gap between the two is where every recent enforcement action has lived. In July 2025 the Attorney General extracted the largest CCPA settlement to date, $1.55 million, from a health-information website that had done the recitation correctly. It posted the rights. It built three separate opt-out mechanisms. The problem was that none of them worked: after a consumer used all three, investigators still found 118 advertising cookies transmitting data. The policy was fine. The practice behind it was not.
That is the lens for everything below. The boilerplate is the easy part. The watch-outs are about the machinery underneath it — and about one sentence in the pasted text that is probably false.
First: Does It Even Apply, and to Which Data?
Two scoping questions come before any of the rights, and a medical practice has to answer both.
Does the practice qualify as a “business” at all? The CCPA reaches a for-profit entity only if it crosses one of three thresholds (Civ. Code § 1798.140): more than $25 million in annual gross revenue; buying, selling, or sharing the personal information of 100,000 or more California consumers or households; or deriving half its revenue from selling or sharing personal information. A great many solo and small practices clear none of these. That sounds like relief, and it is a trap. Posting a full rights notice you are not obligated to provide does not make you safer — it binds you to promises you may have built no process to keep, and a recited right you then fail to honor is a misrepresentation in its own right. If you qualify, comply for real. If you do not, do not post a policy that says you do; post an accurate one. (Nonprofits sit outside the law entirely, subject to a common-branding-and-control caveat for affiliated for-profits.)
The exemption is about the data, not the practice. This is the misconception that does the most damage, because it is repeated confidently by vendors: “we’re a HIPAA-covered provider, so the CCPA doesn’t apply to us.” The exemption in Civil Code § 1798.145(c) is narrower than that and aimed at information, not entities. It exempts protected health information held by a covered entity or business associate under HIPAA, medical information governed by California’s Confidentiality of Medical Information Act, clinical-trial data, and properly de-identified data. It does not exempt the practice. And the website, as it happens, collects a substantial amount of personal information that is none of those exempt categories: contact-form submissions from people who are not yet patients, newsletter and appointment-request leads, general visitor analytics and device identifiers, and — since 2023 — job-applicant and employee data, which the CPRA pulled fully into scope.
So the pasted rights block is usually wrong in both directions at once. It is over-inclusive, implying that a patient can file a CCPA deletion request for their chart, when the chart is governed by HIPAA and CMIA on entirely different terms. And it is under-inclusive, because the data the CCPA actually reaches — the marketing and website layer — is the data the practice is least likely to have built any request-handling machinery for. The correct structure separates the two regimes: PHI and medical information live under the HIPAA Notice of Privacy Practices; the non-clinical website and marketing data lives under a CCPA notice. Two notices, two regimes, no blurring of which data each one governs.
Second: The “We Do Not Sell or Share” Sentence Is the Dangerous One
The pasted text says the practice does not sell personal information or share it for cross-context behavioral advertising. That is the sentence most likely to be untrue, and an untrue privacy reassurance is worse than an honest disclosure, because it is independently actionable as a deceptive practice under California’s Unfair Competition Law — a second count stacked on the CCPA violation.
Here is why it is usually untrue. Under the CPRA, “sharing” is defined as making personal information available to a third party for cross-context behavioral advertising, and “sale” has been read — beginning with the Sephora action and reaffirmed in 2025 — to include simply letting third-party advertising and analytics trackers fire on your pages. A practice website that runs a Meta Pixel, Google Ads conversion tags, or Google Analytics configured with advertising features is, under that reading, sharing or selling personal information whether or not a dollar changes hands and whether or not anyone at the practice thinks of it as “selling data.” The comforting sentence in the footer and the tracking tags in the page header are, in most cases, contradicting each other.
What to implement is unglamorous: find out what is actually firing. Most practice owners have never inventoried the third-party scripts on their own site, and the Healthline investigation found dozens running invisibly in the first milliseconds of page load. Once you know, you have two honest options. Turn the third-party advertising and analytics sharing off, and then the sentence is true. Or keep it, disclose it plainly, post a functioning “Do Not Sell or Share My Personal Information” link, and honor opt-outs. What you cannot do is keep the trackers and keep the sentence that says you don’t.
Third: A Posted Opt-Out Is Not a Working Opt-Out
This is the whole lesson of the 2025 enforcement year, and it is worth stating as a flat rule: the regulator will test the button. Healthline’s three opt-out paths — a Do-Not-Sell-or-Share link, a cookie banner, and detection of the browser’s opt-out preference signal — were each misconfigured, and the Attorney General’s office ran the test and watched the data keep flowing. The cookie banner that claimed to disable tracking but did not became a separate deceptive-practice count.
Three things follow for implementation. Honor the Global Privacy Control: the CCPA requires businesses to treat the browser-level opt-out preference signal as a valid opt-out, and ignoring it is a standalone violation. Test the opt-out end to end, meaning verify that the data actually stops leaving the site after a consumer opts out — not merely that the button depresses. And do not deploy a consent banner that represents more control than it delivers. Practices that want defensible proof should have a vendor technically audit the opt-out flow, and there is a real argument for retaining that vendor through counsel so the testing sits under privilege.
Fourth: Purpose Limitation, and the Special Hazard of Inferred Health Data
Healthline’s most consequential theory had nothing to do with broken buttons. It was that sharing the titles of articles a reader viewed — titles like “Newly Diagnosed with HIV? Important Things to Know” — violated the CCPA’s purpose-limitation principle, because transmitting data that infers a medical diagnosis to advertisers fell outside what a consumer would reasonably expect, even though the privacy policy disclosed targeted advertising in general terms. It was the first enforcement action to fine a company for disclosing inferred sensitive information rather than explicit health data.
For a medical practice this is not an abstract risk; it is the most likely way the website leaks. A contact form that asks which condition the visitor wants treated, a service page whose URL is itself a diagnosis (“/services/addiction-treatment,” “/conditions/infertility”), an appointment widget that records the specialty selected — any of these, fed to an advertising pixel, transmits inferred health information of exactly the kind the Attorney General has now shown it will pursue. Health information is sensitive personal information under the CPRA, carrying its own right to limit use, and the deeper point is that disclosure can be unlawful even when it is technically disclosed in the policy, if it sits outside the consumer’s reasonable expectations. The implementation is to keep condition-specific pages and forms from feeding ad and analytics trackers at all, and to map where anything health-adjacent flows before a regulator maps it for you.
Fifth: The Rights You Recited Each Need Machinery
Every line in the pasted block implies an operational obligation that the words alone do not satisfy. The ones practices most often skip:
- Notice at collection, given at or before the point of collection, is a separate requirement from the privacy policy itself (Civ. Code § 1798.100). A policy buried in the footer is not notice at the contact form.
- At least two methods to submit requests. A business generally must offer more than one channel; only businesses operating exclusively online may rely on a single email address. A web intake form plus a designated email is the usual minimum.
- A correction mechanism. The right to correct (§ 1798.106) is newer and needs an actual intake and process, not just a sentence promising it exists.
- A “Limit the Use of My Sensitive Personal Information” link, where the practice processes sensitive information beyond the statute’s permitted purposes — which, for a site touching health inferences, is a live question.
- Verification you do not over-build. This is where Honda and Todd Snyder were penalized in 2025: requiring identity documents for an opt-out, which needs no verification, is itself a violation, and the CPPA’s Enforcement Advisory 2024-01 treats demanding more information than necessary as a data-minimization breach. The opt-out must also be as easy as the opt-in; an asymmetric, multi-step cancellation path is a dark pattern.
- Timelines and records. Acknowledge within ten business days, respond within forty-five (one forty-five-day extension is available), and keep request records for twenty-four months.
- An annual refresh. The policy must be updated every twelve months, and a notice dated three years ago is itself evidence of a program that is not being run.
Sixth: The Vendor Contracts No One Reads
Healthline, Honda, Todd Snyder, and American Honda were all faulted, in part, on contracts. The CCPA requires specific data-processing terms in agreements with service providers, contractors, and third parties — limiting them to specified purposes, obligating them to pass through opt-out signals, barring re-identification. The practice that drops in a Google Analytics tag or a Meta Pixel without those terms is exposed, and the Attorney General made a point of the fact that Healthline had “assumed, but not verified” that its advertising vendors had signed up to the required framework — and many had not. Inventory every third party that touches website data, paper each one with CCPA-compliant terms, and verify rather than assume. The standard form the vendor hands you is written for the vendor.
What Enforcement Actually Looks Like Now
Two facts reset the risk calculus. First, the thirty-day window to cure a violation after notice — the safety net everyone remembers from the original CCPA — was eliminated as of January 1, 2023. The Attorney General and the CPPA may offer a chance to fix; they are not required to, and in 2025 they increasingly did not. Second, there are now two enforcers operating in parallel: the Attorney General and the California Privacy Protection Agency, which can impose administrative fines directly. Penalties run $2,500 per violation and $7,500 for intentional violations or those involving consumers under sixteen, and “per violation” can be read per consumer — a single misconfigured tracker firing across thousands of California visitors is not one violation. Healthline’s $1.55 million came packaged with a three-year compliance program and annual reporting to the Attorney General. The throughline of the year is that health and adtech are where the attention has turned.
A brief word on what is coming, because a stress-tested reader will ask. The CPPA finalized a major regulatory package that took effect January 1, 2026, adding obligations on automated decisionmaking, formal risk assessments, and independent cybersecurity audits, with the heavier requirements phasing in across 2027 through 2030. Most of that is keyed to revenue and data-volume thresholds a small practice will not hit, and the automated-decisionmaking rules target “significant decisions” of a kind a typical practice website does not make. But the same package revised the baseline rules that apply now — tightening request handling, service-provider duties, and recordkeeping, and folding under-sixteen data into the sensitive category — so “we’re too small for the new regs” does not mean “nothing changed.”
The Same Ethic, Again
The pattern this series keeps finding holds here too. The fear points at the wrong object. A practice worries about whether its privacy policy contains all the right paragraphs, and a policy generator will happily supply them — the recitation is the part that is easy to buy. The exposure points somewhere else entirely: at whether the opt-out actually stops the data, whether the pixel on the addiction-treatment page is quietly telling an ad network what the visitor came to read, whether the analytics vendor ever signed the terms the policy assumes it signed. None of that is visible in the document. All of it is visible to anyone who tests the site.
So the work that makes a practice website truly comply is not drafting. It is a tracker inventory. A functioning opt-out that someone has actually tested. Condition-specific pages walled off from advertising tags. Vendor contracts that exist and were verified. A “we don’t sell or share” sentence that is true because you confirmed it, not because it sounded reassuring. The policy is a promise. Compliance is keeping it.
This is general commentary, not legal advice. Whether the CCPA applies to a given practice, and which data its exemptions reach, turns on specifics — entity structure, revenue, data flows, and the precise configuration of the website — that only a review of the actual site and contracts can resolve. The statutes and actions referenced here are the right places to start, not a substitute for counsel on a specific build.
Legal Medicine publishes on the law that governs medical practice in California. If this is the kind of argument you want in your inbox, subscribe via Substack and read with us.
Sources
Cal. Civ. Code §§ 1798.100, 1798.106, 1798.121, 1798.125, 1798.140, 1798.145, 1798.155 · California Unfair Competition Law, Bus. & Prof. Code § 17200 · People v. Healthline Media (Cal. AG settlement, July 2025) · People v. Sephora (Cal. AG, 2022) · Honda and Todd Snyder CCPA actions (2025) · CPPA Enforcement Advisory 2024-01 · CPPA regulations effective January 1, 2026.