CCPA/CPRA (state privacy laws)
Updated
The CCPA (California Consumer Privacy Act) is California's main consumer privacy law, and the CPRA (California Privacy Rights Act) is the later law that amended and expanded it. Together they give California residents rights over the personal information businesses hold about them.
General information for clinics in the United States. This is not legal advice; ask your own counsel how the rules apply to your clinic.
The CCPA was passed in 2018. California voters approved the CPRA in 2020, and it also created a dedicated state privacy agency. Since then, a growing number of other states, such as Virginia, Colorado, Connecticut and Texas, have passed comprehensive privacy laws of their own. They share many ideas but differ in detail.
Who it applies to
These laws apply to businesses that meet set thresholds, based on things like annual revenue or how much personal information they handle. Many small clinics fall below them, but group practices and larger hospitals may not, and the thresholds differ by state. Pets aren't people, but the owner's name, phone number, email, address and call recordings are personal information.
The rights people get
The core rights are similar across states: to know what personal information a business collects and why, to get a copy, to have it corrected or deleted, and to opt out of its sale or sharing for certain kinds of advertising. Businesses that are covered also need a clear privacy notice and contracts with the service providers that handle data for them.
Service providers
When a clinic uses software that handles client data on its behalf, such as a PIMS, a texting tool or a phone service, that vendor usually acts as a service provider or processor. A written agreement sets out that the vendor uses the data only to provide the service.
An example
A two-location group in California reviews its privacy notice. It lists the client information it collects at the front desk, the vendors that process it, and how a client can ask for a copy or deletion. It also checks that each vendor has signed a data processing agreement.
How Tilly handles it
Your clinic owns its data. Tilly processes it only to answer your calls and messages, keeps it in the US, deletes it on the schedule you set, and never uses it to train AI models. Each clinic signs a data processing agreement, and our current subprocessors are listed on the subprocessors page.
The vet clinic phone compliance guide puts privacy alongside the other rules for clinic phones.