Portland-area healthcare providers spent the past two years building out their HIPAA compliance program, then found a second privacy law sitting on top of it. Oregon’s Consumer Privacy Act took effect for most for-profit businesses in July 2024, and its exemption for patient data is narrower than many practices assume.
Here’s what the law exempts and where it still reaches inside a typical clinic’s systems. For a pediatric practice or a physical therapy clinic in Portland, that distinction decides what needs its own privacy notice and opt-out link, beyond a HIPAA authorization form. That distinction is the starting point for any healthcare IT support conversation in Portland.
What Oregon’s privacy law exempts for healthcare providers
Personal data maintained in compliance with HIPAA falls outside the law’s scope. So does data covered by certain other federal privacy laws. The complete list of exclusions is written into ORS 646A.572(2), according to the Oregon DOJ’s privacy law guidance for businesses.
A clinic that qualifies as a HIPAA-covered entity does not get a blanket pass just by being a healthcare business. The same guidance also excludes publicly available and deidentified information. The exemption covers records handled under HIPAA. It does not cover everything else the practice collects or uses for marketing.
The law also reaches vendors and service providers that process data on a practice’s behalf, a category the Oregon DOJ calls processors. A billing vendor or scheduling platform a Portland practice contracts with can carry its own compliance obligations under Oregon’s law, separate from whatever falls under the practice’s HIPAA program.
Mapping that boundary is usually the first job when Centerlogic starts healthcare IT support work in Portland, well before assuming existing HIPAA compliance already covers it.
Where the exposure sits in non-PHI systems
Once you separate what’s exempted from what isn’t, the exposure becomes specific and locatable. A patient’s diagnosis and billing record, handled under HIPAA, are covered by that federal law and generally sit outside Oregon’s statute.
A scheduling system storing names and appointment times for marketing follow-up is a different matter. So is a patient portal that also tracks browsing behavior or an event registration page for a community health seminar. None of that is protected health information in the HIPAA sense, so none of it carries the exemption. Oregon consumers still hold rights to access or delete it.
Practices running cloud-based scheduling and patient communication tools need to treat this as its own category, mapped separately from clinical records and reviewed on its own terms. A telehealth intake form that collects insurance details for billing sits closer to HIPAA territory. The same form’s optional field asking how a patient found the practice does not, and needs its own privacy notice language and a way for the patient to opt out.
The DOJ frames this as data minimization, meaning a practice collects only what a specific purpose requires rather than everything a system happens to allow. That’s the layer managed IT for healthcare in Portland increasingly has to account for.
How this interacts with your existing HIPAA obligations
HHS defines protected health information as individually identifiable health information held by a covered entity or its business associates, tied to standards for how that information gets used and disclosed. That definition does real work here too. Information stops being PHI the moment it is collected or used outside the HIPAA relationship, even if it started with the same patient.
A clinic’s billing software holds PHI. The same clinic’s email marketing platform, sending a newsletter to past patients about flu shot availability, is processing personal data under Oregon’s law instead. Both systems need attention, but not the same attention. Sorting that distinction out is usually where ongoing compliance and cybersecurity support in Portland comes in, once the clinical side is already locked down.
HIPAA compliance addresses the medical record, while Oregon’s rules address the consumer relationship layer next to it, including opt-out rights and data minimization requirements HIPAA never asked practices to think about. Oregon’s law also requires a privacy notice describing what personal data a business collects and why, along with how people can exercise their rights over it. Most HIPAA privacy notices were never written to cover that ground. They’re scoped to protected health information alone, not the full set of data a practice’s website and scheduling tools gather.
Why healthcare IT support in Portland needs to cover both
Treating Oregon’s law as an extension of HIPAA, or ignoring it because HIPAA is already handled, leads to the same shortfall. Reasonable safeguards and a working opt-out mechanism apply to the non-PHI side of a practice whether or not anyone has been assigned to own it. That includes recognizing browser-level signals such as Global Privacy Control, not the manual opt-out requests currently buried in most privacy policies.
Building that layer in without weakening the cybersecurity already protecting clinical systems is where most of the practical work happens. None of this requires replacing existing HIPAA safeguards. It requires a second set of eyes on the systems HIPAA was never designed to reach.
Eric Schulz of TCC | The Children’s Clinic points to this kind of layering when he describes his experience with Centerlogic, calling the relationship “extremely reassuring and balanced” once responsibility for each system was clearly assigned. IT support built only around HIPAA leaves the newer law unaddressed. IT support built only around Oregon’s law misses the federal requirement that still carries the bigger stakes. Covering both comes down to knowing which system answers to which rulebook.
If your practice hasn’t mapped which systems fall under HIPAA and which now sit under Oregon’s newer statute, that’s a reasonable place to start. Centerlogic’s healthcare team can help separate the two and build a plan for each.
Frequently asked questions
Does Oregon’s privacy law apply to every healthcare practice in Portland?
No. It generally applies once a business processes the personal data of 100,000 Oregon consumers a year, or 25,000 consumers with more than a quarter of annual revenue from data sales. Many small practices sit under that threshold. Larger practices and multi-location groups with active marketing programs are more likely to cross it.
Is patient scheduling software covered by HIPAA or by Oregon’s privacy law?
It depends on the purpose. Scheduling data used strictly to support treatment and billing under HIPAA is generally exempt. The same system used to drive marketing reminders or waitlist campaigns is processing personal data that Oregon’s law still reaches, even when the underlying patient is the same person.
What happens if a practice doesn’t comply?
Per the Oregon DOJ’s enforcement guidance, the Attorney General can pursue civil penalties of up to $7,500 per violation, plus other relief such as restitution. As of January 2026, the Attorney General is no longer required to give businesses notice before taking enforcement action.



