Back to the hub

Iowa Consumer Data Protection Act HIPAA covered entity exemption

Iowa Code 715D.2(2) exempts persons subject to and complying with HIPAA Title II subtitle F and HITECH Title XIII subtitle D, financial institutions and GLBA data, nonprofit organizations, institutions of higher education, and the state. Iowa conditions its HIPAA exemption on actual compliance rather than naming covered entities.

Applies to: Businesses assessing whether the Iowa Consumer Data Protection Act, Iowa Code chapter 715D, reaches them, in particular healthcare organizations, financial institutions, nonprofits and universities handling Iowa residents' personal data.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Iowa's privacy law is short, and its exemption section does most of the work of deciding who has to care about it. If you are checking whether chapter 715D reaches your organization, Section 715D.2 answers the question in two moves: a threshold test, then two separate exemption lists.

First, do you clear the threshold?

Iowa Code Section 715D.2(1) applies the chapter to a person conducting business in Iowa, or producing products or services targeted to Iowa residents, that during a calendar year does either of the following: controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers and derives over fifty percent of gross revenue from the sale of personal data.

Note what is absent. There is no revenue-only branch, so a large company with few Iowa users stays out. And the second branch needs more than half of gross revenue coming from data sales, which is a genuine data-broker test rather than a trap for ordinary SaaS.

The entity exemptions

Section 715D.2(2) removes five categories entirely:

  • The state or any political subdivision of the state.
  • Financial institutions, affiliates of financial institutions, or data subject to Title V of the federal Gramm-Leach-Bliley Act.
  • Persons who are subject to and comply with regulations promulgated pursuant to Title II, subtitle F of HIPAA and Title XIII, subtitle D of the HITECH Act.
  • Nonprofit organizations.
  • Institutions of higher education.

Why Iowa's HIPAA wording is different

Most state privacy laws exempt "any covered entity or business associate". Nebraska does exactly that at Neb. Rev. Stat. Section 87-1103(2)(c), and Indiana at IC 24-15-1-1(b)(3), both naming the HHS rules at 45 C.F.R. parts 160 and 164.

Iowa does not use the phrase "covered entity" in its exemption at all. It exempts persons who are "subject to and comply with" the HIPAA and HITECH regulations. That conjunction does real work. On its face, an organization that falls under HIPAA but is not complying with it cannot straightforwardly claim to be a person who is subject to and complies with those regulations. Nebraska's and Indiana's formulations carry no such condition. If you are a healthcare organization operating across these three states, the safest reading is that Iowa's exemption is the one you can least afford to take for granted.

Iowa also keeps the familiar data-level backstop at Section 715D.2(3)(k): information originating from, intermingled to be indistinguishable with, or treated in the same manner as exempt information that is maintained by a covered entity or business associate as defined by HIPAA. So the term does appear in chapter 715D, just in the data list rather than the entity list.

The 18 data exemptions

Section 715D.2(3) then removes specific categories of information regardless of who holds them, lettered (a) through (r). They cover protected health information, health records, substance use disorder patient identifying information under 42 U.S.C. Section 290dd-2, human subjects research, Health Care Quality Improvement Act documents, patient safety work product, de-identified health data, public health activities, FCRA-regulated credit information, DPPA data, FERPA education records, Farm Credit Act data, employment and applicant data with emergency contact and benefits carve-outs, and COPPA-regulated children's data.

What is left once the exemptions run out

If the chapter still applies, the obligations are moderate by national standards but the clocks are unusual. Iowa gives controllers 90 days to respond to a consumer request under Section 715D.3(2)(a), extendable once by 45 days, which is the longest base response period of any US state law. Appeals get 60 days under Section 715D.3(3). Enforcement is exclusively with the Attorney General under Section 715D.8(1), there is a 90-day notice and cure period under Section 715D.8(2) with no sunset, civil penalties reach $7,500 per violation under Section 715D.8(3), and Section 715D.8(4) rules out any private right of action. See the Iowa response deadline page for how that 90-day clock works in practice, and the Iowa law overview for the duties themselves.

Next step

If you are unsure whether an Iowa exemption covers your organization or only some of your data, the free 2-minute Obligation Scan checks the thresholds and the exemption lists together and tells you which duties survive. The US state privacy laws hub compares Iowa's exemptions with Nebraska's entity-level version.

Compliance checklist

  • Check the thresholds in Iowa Code Section 715D.2(1) first: 100,000 Iowa consumers, or 25,000 plus over 50 percent of gross revenue from selling personal data.
  • If you handle health data, confirm you are both subject to and complying with the HIPAA and HITECH rules named in Section 715D.2(2), because Iowa's exemption is worded around compliance.
  • Financial institutions and their affiliates should confirm the data is subject to Title V of the Gramm-Leach-Bliley Act, which Section 715D.2(2) exempts alongside the institutions themselves.
  • Nonprofits and institutions of higher education are exempt as entities under Section 715D.2(2), so confirm your organizational status before building a compliance program.
  • Run remaining data sets against the 18 data-level exemptions in Section 715D.2(3), which cover FCRA, DPPA, FERPA, Farm Credit, employment and COPPA data.
  • Remember precise geolocation in Iowa means a radius of 1,750 feet under Section 715D.1(19), which is tighter than California's 1,850 feet.

Sources

Last verified: 2026-09-02

Informational, not legal advice.