Consumer Health Data

Health Data Laws That Reach the Companies HIPAA Never Touched

Correction, September 14, 2026. This guide originally said Maryland allows sensitive data to be collected, processed or shared with consent, and cited Maryland's consumer health data provisions as section 14-4604. Neither Maryland prohibition carries a consent clause, and the provisions are codified at Md. Code, Com. Law §§ 14-4704 and 14-4707.

Key Takeaways

  • These statutes define coverage by the data, not the entity. Nevada's NRS 603A.430 reaches any personally identifiable information a regulated entity uses to identify a consumer's past, present or future health status — including inferences derived from data that was not itself health data.
  • Geofencing near health facilities is banned outright by all three statutes surveyed, at a measured radius: 2,000 feet in Washington, 1,750 feet in Nevada and 1,750 feet in Maryland.
  • The enforcement design differs sharply. Washington routes violations through its Consumer Protection Act; Nevada's NRS 603A.550 makes a violation a deceptive trade practice and states expressly that it creates no private right of action.
  • Maryland took a different route again, prohibiting the sale of sensitive data outright rather than permitting it with consent.
  • The FTC's Health Breach Notification Rule, 16 CFR part 318, covers vendors of personal health records and reached GoodRx in the first action brought under it, resulting in a $1.5 million civil penalty.

Why a Second Body of Health Privacy Law Exists at All

HIPAA's scope is drawn around institutions. It regulates covered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a covered transaction — and, through them, their business associates. That architecture works well for a hospital and poorly for an app.

The result is that the same fact about the same person can be regulated or unregulated depending on the route it travelled. A diagnosis recorded in a clinic's chart sits inside HIPAA. The same condition, inferred from what someone searched, which app they opened, or which building their phone sat inside for forty minutes, sits outside it — held by a company that is not a provider, not a plan, and not anyone's business associate.

Three states have now written statutes aimed squarely at that second category, and they share one design decision: coverage follows the information, not the institution. This guide compares how they draw that line. It covers the Nevada, Maryland and Washington statutes, and the federal rule that overlaps them. It is not a fifty-state chart, because most states have no statute of this kind.

Defining Health Data Without a Provider to Point At

Once coverage no longer turns on who holds the data, the definition has to carry the entire weight of the statute. Nevada's is the most explicit of the three and worth reading in full detail.

Under NRS 603A.430, consumer health data means personally identifiable information linked or reasonably capable of being linked to a consumer "that a regulated entity uses to identify the past, present or future health status of the consumer." The statute then enumerates what that includes: any health condition, status, disease or diagnosis; social, psychological, behavioral or medical interventions; surgeries and other health-related procedures; the use or acquisition of medication; bodily functions, vital signs or symptoms; reproductive or sexual health care; and gender-affirming care.

Two extensions in that definition do most of the work. Biometric and genetic data are covered where they relate to any of the listed categories. And precise geolocation is covered where a regulated entity uses it "to indicate an attempt by a consumer to receive health care services or products" — location becomes health data by virtue of what it is being used to infer.

The final clause is the broadest. Nevada covers any of the above "that is derived or extrapolated from information that is not consumer health data," naming proxy and derivative data explicitly. A statute drafted this way does not permit a company to argue that it never collected health data because it only collected behaviour and did the inferring itself. The inference is the regulated object.

That is the definitional move separating this class of statute from a comprehensive privacy law's list of sensitive categories. A sensitive-data list asks what field the data sits in. These statutes ask what the data reveals.

Consent, and What It Cannot Buy

The three statutes diverge most on whether a consumer's permission is a general-purpose key.

Nevada builds a two-tier structure. NRS 603A.500 governs collection and sharing and conditions them on consent, with prescribed disclosures in the consent request. Selling is handled separately at NRS 603A.535, which prohibits an unauthorized sale, specifies the required contents of an authorization, and separately prohibits conditioning the provision of goods or services on a consumer authorising a sale. Consent to use is therefore not consent to sell, and a sale authorisation cannot be extracted as the price of the product.

Maryland declined to make sale available on any terms. In the Maryland Online Data Privacy Act, enacted as Chapter 455 of 2024 and codified at Com. Law § 14-4707, the list of things a controller may not do runs: except where the collection or processing is strictly necessary to provide or maintain a specific product or service the consumer requested, collect, process or share sensitive data concerning a consumer; and then, flatly, "sell sensitive data." Neither prohibition carries a consent clause. Consent does not unlock collection, processing or sharing in Maryland, and it does not unlock sale.

Maryland also writes a confidentiality condition into access rather than leaving it to policy. Section 14-4704 provides that a person may not give an employee or contractor access to consumer health data unless that person is subject to a contractual or statutory duty of confidentiality, or confidentiality is required as a condition of their employment.

The Prohibition That Is Measured in Feet

Every statute in this group contains one provision that is unusual in privacy law: it regulates physical space, with a number attached.

Washington's RCW 19.373 defines a geofence as a virtual boundary "2,000 feet or less from the perimeter of the physical location," and makes it unlawful to implement one around an entity providing in-person health care services in order to identify or track consumers seeking those services, collect consumer health data from them, or send them notifications, messages or advertisements related to their health data or health care services.

Nevada's NRS 603A.540 sets the radius at 1,750 feet and measures it from "any medical facility, facility for the dependent or any other person or entity that provides in-person health care services or products," prohibiting a geofence implemented for the same three purposes.

Maryland's section 14-4704(3) also uses 1,750 feet, but narrows the protected locations rather than broadening them: the prohibition runs to geofences within 1,750 feet of a mental health facility or a reproductive or sexual health facility, used to identify, track, collect data from or send a notification to a consumer regarding that consumer's health data.

The three provisions are close cousins and not duplicates. Washington's radius is the largest and its protected class of locations is defined functionally. Nevada matches Washington's breadth of locations at a shorter radius. Maryland matches Nevada's radius but protects two named categories of facility.

Who Can Sue, and Who Cannot

The enforcement design is where these statutes differ most in practical consequence, and it is a difference the definitions above would not predict.

Washington's RCW 19.373.090 declares that the practices the chapter covers are matters "vitally affecting the public interest" for the purpose of applying the state Consumer Protection Act, chapter 19.86 RCW, and that a violation is an unfair or deceptive act in trade or commerce for that purpose. Chapter 19.86 is the vehicle; the health data statute supplies the predicate.

Nevada reached the opposite conclusion on the same question. NRS 603A.550 makes a violation a deceptive trade practice for the purposes of the state's deceptive trade practice provisions, and then states in terms that the sections "do not create a private right of action" and must not be construed to affect any other provision of law. A statute with a comparably broad definition of covered data is enforced in Nevada only by the state.

That contrast is the single most consequential variable in this area. Two statutes can define consumer health data in nearly the same words and produce entirely different litigation exposure, because one of them routes to a consumer protection act that private plaintiffs can invoke and the other closes that door explicitly.

The Federal Rule That Was Already There

Before any of these statutes, a federal rule already covered part of the same territory from a different direction. The FTC's Health Breach Notification Rule, 16 CFR part 318, applies to vendors of personal health records, PHR related entities and their third party service providers — a set defined precisely to catch health records that are not held by HIPAA covered entities.

A personal health record under section 318.2 is an electronic record of PHR identifiable health information that has the technical capacity to draw information from multiple sources and is managed, shared and controlled by or primarily for the individual. The rule's definition of a covered health care provider is broad, reaching "any other entity furnishing health care services or supplies."

The rule's operative requirement is notification rather than restriction. Section 318.3 requires a vendor to notify each affected individual and, where the unsecured PHR identifiable health information of 500 or more residents of a State is involved, prominent media outlets serving that jurisdiction. Section 318.4 sets the outer limit at 60 calendar days after discovery of a breach, with notice to the FTC contemporaneous for incidents of 500 or more individuals and annual logging permitted below that.

Section 318.2 also defines a breach of security in a way that matters here: acquisition of unsecured PHR identifiable health information without the individual's authorization, with unauthorized access presumed to be unauthorized acquisition unless the entity has reliable evidence to the contrary. Disclosure need not be an intrusion to be a breach.

That reading was tested in the Commission's first case under the rule. In its February 1, 2023 enforcement action against GoodRx Holdings, the FTC alleged the company had shared users' prescription and health information with Facebook, Google, Criteo, Branch and Twilio, used data shared with Facebook to target its own users with medication-specific advertising, and failed to notify consumers, the FTC and the media of those disclosures. The proposed order carried a $1.5 million civil penalty and permanently prohibited the company from disclosing user health information to applicable third parties for advertising purposes. The theory was that a deliberate disclosure to an advertising platform was itself the reportable event.

The Rights Attached, and the Carve-Outs That Limit Them

Defining the data broadly would mean little without a mechanism for a consumer to act on it, and Nevada's is the most concretely specified of the three.

NRS 603A.505 gives a consumer, on request, four distinct entitlements: confirmation of whether the entity is collecting, sharing or selling consumer health data about them; a list of all third parties with whom that data has been shared or to whom it has been sold; cessation of collecting, sharing or selling it; and deletion of it. The third-party list is the unusual item — it obliges disclosure of the downstream chain rather than the practice in the abstract.

NRS 603A.515 attaches a schedule to the deletion right. Within 30 days of authenticating a request, the regulated entity deletes the data from its records and network and notifies every affiliate, processor, contractor or other third party with which it shared that data. Those recipients have their own 30 days from receiving that notice. Where the data sits on archived or backup systems, deletion may be delayed no more than two years after the request is authenticated, as necessary to restore the system. Deletion therefore propagates outward on a defined clock rather than stopping at the entity the consumer contacted.

Against that breadth, NRS 603A.490 sets out where the Nevada provisions stop. They do not apply to a person or entity subject to HIPAA, nor to financial institutions and their affiliates to the extent regulated under the Gramm-Leach-Bliley Act. They also exclude patient identifying information handled under 42 C.F.R. Part 2, patient safety work product under 42 C.F.R. Part 3, identifiable private information handled under 45 C.F.R. Part 46, information used in research under the human-subjects rules, and information used only for public health activities as described in 45 C.F.R. 164.512(b) — the last of these applying whether or not the information is otherwise subject to HIPAA.

Read together, the definition and the exemption list describe the intended target with some precision. The statute is not a second HIPAA layered over regulated health care. It is aimed at the space HIPAA and the research rules leave open, and it withdraws wherever one of those regimes already governs the same data.

What This Guide Does Not Cover

Three limits are worth stating rather than leaving a reader to infer.

Connecticut amended its comprehensive privacy statute to add consumer health data provisions and belongs in any complete account of this area. It is absent here because the research for this guide could not retrieve the enacted text from the Connecticut General Assembly's server, and a citation that was not fetched and read does not ship. The same applies to New York, where a health information privacy bill has been reported but the session researching this guide could not confirm its enacted status from a legislative source it could open.

Washington's statute is summarised here only where it supplies a comparison. Its own requirements, and the reason its enforcement route drew the attention it did, are covered separately in this site's post on that act rather than restated here.

Finally, this guide describes the consumer health data statutes as their text reads. It does not address how HIPAA's own requirements apply to entities that are covered by it, which is a separate body of rules with a separate enforcement agency, nor does it chart the sensitive-data provisions of the comprehensive state privacy laws, which reach health information on a narrower definition and a different set of thresholds.

Background

For the underlying law rather than this development: Washington privacy law, Nevada privacy law, Maryland privacy law, Healthcare privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

What makes information "consumer health data" if it did not come from a doctor?
Under Nevada's NRS 603A.430 the test is use, not origin: personally identifiable information a regulated entity uses to identify a consumer's past, present or future health status. The definition expressly reaches data derived or extrapolated from information that was not health data, including proxy and derivative data.
Can a company be sued directly by a consumer under these statutes?
It depends on the state. Washington's RCW 19.373.090 makes a violation an unfair or deceptive act for the purpose of the state Consumer Protection Act. Nevada's NRS 603A.550 states expressly that its consumer health data provisions do not create a private right of action, leaving enforcement with the state as a deceptive trade practice.
How close can a geofence be to a health facility?
The statutes state radii rather than leaving it to interpretation. Washington defines a covered geofence as a virtual boundary of 2,000 feet or less from the perimeter of the location. Nevada prohibits a geofence within 1,750 feet of a medical facility, facility for the dependent, or other in-person health care provider. Maryland uses 1,750 feet from a mental health facility or a reproductive or sexual health facility.
Does obtaining consent allow a company to sell consumer health data?
Not uniformly. Nevada permits a sale only with a separate authorization meeting statutory content requirements, and prohibits conditioning goods or services on giving it. Maryland's Online Data Privacy Act lists selling sensitive data among the controller prohibitions without attaching a consent exception.
What does the FTC's Health Breach Notification Rule require, and who does it apply to?
16 CFR part 318 applies to vendors of personal health records, PHR related entities and their third party service providers. Section 318.4 requires notice to affected individuals without unreasonable delay and no later than 60 calendar days after discovery, with contemporaneous notice to the FTC where 500 or more individuals are involved.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.