Washington's My Health My Data Act Covers Health Data HIPAA Does Not
Key Takeaways
- HIPAA reaches covered entities and business associates, not apps and websites collecting health information directly from users
- The Act defines consumer health data broadly, including inferences drawn from non-health data
- It requires consent for collection and sharing, with separate authorization required for any sale
- Violations are enforceable through the Washington Consumer Protection Act, which supplies a private right of action
- A geofencing provision restricts virtual boundaries around facilities providing in-person health services
The Gap the Act Addresses
The Health Insurance Portability and Accountability Act is often described as the law governing health privacy in the United States. It is narrower than that. HIPAA applies to covered entities, meaning health plans, health care clearinghouses and health care providers that conduct certain electronic transactions, and to their business associates. It regulates data by reference to who holds it.
That structure leaves out a large and growing category. A period-tracking application, a fitness wearable, a symptom-search query, a mental health app or a retailer inferring pregnancy from purchase history are collecting information about health without any covered entity relationship. The same data type receives extensive federal protection in one setting and none in the other.
Washington's My Health My Data Act, codified at RCW 19.373, was enacted in 2023 as the first state statute written specifically for that category. Most obligations took effect on March 31, 2024, with a later date of June 30, 2024 for entities meeting the definition of small business. The geofencing provision took effect earlier, in July 2023.
What Counts as Consumer Health Data
The Act defines consumer health data as personal information linked or reasonably linkable to a consumer that identifies the consumer's past, present or future physical or mental health status. The definition then enumerates categories, and the list is wide.
- Individual health conditions, treatment, diseases or diagnoses
- Social, psychological, behavioral and medical interventions
- Health-related surgeries or procedures
- Use or purchase of prescribed medication
- Bodily functions, vital signs, symptoms or measurements
- Diagnoses or diagnostic testing, treatment or medication
- Gender-affirming care information
- Reproductive or sexual health information
- Biometric data and genetic data
- Precise location information that could reasonably indicate an attempt to acquire health services or supplies
- Data that identifies a consumer seeking health care services
- Any information processed to associate or identify a consumer with the above, including data derived from non-health information
The final category is the one that extends the Act furthest. Information that is not itself health data becomes consumer health data when it is processed to draw a health inference. A purchase history or browsing pattern used to infer a condition falls within the definition on that basis.
Who the Act Reaches
A regulated entity is any legal entity that conducts business in Washington or produces products or services targeted to Washington consumers, and that alone or jointly determines the purpose and means of collecting, processing, sharing or selling consumer health data. There is no revenue threshold and no data-volume threshold, which distinguishes the Act from comprehensive state privacy laws that apply only above defined sizes.
The term consumer covers Washington residents and also individuals whose consumer health data is collected in Washington. It excludes individuals acting in an employment context. Government agencies, tribal nations and contracted service providers acting on their behalf are excluded from the definition of regulated entity, and data already governed by HIPAA and several other federal and state regimes is carved out.
The Core Requirements
A separate consumer health data privacy policy
Regulated entities must maintain a privacy policy specific to consumer health data, linked prominently and separately from a general privacy policy, disclosing the categories collected, the purposes, the categories shared, and the categories of third parties and affiliates with whom data is shared.
Consent to collect and to share
Collecting or sharing consumer health data requires consent, unless it is necessary to provide a product or service the consumer has requested. Consent must be obtained before collection, and separate consent is required for sharing. The Act specifies that consent be a clear affirmative act, freely given, specific, informed, opt-in and voluntary, and that it cannot be obtained through a deceptive design.
Authorization to sell
Selling consumer health data requires a valid authorization, which is a separate and more demanding instrument than consent. The Act prescribes its contents, including the specific data to be sold, the identity of the purchaser, the purpose, an expiration no later than one year out, and a statement of the right to revoke. Both parties retain copies for six years.
Rights for individuals
Consumers have the right to confirm whether an entity collects, shares or sells their consumer health data, to access it including a list of the third parties it has gone to, to withdraw consent, and to have the data deleted. The deletion right extends to data held by affiliates, processors, contractors and other third parties, and the Act sets a timeline for responses.
Geofencing
The Act makes it unlawful to implement a geofence around an entity providing in-person health care services where the geofence is used to identify or track consumers seeking health services, to collect consumer health data, or to send notifications or advertisements related to consumer health data or services.
Enforcement Is the Distinguishing Feature
A violation of the Act is a violation of the Washington Consumer Protection Act. That statute supplies a private right of action, which means enforcement does not depend on the Attorney General bringing a case. Among US privacy statutes, a broadly applicable private right of action is rare: Illinois BIPA is the primary comparison, and the litigation volume that statute generates illustrates what the mechanism produces.
Whether a given claim succeeds turns on Consumer Protection Act elements, including a showing of injury, so the private right of action is not unlimited. The Act's structure nonetheless places it in a different enforcement category from comprehensive state privacy laws, which route enforcement through the state.
The Pattern It Started
Nevada enacted a consumer health data statute with a comparable structure, though without an equivalent private right of action. Connecticut amended its comprehensive privacy law to add consumer health data provisions. The category of health data outside HIPAA has since become a recurring subject in state legislative sessions, and in enforcement attention to health-related tracking on websites.
Background
For the underlying law rather than this development: Washington privacy law, Healthcare privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
Does the My Health My Data Act apply to companies outside Washington?
Is data already covered by HIPAA also subject to this Act?
What makes an authorization to sell different from consent?
Can individuals sue under the Act?
Sources
Everything above is reported from these documents. Follow them to verify.
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.