Washington Privacy Law
Washington has not enacted a general comprehensive privacy law. Its centrepiece is instead the My Health My Data Act, which the Attorney General’s office describes as the first privacy law in the country directed at personal health data falling outside the reach of HIPAA. The Act reaches “consumer health data” defined by how information is used rather than where it came from, makes selling that data without valid authorization unlawful, and is enforced as a per se violation of the Washington Consumer Protection Act — by the Attorney General and, unusually among recent state privacy statutes, through private action as well. The office’s own recent privacy docket has been directed at the federal government: suits over Medicaid records shared with immigration enforcement and over a demand for the records of 17 million commercial drivers.
Sector-Specific Privacy Laws in Washington
My Health My Data Act (Wash. Rev. Code ch. 19.373)
The Act regulates “consumer health data”, which the Attorney General’s office describes as reaching information derived or extrapolated from non-health data when a regulated entity or its processor uses that information to associate or identify a consumer with consumer health data — a definition that turns on use rather than on the source of the data. The office states that it is unlawful to sell or offer to sell consumer health data without first obtaining valid authorization from the consumer, and that a regulated entity and a small business must prominently publish a link to a consumer health data privacy policy on the homepage. The obligations in sections 4 through 9 took effect March 31, 2024 for regulated entities other than small businesses and June 30, 2024 for small businesses, with section 10 effective July 23, 2023. The office describes the statute as the first privacy law in the country directed at personal health data falling outside the reach of HIPAA, enacted as House Bill 1155, which passed the Legislature on April 17, 2023 and was signed on April 27, 2023.
Biometric identifiers (Wash. Rev. Code ch. 19.375)
Washington prohibits enrolling a biometric identifier in a database for a commercial purpose without notice and consent. Unlike Illinois’s Biometric Information Privacy Act, the chapter does not provide a standalone private right of action; enforcement runs through the Attorney General under the Consumer Protection Act.
Data Breach Notification in Washington
Washington's breach-notification statute (RCW 19.255) requires notice to affected consumers and, for larger breaches, to the Attorney General within 30 days.
Residents must be notified no later than 30 days after the breach is discovered. Notify the Washington Attorney General if more than 500 residents are affected, within 30 days. Complaints are taken by the Washington Attorney General, which enforces the statute.
How Washington Enforces Its Privacy Laws
The MHMDA is enforced through the Consumer Protection Act. The Attorney General’s office states that any violation of the My Health My Data Act “is a per se violation of the Washington Consumer Protection Act (CPA), RCW 19.86, which is enforced by the Attorney General as well as through private action”. That routing, rather than a penalty schedule inside the health-data statute itself, is what supplies the remedies. The office also records the Act’s staggered commencement: section 10 took effect July 23, 2023, sections 4 through 9 on March 31, 2024 for regulated entities that are not small businesses, and the same sections on June 30, 2024 for small businesses. Among the obligations the office highlights are that “it is unlawful for anyone to sell or offer to sell consumer health data without first obtaining valid authorization from the consumer”, and that a regulated entity and a small business “shall prominently publish a link to its consumer health data privacy policy on its homepage”.
Recent Enforcement in Washington
Medicaid data transferred to immigration enforcement — multistate suit, N.D. Cal., July 2025. The Attorney General’s office announced on July 1, 2025 that Washington had joined fourteen other states in suing the United States Department of Health and Human Services and the Department of Homeland Security in the United States District Court for the Northern District of California over the transfer of personal health records from state Medicaid files to DHS for immigration enforcement. The office reports that the transfer was made en masse on June 13, 2025 and that roughly 1.9 million Apple Health clients in Washington are affected, including about 49,000 whose immigration status makes them ineligible for some federally funded programs. The claims asserted include violations of the Administrative Procedure Act, the Social Security Act, HIPAA, the Federal Information Security Modernization Act, the Privacy Act and the Spending Clause, and the coalition sought an injunction against further transfers and against use of the data for immigration enforcement.
Commercial driver records — suit over the CDLIS demand, August 2026. The Attorney General’s office announced on August 13, 2026 that Washington had gone to court over a federal demand for records in the Commercial Driver’s License Information System held by AAMVA, describing records containing the sensitive personal information of 17 million commercial driver’s licence holders — names, dates of birth, Social Security numbers, driver’s licence numbers and state licensing and driving history — going back five years. The office names the Department of Transportation, the Federal Motor Carrier Safety Administration and the Department of Homeland Security, describes proceedings including the United States District Court for the Eastern District of Virginia, and asserts violations of federal privacy laws and the Administrative Procedure Act, including a lack of legitimate need and a failure to consult the states. The office characterises the demand as backed by a threat to terminate more than $10 million in federal funding, and the coalition sought emergency orders to prevent the transfer.
Federal Privacy Laws That Apply in Washington
Federal privacy law applies in Washington by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, Washington obligations run through the state’s breach-notification statute and the Washington Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach Washington Businesses
With no comprehensive state statute, most privacy obligations on a Washington business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Washington businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Washington itself has none, and any business holding personal information about Washington residents is subject to the state’s breach-notification statute described above.
Washington Privacy Law FAQ
Who can enforce Washington’s My Health My Data Act?
What counts as “consumer health data” in Washington?
When did the My Health My Data Act take effect?
Can consumer health data be sold in Washington?
What privacy cases has the Washington Attorney General brought recently?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Wash. Rev. Code ch. 19.373 — My Health My Data Act statute
- Washington Attorney General — Protecting Washingtonians' personal health data and privacy agency
- Washington Attorney General — Suit over sharing personal health data with immigration enforcement (July 1, 2025) agency
- Washington Attorney General — Suit to protect the personal information of millions of drivers (August 13, 2026) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.