Washington

Washington Privacy Law

Washington has not enacted a general comprehensive privacy law. Its centrepiece is instead the My Health My Data Act, which the Attorney General’s office describes as the first privacy law in the country directed at personal health data falling outside the reach of HIPAA. The Act reaches “consumer health data” defined by how information is used rather than where it came from, makes selling that data without valid authorization unlawful, and is enforced as a per se violation of the Washington Consumer Protection Act — by the Attorney General and, unusually among recent state privacy statutes, through private action as well. The office’s own recent privacy docket has been directed at the federal government: suits over Medicaid records shared with immigration enforcement and over a demand for the records of 17 million commercial drivers.

Sector-Specific Privacy Laws in Washington

My Health My Data Act (Wash. Rev. Code ch. 19.373)

The Act regulates “consumer health data”, which the Attorney General’s office describes as reaching information derived or extrapolated from non-health data when a regulated entity or its processor uses that information to associate or identify a consumer with consumer health data — a definition that turns on use rather than on the source of the data. The office states that it is unlawful to sell or offer to sell consumer health data without first obtaining valid authorization from the consumer, and that a regulated entity and a small business must prominently publish a link to a consumer health data privacy policy on the homepage. The obligations in sections 4 through 9 took effect March 31, 2024 for regulated entities other than small businesses and June 30, 2024 for small businesses, with section 10 effective July 23, 2023. The office describes the statute as the first privacy law in the country directed at personal health data falling outside the reach of HIPAA, enacted as House Bill 1155, which passed the Legislature on April 17, 2023 and was signed on April 27, 2023.

Biometric identifiers (Wash. Rev. Code ch. 19.375)

Washington prohibits enrolling a biometric identifier in a database for a commercial purpose without notice and consent. Unlike Illinois’s Biometric Information Privacy Act, the chapter does not provide a standalone private right of action; enforcement runs through the Attorney General under the Consumer Protection Act.

Data Breach Notification in Washington

Washington's breach-notification statute (RCW 19.255) requires notice to affected consumers and, for larger breaches, to the Attorney General within 30 days.

Residents must be notified no later than 30 days after the breach is discovered. Notify the Washington Attorney General if more than 500 residents are affected, within 30 days. Complaints are taken by the Washington Attorney General, which enforces the statute.

How Washington Enforces Its Privacy Laws

The MHMDA is enforced through the Consumer Protection Act. The Attorney General’s office states that any violation of the My Health My Data Act “is a per se violation of the Washington Consumer Protection Act (CPA), RCW 19.86, which is enforced by the Attorney General as well as through private action”. That routing, rather than a penalty schedule inside the health-data statute itself, is what supplies the remedies. The office also records the Act’s staggered commencement: section 10 took effect July 23, 2023, sections 4 through 9 on March 31, 2024 for regulated entities that are not small businesses, and the same sections on June 30, 2024 for small businesses. Among the obligations the office highlights are that “it is unlawful for anyone to sell or offer to sell consumer health data without first obtaining valid authorization from the consumer”, and that a regulated entity and a small business “shall prominently publish a link to its consumer health data privacy policy on its homepage”.

Recent Enforcement in Washington

Medicaid data transferred to immigration enforcement — multistate suit, N.D. Cal., July 2025. The Attorney General’s office announced on July 1, 2025 that Washington had joined fourteen other states in suing the United States Department of Health and Human Services and the Department of Homeland Security in the United States District Court for the Northern District of California over the transfer of personal health records from state Medicaid files to DHS for immigration enforcement. The office reports that the transfer was made en masse on June 13, 2025 and that roughly 1.9 million Apple Health clients in Washington are affected, including about 49,000 whose immigration status makes them ineligible for some federally funded programs. The claims asserted include violations of the Administrative Procedure Act, the Social Security Act, HIPAA, the Federal Information Security Modernization Act, the Privacy Act and the Spending Clause, and the coalition sought an injunction against further transfers and against use of the data for immigration enforcement.

Commercial driver records — suit over the CDLIS demand, August 2026. The Attorney General’s office announced on August 13, 2026 that Washington had gone to court over a federal demand for records in the Commercial Driver’s License Information System held by AAMVA, describing records containing the sensitive personal information of 17 million commercial driver’s licence holders — names, dates of birth, Social Security numbers, driver’s licence numbers and state licensing and driving history — going back five years. The office names the Department of Transportation, the Federal Motor Carrier Safety Administration and the Department of Homeland Security, describes proceedings including the United States District Court for the Eastern District of Virginia, and asserts violations of federal privacy laws and the Administrative Procedure Act, including a lack of legitimate need and a failure to consult the states. The office characterises the demand as backed by a threat to terminate more than $10 million in federal funding, and the coalition sought emergency orders to prevent the transfer.

Federal Privacy Laws That Apply in Washington

Federal privacy law applies in Washington by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, Washington obligations run through the state’s breach-notification statute and the Washington Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach Washington Businesses

With no comprehensive state statute, most privacy obligations on a Washington business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Washington businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Washington itself has none, and any business holding personal information about Washington residents is subject to the state’s breach-notification statute described above.

Washington Privacy Law FAQ

Who can enforce Washington’s My Health My Data Act?
The Attorney General’s office states that any violation of the Act “is a per se violation of the Washington Consumer Protection Act (CPA), RCW 19.86, which is enforced by the Attorney General as well as through private action”. The Act therefore borrows the Consumer Protection Act’s remedies rather than setting out its own, and the private route distinguishes it from the biometric chapter at RCW 19.375, which the office says is enforced by the Attorney General under the same Consumer Protection Act but carries no standalone private right of action.
What counts as “consumer health data” in Washington?
The definition turns on use rather than on the origin of the data. The Attorney General’s office describes it as including information “derived or extrapolated from nonhealth data when that information is used by a regulated entity or their respective processor to associate or identify a consumer with consumer health data”. Data that is not health data in itself can therefore fall inside the Act depending on what the regulated entity does with it.
When did the My Health My Data Act take effect?
In stages. The Attorney General’s office records section 10 as effective July 23, 2023, and sections 4 through 9 as effective March 31, 2024 for regulated entities that are not small businesses and June 30, 2024 for small businesses. The Act was enacted as House Bill 1155, which the office says passed the Legislature on April 17, 2023 and was signed on April 27, 2023.
Can consumer health data be sold in Washington?
Not without authorization. The Attorney General’s office states that “it is unlawful for anyone to sell or offer to sell consumer health data without first obtaining valid authorization from the consumer”. The office separately states that a regulated entity and a small business “shall prominently publish a link to its consumer health data privacy policy on its homepage”.
What privacy cases has the Washington Attorney General brought recently?
Two of the office’s recent announcements concern federal demands for state-held records. On July 1, 2025 it announced a suit with fourteen other states in the Northern District of California over the transfer of state Medicaid health records to the Department of Homeland Security for immigration enforcement, reporting roughly 1.9 million Apple Health clients affected in Washington. On August 13, 2026 it announced action over a federal demand for Commercial Driver’s License Information System records held by AAMVA, covering what the office describes as the sensitive personal information of 17 million drivers going back five years.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.