The short version
- It is not a health care law. It covers any business that collects health-related data from Washington consumers, and it exempts data already governed by HIPAA and several other federal and state privacy laws.
- "Consumer health data" is broad. It includes symptoms, measurements, fitness and biometric data, purchases of medication, and even health information inferred from non-health data.
- The core duties: publish a separate consumer health data privacy policy linked from your homepage, get consent to collect and separate consent to share, sell only with a signed authorization, and answer access and deletion requests within 45 days.
- It has been in force since 2024. Small businesses have had to comply since June 30, 2024; larger regulated entities since March 31, 2024.
- It is enforced through the Consumer Protection Act, and unlike Washington's breach notification law, it does not rule out private lawsuits under that Act. Check that your cyber policy's privacy liability coverage responds to claims under it.
Who the law covers
The Act applies to a "regulated entity": any legal entity that conducts business in Washington, or produces or provides products or services targeted to Washington consumers, and that determines how consumer health data is collected and used. A "small business" follows the same rules on a slightly later schedule; it is one that handles data of fewer than 100,000 consumers a year, or fewer than 25,000 consumers while earning less than half its revenue from consumer health data.
A "consumer" is a Washington resident, or anyone whose consumer health data is collected in Washington. People acting in an employment context are not consumers, so employee health records are outside the Act.
Businesses that may be covered without realizing it
| Business | Health data it may collect |
|---|---|
| Gyms, yoga and pilates studios, personal trainers | Injuries, fitness measurements, heart rate or body composition from wearables |
| Spas and esthetics businesses (and massage businesses, outside treatment records kept under RCW 70.02) | Intake forms listing conditions, medications, allergies, pregnancy; marketing and website data |
| Wellness, nutrition, and coaching practices | Symptoms, diet, weight, mental health goals |
| Salons and barbers | Scalp and skin conditions, allergies |
| Retailers and ecommerce | Purchases of health products that reveal a condition |
| Apps and software companies | Tracked symptoms, sleep, cycles, location near health care providers |
| Dental, therapy, and medical practices | Data outside HIPAA, such as website tracking and marketing lists |
Whether a particular business is covered depends on the data it actually collects and whether an exemption applies. This table is a prompt for review, not a legal conclusion.
What counts as consumer health data
RCW 19.373.010 defines consumer health data as personal information linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status. The listed examples include:
- Health conditions, treatment, diseases, or diagnosis
- Social, psychological, behavioral, and medical interventions
- Health-related surgeries or procedures
- Use or purchase of prescribed medication
- Bodily functions, vital signs, symptoms, or measurements
- Diagnoses or diagnostic testing
- Gender-affirming care and reproductive or sexual health information
- Biometric and genetic data
- Precise location information that could reasonably indicate a consumer is seeking health care services
- Data that identifies a consumer as seeking health care services
- Health information inferred from non-health data, including through algorithms or machine learning
What is exempt
The Act does not apply to protected health information under HIPAA, to health care information handled under Washington's Uniform Health Care Information Act (RCW 70.02), which covers licensed health care providers such as massage therapists, or to personal information governed by laws including the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, and privacy rules adopted by Washington's Insurance Commissioner. A dental office's patient chart is HIPAA data; the same office's website tracking pixels and marketing list may not be.
What the law requires
| Requirement | What it means in practice | Statute |
|---|---|---|
| Consumer health data privacy policy | A policy listing the categories of health data you collect and why, the sources, what you share, the categories of third parties and specific affiliates you share with, and how consumers exercise their rights. Link it prominently on your homepage. The Attorney General says it must be a separate and distinct link and may not contain information the Act does not require. | RCW 19.373.020 |
| Consent to collect | Collect consumer health data only with consent for a specified purpose, or as necessary to provide the product or service the consumer asked for. Consent cannot come from accepting general terms of use or from deceptive design. | RCW 19.373.030 |
| Separate consent to share | Sharing requires consent that is separate and distinct from the consent to collect, unless sharing is necessary to provide the requested service. | RCW 19.373.030 |
| Signed authorization to sell | Selling requires a signed authorization naming the specific data, the buyer, and the purpose. It expires one year after signing, and both seller and buyer keep it for six years. | RCW 19.373.070 |
| Consumer rights | Confirm and give access to the data, including a list of every third party and affiliate it was shared with or sold to; let consumers withdraw consent; delete on request, including from backups within six months. | RCW 19.373.040 |
| Response deadlines | Respond within 45 days, extendable once by 45 more days with notice. Offer an appeal process and answer appeals within 45 days. Requests are free up to twice a year. | RCW 19.373.040 |
| Access limits and security | Restrict access to employees, processors, and contractors who need the data, and maintain administrative, technical, and physical security that meets a reasonable standard of care for your industry. | RCW 19.373.050 |
| Processor contracts | Vendors that process consumer health data for you need a binding contract limiting what they can do. A processor that goes beyond the contract is treated as a regulated entity itself. | RCW 19.373.060 |
| Geofencing ban | No one may set up a virtual boundary of 2,000 feet or less around a place that provides in-person health care services to track consumers, collect their health data, or send them health-related messages or ads. | RCW 19.373.080 |
The geofencing ban applies to "any person," not just regulated entities, and it took effect on July 23, 2023, before the rest of the Act.
Enforcement and the litigation risk
RCW 19.373.090 makes a violation an unfair or deceptive act under Washington's Consumer Protection Act. Washington's breach notification law expressly bars private Consumer Protection Act suits for its violations; the My Health My Data Act contains no such bar. That leaves room for private lawsuits, including class actions, not only Attorney General enforcement.
The Act does not have its own breach notification section. If consumer health data is exposed in a breach, Washington's breach notification law still decides who must be told and when, and medical information is already personal information under that law.
How cyber insurance fits
A cyber policy is where claims under the Act would most likely land, but coverage is not automatic. When you review a policy, ask:
- Does privacy liability cover wrongful collection, not just breaches? Many claims under privacy laws allege that data was collected or shared without consent, with no hacker involved. Some cyber forms cover only claims arising from a security failure or data breach.
- Is there a wrongful collection or tracking-technology exclusion? Some insurers exclude claims tied to pixels, session replay, and similar tools, which can remove exactly the claims this Act invites.
- Are regulatory defense and penalties included, and does the policy define "privacy law" broadly enough to include state consumer health data laws?
- What are the sublimits? Regulatory and privacy coverage is sometimes capped well below the main limit.
For an overview of what cyber policies include and exclude, see the complete cyber insurance guide.
A short compliance checklist
- Inventory the health-related data you collect, including intake forms, booking tools, wearables, and website tracking.
- Decide which data falls under HIPAA or another exemption, and which does not.
- Publish a separate consumer health data privacy policy and link it from your homepage and any page that collects personal information.
- Add specific consent steps for collecting and, separately, for sharing.
- Set up a way to receive, verify, and answer access and deletion requests within 45 days, with an appeal path.
- Sign processor contracts with vendors that touch the data.
- Turn off location-based advertising near health care locations.
- Review your cyber policy's privacy liability wording and exclusions with your broker.