Washington's My Health My Data Act: The Privacy Risk Most Businesses Miss

Washington's My Health My Data Act (RCW 19.373) regulates "consumer health data" collected by businesses that are not covered by HIPAA, such as gyms, wellness studios, apps, and retailers. It requires a separate consumer health data privacy policy linked from your homepage, consent before collecting or sharing, and honoring access and deletion requests. Violations are unfair or deceptive acts under Washington's Consumer Protection Act.

By Trella Commercial · Updated October 5, 2026

The short version

  • It is not a health care law. It covers any business that collects health-related data from Washington consumers, and it exempts data already governed by HIPAA and several other federal and state privacy laws.
  • "Consumer health data" is broad. It includes symptoms, measurements, fitness and biometric data, purchases of medication, and even health information inferred from non-health data.
  • The core duties: publish a separate consumer health data privacy policy linked from your homepage, get consent to collect and separate consent to share, sell only with a signed authorization, and answer access and deletion requests within 45 days.
  • It has been in force since 2024. Small businesses have had to comply since June 30, 2024; larger regulated entities since March 31, 2024.
  • It is enforced through the Consumer Protection Act, and unlike Washington's breach notification law, it does not rule out private lawsuits under that Act. Check that your cyber policy's privacy liability coverage responds to claims under it.

Who the law covers

The Act applies to a "regulated entity": any legal entity that conducts business in Washington, or produces or provides products or services targeted to Washington consumers, and that determines how consumer health data is collected and used. A "small business" follows the same rules on a slightly later schedule; it is one that handles data of fewer than 100,000 consumers a year, or fewer than 25,000 consumers while earning less than half its revenue from consumer health data.

A "consumer" is a Washington resident, or anyone whose consumer health data is collected in Washington. People acting in an employment context are not consumers, so employee health records are outside the Act.

Businesses that may be covered without realizing it

BusinessHealth data it may collect
Gyms, yoga and pilates studios, personal trainersInjuries, fitness measurements, heart rate or body composition from wearables
Spas and esthetics businesses (and massage businesses, outside treatment records kept under RCW 70.02)Intake forms listing conditions, medications, allergies, pregnancy; marketing and website data
Wellness, nutrition, and coaching practicesSymptoms, diet, weight, mental health goals
Salons and barbersScalp and skin conditions, allergies
Retailers and ecommercePurchases of health products that reveal a condition
Apps and software companiesTracked symptoms, sleep, cycles, location near health care providers
Dental, therapy, and medical practicesData outside HIPAA, such as website tracking and marketing lists

Whether a particular business is covered depends on the data it actually collects and whether an exemption applies. This table is a prompt for review, not a legal conclusion.

What counts as consumer health data

RCW 19.373.010 defines consumer health data as personal information linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status. The listed examples include:

  • Health conditions, treatment, diseases, or diagnosis
  • Social, psychological, behavioral, and medical interventions
  • Health-related surgeries or procedures
  • Use or purchase of prescribed medication
  • Bodily functions, vital signs, symptoms, or measurements
  • Diagnoses or diagnostic testing
  • Gender-affirming care and reproductive or sexual health information
  • Biometric and genetic data
  • Precise location information that could reasonably indicate a consumer is seeking health care services
  • Data that identifies a consumer as seeking health care services
  • Health information inferred from non-health data, including through algorithms or machine learning

What is exempt

The Act does not apply to protected health information under HIPAA, to health care information handled under Washington's Uniform Health Care Information Act (RCW 70.02), which covers licensed health care providers such as massage therapists, or to personal information governed by laws including the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, and privacy rules adopted by Washington's Insurance Commissioner. A dental office's patient chart is HIPAA data; the same office's website tracking pixels and marketing list may not be.

What the law requires

RequirementWhat it means in practiceStatute
Consumer health data privacy policyA policy listing the categories of health data you collect and why, the sources, what you share, the categories of third parties and specific affiliates you share with, and how consumers exercise their rights. Link it prominently on your homepage. The Attorney General says it must be a separate and distinct link and may not contain information the Act does not require.RCW 19.373.020
Consent to collectCollect consumer health data only with consent for a specified purpose, or as necessary to provide the product or service the consumer asked for. Consent cannot come from accepting general terms of use or from deceptive design.RCW 19.373.030
Separate consent to shareSharing requires consent that is separate and distinct from the consent to collect, unless sharing is necessary to provide the requested service.RCW 19.373.030
Signed authorization to sellSelling requires a signed authorization naming the specific data, the buyer, and the purpose. It expires one year after signing, and both seller and buyer keep it for six years.RCW 19.373.070
Consumer rightsConfirm and give access to the data, including a list of every third party and affiliate it was shared with or sold to; let consumers withdraw consent; delete on request, including from backups within six months.RCW 19.373.040
Response deadlinesRespond within 45 days, extendable once by 45 more days with notice. Offer an appeal process and answer appeals within 45 days. Requests are free up to twice a year.RCW 19.373.040
Access limits and securityRestrict access to employees, processors, and contractors who need the data, and maintain administrative, technical, and physical security that meets a reasonable standard of care for your industry.RCW 19.373.050
Processor contractsVendors that process consumer health data for you need a binding contract limiting what they can do. A processor that goes beyond the contract is treated as a regulated entity itself.RCW 19.373.060
Geofencing banNo one may set up a virtual boundary of 2,000 feet or less around a place that provides in-person health care services to track consumers, collect their health data, or send them health-related messages or ads.RCW 19.373.080

The geofencing ban applies to "any person," not just regulated entities, and it took effect on July 23, 2023, before the rest of the Act.

Enforcement and the litigation risk

RCW 19.373.090 makes a violation an unfair or deceptive act under Washington's Consumer Protection Act. Washington's breach notification law expressly bars private Consumer Protection Act suits for its violations; the My Health My Data Act contains no such bar. That leaves room for private lawsuits, including class actions, not only Attorney General enforcement.

The Act does not have its own breach notification section. If consumer health data is exposed in a breach, Washington's breach notification law still decides who must be told and when, and medical information is already personal information under that law.

How cyber insurance fits

A cyber policy is where claims under the Act would most likely land, but coverage is not automatic. When you review a policy, ask:

  • Does privacy liability cover wrongful collection, not just breaches? Many claims under privacy laws allege that data was collected or shared without consent, with no hacker involved. Some cyber forms cover only claims arising from a security failure or data breach.
  • Is there a wrongful collection or tracking-technology exclusion? Some insurers exclude claims tied to pixels, session replay, and similar tools, which can remove exactly the claims this Act invites.
  • Are regulatory defense and penalties included, and does the policy define "privacy law" broadly enough to include state consumer health data laws?
  • What are the sublimits? Regulatory and privacy coverage is sometimes capped well below the main limit.

For an overview of what cyber policies include and exclude, see the complete cyber insurance guide.

A short compliance checklist

  1. Inventory the health-related data you collect, including intake forms, booking tools, wearables, and website tracking.
  2. Decide which data falls under HIPAA or another exemption, and which does not.
  3. Publish a separate consumer health data privacy policy and link it from your homepage and any page that collects personal information.
  4. Add specific consent steps for collecting and, separately, for sharing.
  5. Set up a way to receive, verify, and answer access and deletion requests within 45 days, with an appeal path.
  6. Sign processor contracts with vendors that touch the data.
  7. Turn off location-based advertising near health care locations.
  8. Review your cyber policy's privacy liability wording and exclusions with your broker.

Common questions

Does the My Health My Data Act apply to my gym or wellness studio?

It can. The Act covers consumer health data collected by businesses not subject to HIPAA, and its definition includes bodily measurements, vital signs, symptoms, and biometric data. A gym or wellness studio that collects injury history, fitness measurements, or wearable data from Washington consumers should assume the Act applies unless an exemption fits.

When did the My Health My Data Act take effect?

Most requirements took effect March 31, 2024 for regulated entities and June 30, 2024 for small businesses. The ban on geofencing around health care locations took effect July 23, 2023.

Can consumers sue under the My Health My Data Act?

The Act makes violations unfair or deceptive acts under Washington's Consumer Protection Act. Unlike Washington's breach notification law, it does not exclude private Consumer Protection Act actions, so consumers as well as the Attorney General can bring claims.

Does HIPAA data fall under the Act?

No. Protected health information governed by HIPAA is exempt. Health-related data a practice collects outside HIPAA, such as through website tracking, marketing, or a separate wellness service, may still be covered.

Does cyber insurance cover My Health My Data Act claims?

It depends on the policy. Breach-related claims usually fall under privacy liability, but claims alleging that data was collected or shared without consent may not, especially if the policy excludes wrongful collection or tracking technologies. Review the wording before you need it.

Sources

This page is general information, not legal advice. Whether the Act applies to your business depends on the data you collect and the exemptions that fit; confirm with a privacy attorney. Statute checked October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.