Skip to content
Pro IT NW

Blog · 6 min read ·

Share

Washington My Health My Data Act: Does It Apply?

There is no future compliance date here. Every effective date in the My Health My Data Act has already passed — section 10 since July 23, 2023, and sections 4 through 9 since March 31, 2024 for most regulated entities (June 30, 2024 for small businesses). If the Act applies to your organization, it already applies, and has for well over a year.

Washington's My Health My Data Act has a search-volume problem: a lot of people are still typing "does this apply to us" into a search bar for a law that has been fully in force since June 2024. There's no pending deadline to plan around. The only question worth answering is whether it already reaches your organization — and, if it does, what an IT team specifically needs to have in place.

Where the Act came from, and why it's not just a HIPAA overlay

The Washington My Health My Data Act (HB 1155) passed the state legislature on April 17, 2023, and was signed into law by Governor Jay Inslee on April 27, 2023. It's codified as RCW 19.373. According to the Washington State Attorney General's office, it is "the first privacy-focused law in the country to protect personal health data that falls outside the ambit of the Health Insurance Portability and Accountability Act, or HIPAA." The Attorney General's office also notes that 76% of Washingtonians expressed support for the Act — which is worth knowing if you're explaining to a skeptical stakeholder why this isn't a compliance fad.

That "outside the ambit of HIPAA" framing is the entire reason this law matters to organizations that already think of themselves as HIPAA-compliant and therefore covered. HIPAA governs a specific set of covered entities and business associates handling protected health information. My Health My Data reaches consumer health data wherever it sits, including in systems, vendors, and departments that HIPAA never touches.

Who's actually covered: the regulated-entity test

The Attorney General's FAQ is direct about who is caught by the Act. Generally, "all persons and businesses that conduct business in Washington (or provide services or products to Washington), and that collect, process, share, or sell consumer health data are impacted by the Act." More precisely, subject to some exceptions, a regulated entity is a legal entity that "(a) conducts business in Washington, or produces or provides products or services that are targeted to consumers in Washington and (b) alone or jointly with others, determines the purpose and means of collecting, processing, sharing, or selling of consumer health data."

Two details in that test matter for IT planning, not just legal review:

  • Location doesn't decide it. The Attorney General states directly: "An entity that only stores data in Washington is not a regulated entity." Merely hosting data in a Washington data center, or in a cloud region physically located in the state, doesn't by itself pull you into scope. What matters is whether you determine the purpose and means of collecting, processing, sharing, or selling consumer health data connected to Washington consumers.
  • Processors and out-of-state entities aren't exempt. A processor handles consumer health data on behalf of a regulated entity or small business, and out-of-state processors must comply with the Act. Separately, sections 9 and 10 apply to "persons" — a broad category including corporations, trusts, unincorporated associations, and partnerships — and out-of-state entities that meet that definition must comply with those two sections regardless of where they're headquartered.

A "small business" category exists with a later compliance date for sections 4 through 9, which is the only place company size changes anything in the Attorney General's guidance.

Effective dates and who enforces this

Every date below has already passed. The Attorney General's FAQ lays out the schedule "on a section-by-section basis": "All persons, as defined in the Act, must comply with section 10 beginning July 23, 2023. Regulated entities that are not small businesses must comply with sections 4 through 9 beginning March 31, 2024. Small businesses, as defined in the Act, must comply with sections 4 through 9 beginning June 30, 2024." The guidance adds that for sections 4 through 9, the effective dates apply to the entirety of each section, not just the specific subsections where the dates appear.

Enforcement isn't limited to a regulator with discretion to decline a case. Per the Attorney General's FAQ, "any violation of the Act is a per se violation of the Washington Consumer Protection Act (CPA), RCW 19.86, which is enforced by the Attorney General as well as through private action." A per se violation means a court doesn't need to separately evaluate whether the conduct was unfair or deceptive under the CPA's general standard — the My Health My Data violation itself establishes it. That, combined with private enforcement, is a materially different exposure than a purely regulator-enforced statute, and it's the fact that should get a compliance question routed to counsel rather than shelved.

What this means operationally for IT

None of what follows is legal advice — it's the practical, IT-side work that a "yes, we're covered" answer to the questions above tends to create. Four areas come up repeatedly.

  1. Know where consumer health data actually lives and flows. Before anyone can answer a deletion request, honor a homepage-disclosure obligation, or scope a data-sharing agreement, the organization needs an inventory: which systems, mailboxes, SharePoint sites, CRM fields, and vendor exports touch consumer health data. This is squarely a data-classification and governance problem — the kind of work Microsoft Purview's sensitivity labels and content scanning are built for — and it has to run before any policy work, not after.
  2. Inferences count, not just explicit health records. The Attorney General's guidance is unambiguous that inferred data is in scope: "The definition of consumer health data includes information that is derived or extrapolated from nonhealth data when that information is used by a regulated entity or their respective processor to associate or identify a consumer with consumer health data." The FAQ cites the well-known 2012 media report describing a retailer that assigned shoppers a "pregnancy prediction score" based on purchase patterns, noting that "this information is protected consumer health data even though it was inferred from nonhealth data." Any analytics, personalization, or marketing pipeline that scores or segments customers based on purchase history needs to be evaluated for whether it's producing exactly this kind of inference — ordinary purchases of toiletries alone don't count, but an app or model that draws a health-status inference from them does.
  3. Deletion requests and the six-year retention aren't actually in conflict. Consumers can request deletion of their consumer health data, including from archived or backup systems. Separately, when a consumer authorizes the sale of their consumer health data, both the seller and purchaser must retain a copy of that authorization for six years. The Attorney General's guidance resolves the apparent tension directly: a business can satisfy both obligations "by redacting the portion of the valid authorization that specifies the consumer health data for sale," for example with a redaction stating "REDACTED pursuant to consumer deletion request on [insert date]." That's a records-management and access-control design point, not a legal one — someone has to be able to execute that redaction reliably and log when it happened.
  4. The homepage link requirement is a distinct, standalone obligation. A regulated entity or small business "shall prominently publish a link to its consumer health data privacy policy on its homepage," and per the Attorney General's guidance, that "must be a separate and distinct link" that "may not contain additional information not required under the My Health My Data Act." In practice, that means it can't be folded into a general privacy policy link — it needs its own, separately labeled link on the homepage, which is a straightforward web change but an easy one to miss during a site redesign.

We covered the Washington Attorney General's separate 2026 Data Privacy Report — on breach notifications and where the office's enforcement attention is headed generally — in Washington's first data privacy report and the mid-market. That report is a different document from the My Health My Data Act FAQ discussed here, but it's the same office, and it's a useful read for the same reason: it tells you what Washington's privacy enforcer is currently paying attention to.

Sources

Every quoted passage above is verbatim from that page. The Act itself is codified at RCW 19.373; we are describing what the Attorney General's office says about it, not quoting or summarizing the statute's text directly.


This page is general information about a state privacy law, not legal advice, and it should not be relied on for specific applications of the Act to your organization. Pro IT NW is an IT consultancy, not a law firm; for questions about whether the My Health My Data Act applies to you, what your exposure is, or how to structure a compliance program, talk to counsel. What we do is the Microsoft-stack engineering work that tends to follow that legal analysis: data discovery and classification with Microsoft Purview, access review, retention and deletion workflows, and Conditional Access and identity controls around wherever consumer health data turns out to live.

Questions we get asked

Does the Washington My Health My Data Act apply to my business?
It depends on whether you meet the Attorney General's definition of a regulated entity: a legal entity that conducts business in Washington, or produces or provides products or services targeted to consumers in Washington, and that alone or jointly with others determines the purpose and means of collecting, processing, sharing, or selling consumer health data. A separate 'small business' category exists with a later compliance date. Out-of-state entities that act as processors on behalf of a regulated entity or small business must comply with the Act, and out-of-state entities that fall within the Act's broader definition of 'person' must comply with sections 9 and 10.
When did the My Health My Data Act take effect?
On a section-by-section basis, and all of it is now in force. All persons, as defined in the Act, had to comply with section 10 beginning July 23, 2023. Regulated entities that are not small businesses had to comply with sections 4 through 9 beginning March 31, 2024. Small businesses had to comply with sections 4 through 9 beginning June 30, 2024.
Is there a private right of action under the My Health My Data Act?
Yes. Section 11 of the Act provides that any violation is a per se violation of the Washington Consumer Protection Act, RCW 19.86, which is enforced by the Attorney General as well as through private action.
Does storing data in Washington make us subject to it?
On its own, no. The Attorney General's guidance states plainly that an entity that only stores data in Washington is not a regulated entity. That said, the analysis doesn't stop there: if you process consumer health data on behalf of a regulated entity or a small business, you're a processor and you must comply regardless of where you're located, and if you fall within the Act's definition of 'person,' sections 9 and 10 reach you too.
Is the My Health My Data Act the same as HIPAA?
No. The Attorney General describes the My Health My Data Act as the first privacy-focused law in the country to protect personal health data that falls outside the ambit of HIPAA. It's a separate, additional layer of protection for health data your organization holds that HIPAA doesn't reach — not a restatement of HIPAA and not a replacement for it.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back with scope and a fixed-fee range.