Nevada
Nevada Consumer Health Data Law (SB 370)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

Nevada's consumer health data privacy law is a standalone statute that protects health information falling outside HIPAA, enacted as Senate Bill 370 in 2023 and codified in Nevada Revised Statutes Chapter 603A. It took effect March 31, 2024, and it closely mirrors Washington's My Health My Data Act: it requires a published consumer health data privacy policy, affirmative consent before a business collects or shares such data, separate authorization before any sale, and it bans geofencing around medical facilities.
As of 2026, the single most important difference from the Washington model is enforcement. Nevada's law has no private right of action. A violation is treated as a deceptive trade practice that only the Nevada Attorney General may pursue, and the civil penalty under Nevada's consumer protection statutes runs up to $10,000 per violation for breaching a resulting court order or injunction, or up to $15,000 per violation if a court finds the violation was willful. That makes the Nevada law materially easier to defend against than Washington's, where private plaintiffs can sue directly.
Jurisdiction scope: This covers Nevada's consumer health data privacy law (SB 370, NRS ch. 603A) and Nevada SB 220. It is general legal information, not legal advice.
What Nevada's consumer health data law is and when it took effect
Nevada's consumer health data privacy law began as Senate Bill 370 during the 82nd (2023) session of the Nevada Legislature. Governor Joe Lombardo signed it in June 2023, and it was codified into Nevada Revised Statutes Chapter 603A, the same chapter that already housed Nevada's data security and earlier privacy provisions. The consumer health data sections begin at NRS 603A.400, with the substantive duties grouped at NRS 603A.500 to 603A.550.
The law took effect March 31, 2024. Nevada did not phase in a delayed compliance date for small businesses, so every covered entity faced the same effective date. That uniform start contrasts with Washington, which gave small businesses an extra grace period before their obligations began.
The statute fills a gap that HIPAA leaves open. HIPAA governs covered entities such as hospitals, health plans, and their business associates, but it does not reach the health-adjacent data that apps, websites, advertisers, and data brokers collect outside the clinical setting. Nevada's law is aimed squarely at that non-HIPAA health data. For the broader Nevada landscape, see the Nevada data privacy laws parent page.
Who is covered: the "regulated entity" test
The law applies to a "regulated entity." Under NRS Chapter 603A, a regulated entity is a person who conducts business in Nevada, or who produces or provides products or services that are targeted to consumers in Nevada, and who determines the purpose and means of processing, sharing, or selling consumer health data. The "determines the purpose and means" language mirrors the controller concept used in comprehensive privacy laws.
A defining feature is that Nevada attached no numerical threshold. Many state privacy laws apply only to businesses above a revenue floor or a consumer-count floor, such as 100,000 consumers. Nevada's consumer health data law has neither. If an entity meets the conduct-and-control test and handles consumer health data, it is covered regardless of size.
The law carves out both entities and data that are already regulated elsewhere. The HIPAA carve-out is entity-level: NRS 603A.490(1)(a) exempts any person or entity that is subject to HIPAA outright, so a HIPAA-regulated organization sits outside the consumer health data regime entirely, not merely for its HIPAA-regulated records. The Gramm-Leach-Bliley carve-out in NRS 603A.490(1)(b) is mixed, reaching a financial institution or an affiliate of a financial institution that is subject to that Act as well as the personally identifiable information the Act regulates. Those exclusions avoid double regulation of clinical and financial records. The remaining field, the health-adjacent data collected by consumer apps and online services, is what the law targets.
What counts as "consumer health data"
The statute defines consumer health data broadly. It is personal information that is linked or reasonably capable of being linked to a consumer and that identifies the consumer's past, present, or future health status. That phrasing deliberately follows Washington's My Health My Data Act so that the two laws cover a similar universe of data.
In practice, consumer health data reaches well beyond diagnoses. It can include information about health conditions and treatments, medications, bodily and reproductive functions, gender-affirming or reproductive care, biometric and genetic data, and precise geolocation data that indicates a consumer is seeking health care services. Data that merely reflects ordinary shopping habits with no link to health status generally falls outside the definition.
Because the definition is tied to whether data identifies health status, the same raw data point can be in or out depending on how it is used. Location data that simply shows a route is not health data, but location data used to infer that a consumer visited a reproductive health clinic can be. That use-sensitive line is why entities have to evaluate the purpose of their processing, not just the data categories on paper.

Core duties of a regulated entity
Nevada's law imposes a stack of obligations on regulated entities. First, an entity must maintain and prominently publish a consumer health data privacy policy. The policy has to disclose the categories of consumer health data collected and the purpose, the categories of sources, the categories shared and the third parties or affiliates that receive the data, and how a consumer may exercise the rights the statute grants.
Second, an entity generally must obtain a consumer's affirmative, voluntary consent before it collects or shares consumer health data, unless the collection or sharing is necessary to provide a product or service the consumer requested. Consent to share must be separate and distinct from the consent to collect, and NRS 603A.500(3) requires the consent request itself to clearly and conspicuously disclose the categories of consumer health data involved, the purpose and intended use, the categories of persons and entities the data will be shared with, and how the consumer may withdraw consent. Nevada does not define consent by statute, so it has no counterpart to Washington's rule that acceptance of a general or broad terms-of-use agreement cannot constitute consent (RCW 19.373.010).
Third, the law treats selling consumer health data as a higher-risk activity. A regulated entity may not sell consumer health data without first obtaining a separate, valid authorization from the consumer that is distinct from the consent used for collection or sharing. The authorization must describe the specific data, the recipient, and the purpose, and it expires after a set period.
Fourth, entities must restrict access to consumer health data so that only employees, processors, and contractors who need it for a permitted purpose can reach it, and they must apply reasonable administrative, technical, and physical safeguards. When an entity uses a processor, it must bind that processor by contract to the same protective terms.
Consumer rights under the Nevada law
The statute gives Nevada consumers a set of rights they can exercise against regulated entities. A regulated entity must respond to a consumer's request without undue delay and not later than 45 days after authenticating it, though it may extend that period by up to another 45 days when reasonably necessary, with notice to the consumer (NRS 603A.510). A consumer may confirm whether the entity is collecting, sharing, or selling the consumer's health data and may obtain a list of all third parties with which it has been shared or to which it has been sold (NRS 603A.505(1)). That list does not extend to affiliates, because NRS 603A.485 defines a third party to exclude an affiliate of a regulated entity.
A consumer may also request deletion of consumer health data. When a valid deletion request is made, the regulated entity must complete the deletion not later than 30 days after authenticating the request (NRS 603A.515), must remove the data from its own records, and must notify its affiliates, processors, and other recipients to delete the data as well, subject to limited exceptions recognized by law.
Finally, a consumer who previously gave consent may withdraw it. Once consent is withdrawn, the entity must stop the collecting, sharing, or selling that depended on that consent. These rights, confirm and obtain the third-party list, delete, and withdraw consent, are the heart of the consumer-facing protection and parallel the rights structure in Washington's act.

The geofencing ban and the 1,750-foot radius
One of the most concrete prohibitions in the law is its ban on geofencing around health care locations. A geofence is a virtual boundary that uses location technology to detect when a device enters or leaves a defined area. The statute prohibits a person from implementing a geofence within 1,750 feet of a medical facility or a provider of in-person health care services.
The ban applies when the geofence is used to identify or track consumers who are seeking in-person health care services, to collect consumer health data from those consumers, or to send notifications, messages, or advertisements to them based on their consumer health data or their health care. The prohibition stands even if the consumer would otherwise have consented, which makes it an outright bar rather than a consent-gated rule.
Nevada's choice to specify a fixed 1,750-foot radius is a notable drafting difference, though a difference of degree rather than kind. Washington's My Health My Data Act does not restate a distance in the operative ban itself, but its definitions section does: RCW 19.373.010 defines a geofence as a virtual boundary of 2,000 feet or less from the facility's perimeter, so Washington's ban is effectively capped at up to 2,000 feet, a wider radius than Nevada's. By writing 1,750 feet directly into the operative prohibition, Nevada still gave businesses and the Attorney General a bright-line measurement without a cross-reference to the definitions.
Nevada vs. Washington: the no-private-right-of-action difference
Nevada modeled its law on Washington's My Health My Data Act, but the enforcement design is where they diverge most. Washington made any violation of its act a per se violation of the Washington Consumer Protection Act, which carries a private right of action. That means individual consumers in Washington can sue regulated entities directly, and the litigation risk has driven much of the compliance anxiety around the Washington law.
Nevada took the opposite approach. A violation of Nevada's consumer health data law is a deceptive trade practice that may be enforced only by the Nevada Attorney General. There is no private right of action, so consumers cannot file their own lawsuits to enforce the statute. The Attorney General may seek injunctive relief and civil penalties under Nevada's deceptive-trade-practice framework of up to $10,000 per violation for breaching a resulting court order or injunction, and up to $15,000 per violation if a court finds the violation was willful.
That single design choice substantially changes the risk picture. Both laws impose nearly identical substantive duties, but the absence of private enforcement in Nevada removes the class-action exposure that defines the Washington regime. The table below summarizes the principal contrasts.
| Feature | Nevada SB 370 (NRS ch. 603A) | Washington MHMDA (ch. 19.373 RCW) |
|---|---|---|
| Effective date | March 31, 2024 (no small-business delay) | March 31, 2024; small businesses June 30, 2024; geofence ban July 23, 2023 |
| Covered party | Regulated entity; no revenue or volume threshold | Regulated entity; no revenue or volume threshold |
| Consent to collect or share | Required (with requested-service exception) | Required (with requested-service exception) |
| Authorization to sell | Separate written authorization required | Separate written authorization required |
| Geofence ban radius | Within 1,750 feet of a medical facility | Up to 2,000 feet, per the statutory definition of geofence (RCW 19.373.010) |
| Private right of action | None | Yes (per se violation of Washington CPA) |
| Public enforcer | Nevada Attorney General | Washington Attorney General |
| Penalty exposure | Up to $10,000 per violation for a court-order breach, up to $15,000 if willful (deceptive trade practice) | CPA remedies, including consumer damages |
For a side-by-side of the broader landscape, see the state data privacy law comparison page and the dedicated Washington My Health My Data Act guide.
Nevada SB 220: the older opt-out-of-sale law
Nevada had a narrower internet privacy law in place years before the consumer health data statute. Senate Bill 220 of the 2019 session is codified at NRS 603A.300 to 603A.360 and took effect October 1, 2019, several months before California's CCPA. It is far more limited in scope than SB 370 and addresses a single right.
SB 220 applies to an "operator" of a commercial website or online service that collects covered information from Nevada consumers who use the site or service. Covered information under NRS 603A.320 is a defined list of personally identifiable items, such as a first and last name, a physical or email address, a telephone number, a Social Security number, or an identifier that allows a specific person to be contacted. The law gives Nevada consumers the right to submit a verified request directing an operator not to sell that covered information.
Operators must set up a designated request address to receive these opt-out requests and must respond within 60 days, with a possible 30-day extension if reasonably necessary and the consumer is notified. Like the consumer health data law, SB 220 has no private right of action. Enforcement rests with the Nevada Attorney General, who may seek an injunction or a civil penalty of up to $5,000 per violation. SB 220 is best understood as a single-right opt-out law that sits alongside, and is much narrower than, the consumer health data regime created by SB 370.
Related guides
- Nevada data privacy laws parent hub
- Washington My Health My Data Act
- State data privacy law comparison
- What is the CCPA?
More Nevada Privacy Laws
More Nevada Laws
Frequently Asked Questions
What is Nevada's consumer health data privacy law?
It is a Nevada statute enacted as Senate Bill 370 in 2023 and codified in NRS Chapter 603A (the consumer health data provisions at NRS 603A.400 et seq.). It protects health information that falls outside HIPAA, requires a published privacy policy and consent before collecting or sharing consumer health data, requires separate authorization before any sale, bans geofencing near medical facilities, and gives consumers confirmation, deletion, and consent-withdrawal rights. It took effect March 31, 2024.
Does Nevada's law have a private right of action?
No. This is the most important difference from Washington's My Health My Data Act. A violation of the Nevada law is a deceptive trade practice that only the Nevada Attorney General may enforce, with civil penalties of up to $10,000 per violation for breaching a resulting court order, or up to $15,000 per violation if a court finds the violation was willful. Consumers cannot sue regulated entities directly under the statute.
When did Nevada's consumer health data law take effect?
March 31, 2024. Unlike Washington, Nevada did not give small businesses a delayed compliance date, so all covered regulated entities faced the same effective date.
Who has to comply with the law?
A regulated entity, defined as a person who conducts business in Nevada or targets products or services to Nevada consumers and who determines the purpose and means of processing consumer health data. There is no revenue or data-volume threshold, so size does not exempt an entity. The carve-outs differ in kind: NRS 603A.490(1)(a) exempts any person or entity that is subject to HIPAA outright, while the Gramm-Leach-Bliley carve-out reaches a financial institution or its affiliate that is subject to that Act as well as the personally identifiable information the Act regulates.
What is consumer health data under the Nevada law?
Personal information that is linked or reasonably capable of being linked to a consumer and that identifies the consumer's past, present, or future health status. It can include health conditions, treatments, medications, reproductive or gender-affirming care, biometric and genetic data, and precise location data indicating a consumer is seeking health care. The definition closely tracks Washington's My Health My Data Act.
What is the geofencing rule?
The law prohibits a person from using a geofence within 1,750 feet of a medical facility or provider of in-person health care services to identify or track consumers seeking care, collect consumer health data, or send health-related messages or advertisements. Nevada specifies the 1,750-foot radius directly in the operative ban, while Washington's act defines a geofence as a boundary of 2,000 feet or less from the facility (RCW 19.373.010), effectively capping its ban at up to 2,000 feet.
Can a business sell consumer health data in Nevada?
Only with a separate, valid written authorization from the consumer that is distinct from the consent used to collect or share the data. The authorization must describe the specific data, the recipient, and the purpose, and it expires after a set period. Without that authorization, selling consumer health data is prohibited.
What is Nevada SB 220 and how is it different?
SB 220 (2019), codified at NRS 603A.300 to 603A.360, is an older and much narrower law. It lets a Nevada consumer direct an operator of a website or online service not to sell the consumer's covered information, and the operator must respond within 60 days. It covers only opt-out-of-sale, not the broad health data duties in SB 370. Like SB 370, it has no private right of action and is enforced by the Attorney General with penalties up to $5,000 per violation.
Updates
Corrected the consumer-rights section (Nevada's request right produces a list of third parties, which by statute excludes affiliates), clarified that the HIPAA exemption applies to the entity itself rather than only to HIPAA-regulated data, and replaced a Washington-specific consent rule with Nevada's own consent-disclosure requirements under NRS 603A.500.
Corrected the Nevada consumer health data law's penalty figure (violations are enforceable by the Attorney General for up to $10,000 per violation for breaching a court order, or up to $15,000 if willful, not $5,000), clarified that Washington's geofencing ban is effectively bounded at 2,000 feet rather than unlimited, added the law's 45-day request-response and 30-day deletion-completion deadlines, and fixed a citation range that had listed the statute as running to NRS 603A.590 instead of 603A.550.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Nevada Revised Statutes, Chapter 603A: SECURITY AND PRIVACY OF PERSONAL INFORMATION
§ 603A.500Collection and sharing of consumer health data by regulated entity prohibited; exceptions; required disclosures for request for consent to collect or share consumer health data.In forcecited in 2 of our articles
1. A regulated entity shall not collect consumer health data except: (a) With the affirmative, voluntary consent of the consumer; or (b) To the extent necessary to provide a product or service that the consumer to whom the consumer health data relates has requested from the regulated entity. 2. A regulated entity shall not share consumer health data except: (a) With the affirmative, voluntary consent of the consumer to whom the consumer health data relates, which must be separate and distinct from the consent provided pursuant to subsection 1 for the collection of the data; (b) To the extent necessary to provide a product or service that the consumer to whom the consumer health data relates has requested from the regulated entity; or (c) Where required or authorized by another provision of law. 3. Any consent required by this section must be obtained before the collection or sharing, as applicable, of consumer health data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at leg.state.nv.us
Also relied on in: Nevada Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Revised Code of Washington
§ 19.373.010Definitions.In forcecited in 6 of our articles
The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1) "Abortion" means the termination of a pregnancy for purposes other than producing a live birth. (2) "Affiliate" means a legal entity that shares common branding with another legal entity and controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company. (3) "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights afforded in this chapter is being made by, or on behalf of, the consumer who is entitled to exercise such consumer rights with respect to the consumer health data at issue.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: MHMDA Consumer Rights (Washington), What Is MHMDA? WA My Health My Data Act, Washington Employee Monitoring Laws: Biometric Privacy, Social Media, and Surveillance (2026)
Explore the law
This article also draws on these acts and chapters (opening at their first section): Nevada Revised Statutes, Chapter 603A: SECURITY AND PRIVACY OF PERSONAL INFORMATION § 603A.010 (Definitions.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Nevada SB 370 (82nd Session, 2023): Enrolled Bill Text(leg.state.nv.us).gov
- Nevada SB 370 (82nd Session, 2023): Bill Overview and History(leg.state.nv.us).gov
- NRS 603A.500 to 603A.550: Consumer Health Data (operative duties)(leg.state.nv.us).gov
- Nevada Office of the Attorney General: Bureau of Consumer Protection(ag.nv.gov).gov
- Nevada SB 220 (80th Session, 2019): Enrolled Bill Text (NRS 603A.300 to 603A.360)(leg.state.nv.us).gov
- Nevada SB 220 (80th Session, 2019): Bill Overview and History(leg.state.nv.us).gov
- Washington My Health My Data Act, Chapter 19.373 RCW (Full Chapter)(app.leg.wa.gov).gov
- NRS 603A.400 to 603A.490: Consumer Health Data Definitions and Applicability(leg.state.nv.us)
- RCW 19.373.010: My Health My Data Act Definitions, including consent(app.leg.wa.gov)