Washington
Washington Data Privacy Laws: My Health My Data Act & More (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Washington has no comprehensive consumer privacy law as of 2026, but the My Health My Data Act (Chapter 19.373 RCW) fills a critical gap: it covers health data far beyond HIPAA's reach, bans geofencing near healthcare facilities, and gives consumers a private right of action through the Washington Consumer Protection Act.
Overview of Data Privacy Law in Washington State
Washington state occupies a unique position in the American data privacy landscape. Despite being home to some of the largest technology companies in the world, the state has repeatedly failed to enact a comprehensive consumer privacy law similar to the California Consumer Privacy Act or Virginia Consumer Data Protection Act.
Washington has not left its residents without protections, however. The state has enacted several targeted privacy statutes addressing specific categories of data and practices. These include one of the strongest health data privacy laws in the nation, a biometric identifier protection statute, and robust data breach notification requirements.
This article covers every major data privacy law currently in effect in Washington, the history of failed comprehensive legislation, what may change in the 2025-2026 legislative session, and the federal overlay that applies to Washington residents regardless of state law.
The Washington My Health My Data Act (MHMDA)
What the Law Covers

The Washington My Health My Data Act, codified as Chapter 19.373 RCW, was signed into law by Governor Jay Inslee on April 27, 2023. It took effect for most regulated entities on March 31, 2024, with small businesses given until June 30, 2024, to comply. The geofencing prohibition took effect earlier, on July 23, 2023.
The MHMDA was passed largely in response to the U.S. Supreme Court decision in Dobbs v. Jackson Women's Health Organization, which overturned Roe v. Wade. Lawmakers were concerned that health data collected by apps, websites, and other digital services could be used to identify individuals seeking reproductive healthcare.
Extremely Broad Definition of Consumer Health Data
The MHMDA defines consumer health data far more broadly than traditional health privacy laws like HIPAA. Under RCW 19.373.010, consumer health data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status.
The statute provides a nonexhaustive list of categories that qualify as health data, including:
- Health conditions, treatments, diseases, or diagnoses
- Social, psychological, behavioral, and medical interventions
- Surgeries, procedures, and use of prescribed medications
- Bodily functions, vital signs, and symptoms
- Reproductive and sexual health information
- Biometric data used in a health context
- Gender-affirming care information
- Data that identifies a consumer seeking healthcare services
- Precise location information that could reveal health-related visits
- Any data derived or inferred from non-health information that relates to health
This broad scope means the law reaches far beyond traditional healthcare providers. Any company that collects data that could reveal something about a person's health status, even indirectly, may be subject to the MHMDA.
Key Consumer Rights Under the MHMDA
The law grants Washington consumers several important rights regarding their health data:
Right to Confirm and Access. Consumers can confirm whether a regulated entity is collecting, sharing, or selling their consumer health data, access that data, and obtain a list of all third parties and affiliates who received it along with a way to contact them.
Right to Deletion. Consumers can request that a regulated entity delete their consumer health data.
Right to Withdraw Consent. Consumers can withdraw previously given consent for collection and sharing of their health data.
Consent Requirements
The MHMDA imposes strict consent requirements on regulated entities. Before collecting consumer health data, a business must obtain the consumer's consent for the specific purpose of collection. Before sharing consumer health data, the business must obtain separate and distinct consent from the consent given for collection.
This dual-consent model means blanket privacy policy acceptance is not sufficient. Companies need clear, affirmative, and purpose-specific consent for both collecting and sharing health data.
Consumer Health Data Privacy Policy
Every regulated entity and small business must maintain a publicly available consumer health data privacy policy. This policy must clearly disclose:
- The categories of consumer health data collected and the purpose for each
- The categories of sources from which consumer health data is collected
- The categories of consumer health data that is shared
- A list of the categories of third parties and specific affiliates that receive shared data
Geofencing Ban Near Healthcare Facilities
One of the most notable provisions of the MHMDA is an absolute ban on geofencing near healthcare facilities. Under RCW 19.373.080, it is unlawful for any person to implement a geofence around an entity that provides in-person healthcare services where that geofence is used to:
- Identify or track consumers seeking healthcare services
- Collect consumer health data from consumers
- Send notifications, messages, or advertisements to consumers related to their health data or healthcare services
The law defines geofence as technology that uses GPS coordinates, cell tower connectivity, cellular data, RFID, Wi-Fi data, or any other spatial or location detection method to establish a virtual boundary within 2,000 feet of a healthcare facility.
This prohibition has no exceptions. Even consumer consent cannot authorize geofencing near healthcare facilities for these purposes.
Private Right of Action and Enforcement
The MHMDA is enforced through the Washington Consumer Protection Act (CPA), Chapter 19.86 RCW. A violation of the MHMDA is a per se violation of the CPA, meaning no additional proof of unfair or deceptive conduct is required.
This matters because the CPA provides both public and private enforcement:
Attorney General Enforcement. The Washington Attorney General can bring enforcement actions under the CPA for MHMDA violations.
Private Right of Action. Individual consumers who are injured by a violation can file a civil lawsuit seeking injunctive relief, actual damages, and reasonable attorney fees and costs. Courts may award treble damages up to $25,000.
The inclusion of a private right of action makes the MHMDA significantly stronger than many other state privacy laws. It means companies face litigation risk not only from the state but from individual consumers and class action plaintiffs.
MHMDA Private Litigation: First Cases (2025)

The MHMDA's private right of action produced its first class action cases in 2025, more than a year after the law's March 31, 2024, effective date.
Amazon SDK Lawsuit (February 2025). On February 10, 2025, a Washington resident filed the first class action under the MHMDA in the Western District of Washington. The complaint alleges that Amazon.com, Inc. and Amazon Advertising, LLC collected location data from tens of millions of users through Amazon's software development kits (SDKs) without affirmative consent and used that information for targeted advertising and third-party data sales. The lawsuit also asserts claims under the federal Wiretap Act and Washington's Consumer Protection Act. As of May 2026, the case is pending.
Uncle Ike's Cannabis Retailer Lawsuit (November 2025). A second class action was filed against Uncle Ike's, a Seattle-area cannabis retailer, alleging the company configured website tracking pixels and cookies to transmit customers' personally identifiable information to Google and other third parties without consent. The complaint specifically alleges the trackers captured details about medical marijuana card appointments and specific products purchased. This case presents a significant question about whether location and purchase data at a cannabis retailer constitutes "consumer health data" under RCW 19.373.010.
The Washington Legislature anticipated private litigation volume. RCW 44.28.819 requires the Joint Legislative Audit and Review Committee to compile a report on enforcement actions brought under the MHMDA and submit findings to the Governor and relevant legislative committees by September 30, 2030.
Small Business Provisions
The MHMDA defines a small business as a regulated entity that satisfies one or both of the following thresholds: it collects, processes, sells, or shares the consumer health data of fewer than 100,000 consumers during a calendar year, or it derives less than 50% of gross revenue from the collection, processing, selling, or sharing of consumer health data and processes data of fewer than 25,000 consumers.
Small businesses received an extended compliance deadline of June 30, 2024, rather than the March 31, 2024, date that applied to larger regulated entities.
Washington Biometric Privacy Law (RCW 19.375)
Scope and Definitions
Washington enacted its biometric privacy law through House Bill 1493, which was signed on May 16, 2017, and is codified as Chapter 19.375 RCW.
Under RCW 19.375.010, a biometric identifier is defined as data generated by automatic measurements of an individual's biological characteristics, including:
- Fingerprints
- Voiceprints
- Eye retinas and irises
- Other unique biological patterns or characteristics used to identify a specific individual
The definition explicitly excludes physical or digital photographs, video or audio recordings (and data generated from them), and information collected, used, or stored for healthcare treatment, payment, or operations under HIPAA.
Notice, Consent, and Enrollment Requirements
Under RCW 19.375.020, a person may not enroll a biometric identifier in a database for a commercial purpose without first:
- Providing notice to the individual
- Obtaining consent from the individual
- Providing a mechanism to prevent the subsequent use of the biometric identifier for a commercial purpose
The notice requirement is satisfied through a disclosure that is reasonably designed to be readily available to affected individuals. The form and manner of the notice and consent depend on the context.
Retention and Security Requirements
Any person who possesses biometric identifiers enrolled for a commercial purpose must:
- Take reasonable care to guard against unauthorized access to and acquisition of biometric identifiers
- Retain biometric identifiers no longer than is reasonably necessary to comply with a court order, statute, or public records retention schedule, or to protect against or prevent actual or potential fraud and criminal activity
Enforcement: No Private Right of Action
A critical distinction between Washington's biometric law and the Illinois Biometric Information Privacy Act (BIPA) is that Washington law has no private right of action. A violation of RCW 19.375 is an unfair or deceptive act under the Consumer Protection Act (RCW 19.86), but enforcement is limited to the Attorney General.
This means individual consumers cannot sue businesses directly for violations of the biometric privacy law. Only the Washington Attorney General can bring enforcement actions.
Exemptions
The biometric privacy law does not apply to:
- Financial institutions or their affiliates subject to Title V of the federal Gramm-Leach-Bliley Act of 1999
- Activities subject to Title V of the federal Health Insurance Portability and Accountability Act (HIPAA) of 1996
Data Breach Notification Law (RCW 19.255)
Notification Requirements

Washington's data breach notification law is codified as Chapter 19.255 RCW. It requires any person or business that conducts business in Washington and owns or licenses data containing personal information to notify affected individuals following the discovery of a security breach.
Under RCW 19.255.010, notification must be made to any Washington resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and was not secured through encryption or other methods.
An exception exists where notice is not required if the breach is not reasonably likely to subject consumers to a risk of harm.
What Constitutes Personal Information
Under RCW 19.255.005, personal information includes an individual's first name or first initial and last name combined with any of the following:
- Social Security number
- Driver license or state identification card number
- Account number, credit card number, or debit card number in combination with any required security code, access code, or password
- Full date of birth
- Health insurance policy number or subscriber identification number combined with a unique identifier used by an insurer
- Student, military, or passport identification number
- Any information about a consumer's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional
Attorney General Notification
When a breach affects more than 500 Washington residents, the person or business must notify the Washington Attorney General within 30 days of discovering the breach.
Content of Notice
Breach notifications must be written in plain language and include, at minimum:
- The name and contact information of the reporting entity
- A list of the types of personal information involved in the breach
- The toll-free telephone numbers and addresses of major credit reporting agencies (if the breach exposed financial data)
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that the notification would impede a criminal investigation. Once law enforcement determines notification will not compromise the investigation, the notice must be sent.
Liability
Under RCW 19.255.020, a processor or business that fails to take reasonable care to guard against unauthorized access to account information, resulting in a breach, is liable to a financial institution for the reasonable actual costs of reissuing affected credit and debit cards. This liability applies only to a "business" as narrowly defined (an entity processing more than six million credit/debit card transactions annually) or a processor/vendor acting on its behalf, not to general damages claims by any injured person.
The Failed Washington Privacy Act
Legislative History
Washington came closer than almost any other state to passing a comprehensive consumer privacy law, yet the effort failed three consecutive years:
SB 5376 (2019). Introduced by Senator Reuven Carlyle, this was the first version of the Washington Privacy Act. It passed the Senate but died in the House in April 2019. The primary disagreement was whether the bill should include a private right of action allowing consumers to sue for violations.
SB 6281 (2020). A revised version was introduced for the 2020 session. It again passed the Senate but failed in the House over the same enforcement dispute.
SB 5062 (2021). The third attempt was introduced in January 2021. The Senate version would not have allowed consumers to sue, while the House advanced a version that included private enforcement. The two chambers could not reach a compromise, and the bill died when the legislative session ended on April 25, 2021.
Why the Bills Failed
The central dispute in every iteration was whether to include a private right of action. The Senate consistently favored Attorney General-only enforcement, arguing that a private right of action would lead to excessive litigation. The House insisted that meaningful enforcement required giving consumers the ability to sue directly.
Consumer advocacy groups, including Consumer Reports and the ACLU of Washington, opposed the bills in their Senate forms, arguing they were too weak without private enforcement and contained broad exemptions that would have limited their effectiveness.
What the Bills Would Have Done
Despite their failure, the proposed Washington Privacy Act would have been a significant step. Key provisions included:
- Right to access, correct, and delete personal data
- Right to opt out of data sales and targeted advertising
- Data protection assessments for high-risk processing activities
- Privacy notice requirements for all covered businesses
- Reasonable data security standards
Current Legislative Efforts: HB 1671 (2025-2026)
House Bill 1671, titled the People's Privacy Act, is the most significant development in Washington comprehensive privacy legislation in years. The bill would apply to persons conducting business in Washington or targeting Washington residents who collect or process personal data.
HB 1671 is modeled on the EPIC and Consumer Reports model state privacy bill and includes data minimization provisions that meaningfully limit the collection and use of personal data. The bill incorporates consumer health data definitions consistent with the existing MHMDA.
The bill's progress in the 2025-2026 session represents the furthest any Washington comprehensive privacy bill has advanced. On February 14, 2025, the House Committee on Technology, Economic Development, and Veterans took executive action and voted with a "do pass as substituted" recommendation, referring the bill to the Appropriations Committee on February 18, 2025. The bill was reintroduced by resolution for the 2026 session on January 12, 2026, and remains in Appropriations without further committee action.
Washington's history of failed comprehensive privacy bills means passage is not assured. The same enforcement disputes that derailed earlier efforts could resurface in floor votes or Senate consideration.
Washington Attorney General: Data Privacy Enforcement
The Washington Attorney General's Office plays a central role in enforcing the state's data privacy laws. Nick Brown took office as Washington's 19th Attorney General in January 2025, succeeding Bob Ferguson who became Governor.
Notable Enforcement Actions
Google Location Tracking ($39.9 Million). In one of the most significant state-level privacy enforcement actions in U.S. history, former Attorney General Bob Ferguson obtained a $39.9 million settlement from Google over deceptive location tracking practices. Washington filed its own lawsuit and recovered more than double what it would have received from joining a multistate settlement. Google was also required to implement court-ordered transparency reforms.
Data Privacy Survey (July 2025). AG Brown's office launched a Data Privacy Survey to learn about the data privacy concerns and challenges facing Washington residents. The results are expected to inform future legislative and enforcement priorities under the MHMDA and other state privacy laws.
Breach Notification Oversight. The AG maintains a public Data Breach Notifications Directory where consumers can see reported breaches affecting Washington residents.
As of May 2026, no formal AG enforcement actions under the MHMDA have been publicly announced. The private litigation landscape (Amazon, Uncle Ike's) has been the primary enforcement activity to date.
Federal Privacy Framework
In the absence of a comprehensive state consumer privacy law, several federal statutes provide baseline privacy protections for Washington residents.

TAKE IT DOWN Act (Pub. L. 119-12). Congress signed this federal law on May 19, 2025. It immediately criminalized the nonconsensual publication of intimate images, including AI-generated deepfake imagery. Online platforms had one year to establish notice-and-removal processes; the FTC began enforcing platform compliance obligations on May 19, 2026. A covered platform must remove a valid takedown request's content, along with known identical copies, within 48 hours.
Health Insurance Portability and Accountability Act (HIPAA). Protects health information held by covered entities such as healthcare providers, health plans, and healthcare clearinghouses. HIPAA does not cover many of the entities and data types that fall under Washington's MHMDA, which is why the MHMDA was necessary.
Gramm-Leach-Bliley Act (GLBA). Requires financial institutions to explain their information-sharing practices and safeguard sensitive data. Washington's biometric law explicitly exempts entities subject to the GLBA.
Children's Online Privacy Protection Act (COPPA). Protects the online privacy of children under 13 by requiring parental consent before data collection.
Fair Credit Reporting Act (FCRA). Regulates the collection, dissemination, and use of consumer credit information by consumer reporting agencies.
FTC Act Section 5. Empowers the Federal Trade Commission to pursue unfair or deceptive acts or practices, including data security failures and misleading privacy representations.
American Privacy Rights Act (APRA). A bipartisan federal comprehensive privacy bill introduced in April 2024 by Sen. Maria Cantwell (D-WA) and Rep. Cathy McMorris Rodgers (R-WA). The bill did not pass before the 118th Congress expired in January 2025 and has not been reintroduced in the 119th Congress as of May 2026. Washington residents should not expect federal comprehensive privacy legislation in the near term.
Practical Compliance Guidance
For Businesses Operating in Washington
Companies that collect data from Washington residents should evaluate their obligations under each of the state privacy laws.
Step 1: Assess MHMDA Applicability. Determine whether your business collects any data that could be considered consumer health data under the MHMDA's broad definition. Location data, biometric data, and inferred health information all qualify. The Uncle Ike's lawsuit illustrates that cannabis retailers, medical appointment schedulers, and any business tracking health-adjacent purchases face real exposure.
Step 2: Implement Dual Consent. If the MHMDA applies, implement separate consent mechanisms for collecting and sharing consumer health data. General privacy policy acceptance is insufficient.
Step 3: Publish a Health Data Privacy Policy. If you collect consumer health data, publish a dedicated privacy policy meeting the MHMDA's specific disclosure requirements.
Step 4: Review Biometric Practices. If your business uses fingerprints, facial recognition, iris scans, or other biometric identifiers for commercial purposes, ensure you are providing notice and obtaining consent under RCW 19.375.
Step 5: Update Breach Response Plans. Ensure your incident response plan accounts for Washington's 30-day AG notification requirement when more than 500 residents are affected.
Step 6: Avoid Geofencing Near Healthcare Facilities. If your business uses location-based targeting, ensure no geofences are set within 2,000 feet of any facility providing in-person healthcare services in Washington.
Step 7: Review Third-Party SDKs and Tracking Pixels. The Amazon and Uncle Ike's lawsuits both center on third-party technology embedded in websites and apps. Audit all pixels, SDKs, and analytics tools that could transmit health-adjacent data to third parties without adequate consent.
For Washington Residents
Washington residents have several rights under existing law:
- You can confirm whether a company collects your health data, access that data (including a list of the third parties who received it), and request its deletion under the MHMDA
- You can withdraw consent for health data collection and sharing at any time
- You must be notified if your personal information is compromised in a data breach
- You can file a private lawsuit if a company violates the MHMDA, seeking actual damages, injunctive relief, attorney fees, and potential treble damages up to $25,000
- You can submit takedown requests to online platforms for nonconsensual intimate images under the federal TAKE IT DOWN Act
To report potential violations of Washington data privacy laws, contact the Washington Attorney General's Office.
More Washington Laws
Frequently Asked Questions
Does Washington have a comprehensive consumer privacy law like California or Virginia?
No. Washington does not have a comprehensive consumer data privacy law as of May 2026. The Washington Privacy Act failed to pass in 2019, 2020, and 2021. HB 1671, the People's Privacy Act, received a 'do pass' recommendation from the House Technology Committee in February 2025 and has remained in the Appropriations Committee since, with no further committee action through the 2026 session, making it the furthest any Washington comprehensive privacy bill has advanced. Washington does have targeted laws covering health data (MHMDA), biometric identifiers (RCW 19.375), and data breach notification (RCW 19.255).
What is the Washington My Health My Data Act and who does it apply to?
The My Health My Data Act (Chapter 19.373 RCW) is a health data privacy law that took effect on March 31, 2024. It applies to any regulated entity that collects, processes, shares, or sells consumer health data and conducts business in Washington or produces products and services targeted at Washington residents. The law defines health data very broadly to include not just medical records but also location data that could reveal healthcare visits, biometric information, reproductive health data, and even information inferred from non-health data.
Can I sue a company that violates my health data privacy rights in Washington?
Yes. The My Health My Data Act includes a private right of action through the Washington Consumer Protection Act (Chapter 19.86 RCW). If a company violates the MHMDA, you can file a civil lawsuit seeking injunctive relief, actual damages, and reasonable attorney fees. Courts may also award treble damages up to $25,000. Two class actions were filed under this provision in 2025, against Amazon and a cannabis retailer, demonstrating active use of this enforcement path. Washington's biometric privacy law (RCW 19.375), by contrast, has no private right of action and can only be enforced by the Attorney General.
What are Washington's data breach notification requirements?
Under RCW 19.255.010, any business that experiences a data breach affecting Washington residents must notify those individuals promptly. If the breach affects more than 500 Washington residents, the business must also notify the Washington Attorney General within 30 days of discovering the breach. The notification must be in plain language and include the types of personal information compromised and contact information for credit reporting agencies if financial data was involved.
Does Washington biometric privacy law allow individuals to sue for violations?
No. Unlike Illinois BIPA, Washington's biometric privacy law (RCW 19.375) does not include a private right of action. Violations are treated as unfair or deceptive acts under the Consumer Protection Act, but only the Washington Attorney General can bring enforcement actions. Individual consumers cannot file lawsuits for biometric privacy violations under Washington law.
What is HB 1671 and could it become Washington's comprehensive privacy law?
HB 1671, the People's Privacy Act, is the most advanced comprehensive privacy bill Washington has seen. It passed the House Technology Committee with a 'do pass' recommendation on February 14, 2025, and was referred to Appropriations on February 18, 2025, where it has remained without further committee action through the 2026 session. The bill would require data minimization, grant consumer rights to access, correct, and delete personal data, and include opt-out rights for targeted advertising and data sales. Whether it passes depends on whether the long-standing dispute over private enforcement rights can be resolved.
What does the TAKE IT DOWN Act mean for Washington residents?
The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that immediately criminalized the nonconsensual sharing of intimate images, including AI-generated deepfakes. Beginning May 19, 2026, covered online platforms must remove such images within 48 hours of a valid takedown request, and the FTC can enforce this requirement. Washington residents can submit takedown requests directly to platforms and report noncompliance to the FTC.
Updates
Corrected the My Health My Data small-business threshold test (the statute's conditions are alternatives, not cumulative requirements), fixed the HB 1671 committee-vote date to February 14, 2025, stated the full confirm-access-deletion rights under RCW 19.373.040, and aligned the AG breach-notification trigger with the statute's 'more than 500 residents' wording.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the geofencing-ban citation from RCW 19.373.060 (the MHMDA processor-contract section) to RCW 19.373.080 (the actual geofencing prohibition). Corrected the breach-liability description: RCW 19.255.020 creates liability to financial institutions for card-reissuance costs from a narrowly defined 'business' (6M+ annual card transactions) or processor/vendor, not a general damages right for any injured person.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: added MHMDA private litigation section covering the February 2025 Amazon SDK class action and November 2025 Uncle Ike's cannabis retailer class action; updated HB 1671 status to reflect the February 14, 2025 'do pass' committee recommendation and Appropriations referral; updated Attorney General section to reflect Nick Brown taking office January 2025 (Bob Ferguson now Governor); added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) to federal framework with FTC enforcement effective May 19, 2026; corrected APRA status (expired with 118th Congress January 2025, not reintroduced as of May 2026); added Step 7 to compliance guidance on third-party SDK and pixel audits; added two new FAQ entries on HB 1671 and the TAKE IT DOWN Act; updated KeyTakeaways; added new sources including RCW 44.28.819, HB 1671 bill report, FTC TAKE IT DOWN Act press release, and MHMDA litigation commentary. Previous title and meta description preserved as both were accurate and converting.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Revised Code of Washington
§ 19.373.030Collection or sharing of consumer health data.In forcecited in 4 of our articles
(1)(a) Except as provided in subsection (2) of this section, beginning March 31, 2024, a regulated entity or a small business may not collect any consumer health data except: (i) With consent from the consumer for such collection for a specified purpose; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business. (b) A regulated entity or a small business may not share any consumer health data except: (i) With consent from the consumer for such sharing that is separate and distinct from the consent obtained to collect consumer health data; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: MHMDA Business Compliance (Washington), MHMDA Consumer Rights (Washington), What Is MHMDA? WA My Health My Data Act
§ 19.373.010Definitions.In forcecited in 6 of our articles
The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1) "Abortion" means the termination of a pregnancy for purposes other than producing a live birth. (2) "Affiliate" means a legal entity that shares common branding with another legal entity and controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company. (3) "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights afforded in this chapter is being made by, or on behalf of, the consumer who is entitled to exercise such consumer rights with respect to the consumer health data at issue.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Employee Monitoring Laws: Biometric Privacy, Social Media, and Surveillance (2026), Nevada Consumer Health Data Law (SB 370)
§ 19.373.080Geofence restrictions.In forcecited in 3 of our articles
It is unlawful for any person to implement a geofence around an entity that provides in-person health care services where such geofence is used to: (1) Identify or track consumers seeking health care services; (2) collect consumer health data from consumers; or (3) send notifications, messages, or advertisements to consumers related to their consumer health data or health care services.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 44.28.819Review of enforcement actions under the Washington my health my data act—Report. (Expires June 30, 2031.)In force
(1) The joint committee must review enforcement actions, as authorized in RCW 19.373.090, brought by the attorney general and consumers to enforce violations of chapter 191, Laws of 2023. (2) The report must include, at a minimum: (a) The number of enforcement actions reported by the attorney general, a consumer, a regulated entity, or a small business that resulted in a settlement, including the average settlement amount; (b) The number of complaints reported, including categories of complaints and the number of complaints for each category, reported by the attorney general, a consumer, a regulated entity, or a small business; (c) The number of enforcement actions brought by the attorney general and consumers, including the categories of violations and the number of violations per category; (e) [(d)] The number of civil actions where a judge determined the position of the nonprevailing party was frivolous, if any; (f) [(e)] The types of resources, including associated costs, expended by the attorney general, a consumer, a regulated entity, or a small business for enforcement actions; and (g) [(f)] Recommendations for potential changes to enforcement provisions of chapter…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.375.020Enrollment, disclosure, and retention of biometric identifiers.In forcecited in 9 of our articles
(1) A person may not enroll a biometric identifier in a database for a commercial purpose, without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent use of a biometric identifier for a commercial purpose. (2) Notice is a disclosure, that is not considered affirmative consent, that is given through a procedure reasonably designed to be readily available to affected individuals. The exact notice and type of consent required to achieve compliance with subsection (1) of this section is context-dependent.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Smart Glasses Recording Laws (2026), Washington Biometric Privacy Laws: Collection, Consent & Penalties (2026), Alabama Smart Glasses Recording Laws
§ 19.375.010Definitions.In forcecited in 4 of our articles
The definitions in this section apply throughout this chapter , unless the context clearly requires otherwise. (1) "Biometric identifier" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual. "Biometric identifier" does not include a physical or digital photograph, video or audio recording or data generated therefrom, or information collected, used, or stored for health care treatment, payment, or operations under the federal health insurance portability and accountability act of 1996. (2) "Biometric system" means an automated identification system capable of capturing, processing, and storing a biometric identifier, comparing the biometric identifier to one or more references, and matching the biometric identifier to a specific individual. (3) "Capture" means the process of collecting a biometric identifier from an individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.255.010Personal information—Notice of security breaches.In forcecited in 5 of our articles
(1) Any person or business that conducts business in this state and that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. (2) Any person or business that maintains or possesses data that may include personal information that the person or business does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):Guy v. Convergent Outsourcing (2023) held RCW 19.255.010(2) reaches only a business that maintains data it does not own or license, and that a subsection (1) claim needs a Washington resident plaintiff. Krefting v. Kaye-Smith (2023) applied the 30-day notice window in subsection (8) without deciding whether it creates a tort duty.
Opinions citing this section in our collection:
- Sarah Nunley v. Chelan-Douglas Health District (Court of Appeals of Washington 2024)✓After hackers took patient records from a health district, the court reversed dismissal of a negligence suit and cited the breach notification statute's notice duty and damages remedy as evidence of Washington policy supporting a common law duty to safeguard personal data.
- In re Sony Gaming Networks & Customer Data Security Breach Litigation (District Court, S.D. California 2014, 996 F. Supp. 2d 942)“…sufficient. The court agrees. With respect to a claim under RCW 19.255.010, it is not enough for Mr. Grigsby to ha…”
- In re Premera Blue Cross Customer Data Security Breach Litigation (District Court, D. Oregon 2016, 198 F. Supp. 3d 1183)“…(2) violation of the Washington Data Breach Disclosure Law, RCW § 19.255.010; 3 (3) negligence; 4 (4) breach of ex…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Washington Security Camera Laws: Rules for Home and Business Surveillance (2026), Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026), Data Breach Notification Deadlines by Country (2026 Comparison Table)
§ 19.255.005Definitions.In forcecited in 2 of our articles
The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1) "Breach of the security of the system" means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 13 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Greek Islands Cuisine Inc v. YourPeople Inc (District Court, E.D. Washington 2024)“…10 RCW 19.255.005(2)(a).…”
- Doe v. Fred Hutchinson Cancer Center (District Court, W.D. Washington 2024)“…tion of the Washington Data 8 Breach Disclosure Law, see RCW 19.255.005 et seq.; and (10) violation of the Wash…”
- Aleshire v. Fred Hutchinson Cancer Center (District Court, W.D. Washington 2024)“…tion of the Washington Data 8 Breach Disclosure Law, see RCW 19.255.005 et seq.; and (10) violation of the Wash…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 19.255.020Liability of processors, businesses, and vendors.In force
(1) For purposes of this section: (a) "Account information" means: (i) The full, unencrypted magnetic stripe of a credit card or debit card; (ii) the full, unencrypted account information contained on an identification device as defined under RCW 19.300.010; or (iii) the unencrypted primary account number on a credit card or debit card or identification device, plus any of the following if not encrypted: Cardholder name, expiration date, or service code. (b) "Breach" has the same meaning as "breach of the security of the system" in RCW 19.255.010. (c) "Business" means an individual, partnership, corporation, association, organization, government entity, or any other legal or commercial entity that processes more than six million credit card and debit card transactions annually, and who provides, offers, or sells goods or services to persons who are residents of Washington. (d) "Credit card" has the same meaning as in RCW 9A.56.280. (e) "Debit card" has the same meaning as in RCW 9A.56.280 and for the purposes of this section, includes a payroll debit card.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2018
Opinions citing this section in our collection:
- Veridian Credit Union v. Eddie Bauer, LLC (District Court, W.D. Washington 2017, 295 F. Supp. 3d 1140)“…y and injunctive relief ( id. ¶¶ 136-43), (4) violation of RCW 19.255.020 (FAC ¶¶ 144-51), and (5) violation of W…”
- Community Bank of Trenton v. Schnuck Markets, Incorporated (Court of Appeals for the Seventh Circuit 2018, 887 F.3d 803)“…liant data collectors who are less than grossly negligent); Wash. Rev. Code Ann. § 19.255.020(3) (2017) (requiring reimbursement). We…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Chapter 19.373 RCW: Washington My Health My Data Act(app.leg.wa.gov).gov
- Chapter 19.375 RCW: Biometric Identifiers(app.leg.wa.gov).gov
- Chapter 19.255 RCW: Breach Notification(app.leg.wa.gov).gov
- RCW 19.375.020: Enrollment, Disclosure, and Retention(app.leg.wa.gov).gov
- HB 1155: My Health My Data Act(app.leg.wa.gov).gov
- SB 5376: Washington Privacy Act (2019)(app.leg.wa.gov).gov
- SB 5062: Washington Privacy Act (2021)(app.leg.wa.gov).gov
- HB 1671: People Privacy Act (2025)(app.leg.wa.gov).gov
- Data Privacy Hub - WA Attorney General(atg.wa.gov).gov
- Protecting Washingtonians Health Data and Privacy(atg.wa.gov).gov
- AG Ferguson Google $40M Settlement(atg.wa.gov).gov
- Data Breach Notifications Directory(atg.wa.gov).gov
- RCW 19.255.005: Definition of Personal Information(app.leg.wa.gov).gov
- RCW 44.28.819: JLARC Review of MHMDA Enforcement Actions(app.leg.wa.gov).gov
- House Bill Report: HB 1671, Technology Committee (Feb 2025)(lawfilesext.leg.wa.gov).gov
- About AG Nick Brown, Washington State(atg.wa.gov).gov
- FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
- TAKE IT DOWN Act: FTC Legal Library(ftc.gov).gov
- First Lawsuit Filed Under Washington's My Health My Data Act (WilmerHale, Feb 2025)(wilmerhale.com)
- Washington Marijuana Retailer Sued Under MHMDA for Website Pixel Use (Hintze Law, Nov 2025)(hintzelaw.com)