Washington
MHMDA Business Compliance (Washington)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 10 primary sources cited on this page. How we verify our legal content

Complying with Washington's My Health My Data Act (MHMDA), chapter 19.373 RCW, means meeting six core duties: publish a separate consumer health data privacy policy, obtain consent before collecting or sharing consumer health data, obtain a separate signed authorization before selling it, honor consumer rights requests, restrict employee and processor access, and follow the geofencing ban. These duties live in RCW 19.373.020 through 19.373.080.
As of 2026, every covered organization is past its compliance deadline: most regulated entities since March 31, 2024, and small businesses since June 30, 2024. The reason MHMDA tops compliance priority lists is enforcement. Under RCW 19.373.090, every violation is a per se violation of the Washington Consumer Protection Act (chapter 19.86 RCW), so a business faces both Attorney General action and private lawsuits, including class actions, under RCW 19.86.090.
Jurisdiction scope: This covers Washington's My Health My Data Act (chapter 19.373 RCW). It is general legal information, not legal advice.
The compliance timeline and who must comply
MHMDA's deadlines depend on entity type, and as of 2026 all have passed. The geofencing restriction now at RCW 19.373.080 took effect July 23, 2023 and applies to any person. Regulated entities that are not small businesses had to comply with the core duties in RCW 19.373.020 through 19.373.070 by March 31, 2024. Small businesses had until June 30, 2024.
Coverage is broad because there is no threshold. Under RCW 19.373.010, a regulated entity is any legal entity that conducts business in Washington or targets Washington consumers and that determines the purpose and means of collecting, processing, sharing, or selling consumer health data. No minimum revenue or consumer count applies, so a small out-of-state app that handles Washington consumers' health data is in scope.
The small business subcategory in RCW 19.373.010 affects timing, not whether the law applies. A small business is a regulated entity that, during a year, processes the consumer health data of fewer than 100,000 consumers, or derives less than half its revenue from such processing while handling data for fewer than 25,000 consumers. RCW 19.373.100 then layers exemptions, including HIPAA protected health information and certain GLBA and FCRA data, which businesses should map at the data level. The full picture of who is covered is in the What is MHMDA? guide.
Duty 1: the separate consumer health data privacy policy
RCW 19.373.020 requires every regulated entity and small business to maintain a consumer health data privacy policy, and this policy must be separate. It cannot be folded into the general website privacy notice, and the statute requires a link to it on the entity's homepage.
The policy must disclose specific items. Under RCW 19.373.020, it must state the categories of consumer health data collected and the purpose for collection, including how the data will be used; the categories of sources from which the data is collected; the categories of consumer health data that are shared; and a list of the categories of third parties and the specific affiliates with whom the data is shared. It must also explain how a consumer can exercise the rights in RCW 19.373.040.
The Act also imposes a consistency rule, and it comes with a cure path rather than an absolute bar. Under RCW 19.373.020(1)(c) and (d), a regulated entity may not collect, use, or share additional categories of consumer health data, or use consumer health data for additional purposes, not disclosed in the policy "without first disclosing the additional categories" or purposes "and obtaining the consumer's affirmative consent" before that collection, use, or sharing. It also may not contract with a processor in a manner inconsistent with the policy. So the policy is not boilerplate; it operationally constrains what the business can do until it is updated and fresh affirmative consent is collected.
Duty 2: consent to collect and a separate consent to share
Consent is the gate under RCW 19.373.030. A regulated entity may not collect any consumer health data except with consent, or to the extent necessary to provide a product or service the consumer has requested. Likewise, it may not share consumer health data except with consent or to that same necessity standard.
The critical detail is that the two consents are distinct. The consent to share must be separate and distinct from the consent obtained to collect the data. A single combined "I agree" does not satisfy the statute; collecting and sharing each need their own affirmative opt-in.
Consent itself is strictly defined in RCW 19.373.010. It must be a clear affirmative act that is freely given, specific, informed, opt-in, voluntary, and unambiguous. It cannot be obtained through broad terms of use, a consumer hovering over or closing content, or any deceptive design or dark pattern. The disclosure that precedes a sharing consent must spell out the categories shared, the purpose, the recipients, and how to withdraw.

Duty 3: separate authorization to sell
Selling consumer health data triggers a higher bar than consent, and the prohibition reaches further than the rest of the Act. Under RCW 19.373.070(1), "it is unlawful for any person to sell or offer to sell consumer health data concerning a consumer without first obtaining valid authorization." Like the geofencing ban, this duty is written against any person rather than only regulated entities, so downstream purchasers, data brokers, and resellers are covered even if they never collected the data themselves. The authorization is a distinct, detailed, signed document, separate from any consent to collect or share.
RCW 19.373.070 lists what the authorization must contain. It must specify the consumer health data to be sold; name the seller and the purchaser; describe the purpose of the sale, including how the data will be gathered and used by the purchaser; state that the provision of goods or services may not be conditioned on the consumer signing it; state that the consumer may revoke it at any time and how; and warn that the data sold may be subject to redisclosure and may no longer be protected by the section. It must also include an expiration date no later than one year from signing, and the consumer's signature and date.
The recordkeeping duty is heavy. Both the seller and the purchaser must retain a copy of the signed valid authorization for six years from the date of its signature or the date the authorization was last in effect, whichever is later. Because the authorization expires after one year and cannot be a condition of service, MHMDA effectively makes selling consumer health data a deliberate, documented, opt-in transaction rather than a default.
Duty 4: honoring consumer rights requests
Under RCW 19.373.040, regulated entities must build a process to receive and fulfill consumer requests to confirm, access, withdraw consent, and delete. The entity must provide one or more secure and reliable methods for submitting requests that account for how consumers interact with it, secure verification, and accessibility, and it cannot force a consumer to create a new account to make a request.
The response timeline is 45 days, extendable once by another 45 days when reasonably necessary with notice to the consumer. Information must generally be provided free of charge up to twice per year per consumer. A refusal must be explained within the window, with appeal instructions, and the entity must maintain a documented appeal process that responds within 45 days and routes a still-denied consumer to the Attorney General.
The deletion duty is especially demanding because it reaches downstream. Under RCW 19.373.040, on a deletion request the entity must delete the data from its records, including archived and backup systems on a limited timeline, and must notify all affiliates, processors, contractors, and third parties that received the data so they delete it too. The consumer-facing detail is covered in the MHMDA consumer rights guide.

Duty 5: access controls, processors, and data security
MHMDA imposes internal-handling duties. Under RCW 19.373.050, a regulated entity must restrict access to consumer health data by its employees, processors, and contractors to what is necessary to provide a product or service the consumer requested, or as the consumer has consented to. The same section requires the entity to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and availability of consumer health data, appropriate to its volume and nature.
Processor relationships are governed by RCW 19.373.060. A processor may process consumer health data only pursuant to a binding contract with the regulated entity and only in a manner consistent with that entity's instructions. A processor that exceeds the entity's instructions, or fails to adhere to the contract, becomes a regulated entity itself with respect to that data, which raises the stakes for vendor management.
Together these duties mean a compliant program needs role-based access limits, documented security controls, and tightly scoped processor contracts. A loosely supervised vendor can convert into a regulated entity and create liability on both sides.
Duty 6: the geofencing prohibition
RCW 19.373.080 is a flat prohibition that applies to any person, not just regulated entities, which is why it carried the earliest July 23, 2023 compliance date. It is unlawful to implement a geofence around an entity that provides in-person health care services where the geofence is used to identify or track consumers seeking health care services, to collect consumer health data from them, or to send them notifications, messages, or advertisements related to their consumer health data or health care services.
A geofence, defined in RCW 19.373.010, is location-detection technology that creates a virtual boundary 2,000 feet or less from the perimeter of a physical location, or that locates a consumer within that boundary. Because the prohibition is absolute for the listed purposes, there is no consent path: a business cannot lawfully run geofenced health-facility tracking or advertising even if a consumer agreed.
For advertising and analytics teams, this means auditing any location-based targeting that could touch clinics, pharmacies, mental health providers, reproductive health facilities, or gender-affirming care providers. The risk is not theoretical, because geofencing near health facilities has been a focus of regulatory attention nationally.
Litigation risk: the private right of action
The dominant compliance driver under MHMDA is its enforcement model. RCW 19.373.090 declares that a violation of the chapter is a violation of the Washington Consumer Protection Act, chapter 19.86 RCW. The Washington Attorney General has confirmed that this makes any MHMDA violation a per se Consumer Protection Act violation, enforced by the Attorney General as well as through private action.
The private action runs through RCW 19.86.090, which lets an injured person sue for actual damages, allows the court to award up to three times the actual damages subject to a statutory cap, and permits recovery of costs and reasonable attorney fees. The fee-shifting and treble-damages structure, combined with class action availability, is what makes MHMDA a litigation risk and not merely a regulatory one.
| Duty | Statute | Core requirement |
|---|---|---|
| Privacy policy | RCW 19.373.020 | Separate policy, homepage link, disclose categories and recipients |
| Consent | RCW 19.373.030 | Opt-in to collect; separate opt-in to share |
| Authorization to sell | RCW 19.373.070 | Signed, specific, 1-year authorization; 6-year retention; binds any person, not only regulated entities |
| Consumer rights | RCW 19.373.040 | Fulfill requests in 45 days; appeal process |
| Access and security | RCW 19.373.050, .060 | Limit access; bind processors; reasonable security |
| Geofencing | RCW 19.373.080 | No tracking or marketing geofence near health facilities |
This guide does not predict outcomes or recommend whether to sue or settle any matter. As of 2026, the prudent posture for any business that touches Washington consumers' health data is to treat the six duties above as live obligations and to document compliance, given that both the state and private plaintiffs can enforce them.
Related guides
- Washington data privacy laws parent hub
- What is MHMDA?
- MHMDA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Washington Laws
Frequently Asked Questions
What does MHMDA require businesses to do?
MHMDA (chapter 19.373 RCW) requires regulated entities to publish a separate consumer health data privacy policy (RCW 19.373.020), obtain consent before collecting or sharing consumer health data with a distinct consent to share (RCW 19.373.030), honor consumer rights requests within 45 days (RCW 19.373.040), restrict access and maintain security (RCW 19.373.050 and .060), and avoid geofencing health facilities (RCW 19.373.080). Two duties are broader still: RCW 19.373.070 makes it unlawful for any person to sell consumer health data without a separate signed authorization, and the geofencing ban also applies to any person.
When did businesses have to comply with MHMDA?
The geofencing ban took effect July 23, 2023 for any person. Regulated entities that are not small businesses had to comply with the core duties by March 31, 2024, and small businesses by June 30, 2024. As of 2026, all of those dates have passed, so every covered organization is fully obligated.
Does a small business have to comply with MHMDA?
Yes. Under RCW 19.373.010, the 'small business' definition (processing data for fewer than 100,000 consumers, or fewer than 25,000 while deriving less than half of revenue from such processing) only affects the compliance date, June 30, 2024, not whether the law applies. Small businesses must meet the same core duties as larger regulated entities.
What must a MHMDA privacy policy include?
Under RCW 19.373.020, the consumer health data privacy policy must be separate from the general privacy notice, linked on the homepage, and disclose the categories of consumer health data collected and why, the sources of that data, the categories of data shared, a list of the categories of third parties and the specific affiliates it is shared with, and how consumers can exercise their rights. Under RCW 19.373.020(1)(c) and (d), the entity cannot collect, use, or share additional categories of data, or use it for additional purposes, that the policy does not disclose without first disclosing those additional categories or purposes and obtaining the consumer's affirmative consent.
What is the difference between consent and authorization under MHMDA?
Consent under RCW 19.373.030 is required to collect or share consumer health data, and the share consent must be separate from the collect consent. Authorization under RCW 19.373.070 is a higher bar required to sell consumer health data: a separate, specific, signed document that names buyer and seller, describes the sale, cannot be a condition of service, expires after one year, and must be retained for six years. The consent duties are written against regulated entities, while the sale prohibition is written against any person.
Can a business use geofencing near a clinic in Washington?
Not for the prohibited purposes. RCW 19.373.080 makes it unlawful to use a geofence within 2,000 feet of an in-person health care facility to track consumers seeking health services, collect their consumer health data, or send them health-related notifications, messages, or ads. The ban is absolute, so it cannot be cured with consumer consent, and it applies to any person, not just regulated entities.
What is the penalty for violating MHMDA?
MHMDA has no separate penalty schedule. Instead, RCW 19.373.090 makes a violation a per se violation of the Washington Consumer Protection Act (chapter 19.86 RCW). That exposes a business to Attorney General enforcement and to private lawsuits under RCW 19.86.090, which allow actual damages, treble damages up to a statutory cap, costs, and attorney fees. The private right of action, including class actions, is the headline litigation risk.
Are processors and vendors covered by MHMDA?
Yes. Under RCW 19.373.060, a processor may handle consumer health data only under a binding contract and only per the regulated entity's instructions. A processor that exceeds those instructions or breaches the contract becomes a regulated entity itself for that data. Under RCW 19.373.050, regulated entities must also restrict employee, processor, and contractor access to what is necessary and maintain reasonable data security.
Updates
Corrected the scope of the consumer health data sale prohibition, which applies to any person and not only regulated entities, and clarified that undisclosed data categories or purposes may be added by updating the privacy policy and obtaining the consumer's affirmative consent.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Revised Code of Washington
§ 19.373.030Collection or sharing of consumer health data.In forcecited in 4 of our articles
(1)(a) Except as provided in subsection (2) of this section, beginning March 31, 2024, a regulated entity or a small business may not collect any consumer health data except: (i) With consent from the consumer for such collection for a specified purpose; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business. (b) A regulated entity or a small business may not share any consumer health data except: (i) With consent from the consumer for such sharing that is separate and distinct from the consent obtained to collect consumer health data; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: MHMDA Consumer Rights (Washington), What Is MHMDA? WA My Health My Data Act, Washington Data Privacy Laws: My Health My Data Act & More (2026)
§ 19.373.020Consumer health data privacy policy.In force
(1)(a) Except as provided in subsection (2) of this section, beginning March 31, 2024, a regulated entity and a small business shall maintain a consumer health data privacy policy that clearly and conspicuously discloses: (i) The categories of consumer health data collected and the purpose for which the data is collected, including how the data will be used; (ii) The categories of sources from which the consumer health data is collected; (iii) The categories of consumer health data that is shared; (iv) A list of the categories of third parties and specific affiliates with whom the regulated entity or the small business shares the consumer health data; and (v) How a consumer can exercise the rights provided in RCW 19.373.040. (b) A regulated entity and a small business shall prominently publish a link to its consumer health data privacy policy on its homepage.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.040Consumer rights and requests—Refusal—Appeal.In forcecited in 2 of our articles
(1)(a) Except as provided in subsection (2) of this section, beginning March 31, 2024, a consumer has the right to confirm whether a regulated entity or a small business is collecting, sharing, or selling consumer health data concerning the consumer and to access such data, including a list of all third parties and affiliates with whom the regulated entity or the small business has shared or sold the consumer health data and an active email address or other online mechanism that the consumer may use to contact these third parties. (b) A consumer has the right to withdraw consent from the regulated entity's or the small business's collection and sharing of consumer health data concerning the consumer. (c) A consumer has the right to have consumer health data concerning the consumer deleted and may exercise that right by informing the regulated entity or the small business of the consumer's request for deletion.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.070Valid authorization to sell—Defects—Provision to consumer.In forcecited in 2 of our articles
(1) Except as provided in subsection (6) of this section, beginning March 31, 2024, it is unlawful for any person to sell or offer to sell consumer health data concerning a consumer without first obtaining valid authorization from the consumer. The sale of consumer health data must be consistent with the valid authorization signed by the consumer. This authorization must be separate and distinct from the consent obtained to collect or share consumer health data, as required under RCW 19.373.030. (2) A valid authorization to sell consumer health data is a document consistent with this section and must be written in plain language.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.050Data security practices.In force
(1) Except as provided in subsection (2) of this section, beginning March 31, 2024, a regulated entity and a small business shall: (a) Restrict access to consumer health data by the employees, processors, and contractors of such regulated entity or small business to only those employees, processors, and contractors for which access is necessary to further the purposes for which the consumer provided consent or where necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business; and (b) Establish, implement, and maintain administrative, technical, and physical data security practices that, at a minimum, satisfy reasonable standard of care within the regulated entity's or the small business's industry to protect the confidentiality, integrity, and accessibility of consumer health data appropriate to the volume and nature of the consumer health data at issue. (2) A small business must comply with this section beginning June 30, 2024.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.060Processors.In force
(1)(a)(i) Except as provided in subsection (2) of this section, beginning March 31, 2024, a processor may process consumer health data only pursuant to a binding contract between the processor and the regulated entity or the small business that sets forth the processing instructions and limit the actions the processor may take with respect to the consumer health data it processes on behalf of the regulated entity or the small business. (ii) A processor may process consumer health data only in a manner that is consistent with the binding instructions set forth in the contract with the regulated entity or the small business. (b) A processor shall assist the regulated entity or the small business by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the regulated entity's and the small business's obligations under this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.080Geofence restrictions.In forcecited in 3 of our articles
It is unlawful for any person to implement a geofence around an entity that provides in-person health care services where such geofence is used to: (1) Identify or track consumers seeking health care services; (2) collect consumer health data from consumers; or (3) send notifications, messages, or advertisements to consumers related to their consumer health data or health care services.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.090Application of consumer protection act.In forcecited in 4 of our articles
The legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. A violation of this chapter is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 19.86.090Civil action for damages—Treble damages authorized—Action by governmental entities.In forcecited in 5 of our articles
Any person who is injured in his or her business or property by a violation of RCW 19.86.020, 19.86.030, 19.86.040, 19.86.050, or 19.86.060, or any person so injured because he or she refuses to accede to a proposal for an arrangement which, if consummated, would be in violation of RCW 19.86.030, 19.86.040, 19.86.050, or 19.86.060, may bring a civil action in superior court to enjoin further violations, to recover the actual damages sustained by him or her, or both, together with the costs of the suit, including a reasonable attorney's fee. In addition, the court may, in its discretion, increase the award of damages up to an amount not to exceed three times the actual damages sustained: PROVIDED, That such increased damage award for violation of RCW 19.86.020 may not exceed twenty-five thousand dollars: PROVIDED FURTHER, That such person may bring a civil action in the district court to recover his or her actual damages, except for damages which exceed the amount specified in RCW 3.66.020, and the costs of the suit, including reasonable attorney's fees.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 529 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance (Washington Supreme Court 1986, 105 Wash. 2d 778)“…izens would be encouraged to bring suit to enforce the CPA. RCW 19.86.090, as amended, first in 1971 and again in…”
- Washington State Physicians Insurance Exchange & Ass'n v. Fisons Corp. (Washington Supreme Court 1993, 122 Wash. 2d 299)“…any trade or commerce are hereby declared unlawful. *312 RCW 19.86.090 creates a private right of action by pr…”
- Bowers v. Transamerica Title Insurance (Washington Supreme Court 1983, 100 Wash. 2d 581)“…d its discretion in awarding attorney fees of $42,805 under RCW 19.86.090. We hold that: 1. An escrow agent i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 19.373.100Exemptions.In forcecited in 2 of our articles
(1) This chapter does not apply to: (a) Information that meets the definition of: (i) Protected health information for purposes of the federal health insurance portability and accountability act of 1996 and related regulations; (ii) Health care information collected, used, or disclosed in accordance with chapter 70.02 RCW; (iii) Patient identifying information collected, used, or disclosed in accordance with 42 C.F.R. Part 2, established pursuant to 42 U.S.C. Sec. 290dd-2; (iv) Identifiable private information for purposes of the federal policy for the protection of human subjects, 45 C.F.R. Part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonization; the protection of human subjects under 21 C.F.R.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
§ 19.373.010Definitions.In forcecited in 6 of our articles
The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1) "Abortion" means the termination of a pregnancy for purposes other than producing a live birth. (2) "Affiliate" means a legal entity that shares common branding with another legal entity and controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" or "controlled" means: (a) Ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; (b) Control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) The power to exercise controlling influence over the management of a company. (3) "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights afforded in this chapter is being made by, or on behalf of, the consumer who is entitled to exercise such consumer rights with respect to the consumer health data at issue.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: Washington Employee Monitoring Laws: Biometric Privacy, Social Media, and Surveillance (2026), Nevada Consumer Health Data Law (SB 370)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- RCW 19.373.020: Consumer health data privacy policy(app.leg.wa.gov).gov
- RCW 19.373.030: Collection or sharing of consumer health data(app.leg.wa.gov).gov
- RCW 19.373.040: Consumer rights and requests, refusal, appeal(app.leg.wa.gov).gov
- RCW 19.373.050: Data security practices(app.leg.wa.gov).gov
- RCW 19.373.060: Processors(app.leg.wa.gov).gov
- RCW 19.373.070: Valid authorization to sell(app.leg.wa.gov).gov
- RCW 19.373.080: Geofence restrictions(app.leg.wa.gov).gov
- RCW 19.373.090: Application of consumer protection act(app.leg.wa.gov).gov
- RCW 19.86.090: Consumer Protection Act private right of action(app.leg.wa.gov).gov
- Washington Attorney General: Protecting Washingtonians' Personal Health Data and Privacy(atg.wa.gov).gov