Washington My Health My Data Act (MHMDA): 2026 Compliance Guide
Table of Contents
The Washington My Health My Data Act (MHMDA) is a U.S. state privacy law that protects consumer health data outside HIPAA, codified at RCW 19.373. It has been in force since 2023, with the main business obligations applying from 2024 onwards. It is widely considered to be one of the strictest personal data laws in the U.S.
Two things make MHMDA stand out when compared to American state privacy laws. First, consumers can sue businesses directly under the Washington Consumer Protection Act. Second, consumer health data is defined broadly and covers categories other laws ignore.
MDMDA also has no size threshold. Businesses are covered the second they handle the health data of a single Washington resident, whether it's a hospital or an ecommerce store selling prescription sunglasses.
Most people assume it's a law for health care companies. It isn't, and applies to any company that touches healthcare data. The first businesses sued under it are a cannabis retailer and Amazon's advertising business, not hospitals.
MHMDA protects health data that HIPAA never touched, and it defines that data so broadly that a tracking pixel inferring someone's health interest can trigger it. Then it adds private plaintiffs to the list of who can enforce it. That combination, broad scope plus the right to sue, is why the plaintiffs' bar moved its pixel-tracking playbook straight to Washington.
What is the My Health My Data Act?
The My Health My Data Act is Washington's consumer-health-data privacy law, passed as House Bill 1155 in 2023 and codified at RCW 19.373. Governor Jay Inslee signed it on April 27, 2023, and the Washington Attorney General calls it the first state law dedicated to consumer health data that sits beyond HIPAA's reach.
The law rolled out in stages. The geofencing ban took effect first, on July 23, 2023. The core obligations (consent, the privacy policy, consumer rights, the rules on selling data) applied to most businesses on March 31, 2024, and to small businesses on June 30, 2024.
The feature that shapes everything else is enforcement: consumers can sue on their own, not just the attorney general. That is what turns MHMDA from a compliance checklist into a litigation-risk question, and the rest of this guide follows from it.
Who does MHMDA apply to?
MHMDA applies to any business that handles the health data of a Washington resident, with no revenue or data-volume threshold (RCW 19.373.010).
The law says any organization that does business in Washington, sells products or services to Washington consumers, or is responsible for how consumer health data is collected or used is in the scope of MDMDA.
Exceptions include government agencies and contracted service providers.
Small businesses are not exempt from MHMDA. And unlike most privacy laws, MHMDA gives nonprofits no exemption: a nonprofit that handles Washington health data is a regulated entity like any business.
MHMDA's reach extends past Washington's borders, too. A consumer is a Washington resident or anyone whose health data is collected in Washington, so an out-of-state company with Washington users is covered. Individuals acting in an employment context are outside the law.
Because data processed on servers in the state can count as collected in Washington, some lawyers read the law to reach non-residents whose data passes through Washington data centers, which widens the potential class.
Consumer health data under MHMDA
Consumer health data is any information linked to a person that identifies their past, present, or future physical or mental health (RCW 19.373.010). Its definition is broader than HIPAA's protected health information, mainly because it includes inferred data and precise location.
The statute lists thirteen kinds of covered data. It reaches the obvious categories and several that catch ordinary businesses off guard:
- Health conditions, diagnoses, treatments, and procedures
- Medications
- Bodily functions, vital signs, and symptoms
- Behavioral and psychological interventions, like therapy or counseling
- Biometric and genetic data
- Gender-affirming care information
- Reproductive or sexual health information, including anything related to abortion
- Precise location that could show someone seeking healthcare services or supplies
- Data that identifies a consumer seeking health care
- Any of the above that a business infers or derives from non-health data, including through algorithms
That last category turns a marketing problem into a legal one. If your analytics or ad tools deduce that someone is pregnant, dieting, or managing a condition, that inference qualifies as consumer health data.
The Washington Attorney General's own examples show where the line falls. Buying toiletries like deodorant or toothpaste is not consumer health data on its own. A retailer's pregnancy-prediction score built from ordinary purchases is. An app that logs digestion or perspiration is. A non-prescription medication becomes covered the moment you use it to infer a health condition.
Two things are carved out: data used in approved clinical research, and data that's been properly deidentified.
What rights do Washington consumers have under MHMDA?
Washington consumers can see, delete, and stop the sharing of their consumer health data, and get a list of everyone it went to (RCW 19.373.040). Businesses have to build a way to honor each of these.
- Confirm whether you collect, share, or sell their health data, and access it
- Get the list of third parties and affiliates you shared or sold it to, with contact details for each
- Withdraw consent to further collection or sharing
- Delete their health data
Deletion reaches downstream. When someone asks you to delete, you also have to tell your affiliates, processors, and any third party you shared the data with to delete it too. You have 45 days to respond, extendable once. If you deny a request you have to offer an appeal, answer it in writing within 45 days, and give the consumer a way to complain to the attorney general.

MHMDA conditions for businesses
Every regulated business is assigned a specific set of duties under MHMDA, starting with a consumer health data privacy policy that's separate from your general privacy policy (RCW 19.373.020).
Here's what businesses must do:
- Publish a consumer health data privacy policy that lists the categories of health data you collect, why, where it comes from, who you share it with (naming specific affiliates, not just categories), and how people exercise their rights. Link it where the statute counts as your homepage, which includes any page that collects data, so in practice a sitewide footer link.
- Get consent before you collect, and a separate consent before you share. Don't collect or use any category you didn't disclose.
- Keep the data secure, with access limited to the people who need it.
- Put a contract around every processor that handles the data for you, and don't let them use it beyond your instructions.
- Don't retaliate against anyone for using their rights.
Need help with MDMDA compliance? Book a call and let Enzuzo show you a structured path
Who enforces MHMDA, and can consumers sue directly?
MHMDA is the rare U.S. privacy law that lets consumers sue businesses directly, through the Washington Consumer Protection Act (RCW 19.373.090). A violation counts as an unfair or deceptive act under the Consumer Protection Act, which both the attorney general and private plaintiffs can bring.
There are no fixed per-violation damages, which is what separates MHMDA from Illinois BIPA. A private plaintiff has to prove actual damages plus injury to their business or property.
A court can then award those actual damages and attorney fees, and it may, at its discretion, increase the award up to three times the actual damages, capped at $25,000. The attorney general can separately seek injunctions, restitution, and civil penalties under RCW 19.86.140.
So the exposure isn't a tidy per-record number; it's a class of Washington plaintiffs, their proven damages, and their lawyers' fees. That's harder to size than BIPA's statutory damages, and it's the reason the compliance work is cheaper than fighting claims in court.
My Health My Data Act lawsuit history
As of September 2026, the MHMDA cases on record all target website and app tracking, not hospitals or health apps directly.
The first case was filed February 10, 2025 as Maxwell v. Amazon (No. 2:25-cv-00261, W.D. Wash.), and later consolidated into the Amazon Ads SDK Litigation.
The complaint alleges Amazon's advertising SDKs, embedded in more than 10,000 mobile apps including The Weather Channel and OfferUp, harvested precise location data that could reveal health-related visits, without consent and without the disclosures MHMDA requires. It's a putative class action seeking damages and an injunction, and as of writing, it's in early motion practice with no ruling on the merits.
A second lawsuit targeted the Seattle cannabis retailer Uncle Ike's over website tracking tools. The allegation is that the retailer aimed to capture and transmit sensitive data to advertising platforms, without explicit consent.
The mechanism is the same in both cases. A tracking pixel fires on page load and collects before anyone has consented, which the statute forbids, and it transmits to an ad platform, which is another violation of MHMDA.
The important caveat: neither defendant is a health care company. Hence any sites running trackers that could infer a visitor's health information are covered under MHMDA.
Does being HIPAA-compliant exempt you from MHMDA?
Being HIPAA-covered does not exempt you from MHMDA because the law only covers regulated data, not HIPAA-regulated companies (RCW 19.373.100). The exemptions focus on specific data, such as protected health information, not the organization holding it.
So a hospital's clinical records stay under HIPAA, but the same hospital's marketing site, appointment analytics, and ad pixels are viewed as consumer health data under MHMDA.
MHMDA also exempts data governed by other regimes, including the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, the Family Educational Rights and Privacy Act, substance-use records under 42 CFR Part 2, Washington's own health-care law, and rules from the state insurance commissioner.

MHMDA consent and authorization to sell
MHMDA runs on two separate permissions: consent to collect or share consumer health data, and a stricter signed authorization to sell it (RCW 19.373.030). They are different instruments with different rules, and mixing them up is a common mistake.
For collecting data, businesses need either the consumer's consent for a specific purpose or a genuine need to provide something they asked for. Sharing that data needs its own separate consent, distinct from the collection consent, unless the sharing is necessary to deliver what the consumer requested.
Consent has a strict statutory meaning (RCW 19.373.010). It's a clear, affirmative, opt-in act; it's not a consumer accepting your terms of use, not someone hovering over or closing a banner, and not anything obtained through deceptive design.
A valid consent request has to name the data collected, the purpose, the categories of entities you'll share with, and instructions for how to withdraw.
Selling consumer health data is tackled differently. A sale is any exchange of that data for money or other valuable consideration, and it needs a signed valid authorization, written in plain language that contains all of:
- The specific health data to be sold
- The seller's name and contact information
- The buyer's name and contact information
- The purpose of the sale and how the buyer will use the data
- A statement that you can't condition goods or services on signing
- The consumer's right to revoke and how to do it
- A warning that the buyer may re-disclose the data and it may lose MHMDA's protection
- An expiration one year from signature
- The consumer's signature and date
The authorization is invalid if it's expired, incomplete, revoked, bundled into another document, or made a condition of getting the product. You give the consumer a copy, and both you and the buyer keep it for six years.
In practice, these rules are strict enough that most businesses treat MHMDA as a near-ban on selling consumer health data, including for most third-party targeted advertising.

MHMDA and website tracking rules
MHMDA reaches your website through four everyday tracking behaviors that quietly create consumer health data. Each one is a place the statute's definition attaches, and each is a place the lawsuits above started.
- A visit to a health-condition page. When a pixel logs the URL of a page about a symptom, treatment, or condition, that URL can identify what the visitor was looking into.
- A health-related search on your site. Scripts that capture and retainon-site search queries, such as specific drug names, and map it to deanonymized data.
- A purchase or behavior that reveals a condition. Cart contents, quiz answers, and content choices can let your tools infer a health status the visitor never stated.
- Precise location near care. Mobile analytics that record a device near a clinic or pharmacy can show someone seeking services.
How is MHMDA different from other state privacy laws?
MHMDA differs from BIPA, MODPA, and CCPA in one decisive way: individuals, not just the attorney general, can enforce it. There are other subtle differences, too, and the table below shows all the details:
| Feature | Washington (MHMDA) | Illinois (BIPA) | Maryland (MODPA) | California (CCPA/CPRA) |
|---|---|---|---|---|
| Who it covers | Any handler of WA health data, no threshold | Any private entity, no threshold | 35,000 consumers | ~$26M revenue or 100,000 consumers |
| Scope | Consumer health data (very broad) | Biometric identifiers only | All personal data | All personal data |
| Can consumers sue? | Yes, via the Consumer Protection Act | Yes, directly | No | Data breach only |
| Damages basis | Actual damages + discretionary enhancement (up to 3x, $25k cap) | Statutory $1,000 / $5,000 per violation | AG penalties only | AG penalties; $100-$750 per consumer for breaches |
| Consent model | Opt-in consent; separate authorization to sell | Written consent before collection | Notice and opt-out; opt-in for sensitive data | Notice and opt-out |
| Geofence rule | 2,000 ft around health facilities | None | 1,750 ft around health facilities | None |
MHMDA's bluetooth geofencing ban
MHMDA makes it unlawful for anyone to run a geofence (not to be confused with cookie consent banner geofencing) within 2,000 feet of an in-person health care provider (RCW 19.373.080). This is to prevent identifying or tracking people seeking care, collecting their health data, or sending them health-related messages or ads.
A geofence is a virtual boundary that triggers an action when a phone crosses it, and the statute measures it as 2,000 feet or less from a location.
The ban has been in force since July 23, 2023. There's no consent exception for those three uses, so if your marketing runs location-based targeting, be sure to cross-verify campaign geographical details.
How to comply with MHMDA: a checklist
MHMDA compliance starts with an audit of healthcare and healthcare-adjacent data in your possession. Much of the exposure hides in website trackers, not databases, which is where Enzuzo's consent management platform plays a key role. It handles consent, pixels, and audit trails.
This checklist should help businesses get started:
- Map the consumer health data you collect, including what your pixels and analytics infer.
- Gate collection behind consent, and stop trackers from firing until a Washington visitor opts in.
- Obtain separate consent before sharing data, and a signed authorization before selling.
- Publish a consumer health data privacy policy and link it sitewide.
- Build the rights workflow: access, deletion with downstream notice, and a 45-day clock.
- Check your location targeting against the 2,000-foot geofence rule.
- Put processor contracts in place with every vendor that touches the data.
A consent platform does the gating and keeps the record that proves it, which is the evidence businesses need if a claim is ever filed. To see how consent records hold up when someone asks for proof, book a demo.
Frequently asked questions
What is the My Health My Data Act?
The My Health My Data Act is a Washington law that protects health data companies collect outside of HIPAA, such as data from websites, apps, and ad trackers. It requires opt-in consent before collection, bans certain geofencing, and lets consumers sue businesses that break the rules.
Who has to comply with MHMDA?
Any business that handles the consumer health data of a Washington resident has to comply, with no revenue or size threshold. That includes out-of-state companies with Washington users, and it reaches far beyond health care because the law's definition of health data covers inferred and location data.
Does MHMDA apply to my website's tracking pixels?
Yes, MHMDA can apply to your tracking pixels whenever they collect or infer health-related data about a Washington visitor. Every lawsuit filed under the act so far involves website or app tracking, so pixels and SDKs are the main source of exposure, not clinical records.
Does MHMDA apply if I'm already HIPAA-compliant?
Yes, MHMDA still applies, because it exempts HIPAA-regulated data, not HIPAA-regulated companies. Your clinical records stay under HIPAA, but your marketing site, analytics, and ad pixels fall under MHMDA.
What counts as consumer health data under MHMDA?
Consumer health data is any information linkable to a person that reveals their physical or mental health, including conditions, medications, biometric and genetic data, gender-affirming and reproductive health information, precise location near care, and health details a company infers from other data.
Can consumers sue under the My Health My Data Act?
Yes, consumers can sue directly under MHMDA through the Washington Consumer Protection Act. There are no fixed per-violation damages, so a plaintiff proves actual damages and fees, and a court may add up to three times that amount, capped at a $25,000 increase, which makes class actions the realistic exposure.
What are the penalties for violating MHMDA?
MHMDA has no fixed statutory penalty. A private plaintiff recovers proven actual damages and attorney fees, plus a possible court-ordered increase up to three times actual damages capped at $25,000, and the attorney general can seek injunctions, restitution, and civil penalties under the Consumer Protection Act.
What is a valid authorization to sell under MHMDA?
A valid authorization is a separate signed document a business needs before selling consumer health data. It has to name the exact data, the seller, and the buyer, state the purpose, confirm service isn't conditioned on signing, allow revocation, expire after one year, and be kept for six years.
Has anyone been sued under MHMDA?
Yes, MHMDA lawsuits have already been filed, starting with the case against Amazon's advertising business in February 2025, now consolidated as In re Amazon Ads SDK Litigation, and a suit against the cannabis retailer Uncle Ike's over website tracking. Both cases center on trackers, not health records.
Does MHMDA apply if my business isn't in Washington?
Yes, MHMDA applies to any business that targets Washington residents or collects their health data, wherever the business is based. Because data processed on Washington servers can also count as collected in the state, the reach can extend even further.
Does MHMDA ban geofencing?
MHMDA does not ban geofencing outright, but it makes it unlawful to run a geofence within 2,000 feet of an in-person health care provider to track people seeking care, collect their health data, or send them health-related ads. Geofences used for other purposes are unaffected.
Does MHMDA apply to nonprofits?
Yes, MHMDA applies to nonprofits, which get no exemption under the law. A nonprofit that handles the consumer health data of a Washington resident has the same obligations as a business, unlike under many other privacy laws.
When did MHMDA take effect?
MHMDA's geofencing ban took effect July 23, 2023, and its main obligations applied to most businesses on March 31, 2024, and to small businesses on June 30, 2024. The law is fully in force and enforceable today.
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.