Of all the state statutes touching a medical practice website, the My Health My Data Act is the one that most reliably surprises people. Three of its design choices break the assumptions practices carry over from other privacy laws, and each break runs in the direction of more coverage rather than less.
It applies based on where the consumer is rather than where the business is. It has no small-business threshold. And a private individual can bring a claim without waiting for a regulator. Any one of those would make it unusual. Together they make it the statute worth understanding first.
What the My Health My Data Act covers
Washington's Act, codified at chapter 19.373 RCW, regulates consumer health data held by a regulated entity. Both halves of that phrase are broader than a practice expects.
Consumer health data
Personal information linked or reasonably linkable to a consumer that identifies their past, present or future physical or mental health status. The definition explicitly contemplates inferences, and it lists categories including individual health conditions, treatment, bodily functions, precise location that could indicate an attempt to acquire health services, and data identifying a consumer seeking health care services.
Two things follow immediately. First, health status can be inferred rather than stated, so a record showing that an identifiable person looked at a page about a specific procedure is the sort of linkage the definition reaches. Second, precise location indicating an attempt to obtain health services is named, which brings advertising practices into scope alongside website analytics.
A regulated entity is any legal entity that conducts business in Washington, or produces or provides products or services targeted to Washington consumers, and that determines the purpose and means of processing consumer health data. There is no revenue floor and no minimum number of records.
Why it reaches practices outside Washington
The geography point is the one that produces the most resistance, and it is worth being precise about why it works this way.
Consumer protection statutes generally attach to the consumer rather than to the seller's location, because the harm they address happens to the consumer. A practice in Arizona that runs a website reachable from Washington, that accepts consultation requests from Washington residents, or that advertises to a national audience is doing business in a way that touches Washington consumers. Physical presence is not the test.
For a specialist practice the exposure is more than theoretical. Hair restoration, aesthetics and plastic surgery routinely draw out-of-state patients who research for months before travelling. Those are precisely the visitors who read many treatment pages, submit a form, and generate exactly the linkage the statute describes.
It is worth being honest about the limits of this reasoning too, because overstating it is its own error. The Act is recent, and the contours of how far its reach extends to a business with no physical presence and no deliberate targeting of Washington will be worked out through cases over time. A practice that has never advertised outside its metropolitan area and takes no out-of-state patients is in a materially different position from one running national campaigns. The point is not that every practice in the country is squarely covered. It is that geography is the wrong first question, and a great many practices stop there.
The workable test is closer to this: does your marketing reach people in Washington, do Washington residents submit forms on your site, and would you accept a patient who travelled from there? Two yeses and the question deserves an actual answer rather than an assumption.
The private right of action
Most state privacy laws are enforced by a state attorney general with limited resources and a queue. A practice can rationally conclude it is unlikely to be at the front of that queue.
Washington took a different route. The Act declares that violations are matters vitally affecting the public interest for the purposes of the Consumer Protection Act, and that a violation is an unfair or deceptive act in trade or commerce. That framing routes enforcement through chapter 19.86 RCW, which individuals may invoke themselves.
The practical consequence is a change in who can start something. A regulator opens matters selectively. Private plaintiffs and the firms that represent them do not operate under the same constraint, and as covered in what the Meta Pixel complaints alleged, tracking exposure is discoverable from outside an organisation by anyone with a browser. A cause of action that any consumer can bring, over a condition anyone can observe without your cooperation, is a different risk profile from a regulator-only statute.
Two qualifications keep this proportionate. A private claim under the Consumer Protection Act is not automatic on a technical violation; a plaintiff has to make out the elements that Act requires, including injury, and how readily that is done in this context is still being worked through. And the volume of activity a statute attracts depends on economics as much as on text.
Neither qualification changes the planning conclusion, though, because the asymmetry runs the wrong way for a defendant. The cost of being in a defensible position is a configuration decision made once. The cost of being in an indefensible one is discovering it through correspondence. When the evidence that decides which position you are in is a network log that anyone can generate about you, without notice, the sensible move is to make sure the log says what you would want it to say.
What the My Health My Data Act requires on a website
Four requirements bear directly on how a practice site is built.
A separate consumer health data privacy policy. Not a section inside the general privacy policy. A distinct document, linked from the homepage, describing the categories collected, the purposes, the categories of third parties receiving it, and how a consumer exercises rights.
Consent before collection, and separate consent before sharing. These are two decisions, and the statute is explicit that consent must be obtained prior to collection and separately prior to sharing. A single accept button collapses two required decisions into one, which is the structural reason a conventional cookie banner does not satisfy this. Selling requires a distinct valid authorisation, which is a further step again.
No geofencing around healthcare facilities. The Act prohibits implementing a geofence around an entity providing in-person health care services for the purposes of identifying or tracking consumers seeking care, collecting their data, or sending them advertising. This one is usually a media-buying question rather than a website question, and it is worth putting to whoever runs paid campaigns.
Rights machinery. Consumers can access, withdraw consent and request deletion, and a withdrawal has to be honoured. Answering a deletion request depends on knowing which third parties received the data, which is an inventory problem before it is a legal one.
Where these obligations bite hardest is the gap between HIPAA and this statute. Data about people who are not patients, prospects who filled in a form and never booked, visitors assembled into advertising audiences, is not protected health information and therefore gets no help from any HIPAA exemption. The boundary is worked through in what counts as PHI on a website, and the two-family structure is mapped in consumer health data under state law.
A practical position
Reading the requirements as a list invites a project. There is a simpler framing that satisfies most of it structurally.
Collect nothing non-essential by default. If no third party receives consumer health data before a visitor agrees, the consent-before-collection requirement is satisfied by construction rather than by configuration. Separate the collect decision from the share decision in the interface itself, so the record can show which one a visitor gave. Detect the visitor's state and show the notice that state expects, which is what state privacy detection does. And keep a durable, append-only record of what each visitor was shown and chose.
That last point is where a private right of action changes the calculus. In a dispute the question becomes what a specific person saw on a specific date and what they agreed to. A configuration describing intended behaviour is an argument. A timestamped record that cannot be edited after the fact is evidence, and producing that is what consent gating exists to do.
Key takeaways
- Coverage follows the consumer. A practice outside Washington with Washington visitors can be in scope.
- There is no revenue or record-count threshold. Smaller regulated entities received a later compliance date, not an exemption.
- Violations route through Washington's Consumer Protection Act, so a private individual can bring a claim without a regulator opening a matter.
- The definition of consumer health data contemplates inferences, so a record linking an identifiable person to a treatment page can qualify.
- Consent to collect and consent to share are separate decisions, and a single accept button cannot express both.
- A separate consumer health data privacy policy is required, linked from the homepage, not a section of the general policy.
Common questions
Does the My Health My Data Act apply to a practice outside Washington?
It can. The Act reaches entities that conduct business in Washington or that provide products or services targeted to consumers in Washington, and its protections attach to consumers who are Washington residents or whose consumer health data is collected in Washington. A practice in another state with Washington visitors should not assume it is outside scope on geography alone.
Is there a small-business exemption?
There is no revenue or record-count threshold of the kind found in comprehensive state privacy laws. Smaller regulated entities received a later compliance date rather than an exemption. This is the main structural difference practices get wrong, because they reason by analogy to laws that do have thresholds.
What makes the private right of action significant?
A violation is treated as an unfair or deceptive act under Washington's Consumer Protection Act, which means an individual consumer may bring a claim rather than waiting for the attorney general to act. Most state privacy statutes are enforceable only by a regulator, so this changes who can initiate a dispute and how many disputes are possible.
Editorial note. This article describes what published guidance, statutes and court filings say as of its publication date. It is general information, not legal advice, and it is not a statement about any particular practice's obligations. Consential.io is not a law firm. Regulations and case law change. Confirm your own position with healthcare counsel licensed in your state before acting on anything here.
Sources
- Chapter 19.373 RCW, Washington My Health My Data Act Washington State Legislature, full chapter text
- Chapter 19.86 RCW, Washington Consumer Protection Act The mechanism through which a violation becomes privately actionable. Cited without a link; see the RCW index.
- 45 CFR 160.103, definitions of covered entity and protected health information For the boundary between PHI and consumer health data
Show the right notice to the right visitor
Consential detects which state framework applies to each visitor and records what they were shown and what they chose.