Nevada and Washington health data statutes arrived within weeks of each other in 2023 and took effect on the same day. They cover the same subject, use a similar structure, and are frequently described together as though they were interchangeable. On the obligations they mostly are. On the consequence of getting it wrong they are not remotely.
For a practice building one implementation to satisfy both, the similarity is good news and the divergence is the thing to plan around. Both are worth understanding, because the pair illustrates how much of your actual risk lives in the enforcement section rather than in the requirements.
Nevada and Washington health data laws compared
| Washington | Nevada | |
|---|---|---|
| Instrument | My Health My Data Act, RCW 19.373 | Senate Bill 370 (2023) |
| Coverage test | Follows the consumer, not the business location | Follows the consumer, not the business location |
| Size threshold | None. Smaller entities got a later date | None of the comprehensive-law kind |
| Consent to collect | Required, before collection | Required, affirmative and voluntary |
| Consent to share | Separate consent required | Separate consent required |
| Sale | Distinct valid authorisation | Distinct written authorisation |
| Geofencing near facilities | Prohibited | Prohibited |
| Published policy | Standalone consumer health data policy | Consumer health data privacy policy |
| Who can sue you | Any consumer, via the Consumer Protection Act | The attorney general only |
Read down the table and eight of the nine rows are effectively the same law. The ninth is the one that changes the number in a risk assessment.
That the two align so closely is not coincidence. Both were drafted in the same period, in response to the same concern about health information falling outside HIPAA, and Nevada's drew visibly on Washington's structure. Where a legislature borrows an approach and changes one thing deliberately, the changed thing is worth reading as a decision rather than an oversight. Nevada looked at a private right of action and chose not to include one.
The row that matters
Washington declares that violations are matters vitally affecting the public interest and constitute unfair or deceptive acts under chapter 19.373 RCW, which routes them into the Consumer Protection Act. That gives individuals standing to bring their own claims.
Nevada, in Senate Bill 370, treats a violation as a deceptive trade practice enforceable by the attorney general. There is no private right of action, and a regulator with a queue behaves differently from an unlimited pool of potential plaintiffs.
The difference compounds in a way that is easy to underrate. Regulator-only enforcement scales with the regulator's budget and priorities, which means the realistic annual number of matters is small and weighted toward large or egregious targets. Private enforcement scales with how easy the violation is to detect and how many people were affected, neither of which has anything to do with the size of the defendant. A small practice is a poor use of an attorney general's time and a perfectly ordinary defendant in a private claim.
The detectability point is what closes the loop. Most compliance failures require inside knowledge to observe. This one requires a browser, and the evidence generates itself identically for a single-location practice and a hospital system. Under regulator-only enforcement that observability produces very little. Under private enforcement it produces a filterable list.
Why one row outweighs eight
Substantive obligations tell you what to build. The enforcement provision tells you what happens when you build it imperfectly, how quickly you find out, and how many separate parties can raise it. For planning purposes the second question usually dominates, because nobody implements anything perfectly.
Where the Nevada and Washington health data rules agree
Four shared features do most of the work of designing an implementation.
Coverage follows the consumer. Neither statute cares where your building is. Both reach entities providing products or services to consumers in the state, which for any practice with a public website and out-of-state patients is a live question rather than a theoretical one.
No meaningful size threshold. This is the reversal of expectations that catches small practices. Comprehensive privacy laws typically exempt businesses below a revenue or record-count floor. These do not, so the reasoning that a single-location practice is too small to be covered does not transfer.
Layered consent. Both separate collection from sharing, and both treat sale as requiring its own authorisation. An interface offering one accept button cannot record which of three distinct permissions a visitor gave, which is an architecture problem rather than a copy problem.
Geofencing prohibitions. Both bar virtual boundaries around facilities providing in-person health care for purposes of identifying or advertising to people seeking care. This one belongs in a conversation with whoever buys media, not with whoever maintains the site.
If you operate in neither state
Most practices reading this are in neither Nevada nor Washington, which makes the natural question why any of it applies. Three reasons, in ascending order of importance.
The first is the coverage test already described. Neither statute asks where you are, and a practice with a public website and a national or regional patient draw is reached through its visitors rather than its address. For a specialty that routinely attracts people willing to travel, that is not a stretched reading.
The second is that these two are a template. Legislatures borrow from each other, and a structure that has now been enacted twice and survived is the structure the next state is most likely to adopt. Building an implementation that satisfies this shape is a bet that the shape recurs, which is a considerably safer bet than betting your own state will stay quiet.
The third is the one that actually decides it. The obligations these statutes impose are, with the exception of the geofencing provision, things a practice would want to be able to demonstrate regardless of which law applies. Knowing what leaves your pages, being able to show what a visitor was told and chose, and not sending health-adjacent data to advertising platforms by default are defensible positions under HIPAA, under comprehensive state privacy laws, under the FTC Act, and in front of a patient who asks. The statutes are a reason to do it now. They are not the only reason it is worth doing.
The practical read
Treat Nevada and Washington less as two jurisdictions to comply with and more as the clearest published description of what regulators currently think good practice looks like for health data on a website. That framing survives whichever state legislates next.
Building one implementation for both
The engineering conclusion is straightforward, with one caveat about how far it can be pushed.
Build to Washington. It is the stricter of the two on the dimension that matters, and an implementation that would satisfy a private plaintiff's scrutiny in Washington is comfortably above what Nevada's attorney general is likely to require. In practice that means: collect nothing non-essential before a visitor agrees, separate the collect decision from the share decision so the record can distinguish them, publish a standalone consumer health data policy, and keep an append-only record of what each visitor was shown and chose.
The caveat is that build to the stricter is an engineering heuristic and not a legal conclusion. Definitions differ in detail, exemptions differ, and notice content requirements differ. A practice that satisfies Washington's architecture has almost certainly satisfied Nevada's architecture and has not thereby been advised that it complies with either. Only counsel reading your specific setup can say that.
The other reason to build structurally rather than state by state is that this list is growing. Two statutes today, with more states drafting, means an implementation keyed to specific state names needs revisiting each session, while one built around the underlying shape does not. That shape is described in consumer health data under state law, and the Washington specifics are in what My Health My Data means for a practice website.
What none of this removes is the need to know which state a given visitor is in, because the notice that should be shown differs. Detecting that server side at request time is what state privacy detection does, and holding non-essential tags until the visitor answers is what consent gating does. Together they produce the record that a private-right-of-action state makes worth having.
Key takeaways
- Eight of nine comparison rows are effectively the same law. The ninth, enforcement, is where the risk difference lives.
- Washington routes violations through its Consumer Protection Act, so any affected consumer can bring a claim. Nevada is attorney general only.
- Both follow the consumer rather than the business location, so a practice in neither state can be in scope for both.
- Neither has the size threshold that exempts small businesses from comprehensive privacy laws.
- Both require separate consent to collect and to share, with sale needing its own authorisation. One accept button cannot express three decisions.
- Build to Washington as an engineering heuristic, not as a legal conclusion. The definitions and notice requirements still differ in detail.
Common questions
What is the main difference between the Nevada and Washington health data laws?
Enforcement. Washington routes violations through its Consumer Protection Act, which allows a private individual to bring a claim. Nevada's statute is enforced by the state attorney general as a deceptive trade practice, with no private right of action. The substantive obligations are broadly similar; who can sue you over them is not.
Do both laws require separate consent to collect and to share?
Both are built around affirmative consent obtained before collection, with a further separate consent before sharing, and a distinct authorisation before any sale. Neither is satisfied by a single undifferentiated accept button.
If I comply with Washington, am I compliant in Nevada?
Building to the stricter of the two is a sound engineering approach and gets you most of the way, but it is not a legal conclusion. Definitions, exemptions and notice requirements differ in detail, and only counsel reviewing your specific operation can tell you where the differences bite.
Editorial note. This article describes what published guidance, statutes and court filings say as of its publication date. It is general information, not legal advice, and it is not a statement about any particular practice's obligations. Consential.io is not a law firm. Regulations and case law change. Confirm your own position with healthcare counsel licensed in your state before acting on anything here.
Sources
- Chapter 19.373 RCW, Washington My Health My Data Act Washington State Legislature, full chapter text
- Nevada Senate Bill No. 370, 82nd Session (2023), enrolled text Nevada Legislature. AN ACT relating to data privacy.
- Chapter 19.86 RCW, Washington Consumer Protection Act The route by which a Washington violation becomes privately actionable. Cited without a link.
One implementation, both states
Consential detects which state framework applies to a visitor and shows the notice that state expects, on an append-only record.