Signed into law on April 27, 2023, by Governor Jay Inslee, the My Health My Data Act is the first law in the United States that focuses on consumer health data privacy beyond HIPAA’s rules. HIPAA mainly protects data handled by healthcare providers, insurers, and their business associates. MHMDA covers many types of entities that collect, process, share, or sell consumer health data. These include technology companies, retail stores, wellness providers, and small medical offices.
Health data under this law has a wide meaning. It includes usual health information like treatments or conditions. It also includes biometric data, genetic information, location data related to healthcare, and data guessed from non-health activities. For example, if a store uses a person’s purchase history of items like non-prescription medicine or certain toiletries to guess their health condition, that data is covered by the Act.
The law applies to “regulated entities.” These are any legal businesses in Washington or those aiming at Washington residents that decide how consumer health data is collected, used, shared, or sold. This includes healthcare providers with offices in Washington, telehealth providers serving Washington customers, marketing firms that handle health-related data, fitness app creators, and even companies outside Washington that process Washington residents’ health data.
Entities that only store consumer data in Washington but do not actively use it are not regulated. Government agencies, tribal nations, and their contractors are also exempt. Unlike some privacy laws, MHMDA does not exempt nonprofits or HIPAA-covered groups if they handle health data outside HIPAA rules. For example, wellness or cosmetic services not covered by HIPAA must follow MHMDA.
This timeline gives smaller businesses more time while keeping privacy rules consistent for all healthcare groups.
By March 2024, or June 2024 for small businesses, regulated entities must do these things:
The Washington Attorney General enforces MHMDA. Breaking the law counts as a violation of the Washington Consumer Protection Act. Penalties can be fines up to $7,500 for each violation.
Consumers can also sue companies for violations. They can get damages up to $25,000 per affected person. Courts may triple the damages and add lawyer fees. This makes it much riskier for companies that don’t follow the rules.
Healthcare leaders and medical office owners in Washington must know that MHMDA covers more than HIPAA. Practices offering services beyond regular treatments, like cosmetic work, wellness programs, or telehealth, must watch their data rules carefully.
Out-of-state practices offering telemedicine to Washington residents and third-party providers like billing firms, marketing agencies, and IT vendors handling health data for Washington consumers also must meet the rules. Healthcare groups across the country need to check if they handle Washington consumer data and how MHMDA affects them.
Using artificial intelligence (AI) and workflow automation can help medical practices follow MHMDA rules with better accuracy and speed. These tools can help in different ways:
Healthcare IT managers can add these AI tools to existing Electronic Health Records (EHR) systems, patient portals, and customer management software. This lowers manual work and helps follow MHMDA’s consent, data protection, and transparency rules.
Following the Washington My Health My Data Act needs work on policies, system upgrades, and staff training. Medical office leaders should:
Because of the penalties and rights to sue introduced by MHMDA, it is smart to work on compliance early. This lowers legal risks and helps build trust with patients.
Washington’s My Health My Data Act adds new rules for all organizations that handle consumer health data. Big and small groups must meet these rules by set deadlines. Medical office leaders and IT staff need to adjust how they work to follow the law and keep providing reliable care in today’s digital world.
The My Health My Data Act is a privacy law in Washington State that protects consumers’ personal health data beyond the scope of HIPAA, requiring consent for data collection and sharing. It reflects widespread support among Washingtonians for enhanced privacy protections.
The Act’s effective dates vary: all persons must comply with section 10 starting July 23, 2023; regulated entities not classified as small businesses must comply with sections 4-9 by March 31, 2024; small businesses by June 30, 2024.
Violations of the My Health My Data Act are considered violations of the Washington Consumer Protection Act, which the Attorney General enforces, alongside private actions.
A regulated entity is any person or business that conducts business in Washington or offers services/products targeted at Washington consumers and that collects, processes, shares, or sells consumer health data.
Yes, businesses outside Washington that collect, process, share, or sell health data of Washington residents are impacted by the Act, specifically if they determine the means of such actions.
Regulated entities and small businesses must prominently publish a link to their Consumer Health Data Privacy Policy on their homepage per section 4(1)(b) of the Act.
Yes, information derived from non-health data that is used to identify a consumer’s health status can be considered consumer health data under the Act.
Regulated entities must retain copies of valid consumer authorizations for six years when selling consumer health data and must comply with deletion requests for consumer health data.
Yes, if a regulated entity infers health status from the purchase of non-prescription medication, that information is classified as consumer health data.
Consumers have the right to request deletion of their health data, and regulated entities must comply by removing the data and retaining a redacted version of the authorization.