Washington: My Health My Data and the Marketers It Catches
A grocery store with in-store nutrition signage could, on some readings, be treated as providing in-person health care services — which would make an app coupon triggered when a shopper walks in a potential violation. That example comes from published legal commentary on Washington’s My Health My Data Act, and it captures why this law unsettles US digital marketing teams more than any other state privacy statute. For anyone running performance marketing or ecommerce marketing at national scale, the exposure is unusual on three counts: the geofencing prohibition is absolute, consumer consent cannot cure it, and unlike Texas or California the law carries a private right of action with treble damages up to $25,000.
A state analysis from Digital, Ecommerce & Performance Marketing in the United States. Companions: California and Texas. This is marketing commentary, not legal advice. The MHMDA’s scope is contested and fact-specific — engage qualified counsel. Last reviewed August 2026.
1. Why this law exists
The MHMDA was signed in April 2023 and aims to close the gap between industry practice and consumer understanding of how health data is collected, stored and transferred. Its primary sponsor described it as part of a legislative response to the Supreme Court’s decision in Dobbs, with particular attention to reproductive health privacy.
Understanding that origin matters commercially, because it explains the law’s shape. It is not a general privacy statute with a health chapter. It is a targeted instrument built to stop a specific set of practices that sit at the centre of ordinary digital marketing — tracking people near clinics, inferring health status from behaviour, and selling the result — and it was drafted to be enforceable by the people affected rather than only by a regulator. Performance marketing teams tend to meet it through location targeting and lookalike modelling rather than through anything they would describe as health data.
Most state privacy laws were written to regulate an industry. This one was written to stop something. The drafting reflects that, and so does the enforcement mechanism.
2. The private right of action changes everything
The MHMDA is enforced through the Washington Consumer Protection Act, and a violation is reported as a per se CPA violation — meaning no additional proof of unfair or deceptive conduct is required. That produces two enforcement routes rather than one.
| Route | Who brings it | Remedies reported |
|---|---|---|
| Attorney General action | State | CPA enforcement |
| Private civil suit | Injured consumers | Injunctive relief, actual damages, fees and costs |
| Treble damages | Court discretion | Up to $25,000 |
| Class action | Plaintiff firms | Aggregated claims |
Sources: reporting that MHMDA violations are enforceable under the Washington Consumer Protection Act as per se violations, with private plaintiffs able to seek injunctive relief, actual damages and reasonable attorney fees and costs, and courts able to award treble damages up to $25,000. Consumer rights firms have publicly advertised class action work under the Act.
The presence of attorney fees and a class mechanism is what distinguishes this from Texas. Texas exposure arrives as a regulator’s letter with a thirty-day cure window. Washington exposure can arrive as a filed complaint from a plaintiff firm that has been looking for exactly your fact pattern.
3. Who counts as a regulated entity
The definition is deliberately wide. A regulated entity is broadly any entity that conducts business in Washington or produces or provides products or services targeted to Washingtonians, and that collects, processes, shares or sells consumer health data.
Two features of that wording matter for marketers. First, physical presence is not required — targeting Washington residents is enough. Second, and significantly, the MHMDA does not contain applicability thresholds based on revenue or number of consumers, so many organisations exempt under other frameworks are not exempt here.
| Business | Assumes it is out of scope because | Why it may not be |
|---|---|---|
| National ecommerce brand | No Washington office | Targeting Washingtonians is sufficient |
| Small wellness startup | Below other states’ thresholds | No thresholds apply here |
| Fitness app | Not a healthcare provider | HIPAA status is not the test |
| Supplement retailer | Sells products, not services | Purchases can imply health status |
| Ad tech vendor | Does not hold the relationship | Processing and sharing are covered |
| Grocery chain | Sells food | Health-adjacent inference and geofencing risk |
Based on the reported MHMDA definition of regulated entities and the absence of revenue or consumer-count thresholds. Scenarios are illustrative of the scope question, not legal conclusions about any business type.
4. The geofencing prohibition
This is the provision most likely to catch a marketing team unaware, and it has applied since 23 July 2023 — earlier than the rest of the Act.
It is unlawful to use a geofence around a facility providing in-person health care services in order to identify or track consumers seeking health care services, collect consumer health data, or send notifications, messages or advertisements related to or derived from health data or use of health care services.
Source: legal commentary describing the MHMDA geofencing prohibition as an absolute prohibition with no provision allowing a business to obtain consumer consent for such activity, effective from 23 July 2023.
The scope question is genuinely unsettled. Commentary has noted that because health care services is broadly defined, a retailer offering in-store nutrition guidance might arguably fall within it — which would make a routine proximity coupon a potential violation depending on the facts. That is an uncomfortable ambiguity to be carrying inside a statute with a private right of action.
5. Consent, three times over
The MHMDA separates consent into distinct permissions rather than treating it as one gate. Reported requirements include opt-in consent to collect consumer health data, a separate consent to share it, and a stand-alone signed authorisation for any sale.
| Activity | Permission required | Common failure |
|---|---|---|
| Collect consumer health data | Opt-in consent | Bundled into general terms |
| Share it | Separate consent | Treated as covered by collection consent |
| Sell it | Stand-alone signed authorisation | No authorisation obtained at all |
| Respond to rights requests | Access, deletion, withdrawal | No workflow, 45-day deadline missed |
| Vendor access | Appropriate contract terms | Standard DPA without health provisions |
Based on reported MHMDA requirements for opt-in consent to collect, separate consent to share, stand-alone authorisation for sale, and consumer rights to access, deletion and withdrawal of consent with 45-day response timelines.
The separation is the point. A single checkbox covering collection, sharing and sale is exactly the bundled-consent pattern the Act was written to prevent, and it is also the pattern most consent platforms produce by default.
6. The second privacy policy
The MHMDA requires a distinct consumer health data privacy policy, linked from the homepage and separate from the general privacy policy. It must disclose what consumer health data is collected, why, the sources, who it is shared with, and how consumers exercise their rights.
This is unusually specific and unusually easy to check. A regulator or plaintiff firm can determine in seconds whether the separate policy exists and is linked from the homepage — no investigation, no subpoena, no technical analysis. It is the lowest-effort compliance signal in the entire statute and one of the most commonly missing.
Any obligation that can be verified from outside your website, in under a minute, will be verified. Build for that first.
7. Health data is broader than you think
The Act protects consumer health data falling outside HIPAA. That is its central purpose, and it means HIPAA compliance answers nothing here. For ecommerce marketing teams in particular this is the trap: you are unlikely to hold medical records, but purchase and browsing data routinely support health inferences, and inference is what the statute reaches.
Reporting notes that data brokers aggregating health-adjacent information — pharmacy loyalty data, wellness app data, fitness tracker feeds — are subject to the Act. For a marketer the relevant question is not whether you handle medical records but whether your data supports an inference about someone’s health status.
| Data you hold | Inference it can support |
|---|---|
| Pharmacy loyalty purchases | Conditions and treatments |
| Fitness tracker feeds | Physical condition, sleep, stress |
| Supplement or nutrition purchases | Dietary conditions, health goals |
| Search or content behaviour | Symptoms being researched |
| Precise location near clinics | Care being sought |
| Wellness app engagement | Mental and physical health status |
Based on reporting that data brokers aggregating health-adjacent information including pharmacy loyalty data, wellness app data and fitness tracker feeds fall within the Act’s scope. Whether specific data constitutes consumer health data is a legal determination.
8. Three states, three risk profiles
Taken together, the three states in this cluster produce genuinely different compliance postures — which is the strongest argument against treating US privacy as one problem with one answer.
| Dimension | California | Texas | Washington |
|---|---|---|---|
| Size thresholds | Yes | None | None |
| Private right of action | Limited, breach-related | None | Yes, via CPA |
| Cure period | Not in the same form | 30 days | Not equivalent |
| Dedicated regulator | Yes | Attorney General | AG plus private plaintiffs |
| Geofencing | General rules apply | General rules apply | Absolute ban near health facilities |
| Scope trigger | Thresholds met | Not an SBA small business | Targeting Washingtonians |
Comparison assembled from published analyses of all three statutes, simplified for marketing planning. Legal positions on specific points require counsel.
9. What this page does not cover
| Not covered | Why |
|---|---|
| Whether your data is consumer health data | Fact-specific legal determination |
| Authorisation document drafting | Legal work with prescribed content |
| Washington biometric law RCW 19.375 | Separate statute, no private right of action |
| Breach notification duties | Distinct obligations and timelines |
| Nevada and Connecticut equivalents | Similar but materially different |
| Litigation strategy | Counsel, not marketing |
Scope statement. Note that Nevada’s consumer health law broadly mirrors the MHMDA but reportedly lacks a private right of action and defines consumer health data more narrowly, and Connecticut has amended its privacy act to include consumer health data and geofence restrictions.
10. The compliance sequence
Indicative sequencing. The geofence audit sits first because it is the only obligation here that consent cannot cure — and because it has been in force since July 2023.
11. Mistakes to avoid
| Mistake | Why it happens | What it costs |
|---|---|---|
| Assuming HIPAA compliance covers it | Health equals HIPAA instinct | The Act exists to reach non-HIPAA data |
| Assuming no Washington office means no exposure | Presence-based thinking | Targeting Washingtonians is enough |
| Adding consent to a health-facility geofence | Standard compliance reflex | Consent cannot cure this prohibition |
| One consent covering collect, share and sell | Default CMP behaviour | Precisely the bundling the Act targets |
| No separate health privacy policy | General policy assumed sufficient | Trivially verifiable from outside |
| Standard DPA with ad tech vendors | Existing template reused | Health-specific terms absent |
Recurring errors in MHMDA compliance for marketing teams; illustrative.
12. What changes next
Retention limits are pending. As of February 2026 statewide retention limits were not yet enacted, with competing proposals setting a 21-day default in the Senate and a 72-hour cap in the House. Either would materially change how long health-adjacent data can be held.
The model is spreading. Nevada has enacted a broadly similar law without a private right of action and with a narrower definition, and Connecticut has amended its privacy act to cover consumer health data and restrict geofence advertising. Compliance built for Washington travels.
Comprehensive state privacy is still pending. A general Washington Privacy Act has failed repeatedly and had not passed as of 2026, which means health data remains the sharpest edge of Washington privacy law rather than one component of a broader statute.
Key Takeaways
- The MHMDA carries a private right of action with injunctive relief, actual damages, attorney fees and treble damages up to $25,000.
- A violation is reported as a per se Consumer Protection Act violation — no separate proof of unfair or deceptive conduct required.
- The geofencing ban near health facilities is absolute. Consent cannot cure it; the only compliant option is not to run it.
- There are no revenue or consumer-count thresholds, and targeting Washingtonians is enough to be covered without any local presence.
- HIPAA compliance answers nothing here. The Act was written to reach health data that falls outside HIPAA.
- Collection, sharing and sale each need separate permission, with a stand-alone signed authorisation for sale.
- A separate consumer health data privacy policy must be linked from the homepage — verifiable from outside in under a minute.
Frequently Asked Questions
We are HIPAA compliant. Does the MHMDA still apply?
Very possibly. The Act was specifically designed to protect consumer health data falling outside HIPAA, so HIPAA status is not the test. Fitness apps, wellness platforms, supplement retailers and data brokers handling health-adjacent information can all fall within scope.
We have no Washington presence. Are we exempt?
Not necessarily. The definition of a regulated entity covers businesses that conduct business in Washington or that produce or provide products or services targeted to Washingtonians. A national ecommerce brand with no office in the state can still be covered.
Can we geofence a health facility if we get consent?
Reported analysis describes the prohibition as absolute, with no provision permitting consent-based geofencing for the covered purposes. The compliant answer is not to run the geofence rather than to build a consent flow around it.
Why is the private right of action such a big deal?
Because it changes who can bring a claim and what it costs. Texas exposure arrives as a regulator’s letter with a thirty-day cure period. Washington exposure can arrive as a class action from a plaintiff firm, with attorney fees and treble damages up to $25,000 available.
Is one consent checkbox enough?
No. Reported requirements separate opt-in consent to collect, a distinct consent to share, and a stand-alone signed authorisation to sell. Bundling all three into a single acceptance is the pattern the Act was written to prevent.
Do we really need a second privacy policy?
Yes — a separate consumer health data privacy policy linked from the homepage, disclosing what is collected, why, from where, with whom it is shared and how rights are exercised. It is also the easiest obligation for anyone outside your company to check.
How broad is consumer health data really?
Broad enough that the useful question is not whether you hold medical records but whether your data supports an inference about someone’s health. Pharmacy loyalty purchases, fitness tracker feeds and wellness app engagement have all been identified as within scope.
Could an ordinary retail geofence be a problem?
Possibly, depending on facts. Commentary has observed that because health care services is broadly defined, a retailer offering in-store nutrition guidance might arguably fall within it — making a proximity coupon a potential issue. The ambiguity is real and worth legal input.
What should we do first?
Audit every active geofence, because that obligation cannot be cured by consent and has been in force since July 2023. Then publish the separate health privacy policy, since it is the most easily verified requirement in the statute. Both sit with whoever owns your performance marketing stack rather than with legal alone.
Conclusion
Washington’s My Health My Data Act is the sharpest privacy exposure in this cluster, and the reason is structural rather than substantive. It has no size thresholds, reaches businesses with no presence in the state, covers data that HIPAA does not, contains one prohibition that consent cannot cure — and it lets private plaintiffs bring the claim, with fees and treble damages attached.
Together with California and Texas it makes the case against treating US privacy as a single problem. California will test what your tags actually do. Texas will catch you because you assumed you were too small. Washington will let a plaintiff firm decide the answer. Three states, three failure modes, and one uncomfortable implication: compliance built for the least demanding of them is not compliance at all.
The practical translation for a digital marketing team is that state privacy law is now a media planning input rather than a legal footnote. It determines which audiences you may build, which signals you may pass back to the ad platforms, and which location tactics are available at all — which is why it sits inside this US performance marketing cluster rather than in a compliance appendix. The capability pages on performance marketing under consent and first-party data cover what to build once you know the constraints.
Work With Me
If you run location-based advertising anywhere in the US and nobody has mapped which geofences sit near health facilities, that audit is worth doing before someone else does it for you.
