Washington: My Health My Data and the Marketers It Catches

Sharing is caring!

A grocery store with in-store nutrition signage could, on some readings, be treated as providing in-person health care services — which would make an app coupon triggered when a shopper walks in a potential violation. That example comes from published legal commentary on Washington’s My Health My Data Act, and it captures why this law unsettles US digital marketing teams more than any other state privacy statute. For anyone running performance marketing or ecommerce marketing at national scale, the exposure is unusual on three counts: the geofencing prohibition is absolute, consumer consent cannot cure it, and unlike Texas or California the law carries a private right of action with treble damages up to $25,000.

A state analysis from Digital, Ecommerce & Performance Marketing in the United States. Companions: California and Texas. This is marketing commentary, not legal advice. The MHMDA’s scope is contested and fact-specific — engage qualified counsel. Last reviewed August 2026.

$25,000Treble damages available per claim
PrivateRight of action, unlike Texas
AbsoluteGeofencing ban, no consent exception
$0Revenue threshold to be covered
2Separate privacy policies required
BeyondHIPAA — that is the point of it

1. Why this law exists

The MHMDA was signed in April 2023 and aims to close the gap between industry practice and consumer understanding of how health data is collected, stored and transferred. Its primary sponsor described it as part of a legislative response to the Supreme Court’s decision in Dobbs, with particular attention to reproductive health privacy.

Understanding that origin matters commercially, because it explains the law’s shape. It is not a general privacy statute with a health chapter. It is a targeted instrument built to stop a specific set of practices that sit at the centre of ordinary digital marketing — tracking people near clinics, inferring health status from behaviour, and selling the result — and it was drafted to be enforceable by the people affected rather than only by a regulator. Performance marketing teams tend to meet it through location targeting and lookalike modelling rather than through anything they would describe as health data.

Most state privacy laws were written to regulate an industry. This one was written to stop something. The drafting reflects that, and so does the enforcement mechanism.

2. The private right of action changes everything

The MHMDA is enforced through the Washington Consumer Protection Act, and a violation is reported as a per se CPA violation — meaning no additional proof of unfair or deceptive conduct is required. That produces two enforcement routes rather than one.

RouteWho brings itRemedies reported
Attorney General actionStateCPA enforcement
Private civil suitInjured consumersInjunctive relief, actual damages, fees and costs
Treble damagesCourt discretionUp to $25,000
Class actionPlaintiff firmsAggregated claims

Sources: reporting that MHMDA violations are enforceable under the Washington Consumer Protection Act as per se violations, with private plaintiffs able to seek injunctive relief, actual damages and reasonable attorney fees and costs, and courts able to award treble damages up to $25,000. Consumer rights firms have publicly advertised class action work under the Act.

The presence of attorney fees and a class mechanism is what distinguishes this from Texas. Texas exposure arrives as a regulator’s letter with a thirty-day cure window. Washington exposure can arrive as a filed complaint from a plaintiff firm that has been looking for exactly your fact pattern.

3. Who counts as a regulated entity

The definition is deliberately wide. A regulated entity is broadly any entity that conducts business in Washington or produces or provides products or services targeted to Washingtonians, and that collects, processes, shares or sells consumer health data.

Two features of that wording matter for marketers. First, physical presence is not required — targeting Washington residents is enough. Second, and significantly, the MHMDA does not contain applicability thresholds based on revenue or number of consumers, so many organisations exempt under other frameworks are not exempt here.

BusinessAssumes it is out of scope becauseWhy it may not be
National ecommerce brandNo Washington officeTargeting Washingtonians is sufficient
Small wellness startupBelow other states’ thresholdsNo thresholds apply here
Fitness appNot a healthcare providerHIPAA status is not the test
Supplement retailerSells products, not servicesPurchases can imply health status
Ad tech vendorDoes not hold the relationshipProcessing and sharing are covered
Grocery chainSells foodHealth-adjacent inference and geofencing risk

Based on the reported MHMDA definition of regulated entities and the absence of revenue or consumer-count thresholds. Scenarios are illustrative of the scope question, not legal conclusions about any business type.

4. The geofencing prohibition

This is the provision most likely to catch a marketing team unaware, and it has applied since 23 July 2023 — earlier than the rest of the Act.

It is unlawful to use a geofence around a facility providing in-person health care services in order to identify or track consumers seeking health care services, collect consumer health data, or send notifications, messages or advertisements related to or derived from health data or use of health care services.

The one place consent does not help you Everywhere else in privacy law Get consent Proceed Geofencing under MHMDA Get consent Still prohibited Reported as an absolute prohibition with no consent provision. Which means the usual compliance answer — add a consent step — does not apply. The only compliant option is not to run the geofence. In force since 23 July 2023, ahead of the rest of the Act. Source: published MHMDA analysis describing the geofencing ban as absolute with no consent-based exception.

Source: legal commentary describing the MHMDA geofencing prohibition as an absolute prohibition with no provision allowing a business to obtain consumer consent for such activity, effective from 23 July 2023.

The scope question is genuinely unsettled. Commentary has noted that because health care services is broadly defined, a retailer offering in-store nutrition guidance might arguably fall within it — which would make a routine proximity coupon a potential violation depending on the facts. That is an uncomfortable ambiguity to be carrying inside a statute with a private right of action.

5. Consent, three times over

The MHMDA separates consent into distinct permissions rather than treating it as one gate. Reported requirements include opt-in consent to collect consumer health data, a separate consent to share it, and a stand-alone signed authorisation for any sale.

ActivityPermission requiredCommon failure
Collect consumer health dataOpt-in consentBundled into general terms
Share itSeparate consentTreated as covered by collection consent
Sell itStand-alone signed authorisationNo authorisation obtained at all
Respond to rights requestsAccess, deletion, withdrawalNo workflow, 45-day deadline missed
Vendor accessAppropriate contract termsStandard DPA without health provisions

Based on reported MHMDA requirements for opt-in consent to collect, separate consent to share, stand-alone authorisation for sale, and consumer rights to access, deletion and withdrawal of consent with 45-day response timelines.

The separation is the point. A single checkbox covering collection, sharing and sale is exactly the bundled-consent pattern the Act was written to prevent, and it is also the pattern most consent platforms produce by default.

6. The second privacy policy

The MHMDA requires a distinct consumer health data privacy policy, linked from the homepage and separate from the general privacy policy. It must disclose what consumer health data is collected, why, the sources, who it is shared with, and how consumers exercise their rights.

This is unusually specific and unusually easy to check. A regulator or plaintiff firm can determine in seconds whether the separate policy exists and is linked from the homepage — no investigation, no subpoena, no technical analysis. It is the lowest-effort compliance signal in the entire statute and one of the most commonly missing.

Any obligation that can be verified from outside your website, in under a minute, will be verified. Build for that first.

7. Health data is broader than you think

The Act protects consumer health data falling outside HIPAA. That is its central purpose, and it means HIPAA compliance answers nothing here. For ecommerce marketing teams in particular this is the trap: you are unlikely to hold medical records, but purchase and browsing data routinely support health inferences, and inference is what the statute reaches.

Reporting notes that data brokers aggregating health-adjacent information — pharmacy loyalty data, wellness app data, fitness tracker feeds — are subject to the Act. For a marketer the relevant question is not whether you handle medical records but whether your data supports an inference about someone’s health status.

Data you holdInference it can support
Pharmacy loyalty purchasesConditions and treatments
Fitness tracker feedsPhysical condition, sleep, stress
Supplement or nutrition purchasesDietary conditions, health goals
Search or content behaviourSymptoms being researched
Precise location near clinicsCare being sought
Wellness app engagementMental and physical health status

Based on reporting that data brokers aggregating health-adjacent information including pharmacy loyalty data, wellness app data and fitness tracker feeds fall within the Act’s scope. Whether specific data constitutes consumer health data is a legal determination.

8. Three states, three risk profiles

Taken together, the three states in this cluster produce genuinely different compliance postures — which is the strongest argument against treating US privacy as one problem with one answer.

DimensionCaliforniaTexasWashington
Size thresholdsYesNoneNone
Private right of actionLimited, breach-relatedNoneYes, via CPA
Cure periodNot in the same form30 daysNot equivalent
Dedicated regulatorYesAttorney GeneralAG plus private plaintiffs
GeofencingGeneral rules applyGeneral rules applyAbsolute ban near health facilities
Scope triggerThresholds metNot an SBA small businessTargeting Washingtonians

Comparison assembled from published analyses of all three statutes, simplified for marketing planning. Legal positions on specific points require counsel.

9. What this page does not cover

Not coveredWhy
Whether your data is consumer health dataFact-specific legal determination
Authorisation document draftingLegal work with prescribed content
Washington biometric law RCW 19.375Separate statute, no private right of action
Breach notification dutiesDistinct obligations and timelines
Nevada and Connecticut equivalentsSimilar but materially different
Litigation strategyCounsel, not marketing

Scope statement. Note that Nevada’s consumer health law broadly mirrors the MHMDA but reportedly lacks a private right of action and defines consumer health data more narrowly, and Connecticut has amended its privacy act to include consumer health data and geofence restrictions.

10. The compliance sequence

Stop the geofence first, then rebuild consent: 12 weeks Week 0 Week 4 Week 8 Week 12 Audit every active geofence Publish separate health privacy policy Map health-inferring data flows Unbundle collect, share and sell consent Rights workflow within 45 days Vendor terms for health data Red = stop and publish, amber = mapping and consent, green = process, grey = contracts. Indicative; run with counsel.

Indicative sequencing. The geofence audit sits first because it is the only obligation here that consent cannot cure — and because it has been in force since July 2023.

11. Mistakes to avoid

MistakeWhy it happensWhat it costs
Assuming HIPAA compliance covers itHealth equals HIPAA instinctThe Act exists to reach non-HIPAA data
Assuming no Washington office means no exposurePresence-based thinkingTargeting Washingtonians is enough
Adding consent to a health-facility geofenceStandard compliance reflexConsent cannot cure this prohibition
One consent covering collect, share and sellDefault CMP behaviourPrecisely the bundling the Act targets
No separate health privacy policyGeneral policy assumed sufficientTrivially verifiable from outside
Standard DPA with ad tech vendorsExisting template reusedHealth-specific terms absent

Recurring errors in MHMDA compliance for marketing teams; illustrative.

12. What changes next

Retention limits are pending. As of February 2026 statewide retention limits were not yet enacted, with competing proposals setting a 21-day default in the Senate and a 72-hour cap in the House. Either would materially change how long health-adjacent data can be held.

The model is spreading. Nevada has enacted a broadly similar law without a private right of action and with a narrower definition, and Connecticut has amended its privacy act to cover consumer health data and restrict geofence advertising. Compliance built for Washington travels.

Comprehensive state privacy is still pending. A general Washington Privacy Act has failed repeatedly and had not passed as of 2026, which means health data remains the sharpest edge of Washington privacy law rather than one component of a broader statute.

Key Takeaways

  • The MHMDA carries a private right of action with injunctive relief, actual damages, attorney fees and treble damages up to $25,000.
  • A violation is reported as a per se Consumer Protection Act violation — no separate proof of unfair or deceptive conduct required.
  • The geofencing ban near health facilities is absolute. Consent cannot cure it; the only compliant option is not to run it.
  • There are no revenue or consumer-count thresholds, and targeting Washingtonians is enough to be covered without any local presence.
  • HIPAA compliance answers nothing here. The Act was written to reach health data that falls outside HIPAA.
  • Collection, sharing and sale each need separate permission, with a stand-alone signed authorisation for sale.
  • A separate consumer health data privacy policy must be linked from the homepage — verifiable from outside in under a minute.

Frequently Asked Questions

We are HIPAA compliant. Does the MHMDA still apply?

Very possibly. The Act was specifically designed to protect consumer health data falling outside HIPAA, so HIPAA status is not the test. Fitness apps, wellness platforms, supplement retailers and data brokers handling health-adjacent information can all fall within scope.

We have no Washington presence. Are we exempt?

Not necessarily. The definition of a regulated entity covers businesses that conduct business in Washington or that produce or provide products or services targeted to Washingtonians. A national ecommerce brand with no office in the state can still be covered.

Can we geofence a health facility if we get consent?

Reported analysis describes the prohibition as absolute, with no provision permitting consent-based geofencing for the covered purposes. The compliant answer is not to run the geofence rather than to build a consent flow around it.

Why is the private right of action such a big deal?

Because it changes who can bring a claim and what it costs. Texas exposure arrives as a regulator’s letter with a thirty-day cure period. Washington exposure can arrive as a class action from a plaintiff firm, with attorney fees and treble damages up to $25,000 available.

Is one consent checkbox enough?

No. Reported requirements separate opt-in consent to collect, a distinct consent to share, and a stand-alone signed authorisation to sell. Bundling all three into a single acceptance is the pattern the Act was written to prevent.

Do we really need a second privacy policy?

Yes — a separate consumer health data privacy policy linked from the homepage, disclosing what is collected, why, from where, with whom it is shared and how rights are exercised. It is also the easiest obligation for anyone outside your company to check.

How broad is consumer health data really?

Broad enough that the useful question is not whether you hold medical records but whether your data supports an inference about someone’s health. Pharmacy loyalty purchases, fitness tracker feeds and wellness app engagement have all been identified as within scope.

Could an ordinary retail geofence be a problem?

Possibly, depending on facts. Commentary has observed that because health care services is broadly defined, a retailer offering in-store nutrition guidance might arguably fall within it — making a proximity coupon a potential issue. The ambiguity is real and worth legal input.

What should we do first?

Audit every active geofence, because that obligation cannot be cured by consent and has been in force since July 2023. Then publish the separate health privacy policy, since it is the most easily verified requirement in the statute. Both sit with whoever owns your performance marketing stack rather than with legal alone.

Conclusion

Washington’s My Health My Data Act is the sharpest privacy exposure in this cluster, and the reason is structural rather than substantive. It has no size thresholds, reaches businesses with no presence in the state, covers data that HIPAA does not, contains one prohibition that consent cannot cure — and it lets private plaintiffs bring the claim, with fees and treble damages attached.

Together with California and Texas it makes the case against treating US privacy as a single problem. California will test what your tags actually do. Texas will catch you because you assumed you were too small. Washington will let a plaintiff firm decide the answer. Three states, three failure modes, and one uncomfortable implication: compliance built for the least demanding of them is not compliance at all.

The practical translation for a digital marketing team is that state privacy law is now a media planning input rather than a legal footnote. It determines which audiences you may build, which signals you may pass back to the ad platforms, and which location tactics are available at all — which is why it sits inside this US performance marketing cluster rather than in a compliance appendix. The capability pages on performance marketing under consent and first-party data cover what to build once you know the constraints.

Work With Me

If you run location-based advertising anywhere in the US and nobody has mapped which geofences sit near health facilities, that audit is worth doing before someone else does it for you.

Comments

comments

Sharing is caring!

Leave a Reply