A Washington state privacy law that adds strict requirements for collecting, sharing, selling, and protecting consumer health data. It expands notice, consent, deletion, and access obligations, and it applies to many businesses that target Washington residents even if they are not covered by HIPAA.
What the law covers
My Health My Data Act is a Washington privacy law built around consumer health data, so the core issue is not just collection, but whether a business has lawful notice, consent, sharing limits, deletion handling, and access control over highly sensitive data. It applies more broadly than HIPAA, which makes scope analysis a first-order compliance question for many consumer-facing services.
That breadth matters because health-related data can be inferred from purchases, app behavior, location, and other signals, even when a company does not think of itself as a healthcare business. The practical test is whether the organisation handles consumer health data in a way that triggers the act's obligations, not whether it operates inside a traditional provider or payer model.
Why it matters operationally
The law turns privacy design into an operational requirement. Teams need to know what data they collect, where it flows, who receives it, how long it is retained, and whether downstream sharing or sale creates obligations that must be disclosed and controlled. That makes data inventory, consent logic, and deletion workflows central to compliance.
For practitioners, the important point is that compliance failures often come from ordinary product and analytics paths, not from obvious health-record systems. Marketing tags, SDKs, ad-tech integrations, and customer support exports can all become part of the regulated data path if they involve consumer health data.
Broad privacy governance is especially relevant here, and the NIST Privacy Framework is a useful companion for structuring data processing, risk management, and privacy controls around those flows.
Security and privacy control expectations
Even though the act is a privacy law, the control implications are security-relevant. Consumer health data needs tighter handling than ordinary business data because misuse, overcollection, or unauthorized sharing can create both legal exposure and trust damage. A practical reading of the law is that access restriction, retention discipline, and secure deletion are part of compliance, not separate concerns.
Authoritative control catalogs can help translate that requirement into operational safeguards. The access, audit, and confidentiality controls in NIST SP 800-53 Rev 5 Security and Privacy Controls support the same underlying needs: limit who can see sensitive data, trace what happened to it, and reduce the chance of improper disclosure.
Because many consumer systems depend on third-party scripts, APIs, and analytics platforms, privacy obligations also intersect with data governance and vendor oversight. The NIST Privacy Framework helps connect those controls to processing purposes, while the SOC 2 Trust Services Criteria (AICPA) are commonly used to evidence security, confidentiality, and privacy discipline in service environments.
How businesses should interpret scope
Scope is the part that most often surprises organisations. The act is designed to reach companies that target Washington residents, so geographic location, audience targeting, and the nature of the data all matter. A business may be outside HIPAA and still have to treat its consumer data handling as regulated health data processing under this law.
That means the analysis should start with data classification and customer targeting, then move to disclosure and consent mechanics. If a product, website, or app can infer health-related information from user activity, the team should map those data elements to the law's obligations before launch rather than after a complaint or enforcement inquiry.
For teams already managing sensitive data at scale, privacy design should be treated as a product control, not an afterthought. The NIST Privacy Framework and NIST Cybersecurity Framework 2.0 are both useful for linking governance, protection, and response expectations to day-to-day business operations.
Risk and Threat Considerations
My Health My Data Act creates material exposure when consumer health data is collected more broadly than expected, shared through third parties, or retained after it should have been deleted. The biggest practical risk is not only regulatory enforcement, but also the downstream harm that follows from unauthorized disclosure of intimate consumer information.
Failure mechanism: Organisations often fail at data mapping and third-party visibility, so health-related data moves through ad-tech, analytics, or support systems without the notice, consent, or deletion controls the law expects.
Impact: That can trigger legal liability, consumer trust loss, and a wider privacy incident if sensitive data is exposed, sold, or retained beyond its lawful purpose.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | Governs privacy risk and accountability for regulated consumer health data processing. |
| PR.DS — Data Security | Protects sensitive data through handling, storage, and transfer safeguards relevant to health data. | |
| PR.AC — Identity Management, Authentication, and Access Control | Limits who can access sensitive consumer data and supports least-privilege handling. | |
| Recommendation — Assign ownership for consumer health data governance and track disclosure, retention, and response obligations. Protect consumer health data in transit, at rest, and during sharing to reduce unauthorized exposure. Restrict access to consumer health data to approved roles and purposes only. | ||
| CIS Controls v8 | 3 — Data Protection | Calls for safeguarding sensitive information through classification, handling, and disposal controls. |
| 6 — Access Control Management | Supports limiting access to sensitive data paths and reducing disclosure risk. | |
| Recommendation — Classify consumer health data and enforce handling and disposal controls for it. Remove unnecessary access to consumer health data and review who can reach it. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Supports strong authentication for systems that expose regulated consumer data. |
| Recommendation — Use strong, phishing-resistant authentication for administrative and data-access systems. | ||
Practitioner Guidance
Why practitioners should care: This law is a governance test as much as a legal one. The fastest way to miss it is to treat health data as a narrow clinical category instead of a broader consumer-data problem tied to inference, sharing, and deletion.
Common misunderstanding: Many teams assume HIPAA coverage defines the boundary. In practice, the compliance question is whether the business handles consumer health data in a way that brings Washington's broader obligations into scope.
Practitioner takeaway: The safest operational posture is to classify consumer health data early, trace every sharing path, and make consent and deletion workflows visible before the data reaches production use.
Related resources from NHI Mgmt Group
- How should security teams govern MCP-enabled AI assistants that can act on tools and data?
- What should organisations do before letting AI agents act on business data?
- Who is accountable when a connected health app mishandles patient data?
- How should security teams govern AI-driven security functions that act on mailbox or reporting data?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org