EnglishEspañol
Nevada flag

Nevada

Nevada Consumer Health Data Law (SB 370)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

Nevada Consumer Health Data Law (SB 370)

Frequently Asked Questions

What is Nevada's consumer health data privacy law?

It is a Nevada statute enacted as Senate Bill 370 in 2023 and codified in NRS Chapter 603A (the consumer health data provisions at NRS 603A.400 et seq.). It protects health information that falls outside HIPAA, requires a published privacy policy and consent before collecting or sharing consumer health data, requires separate authorization before any sale, bans geofencing near medical facilities, and gives consumers confirmation, deletion, and consent-withdrawal rights. It took effect March 31, 2024.

Does Nevada's law have a private right of action?

No. This is the most important difference from Washington's My Health My Data Act. A violation of the Nevada law is a deceptive trade practice that only the Nevada Attorney General may enforce, with civil penalties of up to $10,000 per violation for breaching a resulting court order, or up to $15,000 per violation if a court finds the violation was willful. Consumers cannot sue regulated entities directly under the statute.

When did Nevada's consumer health data law take effect?

March 31, 2024. Unlike Washington, Nevada did not give small businesses a delayed compliance date, so all covered regulated entities faced the same effective date.

Who has to comply with the law?

A regulated entity, defined as a person who conducts business in Nevada or targets products or services to Nevada consumers and who determines the purpose and means of processing consumer health data. There is no revenue or data-volume threshold, so size does not exempt an entity. The carve-outs differ in kind: NRS 603A.490(1)(a) exempts any person or entity that is subject to HIPAA outright, while the Gramm-Leach-Bliley carve-out reaches a financial institution or its affiliate that is subject to that Act as well as the personally identifiable information the Act regulates.

What is consumer health data under the Nevada law?

Personal information that is linked or reasonably capable of being linked to a consumer and that identifies the consumer's past, present, or future health status. It can include health conditions, treatments, medications, reproductive or gender-affirming care, biometric and genetic data, and precise location data indicating a consumer is seeking health care. The definition closely tracks Washington's My Health My Data Act.

What is the geofencing rule?

The law prohibits a person from using a geofence within 1,750 feet of a medical facility or provider of in-person health care services to identify or track consumers seeking care, collect consumer health data, or send health-related messages or advertisements. Nevada specifies the 1,750-foot radius directly in the operative ban, while Washington's act defines a geofence as a boundary of 2,000 feet or less from the facility (RCW 19.373.010), effectively capping its ban at up to 2,000 feet.

Can a business sell consumer health data in Nevada?

Only with a separate, valid written authorization from the consumer that is distinct from the consent used to collect or share the data. The authorization must describe the specific data, the recipient, and the purpose, and it expires after a set period. Without that authorization, selling consumer health data is prohibited.

What is Nevada SB 220 and how is it different?

SB 220 (2019), codified at NRS 603A.300 to 603A.360, is an older and much narrower law. It lets a Nevada consumer direct an operator of a website or online service not to sell the consumer's covered information, and the operator must respond within 60 days. It covers only opt-out-of-sale, not the broad health data duties in SB 370. Like SB 370, it has no private right of action and is enforced by the Attorney General with penalties up to $5,000 per violation.

Updates

Corrected the consumer-rights section (Nevada's request right produces a list of third parties, which by statute excludes affiliates), clarified that the HIPAA exemption applies to the entity itself rather than only to HIPAA-regulated data, and replaced a Washington-specific consent rule with Nevada's own consent-disclosure requirements under NRS 603A.500.

Corrected the Nevada consumer health data law's penalty figure (violations are enforceable by the Attorney General for up to $10,000 per violation for breaching a court order, or up to $15,000 if willful, not $5,000), clarified that Washington's geofencing ban is effectively bounded at 2,000 feet rather than unlimited, added the law's 45-day request-response and 30-day deletion-completion deadlines, and fixed a citation range that had listed the statute as running to NRS 603A.590 instead of 603A.550.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Nevada SB 370 (82nd Session, 2023): Enrolled Bill Text(leg.state.nv.us).gov
  2. Nevada SB 370 (82nd Session, 2023): Bill Overview and History(leg.state.nv.us).gov
  3. NRS 603A.500 to 603A.550: Consumer Health Data (operative duties)(leg.state.nv.us).gov
  4. Nevada Office of the Attorney General: Bureau of Consumer Protection(ag.nv.gov).gov
  5. Nevada SB 220 (80th Session, 2019): Enrolled Bill Text (NRS 603A.300 to 603A.360)(leg.state.nv.us).gov
  6. Nevada SB 220 (80th Session, 2019): Bill Overview and History(leg.state.nv.us).gov
  7. Washington My Health My Data Act, Chapter 19.373 RCW (Full Chapter)(app.leg.wa.gov).gov
  8. NRS 603A.400 to 603A.490: Consumer Health Data Definitions and Applicability(leg.state.nv.us)
  9. RCW 19.373.010: My Health My Data Act Definitions, including consent(app.leg.wa.gov)
Share: