EnglishEspañol
Washington flag

Washington

MHMDA Business Compliance (Washington)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 10 primary sources cited on this page. How we verify our legal content

MHMDA Business Compliance (Washington)

Frequently Asked Questions

What does MHMDA require businesses to do?

MHMDA (chapter 19.373 RCW) requires regulated entities to publish a separate consumer health data privacy policy (RCW 19.373.020), obtain consent before collecting or sharing consumer health data with a distinct consent to share (RCW 19.373.030), honor consumer rights requests within 45 days (RCW 19.373.040), restrict access and maintain security (RCW 19.373.050 and .060), and avoid geofencing health facilities (RCW 19.373.080). Two duties are broader still: RCW 19.373.070 makes it unlawful for any person to sell consumer health data without a separate signed authorization, and the geofencing ban also applies to any person.

When did businesses have to comply with MHMDA?

The geofencing ban took effect July 23, 2023 for any person. Regulated entities that are not small businesses had to comply with the core duties by March 31, 2024, and small businesses by June 30, 2024. As of 2026, all of those dates have passed, so every covered organization is fully obligated.

Does a small business have to comply with MHMDA?

Yes. Under RCW 19.373.010, the 'small business' definition (processing data for fewer than 100,000 consumers, or fewer than 25,000 while deriving less than half of revenue from such processing) only affects the compliance date, June 30, 2024, not whether the law applies. Small businesses must meet the same core duties as larger regulated entities.

What must a MHMDA privacy policy include?

Under RCW 19.373.020, the consumer health data privacy policy must be separate from the general privacy notice, linked on the homepage, and disclose the categories of consumer health data collected and why, the sources of that data, the categories of data shared, a list of the categories of third parties and the specific affiliates it is shared with, and how consumers can exercise their rights. Under RCW 19.373.020(1)(c) and (d), the entity cannot collect, use, or share additional categories of data, or use it for additional purposes, that the policy does not disclose without first disclosing those additional categories or purposes and obtaining the consumer's affirmative consent.

What is the difference between consent and authorization under MHMDA?

Consent under RCW 19.373.030 is required to collect or share consumer health data, and the share consent must be separate from the collect consent. Authorization under RCW 19.373.070 is a higher bar required to sell consumer health data: a separate, specific, signed document that names buyer and seller, describes the sale, cannot be a condition of service, expires after one year, and must be retained for six years. The consent duties are written against regulated entities, while the sale prohibition is written against any person.

Can a business use geofencing near a clinic in Washington?

Not for the prohibited purposes. RCW 19.373.080 makes it unlawful to use a geofence within 2,000 feet of an in-person health care facility to track consumers seeking health services, collect their consumer health data, or send them health-related notifications, messages, or ads. The ban is absolute, so it cannot be cured with consumer consent, and it applies to any person, not just regulated entities.

What is the penalty for violating MHMDA?

MHMDA has no separate penalty schedule. Instead, RCW 19.373.090 makes a violation a per se violation of the Washington Consumer Protection Act (chapter 19.86 RCW). That exposes a business to Attorney General enforcement and to private lawsuits under RCW 19.86.090, which allow actual damages, treble damages up to a statutory cap, costs, and attorney fees. The private right of action, including class actions, is the headline litigation risk.

Are processors and vendors covered by MHMDA?

Yes. Under RCW 19.373.060, a processor may handle consumer health data only under a binding contract and only per the regulated entity's instructions. A processor that exceeds those instructions or breaches the contract becomes a regulated entity itself for that data. Under RCW 19.373.050, regulated entities must also restrict employee, processor, and contractor access to what is necessary and maintain reasonable data security.

Updates

Corrected the scope of the consumer health data sale prohibition, which applies to any person and not only regulated entities, and clarified that undisclosed data categories or purposes may be added by updating the privacy policy and obtaining the consumer's affirmative consent.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. RCW 19.373.020: Consumer health data privacy policy(app.leg.wa.gov).gov
  2. RCW 19.373.030: Collection or sharing of consumer health data(app.leg.wa.gov).gov
  3. RCW 19.373.040: Consumer rights and requests, refusal, appeal(app.leg.wa.gov).gov
  4. RCW 19.373.050: Data security practices(app.leg.wa.gov).gov
  5. RCW 19.373.060: Processors(app.leg.wa.gov).gov
  6. RCW 19.373.070: Valid authorization to sell(app.leg.wa.gov).gov
  7. RCW 19.373.080: Geofence restrictions(app.leg.wa.gov).gov
  8. RCW 19.373.090: Application of consumer protection act(app.leg.wa.gov).gov
  9. RCW 19.86.090: Consumer Protection Act private right of action(app.leg.wa.gov).gov
  10. Washington Attorney General: Protecting Washingtonians' Personal Health Data and Privacy(atg.wa.gov).gov
Share: