Everything you need to know about MHMDA compliance, data security requirements, and secure data disposal.
Washington's My Health My Data Act (MHMDA) is the first law in the United States specifically designed to protect consumer health data that falls outside the scope of HIPAA. Signed into law in April 2023, it closes a long-standing gap in US privacy regulation: the vast amount of health-adjacent data collected by wellness apps, fitness trackers, period-tracking apps, and other non-medical businesses that HIPAA was never designed to cover.
Background
The MHMDA was passed by the Washington State Legislature on April 17, 2023, and signed by Governor Jay Inslee on April 27, 2023, following the Washington Attorney General's push to expand health data privacy protections. Different sections of the law took effect on a staggered basis: certain provisions became effective July 23, 2023, while the core substantive requirements took effect March 31, 2024, for most regulated entities, with small businesses given an additional three months, until June 30, 2024, to comply.
Who Must Comply
The MHMDA applies to any "regulated entity" — a legal entity that conducts business in Washington, or produces or provides products or services targeted to Washington consumers, and that determines the purpose and means of collecting, processing, sharing, or selling consumer health data. Notably, unlike most US state privacy laws, the MHMDA does not include revenue or data-volume thresholds for applicability, meaning even small companies collecting consumer health data can be fully subject to the law (subject to the separate, narrower "small business" compliance timeline extension).
What Counts as "Consumer Health Data"
The law defines consumer health data broadly to include information that identifies a consumer's past, present, or future physical or mental health status — including data related to reproductive or sexual health, gender-affirming care, biometric data, and even inferred health information, such as data used to determine a consumer's interest in health-related products or services.
Key Requirements
Regulated entities under the MHMDA must:
- Publish a standalone consumer health data privacy policy, separate from a general privacy policy, disclosing the categories of health data collected and shared and the specific third parties or affiliates receiving it
- Obtain specific, separate consumer consent before collecting consumer health data beyond what is strictly necessary to provide a requested product or service
- Obtain separate, express authorization before selling consumer health data
- Honor consumer rights to access, delete, and withdraw consent
- Refrain from implementing geofences around healthcare facilities to identify, track, or target individuals seeking healthcare services
Consumer Rights
Consumers have the right to confirm whether a regulated entity is collecting their consumer health data, to access that data, to request deletion, and to withdraw consent for collection or sharing — with deletion requests required to propagate to any third parties or affiliates the data was shared with.
Enforcement and the Private Right of Action
The MHMDA is unusually aggressive in its enforcement structure. It is enforced both by the Washington Attorney General and — critically — through a private right of action, meaning individual consumers can sue regulated entities directly for violations. The Washington Attorney General's office has indicated it views the law as a strict liability statute, where a violation constitutes a per se violation of the Washington Consumer Protection Act, exposing entities to penalties of up to $7,500 per violation, in addition to potential damages from private litigation.
Secure Disposal of Consumer Health Data
The MHMDA's deletion rights require regulated entities to permanently remove consumer health data upon a valid deletion request, and general data security expectations under the law extend to how that data is stored and eventually disposed of. Because consumer health data is treated as a particularly sensitive category, and because the law's private right of action creates significant litigation exposure, organizations retiring servers, devices, or storage media that processed consumer health data should use verifiable, standards-based erasure methods rather than standard deletion, and retain documentation of destruction as part of their broader compliance and litigation-risk management strategy.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
The MHMDA set a new bar for consumer health data protection in the US, inspiring similar legislation in states like Nevada and Connecticut. Its lack of applicability thresholds and its private right of action make it one of the higher-risk state privacy laws to get wrong — organizations handling anything resembling health data about Washington consumers need dedicated consent flows, a standalone privacy policy, and rigorous, documented data disposal practices.
No comments yet. Be the first to comment.