Consumer Health Data Privacy Laws by State: Washington, Nevada, Connecticut
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Three US states regulate consumer health data that HIPAA does not reach: Washington, Nevada, and Connecticut. Washington's My Health My Data Act is the strictest of them and the only US consumer privacy law that lets an individual sue you directly. All three took effect around March 31, 2024. New York passed a fourth in 2025, but Governor Hochul vetoed it on December 19, 2025, and a revised version was reintroduced in 2026.
The pattern behind these laws is worth understanding before the details. HIPAA covers health providers, health plans, clearinghouses, and their business associates. It says almost nothing about the fitness tracker on your wrist, the period app on your phone, the supplement you bought online, or the ad network that watched you visit a clinic. That gap is where consumer health data laws live, and it means the companies most exposed by them are usually the ones that never considered themselves healthcare businesses at all.
What counts as consumer health data outside HIPAA
Each of these laws defines health data far more broadly than a medical record. Washington's version, which the others resemble, covers personal information that is linked or reasonably linkable to a consumer and identifies that person's past, present, or future physical or mental health status. In practice the statute reaches:
- Conditions, treatments, procedures, and medications, whether reported by the person or inferred by you.
- Bodily functions and vital signs, which is where wearables and fitness apps get pulled in.
- Reproductive and sexual health, and gender-affirming care, the categories that motivated these laws politically.
- Biometric data used to identify a person or assess health.
- Precise location that could reasonably indicate an attempt to acquire health services or supplies.
- Data derived or inferred from any of the above by an algorithm or machine learning model.
That last item does most of the damage. A retailer that never asks a health question can still hold consumer health data because a model inferred a pregnancy or a chronic condition from purchase history. If you feed customer records into internal AI assistants, the inference problem compounds, and it is worth constraining which systems and records those agents can reach before you find out what they concluded. An inference is regulated data in Washington the same as a diagnosis is.
Which states have health data privacy laws in 2026
The table below covers the laws actually in force. Verify the current statutory text before relying on any single row, since these are amended frequently.
| State | Law | In force | Who it covers | Enforcement |
|---|---|---|---|---|
| Washington | My Health My Data Act (MHMDA), RCW 19.373 | March 31, 2024 (small businesses June 30, 2024) | Any entity targeting Washington consumers that determines the purpose and means of handling consumer health data. No size threshold. | Attorney General and private plaintiffs, via the Consumer Protection Act. The only broad private right of action in US privacy law. |
| Nevada | Senate Bill 370 | March 31, 2024 | Same structure as Washington: purpose-and-means test, no size threshold | Nevada Attorney General only, as a deceptive trade practice. No private right of action. |
| Connecticut | Consumer health data provisions added to the CTDPA by Senate Bill 3 | 2023 to 2024, inside the CTDPA | Entities already in scope of the Connecticut Data Privacy Act | Connecticut Attorney General only. No private right of action. |
| New York | Health Information Privacy Act (S929) | Not in force. Vetoed December 19, 2025; revised bill reintroduced in 2026 | Would have covered regulated health information on a strict-necessity standard | Would have been the New York Attorney General. No private right of action as drafted. |
Washington MHMDA: the one with real litigation risk
Washington is the law to plan around, for one reason. Every other US privacy statute is enforced by a state attorney general, and California's narrow private claim applies only to certain data breaches. A MHMDA violation is treated as an unfair or deceptive act under the Washington Consumer Protection Act, which already carries a private right of action. Consumers can sue without waiting for a regulator.
That is not an automatic win for plaintiffs. There are no statutory damages in the statute, so a claimant has to prove injury and causation like any other Consumer Protection Act case. But the Consumer Protection Act allows civil penalties up to $7,500 per violation, and a private plaintiff who proves injury can recover actual damages trebled up to $25,000 plus attorneys' fees. The first case arrived fast: Maxwell v. Amazon.com, Inc. and Amazon Advertising, LLC was filed in the Western District of Washington on February 10, 2025, alleging that an advertising SDK embedded in third-party mobile apps collected timestamped latitude and longitude along with mobile advertising IDs. The theory was not that Amazon ran a clinic. It was that location data revealed health-seeking behavior.
Two operational requirements deserve attention because they are the ones teams fail. First, the deadline: respond without undue delay and within 45 days of receipt, extendable once by 45 more days when reasonably necessary if you notify the consumer inside the first window. Second, deletion has to travel. You must erase the data from your own records and networks and instruct every affiliate, processor, contractor, and other third party that received it to delete it too. You cannot issue that instruction if you cannot name the recipients, and most companies cannot, because the sharing happened through a pixel, an analytics SDK, or a warehouse sync nobody inventoried. The full requirements are covered on our My Health My Data Act compliance guide.
Nevada SB 370: similar rules, softer consequences
Nevada's law took effect the same day and follows the same logic. It applies to anyone conducting business in Nevada or targeting Nevada consumers who determines the purpose and means of processing, sharing, or selling consumer health data, again with no revenue or headcount threshold. Selling consumer health data requires a written authorization that describes the data, states the purpose, names the parties, and carries an expiration date and a right to revoke.
The difference is who can come after you. Nevada created no private right of action. The Nevada Attorney General enforces SB 370 as a deceptive trade practice. A company operating in both states should build to Washington's standard and treat Nevada as covered by the same process, rather than maintaining two workflows for laws that ask for nearly the same thing.
Connecticut: health data folded into an existing law
Connecticut took the third path. Instead of a standalone statute, Senate Bill 3 amended the Connecticut Data Privacy Act to add consumer health data rules on consent, contracting, and geofencing around healthcare facilities. The practical effect is that health data obligations sit inside a comprehensive privacy law you may already be complying with, on the CTDPA's own timing and enforcement. If the CTDPA applies to your business, the health data provisions apply with it, and there is no separate threshold to evaluate.
Do the comprehensive state privacy laws already cover health data?
Partly, and the overlap causes real confusion. The twenty comprehensive state privacy laws almost all classify health data as sensitive data, which typically means you need opt-in consent before processing it and must run a data protection assessment. That is a meaningful obligation, but it is a consent-and-assessment rule attached to a broader law with size thresholds, not a dedicated health data regime.
Washington and Nevada are different in kind because they have no thresholds, they define health data more expansively, and Washington adds private litigation. So a mid-market company can sit comfortably below the 100,000-consumer line in Virginia or Colorado and still be fully regulated in Washington. Our guide to which state privacy laws apply to your business walks through the comprehensive-law thresholds, and the state privacy law overview tracks all twenty.
What is the difference between HIPAA and consumer health data laws?
HIPAA regulates a defined set of organizations: health plans, healthcare clearinghouses, providers who bill electronically, and their business associates. Consumer health data laws regulate health-related information held by everyone else. Data already governed as HIPAA protected health information is carved out of Washington's law, so the two rarely apply to the same records. The less HIPAA covers you, the more MHMDA does.
Being a covered entity does not put you outside every state law, though, and that is the part providers get wrong most often. Nine states exempt HIPAA covered entities at the entity level, but California, Colorado, Delaware, Minnesota, New Jersey, and Oregon exempt only the protected health information, which leaves a hospital's marketing lists, website analytics, retail operations, and California employees fully in scope. The split is set out state by state in the guide to HIPAA exemptions from state privacy laws, and the request-handling side, including the 30-day clock in 45 CFR 164.524, sits on the HIPAA right of access page.
Does my company need a consumer health data privacy policy?
If Washington's law applies to you, yes, and it has to be a separate document. MHMDA requires a distinct consumer health data privacy policy, linked prominently from your homepage, disclosing the categories of health data you collect, the purposes, the categories of sources, and the third parties and affiliates you share with. Burying these disclosures inside a general privacy policy does not satisfy the requirement.
Can I use geofencing around a hospital or clinic?
No, not in Washington. MHMDA makes it unlawful to use a geofence of 2,000 feet or less around an in-person healthcare facility to identify or track consumers seeking services, collect consumer health data, or send health-related messages or advertisements. Connecticut added a comparable geofencing restriction through Senate Bill 3. Treat any location-based targeting near medical facilities as prohibited.
Where the operational work actually is
None of this is primarily a legal drafting problem. Once counsel has decided which laws reach you, the recurring work is the same as any privacy request program, with one extra dimension: you have to know where health-adjacent data sits, including data you inferred rather than collected, and you have to know who you sent it to.
A defensible process needs four things. You need intake that timestamps arrival, because the 45-day clock runs from receipt. You need discovery that finds the data across databases, warehouses, support tools, and analytics, not just the one system you remembered. You need a downstream recipient list so a deletion instruction can actually be issued to affiliates and processors. And you need a record of what was searched, found, redacted, approved, and sent, because in a private-right-of-action state the question will eventually be what you did, not what your policy said.
Obtainer handles that operational half: it intakes the request, finds where the person's data lives across your systems, compiles a source-system manifest that shows which downstream recipients need a deletion instruction, drafts a deadline-safe response, and tracks the clock. A human reviews, redacts, and approves before anything goes out. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. If you are working out your Washington exposure, start with the MHMDA compliance guide, and if deletion propagation is the piece you are worried about, see how deletion requests are handled end to end.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.