My Health My Data Act (MHMDA) Compliance: Washington Consumer Health Data Requests
Washington's My Health My Data Act is the one US privacy law a consumer can sue you over directly, and it has no revenue or headcount threshold to hide behind. It also reaches companies that have never thought of themselves as healthcare: a fitness app, a pharmacy delivery service, an ecommerce store selling supplements, an ad SDK logging location near a clinic. A deletion request under MHMDA has to reach your affiliates, processors, and contractors too. Obtainer finds where a person's health data actually lives across your systems, compiles one reviewable manifest, drafts the response, and keeps the 45-day clock and the evidence trail in one place.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The My Health My Data Act (MHMDA), RCW 19.373, has applied to regulated entities since March 31, 2024, and to small businesses since June 30, 2024, so every entity it covers is already in scope. It is not a comprehensive privacy law and it does not work like one. A "regulated entity" is any legal entity that conducts business in Washington, or produces or provides products or services targeted to consumers in Washington, and that alone or jointly with others determines the purpose and means of collecting, processing, sharing, or selling consumer health data. There is no revenue floor and no consumer-count threshold for coverage. Qualifying as a small business only moved your compliance date, it never exempted you. "Consumer health data" means personal information linked or reasonably linkable to a consumer that identifies that person's past, present, or future physical or mental health status, and the statute reads it broadly: health conditions, treatments, procedures, medications, bodily functions, gender-affirming care, reproductive and sexual health, biometric data, precise location that could reasonably indicate an attempt to acquire health services, and data derived or inferred from any of it by an algorithm. That last clause is why non-healthcare companies get caught. A "consumer" is a Washington resident or any natural person whose consumer health data is collected in Washington, so out-of-state visitors count, and the definition expressly excludes an individual acting in an employment context, which means MHMDA is not an employee-data law. Consumers can confirm whether you collect, share, or sell their health data and access it along with a list of the third parties and affiliates it went to, withdraw consent, and request deletion. You must respond without undue delay and within 45 days of receipt, extendable once by 45 more days when reasonably necessary if you notify the consumer inside the first window. Deletion is the hard one: you must delete the data from your own records and networks and instruct all affiliates, processors, contractors, and other third parties that received it to do the same. Consent to collect, consent to share, and authorization to sell are three separate permissions, and a sale needs a signed authorization naming the purchaser and purpose, with an expiration date and a right to revoke. Using a geofence of 2,000 feet or less around an in-person healthcare facility to track consumers, collect health data, or send health-related ads is flatly illegal. You must also publish a distinct consumer health data privacy policy and link it prominently from your homepage. Enforcement runs through the Washington Consumer Protection Act, which means the Attorney General can act and, uniquely among US privacy laws, a consumer can sue you directly. Obtainer covers the operational half: intake, discovery of where the person's health data sits, a source-system manifest that shows which downstream recipients need a deletion instruction, a drafted deadline-safe response, 45-day tracking, and a timestamped record of what was searched, found, redacted, and sent. Nothing is disclosed or erased automatically; a human reviews and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.
Why it fits
Health-adjacent apps, wellness and fitness products, telehealth and pharmacy services, supplement and medical-device ecommerce, and any adtech, analytics, or SaaS business that reaches Washington consumers and is not already covered by HIPAA, plus multi-state privacy teams that need MHMDA tracked separately from their comprehensive-law process.
The only US privacy law a consumer can sue you over directly
Every other state privacy law is enforced by an attorney general, with California allowing a narrow private claim for data breaches only. MHMDA is different: a violation is treated as an unfair or deceptive act under the Washington Consumer Protection Act, which already carries a private right of action. A plaintiff still has to prove injury and causation, so it is not automatic, but the door is open. The Consumer Protection Act allows civil penalties up to $7,500 per violation, and a private plaintiff who proves injury can recover actual damages trebled up to $25,000 plus attorneys' fees. The first case arrived quickly: Maxwell v. Amazon.com, Inc. and Amazon Advertising, LLC was filed in the Western District of Washington on February 10, 2025, over an advertising SDK embedded in third-party mobile apps that allegedly collected timestamped latitude and longitude and mobile advertising IDs. Nobody in that story set out to collect health data.
No threshold means no safe harbor for being small
The Virginia-model laws let you check a number and walk away: under 100,000 consumers and you are out of scope. MHMDA has no such line for coverage. If you target Washington consumers and you decide why and how consumer health data gets collected, you are a regulated entity whether you have ten customers or ten million. The "small business" definition only bought a later start date, and that date passed on June 30, 2024. The practical first step is not a threshold count, it is finding out whether anything you already hold meets the statute's broad definition of health data, including inferences your models produce.
Deletion has to travel downstream, not just through your database
A MHMDA deletion request obliges you to erase the data across your own records and networks and to instruct every affiliate, processor, contractor, and third party that received it to delete it as well. You cannot send that instruction if you cannot name the recipients, and most teams cannot, because the sharing happened through an ad pixel, an analytics SDK, a support tool, or a warehouse sync nobody has inventoried. Obtainer's discovery pass shows the source system behind every record it finds, which turns the downstream instruction list into something you can produce and evidence rather than approximate.
It reaches companies that are not in healthcare and are not covered by HIPAA
HIPAA governs covered entities and their business associates. MHMDA governs everyone else who touches health-adjacent data about a Washington consumer, and data already regulated as HIPAA protected health information is carved out of it. So the more of your data HIPAA covers, the less MHMDA applies, and the reverse is exactly the trap: a wellness app, a supplement retailer, a telehealth intermediary, a fertility tracker, or an adtech vendor sits outside HIPAA and squarely inside MHMDA. Precise location near a clinic and an inference drawn from a purchase history both count as consumer health data here.
More use cases
Related features
Questions
Common questions about this
Who has to comply with the My Health My Data Act?
Any legal entity that conducts business in Washington, or offers products or services targeted to Washington consumers, and that alone or jointly determines the purpose and means of collecting, processing, sharing, or selling consumer health data. There is no revenue or consumer-volume threshold for coverage. Being a small business under the statute only delayed your compliance date to June 30, 2024, which has passed. Data already regulated as HIPAA protected health information, and certain research and substance use disorder records, are exempt.
Does the My Health My Data Act apply if my company is not in healthcare?
Very likely yes, and that is the point of the law. MHMDA covers consumer health data held outside the HIPAA system, and it defines that data broadly enough to capture fitness and wellness apps, supplement and medical-device retailers, telehealth intermediaries, analytics providers, and advertising technology. Precise location suggesting someone tried to obtain health services counts, and so does a health status your algorithm infers from ordinary behavior. HIPAA-covered data is carved out, so the less HIPAA applies to you, the more MHMDA does.
How long do I have to respond to a My Health My Data Act request?
You must respond without undue delay and in any case within 45 days of receiving the request. You can extend once by another 45 days when reasonably necessary given the complexity and number of requests, provided you tell the consumer about the extension and the reason for it inside the original 45-day window. Consumers can confirm and access their health data, get a list of the third parties and affiliates it was shared or sold to, withdraw consent, and request deletion.
Does the My Health My Data Act have a private right of action?
Yes, and it is the only US consumer privacy law that gives consumers a broad one. A MHMDA violation is treated as an unfair or deceptive act under the Washington Consumer Protection Act, which carries an existing private right of action, so a consumer can sue directly rather than waiting for the Attorney General. Plaintiffs must still prove injury and causation, since the statute sets no automatic statutory damages. California's private right is far narrower and applies only to certain data breaches.
What does a MHMDA deletion request actually require?
More than deleting your own copy. You have to delete the consumer health data from your records and networks, and you must notify all affiliates, processors, contractors, and other third parties that received the data and instruct them to delete it too. That means you need a defensible list of every downstream recipient, which is usually the part companies cannot produce. Requests are free at least twice a year per consumer, and you may authenticate the requester using reasonable methods first.
Does the My Health My Data Act cover employee health data?
No. The statute defines a consumer as a Washington resident, or a natural person whose consumer health data is collected in Washington, and it expressly excludes an individual acting in an employment context. So workplace health information about your own staff is outside MHMDA. It may still be covered elsewhere, including under the CCPA in California, which removed its employee-data exemption on January 1, 2023, so an HR privacy program should not treat the Washington carve-out as a general rule.
Is Nevada's health data law the same as Washington's?
They are close siblings and both took effect on March 31, 2024, but the enforcement risk is not the same. Nevada Senate Bill 370 also regulates consumer health data outside HIPAA and requires a written authorization before any sale, and it likewise turns on whether you determine the purpose and means of processing rather than on a size threshold. The decisive difference is that Nevada has no private right of action and is enforced by the Nevada Attorney General as a deceptive trade practice, while Washington lets consumers sue.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.