Understanding Washington's My Health My Data Act (MHMDA): Compliance Guide
Enacted as Chapter 19.373 RCW, the Washington My Health My Data Act (MHMDA) took full effect in 2024. In the years since, it has completely reshaped the regulatory landscape of consumer privacy in the United States. While the federal Health Insurance Portability and Accountability Act (HIPAA) covers medical records kept by traditional healthcare providers and insurance companies, it does not apply to consumer wellness trackers, fitness apps, health search terms, or digital marketing pixels embedded on health resources. MHMDA was designed specifically to close this "HIPAA loophole" for non-covered entities.
Why is Washington MHMDA a Compliance Trap?
MHMDA is widely considered by corporate counsel to be one of the most aggressive and complex privacy laws in history due to three factors:
- No Volume or Revenue Thresholds: Unlike California's CCPA, Virginia's VCDPA, or other state frameworks that require a business to process data of 100,000+ consumers or make millions of dollars before the law applies, MHMDA has zero commercial exemptions or threshold criteria for general applicability. If you conduct business in Washington or target Washington consumers and collect ANY consumer health data, you must comply.
- Unbelievably Broad Definition of "Consumer Health Data" (CHD): CHD includes not only direct diagnoses or therapies but also heart rates, reproductive health status, gender-affirming care information, search history for medications or wellness services, biometric data, precise location indicators within 1,750 feet of a healthcare provider, and—crucially—any health status inferred or derived from non-health proxy information.
- Private Right of Action: Unlike the vast majority of state privacy laws that can only be enforced by state Attorneys General, MHMDA is explicitly enforceable by individual consumers through a private right of action under the Washington Consumer Protection Act (CPA). This allows class-action attorneys to sue directly, seeking actual damages, treble damages up to $25,000, and mandatory shifting of attorneys' fees, leading to hundreds of class-action filings.
The Digital Marketing Pixel Risk
In 2025 and 2026, the bulk of MHMDA litigation has focused on digital marketing tracking scripts (such as the Meta Pixel, Google Analytics, LinkedIn Insight Tag, and HubSpot analytics). Under the Act's definitions:
If a website contains pages hosting health-related information, articles about medical conditions, symptom searches, or clinic booking tools, the user's interaction with that website constitutes consumer health data. If a tracking pixel transmits that browsing behavior (including URLs or metadata) back to social media or advertising platforms without an MHMDA-compliant opt-in consent, that transmission constitutes the unconsented collection and sharing of consumer health data.
This operational gap has led to immediate "Critical Risk" exposure for businesses that fail to segment their marketing analytics or employ robust tag management.
The Six Mandatory Gates to MHMDA Compliance
To achieve full compliance and insulate the business from litigation, organizations must strictly implement six statutory mechanisms:
- Consumer Health Privacy Policy: Publish a separate, dedicated privacy disclosure page. It must be accessible directly via a homepage link containing the exact phrase "Consumer Health Privacy Policy" and outline all data categories, sources, purposes, and recipient third parties.
- Prior Affirmative Collection Consent: Deploy a cookie/tracker consent manager that prevents any health data or pixel tracking scripts from initializing until the consumer clicks a clear, affirmative, voluntary "Opt-in" button specifically dedicated to MHMDA data collection.
- Separate Prior Sharing Consent: If you disclose, transmit, or share consumer health data with affiliate entities or analytics networks, you must obtain a separate, standalone opt-in consent that is operationally distinct from the collection consent.
- Signed Written Authorization for Sales: Under MHMDA, selling or transferring consumer health data for monetary or other valuable consideration requires a written, signed contractual authorization document that specifies the recipient, purposes, and a 6-year retention schedule. Standard cookie banners or online check-boxes are insufficient.
- Non-Revocable Deletion Infrastructure: Upon receiving a deletion request, the organization must permanently delete the consumer's health data across all primary systems, third-party processors, mirrors, and crucially, all offline backups and archives, within 30 days.
- Strict Geofencing Ban: Operationally restrict the usage of geofences (creating a virtual boundary within 1,750 feet) around hospitals, clinics, counseling centers, pharmacies, or physical health service providers to target marketing, track users, or harvest behavioral information.