RoutineMetric

Washington My Health My Data (MHMDA) Compliance & Liability Screener

Analyze MHMDA statutory scope, tracking pixel class-action exposure, and compliance readiness under Chapter 19.373 RCW.

1. Threshold Applicability & Organization Setup

Washington State NexusDo you conduct business in WA state, or target products or services to WA consumers?
Collect/Share Personal DataDo you collect, process, share, or sell any consumer personal data?
Total unique consumers processed annually (used for Small Business classification).
Gross Revenue From CHD ≥ 50%Do you derive 50% or more of gross revenue from CHD processing, sharing, or sales?

2. Narrow Statutory Exemptions (Data-Level)

MHMDA does not have broad entity-level commercial exemptions. However, specific classes of information governed by federal frameworks are excluded. Select the checkboxes below if ALL your collected health-related data is covered by:

3. Consumer Health Data (CHD) Scope & Digital Trackers

Check all categories of data that your website, mobile app, services, or trackers collect or process. Under MHMDA, CHD includes physical/mental health status, but extends far beyond traditional medical records:

4. MHMDA Operational Pillars (Current Capabilities)

Evaluate your current data management processes against the six mandatory statutory gates. Toggle the switches to YES if you fully implement the capability:

Pillar 1: Homepage Consumer Health Privacy LinkA completely separate, dedicated policy page linked from the homepage using the exact words "Consumer Health Privacy Policy".
Pillar 2: Explicit Opt-in Consent prior to CollectionObtaining granular, voluntary, affirmative prior consent on your app/website before any health data collection begins.
Pillar 3: Independent Consent for SharingA completely distinct prior opt-in consent flow specifically for sharing health data with affiliates or analytics networks.
Pillar 4: Signed Written Contractual Sale AuthorizationStrict written, physically or digitally signed agreements detailing recipient entities and purposes prior to any data sale.
Pillar 5: Deletion & Backup Purging MechanismInfrastructure to access, confirm, and permanently delete consumer records across primary systems, backups, and offsite archives.
Pillar 6: Strict Geofencing RestrictionsNo geofencing around physical medical clinics, mental therapy offices, or alternative medicine locations to track or advertise.
Applicability Status
Small Business - Full Scope

Your organization is classified as a Small Business under MHMDA. Both standard Regulated Entities and Small Businesses must now be in full compliance.

Compliance Readiness Score17%

Pillars Implemented1 of 6
Statutory EnforcementFully Enforced (2026)
Litigation Risk Exposure
CRITICAL EXPOSURE

CRITICAL EXPOSURE: Third-party tracking pixels (e.g., Meta Pixel, Google Analytics) on health-related pages combined with missing MHMDA-compliant consent policies is a prime target for active CPA class-action lawsuits in Washington.

Immediate Priority Tasks

  • Pause Digital PixelsStop active trackers on pages hosting health/wellness information.
  • Homepage Privacy Policy LinkAdd homepage link specifically named "Consumer Health Privacy Policy".
  • Establish Prior Opt-InObtain explicit separate consent before collecting user health data.
  • Propagate DeletionsBuild non-revocable customer deletion pipeline that flushes backups.
Advertisement
Bottom Banner Ad (728x90)

Understanding Washington's My Health My Data Act (MHMDA): Compliance Guide

Enacted as Chapter 19.373 RCW, the Washington My Health My Data Act (MHMDA) took full effect in 2024. In the years since, it has completely reshaped the regulatory landscape of consumer privacy in the United States. While the federal Health Insurance Portability and Accountability Act (HIPAA) covers medical records kept by traditional healthcare providers and insurance companies, it does not apply to consumer wellness trackers, fitness apps, health search terms, or digital marketing pixels embedded on health resources. MHMDA was designed specifically to close this "HIPAA loophole" for non-covered entities.

Why is Washington MHMDA a Compliance Trap?

MHMDA is widely considered by corporate counsel to be one of the most aggressive and complex privacy laws in history due to three factors:

  • No Volume or Revenue Thresholds: Unlike California's CCPA, Virginia's VCDPA, or other state frameworks that require a business to process data of 100,000+ consumers or make millions of dollars before the law applies, MHMDA has zero commercial exemptions or threshold criteria for general applicability. If you conduct business in Washington or target Washington consumers and collect ANY consumer health data, you must comply.
  • Unbelievably Broad Definition of "Consumer Health Data" (CHD): CHD includes not only direct diagnoses or therapies but also heart rates, reproductive health status, gender-affirming care information, search history for medications or wellness services, biometric data, precise location indicators within 1,750 feet of a healthcare provider, and—crucially—any health status inferred or derived from non-health proxy information.
  • Private Right of Action: Unlike the vast majority of state privacy laws that can only be enforced by state Attorneys General, MHMDA is explicitly enforceable by individual consumers through a private right of action under the Washington Consumer Protection Act (CPA). This allows class-action attorneys to sue directly, seeking actual damages, treble damages up to $25,000, and mandatory shifting of attorneys' fees, leading to hundreds of class-action filings.

The Digital Marketing Pixel Risk

In 2025 and 2026, the bulk of MHMDA litigation has focused on digital marketing tracking scripts (such as the Meta Pixel, Google Analytics, LinkedIn Insight Tag, and HubSpot analytics). Under the Act's definitions:

If a website contains pages hosting health-related information, articles about medical conditions, symptom searches, or clinic booking tools, the user's interaction with that website constitutes consumer health data. If a tracking pixel transmits that browsing behavior (including URLs or metadata) back to social media or advertising platforms without an MHMDA-compliant opt-in consent, that transmission constitutes the unconsented collection and sharing of consumer health data.

This operational gap has led to immediate "Critical Risk" exposure for businesses that fail to segment their marketing analytics or employ robust tag management.

The Six Mandatory Gates to MHMDA Compliance

To achieve full compliance and insulate the business from litigation, organizations must strictly implement six statutory mechanisms:

  1. Consumer Health Privacy Policy: Publish a separate, dedicated privacy disclosure page. It must be accessible directly via a homepage link containing the exact phrase "Consumer Health Privacy Policy" and outline all data categories, sources, purposes, and recipient third parties.
  2. Prior Affirmative Collection Consent: Deploy a cookie/tracker consent manager that prevents any health data or pixel tracking scripts from initializing until the consumer clicks a clear, affirmative, voluntary "Opt-in" button specifically dedicated to MHMDA data collection.
  3. Separate Prior Sharing Consent: If you disclose, transmit, or share consumer health data with affiliate entities or analytics networks, you must obtain a separate, standalone opt-in consent that is operationally distinct from the collection consent.
  4. Signed Written Authorization for Sales: Under MHMDA, selling or transferring consumer health data for monetary or other valuable consideration requires a written, signed contractual authorization document that specifies the recipient, purposes, and a 6-year retention schedule. Standard cookie banners or online check-boxes are insufficient.
  5. Non-Revocable Deletion Infrastructure: Upon receiving a deletion request, the organization must permanently delete the consumer's health data across all primary systems, third-party processors, mirrors, and crucially, all offline backups and archives, within 30 days.
  6. Strict Geofencing Ban: Operationally restrict the usage of geofences (creating a virtual boundary within 1,750 feet) around hospitals, clinics, counseling centers, pharmacies, or physical health service providers to target marketing, track users, or harvest behavioral information.
Advertisement