{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/washington",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/washington.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/washington",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/washington/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/washington/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "washington",
    "frontmatter": {
      "title": "Washington Consumer Privacy Law (My Health My Data Act)",
      "description": "Washington has no comprehensive consumer-privacy statute, but the My Health My Data Act (ch. 19.373 RCW) reaches biometrics, precise location, and health inferences across most consumer businesses — and a violation is a per se Consumer Protection Act violation that consumers can sue over.",
      "state": "Washington",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "My Health My Data Act, ch. 19.373 RCW (main regulated-entity duties operative March 31, 2024; small-business duties generally June 30, 2024; geofencing ban separately in force), alongside the breach-notification statute (ch. 19.255 RCW) and the biometric-identifier statute (ch. 19.375 RCW) — Washington has no comprehensive consumer-privacy act",
        "appliesTo": "Any legal entity that conducts business in Washington or targets products or services to Washington consumers and determines how consumer health data is handled — a category that sweeps in biometrics, genetic data, precise location near health services, and health inferences derived from non-health data, so many non-health businesses are covered; small businesses generally had later dates, not an exemption",
        "privacyPolicyRequired": "Yes — a dedicated consumer health data privacy policy with statutorily fixed contents and a prominently published homepage link (RCW 19.373.020); no Washington statute fixes the contents of a general privacy policy",
        "privateRightOfAction": "Yes — an MHMDA violation is a per se Consumer Protection Act violation (RCW 19.373.090), so consumers injured in their business or property can sue under RCW 19.86.090; the biometric chapter, by contrast, is Attorney General-only",
        "regulator": "Washington Attorney General (under the Consumer Protection Act), alongside private CPA suits",
        "bottomLine": "Washington never passed a comprehensive privacy act, but the My Health My Data Act functions like one for a wide swath of businesses — consumer health data includes biometrics, precise location, and inferences, every covered business needs a separate homepage-linked health-data privacy policy, selling that data requires a signed authorization, and violations carry class-action exposure through the Consumer Protection Act.",
        "lawCoverage": "sectoral",
        "policyMandate": "sectoralPolicy",
        "consumersCanSue": "broad",
        "sensitiveDataConsent": "categorySpecific",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Washington My Health My Data Act",
        "MHMDA consumer health data definition",
        "Washington consumer health data privacy policy",
        "MHMDA consent and authorization to sell",
        "Washington geofencing ban health care",
        "Washington data breach notification RCW 19.255",
        "Washington biometric privacy RCW 19.375",
        "MHMDA private right of action Consumer Protection Act",
        "Washington Attorney General privacy enforcement",
        "My Health My Data Act class action litigation"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Washington?",
        "heading": "Which privacy laws apply to your business in Washington?",
        "answerText": "Washington has no comprehensive consumer-privacy statute, but the My Health My Data Act (MHMDA), chapter 19.373 RCW, functions as a near-comprehensive law in practice. It covers any legal entity that conducts business in Washington or targets products or services to Washington consumers and that determines the purpose and means of collecting, processing, sharing, or selling consumer health data — and it defines that data to reach far beyond health companies: reproductive and sexual health information, biometric data, genetic data, precise location information that could indicate an attempt to obtain health services, and data identifying a consumer seeking health care services all qualify, as do inferences about health derived or extrapolated from non-health information by algorithms or machine learning.",
        "sources": [
          {
            "id": "q1-regulated-entity",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(23)",
            "citation": "Wash. Rev. Code § 19.373.010(23).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "A regulated entity is any legal entity that conducts business in Washington or targets products or services to Washington consumers and determines the purpose and means of collecting, processing, sharing, or selling consumer health data — with no revenue or volume threshold.",
            "verbatimQuote": "\"Regulated entity\" means any legal entity that: (a) Conducts business in Washington, or produces or provides products or services that are targeted to consumers in Washington; and (b) alone or jointly with others, determines the purpose and means of collecting, processing, sharing, or selling of consumer health data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-regulated-entity"
          },
          {
            "id": "q1-chd-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(8)",
            "citation": "Wash. Rev. Code § 19.373.010(8).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "Consumer health data is personal information linked or reasonably linkable to a consumer that identifies past, present, or future physical or mental health status — expressly including reproductive or sexual health information, biometric data, genetic data, precise location information indicating an attempt to obtain health services, and data identifying a consumer seeking health care services.",
            "verbatimQuote": "\"Consumer health data\" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. (b) For the purposes of this definition, physical or mental health status includes, but is not limited to: (i) Individual health conditions, treatment, diseases, or diagnosis; (ii) Social, psychological, behavioral, and medical interventions; (iii) Health-related surgeries or procedures; (iv) Use or purchase of prescribed medication; (v) Bodily functions, vital signs, symptoms, or measurements of the information described in this subsection (8)(b); (vi) Diagnoses or diagnostic testing, treatment, or medication; (vii) Gender-affirming care information; (viii) Reproductive or sexual health information; (ix) Biometric data; (x) Genetic data; (xi) Precise location information that could reasonably indicate a consumer's attempt to acquire or receive health services or supplies; (xii) Data that identifies a consumer seeking health care services;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-chd-definition"
          },
          {
            "id": "q1-chd-inference",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(8)(b)(xiii)",
            "citation": "Wash. Rev. Code § 19.373.010(8)(b)(xiii).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "Consumer health data includes information used to associate or identify a consumer with health data that is derived or extrapolated from non-health information, including by algorithms or machine learning — the inference clause that pulls ad-tech and analytics processing into scope.",
            "verbatimQuote": "Any information that a regulated entity or a small business, or their respective processor, processes to associate or identify a consumer with the data described in (b)(i) through (xii) of this subsection that is derived or extrapolated from nonhealth information (such as proxy, derivative, inferred, or emergent data by any means, including algorithms or machine learning).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-chd-inference"
          },
          {
            "id": "q1-mhmda-intent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.005",
            "citation": "Wash. Rev. Code § 19.373.005(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.005",
            "proposition": "The legislature enacted the MHMDA to close the gap left by HIPAA, which does not protect health data collected by non-covered entities such as apps and websites.",
            "verbatimQuote": "However, HIPAA only covers health data collected by specific health care entities, including most health care providers. Health data collected by noncovered entities, including certain apps and websites, are not afforded the same protections. Chapter 191, Laws of 2023 works to close the gap between consumer knowledge and industry practice by providing stronger privacy protections for all Washington consumers' health data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-mhmda-intent"
          },
          {
            "id": "q1-consumer-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(7)",
            "citation": "Wash. Rev. Code § 19.373.010(7).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "A consumer is a Washington resident or any natural person whose consumer health data is collected in Washington, acting in an individual or household context — individuals acting in an employment context are excluded.",
            "verbatimQuote": "\"Consumer\" means (a) a natural person who is a Washington resident; or (b) a natural person whose consumer health data is collected in Washington. \"Consumer\" means a natural person who acts only in an individual or household context, however identified, including by any unique identifier. \"Consumer\" does not include an individual acting in an employment context.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-consumer-def"
          },
          {
            "id": "q1-small-business",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(28)",
            "citation": "Wash. Rev. Code § 19.373.010(28).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "A small business is a regulated entity that handles consumer health data of fewer than 100,000 consumers a year, or derives less than 50 percent of gross revenue from such data and handles fewer than 25,000 consumers' data — a category that gets delayed compliance dates, not an exemption.",
            "verbatimQuote": "\"Small business\" means a regulated entity that satisfies one or both of the following thresholds: (a) Collects, processes, sells, or shares consumer health data of fewer than 100,000 consumers during a calendar year; or (b) Derives less than 50 percent of gross revenue from the collection, processing, selling, or sharing of consumer health data, and controls, processes, sells, or shares consumer health data of fewer than 25,000 consumers.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-small-business"
          },
          {
            "id": "q1-policy-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(2)",
            "citation": "Wash. Rev. Code § 19.373.020(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the consumer health data privacy policy section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-policy-small-business-date"
          },
          {
            "id": "q1-collection-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(2)",
            "citation": "Wash. Rev. Code § 19.373.030(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the collection and sharing consent section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-collection-small-business-date"
          },
          {
            "id": "q1-rights-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(2)",
            "citation": "Wash. Rev. Code § 19.373.040(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the consumer rights section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-rights-small-business-date"
          },
          {
            "id": "q1-security-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.050(2)",
            "citation": "Wash. Rev. Code § 19.373.050(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.050",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the data-security section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-security-small-business-date"
          },
          {
            "id": "q1-processor-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.060(2)",
            "citation": "Wash. Rev. Code § 19.373.060(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.060",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the processor-contract section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-processor-small-business-date"
          },
          {
            "id": "q1-sale-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.070(6)",
            "citation": "Wash. Rev. Code § 19.373.070(6).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the sale-authorization section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-sale-small-business-date"
          },
          {
            "id": "q1-geofence-ban",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.080",
            "citation": "Wash. Rev. Code § 19.373.080.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.080",
            "proposition": "The geofencing ban is written as an unlawful act for any person and does not include the small-business delayed-date sentence used in other MHMDA sections.",
            "verbatimQuote": "It is unlawful for any person to implement a geofence around an entity that provides in-person health care services where such geofence is used to: (1) Identify or track consumers seeking health care services; (2) collect consumer health data from consumers; or (3) send notifications, messages, or advertisements to consumers related to their consumer health data or health care services.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-geofence-ban"
          },
          {
            "id": "q1-exemptions-phi",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.100(1)",
            "citation": "Wash. Rev. Code § 19.373.100(1)(a)(i).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.100",
            "proposition": "The MHMDA does not apply to information that meets the definition of protected health information under HIPAA — a data-level exemption, not an entity-level one.",
            "verbatimQuote": "This chapter does not apply to: (a) Information that meets the definition of: (i) Protected health information for purposes of the federal health insurance portability and accountability act of 1996 and related regulations;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-exemptions-phi"
          },
          {
            "id": "q1-exemptions-health",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.100(1)",
            "citation": "Wash. Rev. Code § 19.373.100(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.100",
            "proposition": "The MHMDA exempts multiple health-care-related information categories, intermingled indistinguishable information maintained by covered entities and similar holders, public-health-only information, limited data sets, and other listed data sets.",
            "verbatimQuote": "This chapter does not apply to: (a) Information that meets the definition of: (i) Protected health information for purposes of the federal health insurance portability and accountability act of 1996 and related regulations; (ii) Health care information collected, used, or disclosed in accordance with chapter 70.02 RCW; (iii) Patient identifying information collected, used, or disclosed in accordance with 42 C.F.R. Part 2, established pursuant to 42 U.S.C. Sec. 290dd-2; (iv) Identifiable private information for purposes of the federal policy for the protection of human subjects, 45 C.F.R. Part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonization; the protection of human subjects under 21 C.F.R. Parts 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the requirements set forth in this subsection; (v) Information and documents created specifically for, and collected and maintained by: (A) A quality improvement committee for purposes of RCW 43.70.510 , 70.230.080 , or 70.41.200 ; (B) A peer review committee for purposes of RCW 4.24.250 ; (C) A quality assurance committee for purposes of RCW 74.42.640 or 18.20.390 ; (D) A hospital, as defined in RCW 43.70.056 , for reporting of health care-associated infections for purposes of RCW 43.70.056 , a notification of an incident for purposes of RCW 70.56.040 (5), or reports regarding adverse events for purposes of RCW 70.56.020 (2)(b); or (E) A manufacturer, as defined in 21 C.F.R. Sec. 820.3(o), when collected, used, or disclosed for purposes specified in chapter 70.02 RCW; (vi) Information and documents created for purposes of the federal health care quality improvement act of 1986, and related regulations; (vii) Patient safety work product for purposes of 42 C.F.R. Part 3, established pursuant to 42 U.S.C. Sec. 299b-21 through 299b-26; (viii) Information that is (A) deidentified in accordance with the requirements for deidentification set forth in 45 C.F.R. Part 164, and (B) derived from any of the health care-related information listed in this subsection (1)(a)(viii); (b) Information originating from, and intermingled to be indistinguishable with, information under (a) of this subsection that is maintained by: (i) A covered entity or business associate as defined by the health insurance portability and accountability act of 1996 and related regulations; (ii) A health care facility or health care provider as defined in RCW 70.02.010 ; or (iii) A program or a qualified service organization as defined by 42 C.F.R. Part 2, established pursuant to 42 U.S.C. Sec. 290dd-2; (c) Information used only for public health activities and purposes as described in 45 C.F.R. Sec. 164.512 or that is part of a limited data set, as defined, and is used, disclosed, and maintained in the manner required, by 45 C.F.R. Sec. 164.514; or (d) Identifiable data collected, used, or disclosed in accordance with chapter 43.371 RCW or RCW 69.43.165 .",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-exemptions-health"
          },
          {
            "id": "q1-exemptions-federal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.100(2)",
            "citation": "Wash. Rev. Code § 19.373.100(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.100",
            "proposition": "Personal information governed by and handled pursuant to the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, or FERPA is exempt from the MHMDA.",
            "verbatimQuote": "Personal information that is governed by and collected, used, or disclosed pursuant to the following regulations, parts, titles, or acts, is exempt from this chapter: (a) The Gramm-Leach-Bliley act (15 U.S.C. 6801 et seq.) and implementing regulations; (b) part C of Title XI of the social security act (42 U.S.C. 1320d et seq.); (c) the fair credit reporting act (15 U.S.C. 1681 et seq.); (d) the family educational rights and privacy act (20 U.S.C. 1232g; Part 99 of Title 34, C.F.R.);",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-exemptions-federal"
          },
          {
            "id": "q1-biometric-enroll",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.375.020",
            "citation": "Wash. Rev. Code § 19.375.020(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.375.020",
            "proposition": "Washington's biometric statute bars enrolling a biometric identifier in a database for a commercial purpose without first providing notice, obtaining consent, or providing a mechanism to prevent subsequent commercial use.",
            "verbatimQuote": "A person may not enroll a biometric identifier in a database for a commercial purpose, without first providing notice, obtaining consent, or providing a mechanism to prevent the subsequent use of a biometric identifier for a commercial purpose.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-biometric-enroll"
          },
          {
            "id": "q1-breach-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.010",
            "citation": "Wash. Rev. Code § 19.255.010(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.010",
            "proposition": "Any person or business that conducts business in Washington and owns or licenses data including personal information must disclose a breach of the security of the system to any affected Washington resident whose unsecured personal information was acquired by an unauthorized person.",
            "verbatimQuote": "Any person or business that conducts business in this state and that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q1-breach-duty"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Washington consumer health data privacy policy contain?",
        "heading": "What must your Washington consumer health data privacy policy contain?",
        "answerText": "Washington requires a dedicated consumer health data privacy policy, with contents fixed by statute. Beginning March 31, 2024, a regulated entity must maintain a policy that clearly and conspicuously discloses: the categories of consumer health data collected and the purposes for which they are collected, including how the data will be used; the categories of sources; the categories of consumer health data shared; a list of the categories of third parties and the specific affiliates with whom the data is shared; and how consumers can exercise their statutory rights. The business must also prominently publish a link to that policy on its homepage.",
        "sources": [
          {
            "id": "q2-policy-contents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(a)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(a).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "Beginning March 31, 2024, a regulated entity and a small business must maintain a consumer health data privacy policy that clearly and conspicuously discloses five fixed elements, including a list of the categories of third parties and the specific affiliates receiving the data.",
            "verbatimQuote": "beginning March 31, 2024, a regulated entity and a small business shall maintain a consumer health data privacy policy that clearly and conspicuously discloses: (i) The categories of consumer health data collected and the purpose for which the data is collected, including how the data will be used; (ii) The categories of sources from which the consumer health data is collected; (iii) The categories of consumer health data that is shared; (iv) A list of the categories of third parties and specific affiliates with whom the regulated entity or the small business shares the consumer health data; and (v) How a consumer can exercise the rights provided in RCW 19.373.040",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-policy-contents"
          },
          {
            "id": "q2-homepage-link",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(b)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(b).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "A regulated entity and a small business must prominently publish a link to the consumer health data privacy policy on the homepage.",
            "verbatimQuote": "A regulated entity and a small business shall prominently publish a link to its consumer health data privacy policy on its homepage.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-homepage-link"
          },
          {
            "id": "q2-homepage-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(16)",
            "citation": "Wash. Rev. Code § 19.373.010(16).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "For the MHMDA, homepage includes the introductory website page, any webpage where personal information is collected, and for mobile apps the platform or download page plus an in-app link.",
            "verbatimQuote": "\"Homepage\" means the introductory page of an internet website and any internet web page where personal information is collected. In the case of an online service, such as a mobile application, homepage means the application's platform page or download page, and a link within the application, such as from the application configuration, \"about,\" \"information,\" or settings page.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-homepage-definition"
          },
          {
            "id": "q2-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(2)",
            "citation": "Wash. Rev. Code § 19.373.020(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "Small businesses had a delayed compliance date for the consumer health data privacy policy duty — June 30, 2024.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-small-business-date"
          },
          {
            "id": "q2-new-categories",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(c)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(c).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "A business may not collect, use, or share additional categories of consumer health data not disclosed in the policy without first disclosing them and obtaining the consumer's affirmative consent.",
            "verbatimQuote": "A regulated entity or a small business may not collect, use, or share additional categories of consumer health data not disclosed in the consumer health data privacy policy without first disclosing the additional categories and obtaining the consumer's affirmative consent prior to the collection, use, or sharing of such consumer health data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-new-categories"
          },
          {
            "id": "q2-new-purposes",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(d)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(d).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "A business may not collect, use, or share consumer health data for additional purposes not disclosed in the policy without first disclosing them and obtaining the consumer's affirmative consent.",
            "verbatimQuote": "A regulated entity or a small business may not collect, use, or share consumer health data for additional purposes not disclosed in the consumer health data privacy policy without first disclosing the additional purposes and obtaining the consumer's affirmative consent prior to the collection, use, or sharing of such consumer health data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-new-purposes"
          },
          {
            "id": "q2-processor-consistency",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(e)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(e).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "It is a violation of the MHMDA to contract with a processor to process consumer health data in a manner inconsistent with the business's consumer health data privacy policy.",
            "verbatimQuote": "It is a violation of this chapter for a regulated entity or a small business to contract with a processor to process consumer health data in a manner that is inconsistent with the regulated entity's or the small business's consumer health data privacy policy.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-processor-consistency"
          },
          {
            "id": "q2-ftc5",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q2-ftc5"
          }
        ]
      },
      {
        "slug": "consent-and-authorization",
        "label": "When do you need consent — and when a signed authorization — to handle health data in Washington?",
        "heading": "When do you need consent — and when a signed authorization — to handle health data in Washington?",
        "answerText": "The MHMDA runs on a two-tier opt-in structure, with a third, stricter tier for sales. For regulated entities after March 31, 2024, and small businesses after June 30, 2024, a business may not collect consumer health data except with the consumer's consent for a specified purpose, or to the extent necessary to provide a product or service the consumer requested. It may not share that data except with a consent that is separate and distinct from the collection consent, or again as necessary to provide the requested product or service. And it is unlawful for any person to sell consumer health data without first obtaining a valid authorization signed by the consumer — separate and distinct from both consents.",
        "sources": [
          {
            "id": "q3-collection-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(a)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(a).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "A business may not collect consumer health data except with consent for a specified purpose or to the extent necessary to provide a product or service the consumer requested.",
            "verbatimQuote": "beginning March 31, 2024, a regulated entity or a small business may not collect any consumer health data except: (i) With consent from the consumer for such collection for a specified purpose; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-collection-consent"
          },
          {
            "id": "q3-sharing-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(b)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(b).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "Sharing consumer health data requires a consent separate and distinct from the consent obtained to collect it, unless the sharing is necessary to provide a requested product or service.",
            "verbatimQuote": "A regulated entity or a small business may not share any consumer health data except: (i) With consent from the consumer for such sharing that is separate and distinct from the consent obtained to collect consumer health data; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-sharing-consent"
          },
          {
            "id": "q3-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(2)",
            "citation": "Wash. Rev. Code § 19.373.030(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the MHMDA collection and sharing consent section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-small-business-date"
          },
          {
            "id": "q3-sale-authorization",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.070(1)",
            "citation": "Wash. Rev. Code § 19.373.070(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070",
            "proposition": "It is unlawful for any person to sell or offer to sell consumer health data without first obtaining a valid authorization signed by the consumer, separate and distinct from the collection and sharing consents.",
            "verbatimQuote": "beginning March 31, 2024, it is unlawful for any person to sell or offer to sell consumer health data concerning a consumer without first obtaining valid authorization from the consumer. The sale of consumer health data must be consistent with the valid authorization signed by the consumer. This authorization must be separate and distinct from the consent obtained to collect or share consumer health data, as required under RCW 19.373.030",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-sale-authorization"
          },
          {
            "id": "q3-consent-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(6)",
            "citation": "Wash. Rev. Code § 19.373.010(6).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "Consent means a clear affirmative act signifying freely given, specific, informed, opt-in, voluntary, and unambiguous agreement — and may not be obtained through broad terms-of-use acceptance, hovering or closing content, or deceptive designs.",
            "verbatimQuote": "\"Consent\" means a clear affirmative act that signifies a consumer's freely given, specific, informed, opt-in, voluntary, and unambiguous agreement, which may include written consent provided by electronic means. (b) \"Consent\" may not be obtained by: (i) A consumer's acceptance of a general or broad terms of use agreement or a similar document that contains descriptions of personal data processing along with other unrelated information; (ii) A consumer hovering over, muting, pausing, or closing a given piece of content; or (iii) A consumer's agreement obtained through the use of deceptive designs.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-consent-definition"
          },
          {
            "id": "q3-consent-request",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(c)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(c).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "The request for consent must be made before collection or sharing and must clearly and conspicuously disclose the categories of data, the purpose and specific uses, the categories of recipient entities, and how to withdraw consent.",
            "verbatimQuote": "Consent required under this section must be obtained prior to the collection or sharing, as applicable, of any consumer health data, and the request for consent must clearly and conspicuously disclose: (i) The categories of consumer health data collected or shared; (ii) the purpose of the collection or sharing of the consumer health data, including the specific ways in which it will be used; (iii) the categories of entities with whom the consumer health data is shared; and (iv) how the consumer can withdraw consent from future collection or sharing of the consumer's health data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-consent-request"
          },
          {
            "id": "q3-authorization-contents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.070(2)",
            "citation": "Wash. Rev. Code § 19.373.070(2)-(5).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070",
            "proposition": "A valid authorization to sell must be a plain-language document with the specific data sold, seller and purchaser contact information, sale purpose, data gathering and use details, non-conditioning and revocation statements, redisclosure warning, one-year expiration, signature and date; invalid authorizations, consumer copies, and six-year retention are also specified.",
            "verbatimQuote": "A valid authorization to sell consumer health data is a document consistent with this section and must be written in plain language. The valid authorization to sell consumer health data must contain the following: (a) The specific consumer health data concerning the consumer that the person intends to sell; (b) The name and contact information of the person collecting and selling the consumer health data; (c) The name and contact information of the person purchasing the consumer health data from the seller identified in (b) of this subsection; (d) A description of the purpose for the sale, including how the consumer health data will be gathered and how it will be used by the purchaser identified in (c) of this subsection when sold; (e) A statement that the provision of goods or services may not be conditioned on the consumer signing the valid authorization; (f) A statement that the consumer has a right to revoke the valid authorization at any time and a description on how to submit a revocation of the valid authorization; (g) A statement that the consumer health data sold pursuant to the valid authorization may be subject to redisclosure by the purchaser and may no longer be protected by this section; (h) An expiration date for the valid authorization that expires one year from when the consumer signs the valid authorization; and (i) The signature of the consumer and date. (3) An authorization is not valid if the document has any of the following defects: (a) The expiration date has passed; (b) The authorization does not contain all the information required under this section; (c) The authorization has been revoked by the consumer; (d) The authorization has been combined with other documents to create a compound authorization; or (e) The provision of goods or services is conditioned on the consumer signing the authorization. (4) A copy of the signed valid authorization must be provided to the consumer. (5) The seller and purchaser of consumer health data must retain a copy of all valid authorizations for sale of consumer health data for six years from the date of its signature or the date when it was last in effect, whichever is later.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q3-authorization-contents"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors and processors say?",
        "heading": "What must your contracts with vendors and processors say?",
        "answerText": "For consumer health data, a written contract is a statutory requirement. A processor may process such data only pursuant to a binding contract that sets forth the processing instructions and limits the actions the processor may take with the data it handles on the business's behalf.",
        "sources": [
          {
            "id": "q4-processor-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.060(1)(a)",
            "citation": "Wash. Rev. Code § 19.373.060(1)(a)(i).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.060",
            "proposition": "A processor may process consumer health data only under a binding contract that sets forth processing instructions and limits the actions the processor may take.",
            "verbatimQuote": "beginning March 31, 2024, a processor may process consumer health data only pursuant to a binding contract between the processor and the regulated entity or the small business that sets forth the processing instructions and limit the actions the processor may take with respect to the consumer health data it processes on behalf of the regulated entity or the small business.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-processor-contract"
          },
          {
            "id": "q4-processor-duties",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.060(1)(b)",
            "citation": "Wash. Rev. Code § 19.373.060(1)(b).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.060",
            "proposition": "A processor must assist the business by appropriate technical and organizational measures in fulfilling the business's obligations under the MHMDA.",
            "verbatimQuote": "A processor shall assist the regulated entity or the small business by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the regulated entity's and the small business's obligations under this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-processor-duties"
          },
          {
            "id": "q4-outside-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.060(1)(c)",
            "citation": "Wash. Rev. Code § 19.373.060(1)(c).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.060",
            "proposition": "A processor that fails to adhere to the business's instructions or processes consumer health data outside the scope of its contract is considered a regulated entity or small business for that data and subject to the full statute.",
            "verbatimQuote": "If a processor fails to adhere to the regulated entity's or the small business's instructions or processes consumer health data in a manner that is outside the scope of the processor's contract with the regulated entity or the small business, the processor is considered a regulated entity or a small business with regard to such data and is subject to all the requirements of this chapter with regard to such data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-outside-scope"
          },
          {
            "id": "q4-policy-consistency",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.020(1)(e)",
            "citation": "Wash. Rev. Code § 19.373.020(1)(e).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.020",
            "proposition": "Contracting with a processor to process consumer health data in a manner inconsistent with the consumer health data privacy policy is itself a violation of the MHMDA.",
            "verbatimQuote": "It is a violation of this chapter for a regulated entity or a small business to contract with a processor to process consumer health data in a manner that is inconsistent with the regulated entity's or the small business's consumer health data privacy policy.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-policy-consistency"
          },
          {
            "id": "q4-security-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.050(1)",
            "citation": "Wash. Rev. Code § 19.373.050(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.050",
            "proposition": "The MHMDA requires businesses to restrict employee, processor, and contractor access to consumer health data to what is necessary for consented purposes or requested products or services, and to maintain administrative, technical, and physical safeguards satisfying at least the reasonable industry standard of care.",
            "verbatimQuote": "beginning March 31, 2024, a regulated entity and a small business shall: (a) Restrict access to consumer health data by the employees, processors, and contractors of such regulated entity or small business to only those employees, processors, and contractors for which access is necessary to further the purposes for which the consumer provided consent or where necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business; and (b) Establish, implement, and maintain administrative, technical, and physical data security practices that, at a minimum, satisfy reasonable standard of care within the regulated entity's or the small business's industry to protect the confidentiality, integrity, and accessibility of consumer health data appropriate to the volume and nature of the consumer health data at issue.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-security-duty"
          },
          {
            "id": "q4-security-small-business-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.050(2)",
            "citation": "Wash. Rev. Code § 19.373.050(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.050",
            "proposition": "Small businesses had a June 30, 2024 compliance date for the MHMDA data-security section.",
            "verbatimQuote": "A small business must comply with this section beginning June 30, 2024.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-security-small-business-date"
          },
          {
            "id": "q4-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-glba-safeguards"
          },
          {
            "id": "q4-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,and%20a%20business%20associate%20must",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted uses and disclosures of protected health information and binds the business associate to safeguard it.",
            "verbatimQuote": "A contract between the covered entity and a business associate must",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q4-hipaa-baa"
          }
        ]
      },
      {
        "slug": "consumer-rights",
        "label": "What rights can Washington consumers exercise over their health data?",
        "heading": "What rights can Washington consumers exercise over their health data?",
        "answerText": "Three rights, each enforceable on a 45-day clock. A consumer has the right to confirm whether a business is collecting, sharing, or selling consumer health data about them and to access it — including a list of all third parties and affiliates that received the data and an active email address or other online mechanism for contacting those third parties. A consumer may withdraw consent to collection and sharing. And a consumer may have the data deleted — a deletion that must reach every part of the business's network, including archived and backup systems, and that the business must propagate by notifying all affiliates, processors, contractors, and other third parties that received the data.",
        "sources": [
          {
            "id": "q5-access",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(1)(a)",
            "citation": "Wash. Rev. Code § 19.373.040(1)(a).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "A consumer has the right to confirm whether a business is collecting, sharing, or selling their consumer health data and to access it, including a list of all third parties and affiliates that received it with an active email address or other online contact mechanism.",
            "verbatimQuote": "a consumer has the right to confirm whether a regulated entity or a small business is collecting, sharing, or selling consumer health data concerning the consumer and to access such data, including a list of all third parties and affiliates with whom the regulated entity or the small business has shared or sold the consumer health data and an active email address or other online mechanism that the consumer may use to contact these third parties.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-access"
          },
          {
            "id": "q5-withdraw",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(1)(b)",
            "citation": "Wash. Rev. Code § 19.373.040(1)(b).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "A consumer has the right to withdraw consent from the business's collection and sharing of consumer health data — the act's consent-based counterpart to an opt-out right.",
            "verbatimQuote": "A consumer has the right to withdraw consent from the regulated entity's or the small business's collection and sharing of consumer health data concerning the consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-withdraw"
          },
          {
            "id": "q5-delete",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(1)(c)",
            "citation": "Wash. Rev. Code § 19.373.040(1)(c).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "On a deletion request, the business must delete the consumer health data from all parts of its network including archived and backup systems, notify all affiliates, processors, contractors, and other third parties that received the data of the deletion request, and archived or backup deletion may be delayed up to six months from authentication.",
            "verbatimQuote": "A consumer has the right to have consumer health data concerning the consumer deleted and may exercise that right by informing the regulated entity or the small business of the consumer's request for deletion. (i) A regulated entity or a small business that receives a consumer's request to delete any consumer health data concerning the consumer shall: (A) Delete the consumer health data from its records, including from all parts of the regulated entity's or the small business's network, including archived or backup systems pursuant to (c)(iii) of this subsection; and (B) Notify all affiliates, processors, contractors, and other third parties with whom the regulated entity or the small business has shared consumer health data of the deletion request. (ii) All affiliates, processors, contractors, and other third parties that receive notice of a consumer's deletion request shall honor the consumer's deletion request and delete the consumer health data from its records, subject to the same requirements of this chapter. (iii) If consumer health data that a consumer requests to be deleted is stored on archived or backup systems, then the request for deletion may be delayed to enable restoration of the archived or backup systems and such delay may not exceed six months from authenticating the deletion request.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-delete"
          },
          {
            "id": "q5-deadline",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(1)(g)",
            "citation": "Wash. Rev. Code § 19.373.040(1)(g).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "Consumer requests must be honored without undue delay and in all cases within 45 days of receipt, with one 45-day extension when reasonably necessary.",
            "verbatimQuote": "A regulated entity and a small business shall comply with the consumer's requests under subsection (1)(a) through (c) of this section [(a) through (c) of this subsection] without undue delay, but in all cases within 45 days of receipt of the request submitted pursuant to the methods described in this section. A regulated entity and a small business must promptly take steps to authenticate a consumer request but this does not extend the regulated entity's and the small business's duty to comply with the consumer's request within 45 days of receipt of the consumer's request. The response period may be extended once by 45 additional days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the regulated entity or the small business informs the consumer of any such extension within the initial 45-day response period, together with the reason for the extension.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-deadline"
          },
          {
            "id": "q5-appeal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.040(1)(h)",
            "citation": "Wash. Rev. Code § 19.373.040(1)(h).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.040",
            "proposition": "A business must establish a conspicuous appeal process for refusals to act on consumer requests, answer appeals in writing within 45 days, and on denial give the consumer a way to submit a complaint to the Attorney General.",
            "verbatimQuote": "A regulated entity and a small business shall establish a process for a consumer to appeal the regulated entity's or the small business's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision. The appeal process must be conspicuously available and similar to the process for submitting requests to initiate action pursuant to this section. Within 45 days of receipt of an appeal, a regulated entity or a small business shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, the regulated entity or the small business shall also provide the consumer with an online mechanism, if available, or other method through which the consumer may contact the attorney general to submit a complaint.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-appeal"
          },
          {
            "id": "q5-collection-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(a)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(a).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "Collection of consumer health data is unlawful except with consent for a specified purpose or as necessary to provide a requested product or service.",
            "verbatimQuote": "beginning March 31, 2024, a regulated entity or a small business may not collect any consumer health data except: (i) With consent from the consumer for such collection for a specified purpose; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-collection-consent"
          },
          {
            "id": "q5-sharing-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(b)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(b).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "Sharing consumer health data is unlawful except with separate sharing consent or as necessary to provide a requested product or service.",
            "verbatimQuote": "A regulated entity or a small business may not share any consumer health data except: (i) With consent from the consumer for such sharing that is separate and distinct from the consent obtained to collect consumer health data; or (ii) To the extent necessary to provide a product or service that the consumer to whom such consumer health data relates has requested from such regulated entity or small business.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-sharing-consent"
          },
          {
            "id": "q5-sale-authorization",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.070(1)",
            "citation": "Wash. Rev. Code § 19.373.070(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070",
            "proposition": "Selling consumer health data is unlawful without a valid consumer authorization that is separate and distinct from collection and sharing consents.",
            "verbatimQuote": "beginning March 31, 2024, it is unlawful for any person to sell or offer to sell consumer health data concerning a consumer without first obtaining valid authorization from the consumer. The sale of consumer health data must be consistent with the valid authorization signed by the consumer. This authorization must be separate and distinct from the consent obtained to collect or share consumer health data, as required under RCW 19.373.030",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-sale-authorization"
          },
          {
            "id": "q5-nondiscrimination",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.030(1)(d)",
            "citation": "Wash. Rev. Code § 19.373.030(1)(d).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030",
            "proposition": "A business may not unlawfully discriminate against a consumer for exercising any rights under the MHMDA.",
            "verbatimQuote": "A regulated entity or a small business may not unlawfully discriminate against a consumer for exercising any rights included in this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q5-nondiscrimination"
          }
        ]
      },
      {
        "slug": "geofencing-ban",
        "label": "Can you use geofencing near health care facilities in Washington?",
        "heading": "Can you use geofencing near health care facilities in Washington?",
        "answerText": "No — not for anything touching consumer health data. The MHMDA makes it unlawful for any person to implement a geofence around an entity that provides in-person health care services where the geofence is used to identify or track consumers seeking health care services, to collect consumer health data from them, or to send them notifications, messages, or advertisements related to their health data or health care services.",
        "sources": [
          {
            "id": "q6-geofence-ban",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.080",
            "citation": "Wash. Rev. Code § 19.373.080.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.080",
            "proposition": "It is unlawful for any person to implement a geofence around an entity providing in-person health care services to identify or track consumers seeking health care services, collect their consumer health data, or send them health-related notifications, messages, or advertisements — with no consent exception.",
            "verbatimQuote": "It is unlawful for any person to implement a geofence around an entity that provides in-person health care services where such geofence is used to: (1) Identify or track consumers seeking health care services; (2) collect consumer health data from consumers; or (3) send notifications, messages, or advertisements to consumers related to their consumer health data or health care services.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q6-geofence-ban"
          },
          {
            "id": "q6-geofence-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(14)",
            "citation": "Wash. Rev. Code § 19.373.010(14).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "A geofence is a virtual boundary of 2,000 feet or less around a physical location, established by GPS, cell-tower connectivity, cellular data, RFID, Wi-Fi data, or any other form of spatial or location detection.",
            "verbatimQuote": "\"Geofence\" means technology that uses global positioning coordinates, cell tower connectivity, cellular data, radio frequency identification, Wifi data, and/or any other form of spatial or location detection to establish a virtual boundary around a specific physical location, or to locate a consumer within a virtual boundary. For purposes of this definition, \"geofence\" means a virtual boundary that is 2,000 feet or less from the perimeter of the physical location.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q6-geofence-def"
          },
          {
            "id": "q6-hcs-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.010(15)",
            "citation": "Wash. Rev. Code § 19.373.010(15).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.010",
            "proposition": "Health care services means any service provided to a person to assess, measure, improve, or learn about a person's mental or physical health — a definition that reaches far beyond hospitals and clinics.",
            "verbatimQuote": "\"Health care services\" means any service provided to a person to assess, measure, improve, or learn about a person's mental or physical health, including but not limited to: (a) Individual health conditions, status, diseases, or diagnoses; (b) Social, psychological, behavioral, and medical interventions; (c) Health-related surgeries or procedures; (d) Use or purchase of medication;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q6-hcs-def"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Washington?",
        "heading": "When must you notify people of a data breach in Washington?",
        "answerText": "Any person or business that conducts business in Washington and owns or licenses data including personal information must disclose a breach of the security of the system to every Washington resident whose unsecured personal information was, or is reasonably believed to have been, acquired by an unauthorized person — though notice is not required if the breach is not reasonably likely to subject consumers to a risk of harm. Notice to affected consumers must go out in the most expedient time possible and no more than 30 calendar days after the breach was discovered. If a single breach requires notifying more than 500 Washington residents, the business must also notify the Attorney General within the same 30-day window.",
        "sources": [
          {
            "id": "q7-breach-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.010(1)",
            "citation": "Wash. Rev. Code § 19.255.010(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.010",
            "proposition": "A person or business doing business in Washington must disclose a breach to any resident whose unsecured personal information was or is reasonably believed to have been acquired by an unauthorized person, unless the breach is not reasonably likely to subject consumers to a risk of harm; secured data is covered when the decryption means was also acquired.",
            "verbatimQuote": "Any person or business that conducts business in this state and that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-breach-duty"
          },
          {
            "id": "q7-thirty-days",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.010(8)",
            "citation": "Wash. Rev. Code § 19.255.010(8).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.010",
            "proposition": "Consumer notification must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after discovery of the breach, subject to law-enforcement and scoping delays.",
            "verbatimQuote": "Notification to affected consumers under this section must be made in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered, unless the delay is at the request of law enforcement as provided in subsection (3) of this section, or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-thirty-days"
          },
          {
            "id": "q7-ag-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.010(7)",
            "citation": "Wash. Rev. Code § 19.255.010(7).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.010",
            "proposition": "A breach requiring notice to more than 500 Washington residents also requires notice to the Attorney General within 30 days of discovery, with fixed contents including affected counts, data types, timeframe, containment steps, and a sample consumer notice.",
            "verbatimQuote": "Any person or business that is required to issue a notification pursuant to this section to more than five hundred Washington residents as a result of a single breach shall notify the attorney general of the breach no more than thirty days after the breach was discovered. (a) The notice to the attorney general shall include the following information: (i) The number of Washington consumers affected by the breach, or an estimate if the exact number is not known; (ii) A list of the types of personal information that were or are reasonably believed to have been the subject of a breach; (iii) A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; (iv) A summary of steps taken to contain the breach; and (v) A single sample copy of the security breach notification, excluding any personally identifiable information. (b) The notice to the attorney general must be updated if any of the information identified in (a) of this subsection is unknown at the time notice is due.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-ag-notice"
          },
          {
            "id": "q7-pi-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.005(2)",
            "citation": "Wash. Rev. Code § 19.255.005(2)(a).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.005",
            "proposition": "Personal information includes name combined with Social Security, driver's license, financial-account, date-of-birth, private-key, government-ID, health-insurance, medical, or biometric data elements; username or email combined with credentials permitting account access; and listed data elements without a name if they are usable and would enable identity theft.",
            "verbatimQuote": "An individual's first name or first initial and last name in combination with any one or more of the following data elements: (A) Social security number; (B) Driver's license number or Washington identification card number; (C) Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account, or any other numbers or information that can be used to access a person's financial account; (D) Full date of birth; (E) Private key that is unique to an individual and that is used to authenticate or sign an electronic record; (F) Student, military, or passport identification number; (G) Health insurance policy number or health insurance identification number; (H) Any information about a consumer's medical history or mental or physical condition or about a health care professional's medical diagnosis or treatment of the consumer; or (I) Biometric data generated by automatic measurements of an individual's biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual; (ii) User name or email address in combination with a password or security questions and answers that would permit access to an online account; and (iii) Any of the data elements or any combination of the data elements described in (a)(i) of this subsection without the consumer's first name or first initial and last name if: (A) Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and (B) The data element or combination of data elements would enable a person to commit identity theft against a consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-pi-definition"
          },
          {
            "id": "q7-secured",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.005(3)",
            "citation": "Wash. Rev. Code § 19.255.005(3).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.005",
            "proposition": "Secured means encrypted in a manner that meets or exceeds the NIST standard or otherwise modified so the personal information is rendered unreadable, unusable, or undecipherable by an unauthorized person — the statute's encryption safe harbor.",
            "verbatimQuote": "\"Secured\" means encrypted in a manner that meets or exceeds the national institute of standards and technology standard or is otherwise modified so that the personal information is rendered unreadable, unusable, or undecipherable by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-secured"
          },
          {
            "id": "q7-hipaa-deemed",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.030",
            "citation": "Wash. Rev. Code § 19.255.030(1).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.030",
            "proposition": "A HIPAA covered entity is deemed compliant with the Washington breach statute for protected health information if it complies with the HITECH Act's breach-notification provisions, though it must still notify the Washington Attorney General.",
            "verbatimQuote": "A covered entity under the federal health insurance portability and accountability act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal health information technology for economic and clinical health act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010 (7) in compliance with the timeliness of notification requirements of section 13402 of the federal health information technology for economic and clinical health act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010 (7).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q7-hipaa-deemed"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under Washington privacy law?",
        "heading": "Can a consumer sue your business under Washington privacy law?",
        "answerText": "Yes — and this is the headline risk of the MHMDA. The act declares that a violation is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the Consumer Protection Act, and that the practices it covers are matters vitally affecting the public interest. That per se designation plugs directly into the CPA's private remedy: any person injured in business or property by a CPA violation may sue for actual damages, costs, and attorney fees, and the court may treble damages up to $25,000. The CPA confirms the chain — a claimant can establish public-interest injury by showing the act violates a statute that incorporates the CPA.",
        "sources": [
          {
            "id": "q8-mhmda-cpa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.373.090",
            "citation": "Wash. Rev. Code § 19.373.090.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.090",
            "proposition": "A violation of the MHMDA is per se an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of the Consumer Protection Act, and the covered practices are declared matters vitally affecting the public interest.",
            "verbatimQuote": "The legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. A violation of this chapter is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-mhmda-cpa"
          },
          {
            "id": "q8-cpa-private-action",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.86.090",
            "citation": "Wash. Rev. Code § 19.86.090.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.86.090",
            "proposition": "Any person injured in business or property by a CPA violation may sue for injunctive relief, actual damages, costs, and attorney fees, and the court may treble damages up to $25,000 for unfair-practice violations — the vehicle for private MHMDA claims.",
            "verbatimQuote": "Any person who is injured in his or her business or property by a violation of RCW 19.86.020 , 19.86.030 , 19.86.040 , 19.86.050 , or 19.86.060 , or any person so injured because he or she refuses to accede to a proposal for an arrangement which, if consummated, would be in violation of RCW 19.86.030 , 19.86.040 , 19.86.050 , or 19.86.060 , may bring a civil action in superior court to enjoin further violations, to recover the actual damages sustained by him or her, or both, together with the costs of the suit, including a reasonable attorney's fee. In addition, the court may, in its discretion, increase the award of damages up to an amount not to exceed three times the actual damages sustained: PROVIDED, That such increased damage award for violation of RCW 19.86.020 may not exceed twenty-five thousand dollars",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-cpa-private-action"
          },
          {
            "id": "q8-cpa-per-se",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.86.093",
            "citation": "Wash. Rev. Code § 19.86.093.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.86.093",
            "proposition": "In a private CPA action, a claimant may establish the public-interest element by showing the act or practice violates a statute that incorporates the CPA.",
            "verbatimQuote": "a claimant may establish that the act or practice is injurious to the public interest because it: (1) Violates a statute that incorporates this chapter;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-cpa-per-se"
          },
          {
            "id": "q8-biometric-ag-only",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.375.030",
            "citation": "Wash. Rev. Code § 19.375.030(2).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.375.030",
            "proposition": "Washington's biometric-identifier chapter may be enforced solely by the Attorney General under the Consumer Protection Act — the express exclusivity clause the MHMDA conspicuously lacks.",
            "verbatimQuote": "This chapter may be enforced solely by the attorney general under the consumer protection act, chapter 19.86 RCW.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-biometric-ag-only"
          },
          {
            "id": "q8-cpa-penalties",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.86.140",
            "citation": "Wash. Rev. Code § 19.86.140.",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.86.140",
            "proposition": "CPA violations of RCW 19.86.020 can carry civil penalties of up to $7,500 per violation, and the Attorney General acting in the name of the state may petition to recover civil penalties.",
            "verbatimQuote": "Every person who violates RCW 19.86.020 shall forfeit and pay a civil penalty of not more than $7,500 for each violation: PROVIDED, That nothing in this paragraph shall apply to any radio or television broadcasting station which broadcasts, or to any publisher, printer or distributor of any newspaper, magazine, billboard or other advertising medium who publishes, prints or distributes, advertising in good faith without knowledge of its false, deceptive or misleading character. For unlawful acts or practices that target or impact specific individuals or communities based on demographic characteristics including, but not limited to, age, race, national origin, citizenship or immigration status, sex, sexual orientation, presence of any sensory, mental, or physical disability, religion, veteran status, or status as a member of the armed forces, as that term is defined in 10 U.S.C. Sec. 101, an enhanced penalty of $5,000 shall apply. For the purpose of this section the superior court issuing any injunction shall retain jurisdiction, and the cause shall be continued, and in such cases the attorney general acting in the name of the state may petition for the recovery of civil penalties.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-cpa-penalties"
          },
          {
            "id": "q8-breach-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "RCW 19.255.040",
            "citation": "Wash. Rev. Code § 19.255.040(2)-(3).",
            "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.255.040",
            "proposition": "The breach chapter routes around the CPA's private-action section but gives any consumer injured by a violation a direct civil action for damages under the chapter itself.",
            "verbatimQuote": "An action to enforce this chapter may not be brought under RCW 19.86.090 . (3)(a) Any consumer injured by a violation of this chapter may institute a civil action to recover damages.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/washington#src-q8-breach-pra"
          }
        ]
      }
    ]
  }
}
