What you need to know about the My Health My Data Act
The My Health My Data Act (MHMDA) is a privacy law enacted by the state of Washington to improve protections for consumer's personal health data....
Healthcare organizations have long operated under HIPAA's privacy rules, but Washington state's new My Health My Data Act (MHMD) represents a significant expansion of health data protections. As recent cases like Amazon's privacy lawsuit demonstrate, health data now extends far beyond traditional medical records.
When HIPAA was enacted in 1996, healthcare data lived primarily in doctors' offices and hospitals. Today, our health information flows through apps, websites, and various digital services - most of which fall outside HIPAA's scope. According to research on HIPAA compliance, this evolution in health information management has led to over 176 million patients being affected by protected health information breaches in the United States.
Washington's MHMD, which took effect in March 2024, addresses this gap by protecting consumer health data wherever it exists.
The act is designed to protect personal health data outside of HIPAA’s scope and was developed to protect consumers' sensitive health data from being collected and shared without their consent. The law requires regulated entities to follow specific requirements about how and when they may collect and share personal health data, addressing an urgent need that resonated with residents; 76% of Washingtonians expressed support for the Act.
If you're a healthcare provider, insurer, or their business associate, you must comply with HIPAA. If you collect any consumer health data in Washington state, including through apps, websites, or other digital services, you must also comply with MHMD. Many organizations may need to comply with both laws.
MHMD defines consumer health data more broadly than HIPAA. It includes traditional health information plus data that could reveal health-related details, such as location tracking showing medical facility visits, fitness app data, or search histories related to health conditions.
HIPAA violations are investigated and enforced by federal regulators (the Office for Civil Rights), while MHMD allows individuals to sue companies directly for violations. This means organizations could face both regulatory penalties and private lawsuits under MHMD.
The My Health My Data Act (MHMDA) is a privacy law enacted by the state of Washington to improve protections for consumer's personal health data....
A Washington state privacy law faces its first major test as Amazon confronts a class-action lawsuit over alleged unauthorized collection of consumer...
At the recent joint HHS and National Institute of Standards and Technology security conference, HHS OCR senior advisor for health information...