Melissa Krasnow | August 25, 2023
The effective date of the Washington My Health My Data Act (Act) is July 23, 2023.
All persons must comply with the Act's geofencing prohibition beginning July 23, 2023.
Beginning March 31, 2024, regulated entities (except small businesses), and beginning June 30, 2024, small businesses, must comply with the Act's consumer rights, privacy policy, consumer health data collection and sharing, and access restriction and data security practices requirements.
Beginning March 31, 2024, processors and regulated entities (except small businesses), and beginning June 30, 2024, small businesses, must comply with the Act's processor contract requirements.
Beginning March 31, 2024, all persons (except small businesses), and beginning June 30, 2024, small businesses, must comply with the Act's consumer health data sale and valid authorization requirements.
A violation of the Act is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the Washington Consumer Protection Act, chapter 19.86 RCW. Any violation of the Act is a per se violation of the Washington Consumer Protection Act, which is enforced by the Washington attorney general and through private action.
This article discusses the Act's definitions. Also see "Washington My Health My Data Act: Requirements and Exceptions" for more information.
"Person" means, where applicable, natural persons, corporations, trusts, unincorporated associations, and partnerships, excluding government agencies, tribal nations, or contracted service providers when processing consumer health data on behalf of a government agency. Out-of-state entities that fall within the definition of person must comply with the Act's consumer health data sale and valid authorization requirements and geofencing prohibition.
"Regulated entity" means any legal entity that does the following.
"Small business" means a regulated entity that satisfies one or both of the following.
"Processor" means a person that processes consumer health data on behalf of a regulated entity or a small business. Out-of-state entities that are processors for regulated entities or a small business must comply with the Act.
"Consumer" means a natural person that does the following.
"Collect" means to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner.
"Process" or "processing" means any operation or set of operations performed on consumer health data.
"Sell" or "sale" means the exchange of consumer health data for monetary or other valuable consideration, excluding the exchange of consumer health data for monetary or other valuable consideration.
"Share" or "sharing" means to release, disclose, disseminate, divulge, make available, provide access to, license, or otherwise communicate orally, in writing, or by electronic or other means, consumer health data by a regulated entity or a small business to a third party or affiliate, excluding the disclosure.
"Consumer health data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. For the purposes of this definition, physical or mental health status includes, but is not limited to, the following.
"Consumer health data" does not include personal information that is used to engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws and is approved, monitored, and governed by an institutional review board, human subjects research ethics review board, or a similar independent oversight entity that determines that the regulated entity or the small business has implemented reasonable safeguards to mitigate privacy risks associated with research, including any risks associated with reidentification.
"Third party" means an entity other than a consumer, regulated entity, processor, small business, or affiliate of the regulated entity or the small business.
"Affiliate" means a legal entity that shares common branding with another legal entity and controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" or "controlled" means the following.
"Personal information" means information that identifies or is reasonably capable of being associated or linked, directly or indirectly, with a particular consumer, including but not limited to, data associated with a persistent unique identifier, such as a cookie ID, an IP address, a device identifier, or any other form of persistent unique identifier, and excluding publicly available information and excluding deidentified data.
"Publicly available information" means information that is the following.
"Deidentified data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable consumer, or a device linked to such consumer, if the regulated entity or the small business that possesses such data does the following.
"Biometric data" means data that is generated from the measurement or technological processing of an individual's physiological, biological, or behavioral characteristics and that identifies a consumer, whether individually or in combination with other data, including, but not limited to the following.
"Health care services" means any service provided to a person to assess, measure, improve, or learn about a person's mental or physical health, including but not limited to the following.
"Homepage" means the introductory page of an Internet website and any Internet Web page where personal information is collected, and in the case of an online service, such as a mobile application, homepage means the application's platform page or download page, and a link within the application, such as from the application configuration, "about," "information," or settings page.
"Consent" means a clear affirmative act that signifies a consumer's freely given, specific, informed, opt-in, voluntary, and unambiguous agreement, which may include written consent provided by electronic means. "Consent" may not be obtained by any of the consumer's following actions.
"Deceptive design" means a user interface designed or manipulated with the effect of subverting or impairing user autonomy, decision-making, or choice.
"Geofence" means technology that uses global positioning coordinates, cell tower connectivity, cellular data, radio frequency identification, Wi-Fi data, and/or any other form of spatial or location detection to establish a virtual boundary around a specific physical location, or to locate a consumer within a virtual boundary. For purposes of this definition, "geofence" means a virtual boundary that is 2,000 feet or less from the perimeter of the physical location.
Opinions expressed in Expert Commentary articles are those of the author and are not necessarily held by the author's employer or IRMI. Expert Commentary articles and other IRMI Online content do not purport to provide legal, accounting, or other professional advice or opinion. If such advice is needed, consult with your attorney, accountant, or other qualified adviser.