If you handle health-related data tied to Washington residents in 2026, HIPAA alone may not cover you. I’d boil this article down to five things: map the data, get opt-in consent where needed, set up deletion request workflows, check every vendor and SDK, and stop any geofencing near care sites.
Here’s the short version in plain English:
- MHMDA reaches past HIPAA. It can apply to data that could reveal someone’s health status, even outside a hospital or clinic system.
- Lawsuit risk is higher. Consumers can sue directly, which can turn a privacy mistake into class-action exposure.
- Consent rules are stricter. Collection and sharing can need express opt-in consent, and selling data can need signed authorization.
- Digital tools are a top risk area. Websites, tracking pixels, apps, remote monitoring tools, and marketing platforms can all create issues.
- Deletion requests must be tracked. I’d make sure each request, ID check, action, and timestamp is logged.
- Geofencing near healthcare sites is banned. That includes tools that use GPS, cellular, SDK, or API-based location signals.
- Third-party vendor risk is your risk. If a third party touches consumer health data, your team still needs tight contract terms and proof of follow-through.
One point stands out: this is not just about PHI. It can reach page visits, symptom-checker use, scheduling activity, and app behavior if those signals point to a person’s health status.
Breaking Down the Washington State My Health, My Data Act With Mike Hintze
This discussion highlights the growing need for measuring cybersecurity in healthcare to ensure patient safety and regulatory compliance.
Quick comparison
| Area | HIPAA | Washington MHMDA | RCW 70.02 |
|---|---|---|---|
| Who it covers | Covered entities and business associates | Any entity doing business in Washington or targeting Washington residents | Washington providers and facilities |
| Data covered | PHI | Consumer health data that may reveal health status | Medical records and provider-held health info |
| Consent rule | TPO use allowed; authorization for some uses | Opt-in consent for collection/sharing; signed authorization for sale | Written authorization for many disclosures |
| Consumer rights | Access, amendment, accounting | Access, deletion, consent withdrawal, appeal | Access and amendment |
| Enforcement | OCR | AG + private lawsuits | Civil action for actual damages |
| Geofencing | Not addressed | Prohibited near healthcare facilities | Not addressed |
If I were leading privacy, security, or compliance work right now, I’d treat 2026 as a hard deadline to tighten notices, consent flows, DSAR handling, retention, and third-party risk reviews.
Washington's legal framework: Key definitions organizations must know
HIPAA vs. Washington MHMDA vs. RCW 70.02: 2026 Compliance Comparison
Not legal advice. Consult counsel for organization-specific guidance.
What counts as consumer health data under MHMDA
Once you've nailed down MHMDA's scope, the next job is figuring out which data fits inside it. MHMDA covers data that may reveal a person's health status. Washington AG guidance helps sort those data points and stands out as a main reference for organizations working through that classification [1]. For 2026, the big task is drawing a clear line between consumer health data, standard PHI, and other records.
How MHMDA differs from HIPAA and RCW 70.02
The toughest judgment calls usually show up in marketing analytics, remote monitoring, and embedded third-party tools. That's where things can get messy fast. These duties can overlap with HIPAA and RCW 70.02, so data mapping is a must if you want to show which rules apply to each dataset and user group [1].
Map each dataset to HIPAA, MHMDA, and RCW 70.02 before assigning controls. That step decides which controls and notices the organization needs to build next.
2026 enforcement posture and private litigation exposure
In Washington, enforcement comes from the Attorney General, and consumers can also sue directly [1]. That means 2026 isn't just about policy language on paper. You need audit-ready logs for notices, consent, and deletion requests. That enterprise risk shapes the notice, consent, and deletion workflows covered next.
sbb-itb-535baee
Compliance requirements healthcare organizations should prioritize in 2026
Privacy notices, opt-in consent, and signed authorization requirements
Once you’ve defined scope, the next job is showing compliance inside day-to-day work. Start with your data map. Use it to confirm how health data is collected, shared, and sold.
For health data collection and sharing, organizations need express opt-in consent. If data is sold, they also need signed authorization. A Consent Management Platform (CMP) with version control is the most practical way to track what each user agreed to and when[1].
Just as important, keep an eye on consent banners for outages or script failures[1]. A banner that stops working can quietly create risk fast.
Consumer rights handling, deletion workflows, and security measures
Access and deletion requests should run through an automated DSAR workflow. If your team misses deadlines, regulators may see gaps in the audit trail[1].
Each step in the process needs to be logged, including:
- The request itself
- Identity verification
- The action taken
- The timestamp
Fulfillment systems should also be limited to managed devices[1].
On the security side, healthcare organizations should focus on data minimization, retention governance, and shadow data discovery. In plain English, that means collecting only the data you clearly disclosed, setting recurring monthly purge cycles for data that’s no longer needed for that disclosed purpose, and using automated discovery tools to find forgotten datasets sitting outside the formal privacy program[1].
Geofencing restrictions near healthcare facilities
MHMDA prohibits geofencing around facilities that provide in-person health services. Organizations should not use GPS or cellular data to create geofences around clinics or hospitals to identify or target people seeking care[1].
Location-based features can also point to a bigger tracking problem. Third-party SDKs, analytics tools, and vendor APIs may create exposure if they collect personal information or make location targeting possible. Review embedded SDKs and APIs for location collection or targeting[1].
A GPS and API audit of every third-party integration should be one of the first technical checks in 2026. After that, teams should review again whenever a new SDK or a marketing platform update is introduced[1].
Where healthcare risk is highest: HIPAA overlap, vendor exposure, and compliance gaps
High-risk use cases: web tracking, apps, remote monitoring, and marketing analytics
The biggest Washington MHMDA risk tends to show up in consumer-facing digital tools and the vendors behind them, especially when they collect health signals outside HIPAA. Risk climbs fast when a tool can reveal someone’s health status and a third party handles that data.
A visit to an oncology, behavioral health, symptom-checker, or scheduling page can count as consumer health data if that visit reveals health status. In that case, opt-in consent may be required.[1] Remote monitoring tools and mobile apps can create the same kind of exposure when third-party SDKs pick up biometric data or activity patterns outside a HIPAA-covered setting. Marketing analytics tools can also trigger MHMDA duties when they track health-related interactions.[1]
Third-party and processor oversight for Washington consumer health data
Your organization is still on the hook for third-party SDKs and APIs used in its digital products. If an analytics platform or another vendor collects consumer health data, the main organization remains accountable for what happens to that data.[1]
This is where things get tricky. A vendor’s data practices can turn into your compliance issue. If a consumer asks for deletion, that request has to reach every service provider and processor that touched the data. Vendor agreements should also be updated so they cover Washington-specific consent and deletion duties, and so third parties can meet opt-in consent and DSAR deadlines.[1]
The same review should apply to ad-tech and mobile app vendors. Before you renew or bring on any third party tied to consumer-facing digital tools, check whether data flows, APIs, and location data could create facility-targeting risk.[1]
That’s why legal scope and healthcare third-party risk management controls need to be reviewed together.
Comparison table: HIPAA, MHMDA, and RCW 70.02 requirements
The differences are easiest to see side by side.
| Feature | HIPAA | Washington MHMDA | RCW 70.02 |
|---|---|---|---|
| Scope | Covered entities & business associates | Any entity doing business in Washington or targeting Washington residents | Washington healthcare providers & facilities |
| Covered Data | Protected Health Information (PHI) | Consumer Health Data, including information that may reveal a health status | Medical records and health care information held by providers |
| Consent | Implied for Treatment, Payment, Operations (TPO); authorization for marketing | Affirmative, opt-in consent for collection and sharing; signed authorization for sale | Written authorization for most disclosures |
| Consumer Rights | Access, amendment, accounting | Access, deletion, withdrawal of consent, appeal | Access and amendment |
| Enforcement | Federal (OCR); no private right of action | State AG and private right of action (class-action risk) | Civil action for actual damages |
| Geofencing | Not addressed | Strictly prohibited near healthcare facilities | Not addressed |
The main gaps come down to scope, consent, and enforcement.
What healthcare leaders should do next in 2026
A 2026 action plan for privacy and cyber risk teams
Once the main duties are clear, the next step is simple: build one plan to run them all.
Start with a full data inventory and flow map for every entry and exit point tied to consumer health data. Then bring consent workflows, DSAR pipelines, purge schedules, geofencing checks, and vendor reviews into one coordinated cross-functional program.
Vendor oversight should sit inside that plan, not off to the side as a separate workstream.
How Censinet supports healthcare risk management at scale

Censinet RiskOps™ helps healthcare organizations manage third-party risk at scale. For teams working through Washington's MHMDA duties, the platform supports structured assessments and documented controls for third-party tools that handle consumer health data.
In vendor-heavy environments, structured risk management helps cut manual gaps and keeps oversight continuous instead of point-in-time.
Key takeaways
Washington's 2026 privacy duties require data mapping, opt-in consent, DSAR automation, geofencing reviews, and vendor controls to work as a single, documented operating model, not as isolated workstreams.
FAQs
Does MHMDA apply if we’re already HIPAA compliant?
Yes. The Washington My Health My Data Act (MHMDA) still applies even if your organization is HIPAA compliant.
Here’s the key point: MHMDA reaches beyond HIPAA. It covers consumer health data that falls outside HIPAA’s scope and uses a much broader definition of health information.
That means data tied to:
- fitness apps
- wearables
- tracked online activity
can still fall under MHMDA.
So even if your organization follows HIPAA, that doesn't automatically satisfy all MHMDA requirements.
What data counts as consumer health data in Washington?
Under Washington’s My Health My Data Act, consumer health data has a broad meaning. It covers personal information that’s linked, or can reasonably be linked, to a person’s past, present, or future physical or mental health.
That reach is pretty broad in practice. It can include biometric and genetic data, reproductive health information, data from health apps, wearables, and trackers, precise location data near healthcare facilities, and even inferences drawn from browsing activity or purchase history that point to health details.
What should healthcare teams prioritize first for 2026 compliance?
Start with a risk-based assessment of every system, vendor, and data flow that touches protected health information and sensitive consumer data.
Think of this as a live inventory. It gives teams a clear view of risk so they can rank issues and focus fixes on high-risk areas like vendors with direct access to sensitive data or core clinical systems.
Tools like Censinet RiskOps™ can help automate assessments, centralize vendor oversight, and keep audit-ready evidence in one place.