Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • Talent Leadership Summit
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    back
    Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    back
    Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • Talent Leadership Summit
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Employment Law & Compliance
  3. Washington State Passes Privacy Protections for Health Data
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Washington State Passes Privacy Protections for Health Data

April 25, 2023 | Jeremy F. Wood and Annie Ziesing © Fisher Phillips

A laptop with a stethoscope on it.


​Washington State lawmakers passed the most consequential privacy legislation in the country since the California Consumer Privacy Act (CCPA) was adopted in 2018, which will soon require businesses to take significant action in order to stay in compliance.

The Washington Senate voted to approve the My Health My Data Act on April 5 after the House passed a similar bill in March. Once the two bills are reconciled, Gov. Jay Inslee is likely to sign it into effect, expanding the privacy rights for medical information and expanding employer obligations well beyond the federal HIPAA law.

HIPAA covers just a narrow host of entities, including health providers and others in the healthcare sector. Washington's law goes further than HIPAA and applies broadly to "regulated entities." This is defined as any legal entity that:

  • Conducts business in Washington or produces or provides products or services that are targeted to consumers in Washington.
  • Collects, shares, or sells consumer health data (CHD).
  • Determines the purpose and means of the processing of CHD.

The Washington law protects CHD, defined as any information that links or reasonably links a consumer to their past, present, or future physical or mental health. This includes information about health conditions, treatment, diagnoses, surgeries, procedures, mental/behavioral health interventions, medication purchase or use, health measurements, gender-affirming care, reproductive and sexual health, biometrics, genetic data, and location data showing a consumer's attempt to acquire or receive health services.

Location data could include any data showing a consumer's visit to a grocery store, pharmacy, or e-commerce website selling pharmaceuticals or contraceptives. Protected CHD does not include de-identified information.

The Washington law protects people who reside in Washington or whose health data is collected in Washington. As Washington is a major hub for cloud data storage, this definition could encompass many entities whose only connection to the state is the presence of their data on Washington-based cloud platforms.

The law's definition of consumers excludes consumers acting in their capacity as employees. It is unclear at this time how a court will decide when a consumer has provided CHD purely as a consumer and when they have done so as an employee. It is also undetermined how this exclusion will affect an employer's liability when the employer acquires an employee's CHD from a regulated entity.

Any consumer injured by a violation of the state law can sue under the Washington Consumer Protection Act. The Washington Attorney General also may sue to enforce the law.

A regulated entity must maintain and publish a consumer health data privacy policy on its internet homepage that discloses:

  • The categories of consumer health date the entity collects.
  • The purpose of collection.
  • The use of collected data.
  • The sources of collection.
  • The categories of data that may be shared.
  • The entities with whom data may be shared.
  • A consumer's rights under the law.

If a regulated entity violates its own policy in collecting, using, or sharing CHD, it must first inform consumers and obtain their affirmative opt-in consent. Regulated entities must obtain a consumer's affirmative opt-in consent before collecting CHD, preferably in writing. Consumers may revoke this consent at any time.

The law provides several exceptions. Consent is not required when a regulated entity must collect CHD to provide a requested service or product, to detect or respond to security incidents, or to identify illegal activity.

Upon request from a consumer, regulated entities must confirm whether they are collecting CHD and allow the consumer to access their own CHD within 45 days.

Sharing Consumer Data

A regulated entity can only share CHD internally with employees or processors on a need-to-know basis, consistent with the stated purpose for which the CHD was collected.

Regulated entities will only be able to share CHD externally with the consumer's specific consent. The law includes exceptions where necessary to provide a requested product or service, or for security and safety.

Regulated entities can share CHD based on opt-in consent in various reasonable forms, but they must have written consent before selling that CHD. That written consent must identify the CHD at issue, the name and online contact information for both buyer and seller, the purpose of the sale, the buyer's intended use of the data, a statement that provision of goods and services is not conditional on the consumer granting consent, and a statement that the CHD may be redisclosed by the buyer to third parties without the protection of the law.

Such written consent is valid for one year, and the consumer may revoke it at any time. Regulated entities must retain copies of written consent for six years from the date of signature, or when the consent was last effective, whichever is later.

Consumers may request confirmation of whether a regulated entity is selling or sharing their CHD, and the regulated entity must respond within 45 days.

The law includes a "right to forgotten" broader than any counterpart on the planet. Consumers have the right to ask regulated entities to delete their CHD without limitation. The law's broad deletion requirements may put regulated entities in a bind when a consumer requests deletion of CHD that entities are legally obligated to maintain.

Facing a deletion request, regulated entities will have 30 days to comply, unless they can show that deletion would require restoring backup systems that may take longer. In complying with deletion requests, regulated entities must direct third parties who received the relevant data, so these requirements should be laid out in contracts with third parties.

Assuming Inslee signs the law, its current effective date is unclear. While some commentators have speculated that it could come into force in March 2024, the bill itself includes no effective date. It could come into effect as soon as July 22.

Next Steps

We recommend you spend the next few months considering the following action steps:

  • Review and revise your internet privacy policies.
  • Review or develop your opt-in procedures.
  • Implement annual consent reminders for data sales.
  • Implement procedures to delete CHD upon request.
  • Review your recordkeeping obligations to make policy determinations of when CHD data must be deleted upon request.
  • Review where your CHD is stored, as well as who processes it and how.

Jeremy F. Wood is an attorney with Fisher Phillips in Seattle. Annie Ziesing is an attorney with Fisher Phillips in New York City. © 2023. All rights reserved. Reprinted with permission.

ESG, Ethics & Compliance
Privacy & Security Compliance
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

Workplace Compliance Newsletter

Keep abreast of employment law and compliance developments and their wide-reaching impacts.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • SHRM India Advisory Council
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Ask an Advisor
  • SHRM Newsletter
  • Post a Job
  • Find an HR Job
  • Advertise with us
  • Copyright & Permission
Contact Us


Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

SHRM India Corporate Information

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now