Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Washington State's Health Data Consent Law: What Counts as "Consumer Health Data"Laws and Regulations
5 min readFor Marketing Technology Teams

Washington State's Health Data Consent Law: What Counts as "Consumer Health Data"

Understanding the Scope

This guide explains the consent requirements under Washington's My Health My Data Act (WMHMDA), effective March 31, 2024. It's aimed at organizations that may not see themselves as healthcare providers but might collect data defined as "Consumer Health Data."

Who must comply: Any organization collecting data related to an individual's "past, present, or future physical or mental health status," except HIPAA-regulated entities and employers processing employee data.

Who should read this: Marketing technology teams, consent platform administrators, and privacy officers at retailers, publishers, fitness centers, supplement providers, and similar businesses unsure if the Act applies to them.

What you won't find here: HIPAA compliance guidance or employment data processing rules, as these are outside WMHMDA's scope.

Key Concepts and Definitions

Consumer Health Data

The Act defines Consumer Health Data as any information linked or reasonably linkable to an individual that identifies their physical or mental health status. For example, data from someone reading your nutrition blog about diabetes, visiting your grocery store's wellness section, or using your fitness app to track injury recovery could be considered Consumer Health Data.

Processing, Sharing, and Sale

WMHMDA outlines three activities with different consent obligations:

Processing includes any operation on Consumer Health Data, such as collection, use, storage, disclosure, analysis, or deletion.

Sharing involves disclosing Consumer Health Data to a third party for cross-context Behavioural Advertising. Transfers to processors and corporate transitions (like mergers) are excluded.

Sale includes both monetary transfers and exchanges for "other valuable consideration," covering most commercial data transfers.

Consent Requirements

When Consent Is Required

WMHMDA requires consent in five scenarios:

  1. Collecting or sharing beyond disclosed purposes (§ 4(1)(c), (d))
    If your privacy notice states you collect email addresses and purchase history, you can't start collecting browsing behavior or sharing data with advertising partners without consent.

  2. Collecting sensitive health data (§ 5(1)(a)(i))
    Consent is needed for categories like precise geolocation, genetic data, biometric identifiers, mental or physical diagnosis, and reproductive or sexual health information.

  3. Using data for non-essential purposes (§ 5(1)(a)(ii))
    If processing isn't essential for delivering what the consumer requested, you need consent. This includes analytics, profiling, or product development.

  4. Sharing for cross-context Behavioural Advertising (§ 5(1)(b)(ii))
    Any disclosure to third parties for ad targeting requires consent, unless it's necessary for your core service, which is rare for advertising.

  5. Selling Consumer Health Data (§ 9(1))
    All sales require consent, including non-monetary exchanges like data-for-services arrangements.

Consent Mechanism Requirements

The statute doesn't specify consent mechanism details but requires consent for specific activities. You can't bundle these permissions into general terms of service acceptance.

Implementation Steps

Step 1: Map Your Data Flows

Identify where health-related data enters your systems:

  • Search queries with health terms
  • Product categories (supplements, fitness equipment, dietary items)
  • Content engagement (articles about wellness, mental health, physical conditions)
  • Form submissions requesting health-related information
  • Location data if you operate gyms, wellness centers, or health-focused retail

Don't assume exemption because you're not a healthcare provider. The statute's definition focuses on what the data reveals, not your industry.

Step 2: Classify Data by Sensitivity

Separate data into three tiers:

Tier 1 - Sensitive categories requiring consent (§ 5(1)(a)(i)): Includes precise geolocation, genetic testing results, biometric identifiers, mental/physical diagnoses, reproductive health, sexual health.

Tier 2 - Health-adjacent data: Purchase history of wellness products, engagement with health content, fitness tracking that doesn't reveal diagnoses.

Tier 3 - Non-health data: Payment information, shipping addresses (without geolocation precision), customer service interactions unrelated to health.

Step 3: Audit Third-Party Relationships

Review every vendor relationship where you transfer data:

  • Does the vendor use the data for cross-context Behavioural Advertising?
  • Are you receiving consideration (money, services, data) in exchange?
  • Is the transfer necessary to deliver your core service, or is it optional?

If you're sharing Tier 1 or Tier 2 data with advertising networks, analytics platforms, or data brokers, you're likely triggering consent requirements under § 7(a) or § 9(1).

Step 4: Configure Consent Mechanisms

Your Consent Management Platform must:

  • Present consent requests separately for each processing activity requiring authorization
  • Distinguish between necessary processing (no consent needed) and optional processing (consent required)
  • Allow withdrawal of consent as easily as granting it
  • Record which specific activities the consumer authorized

Don't gate your entire service behind a single "Accept All" button. The statute implies granular consent for distinct processing purposes.

Common Pitfalls

Assuming your privacy notice satisfies the consent requirement
Disclosure isn't consent. Even if your notice describes data sharing, you still need affirmative authorization for the activities listed in §§ 5, 7, and 9.

Treating all health-adjacent data identically
The statute distinguishes sensitive categories (§ 5(1)(a)(i)) from general Consumer Health Data. Your consent flows should reflect this distinction.

Relying on "legitimate interest" as a workaround
WMHMDA doesn't recognize legitimate interest as an alternative legal basis for processing. If the activity requires consent under the statute, you need consent.

Overlooking non-monetary "sales"
If you're exchanging Consumer Health Data for analytics services, audience insights, or advertising inventory, you're selling under the Act's definition. Consent is mandatory.

Ignoring data collected before March 31, 2024
The statute doesn't grandfather existing data. If you're processing Consumer Health Data collected before the effective date in ways that require consent, obtain that consent now.

Quick Reference Table

Activity Consent Required? Statutory Basis Notes
Collecting data described in your privacy notice No § 4(1)(c) Disclosure satisfies transparency requirement
Collecting beyond privacy notice scope Yes § 4(1)(c), (d) Update notice and obtain consent
Collecting sensitive categories (geolocation, genetic, biometric, diagnosis, reproductive/sexual health) Yes § 5(1)(a)(i) Always requires consent regardless of notice
Processing for service delivery No § 5(1)(a)(ii) "Necessary to provide" exception applies
Processing for secondary purposes (analytics, profiling, research) Yes § 5(1)(a)(ii) Not necessary for core service
Sharing with processors No § 3(26)(b) Excluded from "sharing" definition
Sharing for cross-context Behavioural Advertising Yes § 5(1)(b)(ii), § 7(a) Unless necessary for service (rare)
Transfers during mergers/acquisitions No § 7(a) Excluded from "sharing" definition
Selling for money or other consideration Yes § 9(1) Includes non-monetary exchanges

Effective date: March 31, 2024, for most organizations. If you're collecting data that could identify someone seeking health information or services, start your compliance review now.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like