regulatory updates
The Washington My Health My Data Act, Read for Biometrics
The Washington My Health My Data Act treats biometric data as health data. Who it reaches, what opt-in consent demands, and the three records to keep.
Key Takeaways
- •MHMD treats biometric data, down to gait and keystroke patterns, as consumer health data requiring opt-in consent, a consumer health data privacy policy, and deletion that reaches your processors.
- •The Act carries a private right of action through Washington's Consumer Protection Act. Maxwell v. Amazon pleaded an MHMD count in February 2025 and was voluntarily dismissed that May, before any ruling.
- •In practice the Act comes down to three records: the consent captured before collection, the separate signed authorization for any sale, and proof that deletion reached every processor.
A fingerprint at a gym. A face template at a pharmacy kiosk. A gait pattern read from a phone. Under Washington's My Health My Data Act (MHMD), each one can be consumer health data.
In plain terms, the Act is Washington's consumer health privacy law, passed in 2023. The legislature wrote it because HIPAA "only covers health data collected by specific health care entities," leaving health data collected by other businesses, "including certain apps and websites," without the same protection (RCW 19.373.005).
The Act, chapter 19.373 RCW, demands opt-in consent, a health data privacy policy linked from your homepage, deletion that follows the data into your vendors' systems, and a signed authorization before any sale. Unlike Washington's older biometric statute, it lets consumers sue.
Each duty section sets its own start date. RCW 19.373.020 through .070 (policy, consent, consumer rights, security, processors, sale) each say "beginning March 31, 2024," and give small businesses until June 30, 2024. The geofence ban, RCW 19.373.080, states no date of its own.
This page reads the Act from the biometric side. Take anything you build on it to Washington counsel.
Who the My Health My Data Act applies to
The Act binds "regulated entities" (RCW 19.373.010(23)). A regulated entity does business in Washington or targets Washington consumers. It also decides, alone or with others, why and how consumer health data is collected, processed, shared, or sold. There is no revenue floor.
A "small business" gets the later date and the same duties. It meets either of two tests: health data of fewer than 100,000 consumers in a calendar year, or under half its gross revenue from health data and fewer than 25,000 consumers (RCW 19.373.010(28)).
A "consumer" is a Washington resident, or "a natural person whose consumer health data is collected in Washington" (RCW 19.373.010(7)). Kiosk and store operators, read that second clause again: the law follows the collection as well as the residence.
The same definition carries the exclusion that does the most work: "'Consumer' does not include an individual acting in an employment context." Your employee fingerprint time clock most likely sits outside MHMD. The same scanner pointed at customers can sit inside it. That boundary, more than the word "health," is the first scoping question for any Washington biometric system.
Why a face or a fingerprint counts as health data
Consumer health data is personal information linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status. The statute then lists what health status includes: conditions and treatment, reproductive and sexual health, gender-affirming care, genetic data, precise location that could indicate a health visit, and, as item (ix), "Biometric data" (RCW 19.373.010(8)). Here is how the Act defines it:
"Biometric data" means data that is generated from the measurement or technological processing of an individual's physiological, biological, or behavioral characteristics and that identifies a consumer, whether individually or in combination with other data. Biometric data includes, but is not limited to: (a) Imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template can be extracted; or (b) Keystroke patterns or rhythms and gait patterns or rhythms that contain identifying information.
The list reaches imagery itself, plus keystroke rhythms and gait. Washington's 2017 biometric statute excludes photographs and video from its definition; this one names face imagery from which a template can be extracted.
To "collect" means "to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner" (RCW 19.373.010(5)). Retain is on that list. A face template captured in 2023 and still in your system is being collected today.
What the Act does not cover
The exemptions in RCW 19.373.100 attach to data. Exempt categories include HIPAA protected health information, health care information under Washington's RCW 70.02, and personal information governed by the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, or FERPA.
The trap is reading those as company exemptions. A hospital's patient records are HIPAA data and exempt. Its website visitor data may fall outside HIPAA, and then MHMD reaches it. Data that lives under none of those regimes gets no exit here.
The Act's obligations do not restrict collecting consumer health data to "prevent, detect, protect against, or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities" (RCW 19.373.100(3)). A face match used only for fraud prevention may fit. But subsection (4) puts "the burden of demonstrating that such processing qualifies" on you, so the fraud purpose needs its own record.
Washington's two biometric laws, kept apart
Washington has run a biometric identifiers statute since 2017: RCW 19.375, which governs enrolling identifiers for a commercial purpose and can be enforced solely by the Attorney General. MHMD runs beside it:
| RCW 19.375 (2017) | MHMD (RCW 19.373) | |
|---|---|---|
| Data covered | Biometric identifiers; photos and video excluded | Consumer health data; face imagery and gait included |
| Consent | Notice, consent, or opt-out mechanism | Opt-in consent, or necessity for a requested service |
| Employees | Not excluded | Excluded (employment context) |
| Enforcement | Attorney General only | Attorney General and private CPA suits |
The practical test: who is in front of the sensor? Employees point you toward the older statute. Customers, patients, or the public point you toward MHMD, the one with a plaintiff attached.
The consent you need, and the separate authorization to sell
MHMD's collection rule is opt-in. You may collect consumer health data only with the consumer's consent for a specified purpose, or "to the extent necessary to provide a product or service" the consumer requested (RCW 19.373.030(1)(a)). Sharing needs its own consent, "separate and distinct" from the collection consent. And the consent request has a required shape:
Consent required under this section must be obtained prior to the collection or sharing, as applicable, of any consumer health data, and the request for consent must clearly and conspicuously disclose: (i) The categories of consumer health data collected or shared; (ii) the purpose of the collection or sharing of the consumer health data, including the specific ways in which it will be used; (iii) the categories of entities with whom the consumer health data is shared; and (iv) how the consumer can withdraw consent from future collection or sharing of the consumer's health data.
The definition rules out the shortcuts. Consent "may not be obtained by" accepting general terms of use, by "hovering over, muting, pausing, or closing a given piece of content," or through deceptive designs (RCW 19.373.010(6)(b)). A kiosk that scans on approach, with terms posted on the wall, would be hard to square with this definition.
Selling is a third, higher bar. It needs a written authorization signed by the consumer, separate from any consent to collect or share, listing nine required elements, including the buyer's name and an expiration date one year out (RCW 19.373.070(2)). The statute lists what voids one:
An authorization is not valid if the document has any of the following defects: (a) The expiration date has passed; (b) The authorization does not contain all the information required under this section; (c) The authorization has been revoked by the consumer; (d) The authorization has been combined with other documents to create a compound authorization; or (e) The provision of goods or services is conditioned on the consumer signing the authorization.
Clause (d) rules out bundling "we may sell your data" into onboarding text. The consumer gets a copy, and seller and buyer must keep every authorization for six years (RCW 19.373.070(4), (5)).
Do you need a health data privacy policy?
Yes. The Act names a specific document, the consumer health data privacy policy, and requires a prominent link to it on your homepage (RCW 19.373.020(1)(b)). It has to disclose, clearly and conspicuously (RCW 19.373.020(1)(a)):
- the categories of health data you collect, why, and how you use them;
- the categories of sources they come from;
- the categories you share;
- the categories of third parties, and the specific affiliates, that receive them;
- how consumers exercise their rights under RCW 19.373.040.
A new category or purpose needs disclosure and fresh affirmative consent first (RCW 19.373.020(1)(c), (d)). Contracting with a processor to handle data in a way the policy does not describe is itself a violation (RCW 19.373.020(1)(e)). For a biometric operator, that means naming the real categories: face templates, voice recordings, and any inference your analytics derive.
Consumer rights, processors, and geofencing
Consumers have three core rights (RCW 19.373.040(1)):
- to confirm you hold their health data, and see it with a list of every third party and affiliate that got it;
- to withdraw consent;
- to have it deleted, including from archives and backups.
Deletion follows the data out the door. You must notify "all affiliates, processors, contractors, and other third parties" you shared with, and they must delete too. You have 45 days to comply, extendable once by 45 with notice. Backup restoration can delay deletion by up to six months.
Responses are free up to twice a year per consumer. No one can be made to create an account to ask. A denied appeal must point the consumer to the Attorney General's complaint channel (RCW 19.373.040(1)(d), (f), (h)).
A processor may handle consumer health data only under a binding contract that sets its instructions, and one that strays outside them "is considered a regulated entity" for that data (RCW 19.373.060). You must also limit employee and vendor access to those who need it, and keep security at the reasonable standard of care for your industry (RCW 19.373.050).
No one may put a geofence around an entity providing in-person health care services to track consumers, collect their health data, or send them health-related ads (RCW 19.373.080). A geofence is any virtual boundary "2,000 feet or less from the perimeter" (RCW 19.373.010(14)). Consent does not cure it.
The private right of action, and what a violation costs
A violation "is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW" (RCW 19.373.090), and nothing in the chapter reserves that claim to the Attorney General.
MHMD takes its remedies from the Consumer Protection Act. A private plaintiff "injured in his or her business or property" can win an injunction, actual damages, costs, and a reasonable attorney's fee; the court may raise damages to three times actual, with the increase capped at $25,000 (RCW 19.86.090). The Attorney General can add a civil penalty of up to $7,500 per violation (RCW 19.86.140).
Compare Illinois, where BIPA sets liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless one (740 ILCS 14/20(a)). A Washington plaintiff must first show injury to business or property, and defendants will fight there. But fees plus a class of everyone who walked past one kiosk is its own arithmetic.
What has actually been filed: the Amazon case
Maxwell v. Amazon.com, Inc., No. 2:25-cv-00261 (W.D. Wash.), was filed February 10, 2025. I read the complaint, ECF No. 1, from the public RECAP docket on CourtListener. It alleged that Amazon's advertising software kit, running inside third-party apps, "harvested the location data of tens of millions of Americans without their consent." It was an adtech location case; no scanner appears in it.
The MHMD count runs eight paragraphs. The word "biometric" appears once in the 27-page complaint, in paragraph 132, as a label: Amazon "collected Plaintiff's consumer health data, including biometric data and precise location information." No biometric fact supports it. Paragraph 133 then alleges that Amazon never obtained consent and never disclosed the categories, the purpose, the recipients, or how to withdraw consent. That is RCW 19.373.030(1)(c), item by item.
The case never reached a ruling. On April 14, 2025, the court consolidated it into In re Amazon Ads SDK Litigation, No. 2:25-cv-00252-BJR. Maxwell voluntarily dismissed her claims without prejudice on May 29, 2025, and the consolidated case closed on June 6, 2025, after the last plaintiff dismissed too.
Two lessons from that docket. A plaintiff can put "biometric data" into an MHMD count with one sentence, so the definitions decide what gets pleaded. And paragraph 133 shows the checklist a plaintiff will run against you: the four disclosures in your consent request.
The three records a Washington defendant will be asked for
Strip the Act to what a regulated entity would hand a court, and it comes down to three records: the consent captured before collection, the signed authorization for any sale, and the deletion trail through every processor. The audit trail checklist linked above lays them out.
The first request may come from the Attorney General, before any lawsuit. Because MHMD runs through the Consumer Protection Act, the Attorney General can serve a civil investigative demand for documents, written answers to interrogatories, oral testimony, or any mix (RCW 19.86.110(1)). The demand must name the statute, describe the classes of material "with reasonable specificity," and set a return date (RCW 19.86.110(2)). A petition to extend, modify, or set it aside is due before that date or within 20 days of service, whichever is shorter (RCW 19.86.110(8)). And no record written after the demand arrives can show consent that came before collection.
I drafted that shape for one biometric consumer from the chapter's duties. Run it before anyone else asks.
Records request: one Washington consumer, one face template
- Consent. The request as this consumer saw it, with the four disclosures from RCW 19.373.030(1)(c), the policy version in force, and the time of consent.
- First capture. When the template was first collected, which must fall after consent.
- Recipients. Every processor and third party that received the data, and the contract binding each.
- Access. Each employee and vendor who could reach the template, and why.
- Sale. The signed RCW 19.373.070 authorization with all nine elements, kept six years, or the record showing no sale.
- Deletion. For any request: when it arrived, how it was authenticated, when you complied (45 days, or one noticed extension), and each recipient's dated confirmation.
Ordinary system logs will not carry most of this. BES-1, the evidence standard Clavira publishes, calls operational logs "purpose-agnostic": they record that an event occurred, and leave out the consent scope that permitted it. The consent, recipients, and access lines all ask about that scope.
Pick one Washington customer whose face or voice template your systems hold, and answer that request for them by Friday. Any line without a document behind it is where to start.