What is the difference between MHMDA and HIPAA?
HIPAA and Washington's My Health My Data Act cover different data. HIPAA applies only to covered entities, such as health plans and providers, and their business associates. MHMDA applies to any business handling Washington consumers' health data, filling the gap for apps and websites, and it exempts data already regulated by HIPAA.
Applies to: Businesses handling health-related data of Washington residents that need to know whether HIPAA, the My Health My Data Act, or both apply, especially apps, websites, and wellness services outside traditional health care.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
People assume HIPAA protects all their health data. It does not, and that assumption is exactly the gap Washington's My Health My Data Act was written to close. The two laws sound like they cover the same ground, but they reach different businesses and different data. If you run a health app, a wellness site, or any service that touches Washington residents' health information, the difference decides which rules you follow.
Who does HIPAA actually cover?
HIPAA is narrower than its reputation. It applies only to "covered entities," which the Department of Health and Human Services defines as health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a standard transaction, plus the "business associates" those entities hire. A hospital, an insurer, and a billing vendor are covered. A period-tracking app, a symptom checker, a wearable maker, or an ad network that infers health interests usually is not, because none of them is a covered entity or a business associate. Health data those businesses hold sits outside HIPAA entirely.
What does MHMDA cover that HIPAA does not?
Washington's law starts from the opposite end. MHMDA regulates "consumer health data," defined broadly to include data that identifies a person's past, present, or future physical or mental health, including health status inferred from non-health data. It applies to any "regulated entity" that conducts business in Washington or targets Washington consumers and decides how consumer health data is collected or used, with no revenue or consumer-count threshold to trigger coverage. Its duties are strict: opt-in consent to collect, separate consent to share, a signed authorization to sell, and a ban on geofencing within 2,000 feet of a health care facility. The Washington My Health My Data guide covers those obligations in detail, and consumer health data laws by state shows how Nevada and Connecticut compare.
Does MHMDA apply if you already follow HIPAA?
For the data HIPAA already governs, MHMDA steps back. RCW 19.373.100 exempts protected health information for purposes of HIPAA, health care information handled under Washington's own chapter 70.02 RCW, and information that originates from and is intermingled to be indistinguishable with data maintained by a HIPAA covered entity or business associate. So a hospital's patient records do not pick up a second layer of MHMDA rules. The catch is that many organizations run both kinds of processing. A provider that also offers a direct-to-consumer app may hold HIPAA protected health information on one side and non-exempt consumer health data on the other, and MHMDA reaches the second set. The Connecticut consumer health data page shows a similar structure in another state.
Next step
If you are not sure whether your health-related data falls under HIPAA, MHMDA, or both, the free 2-minute Obligation Scan checks your profile against Washington's regulated-entity test and flags the consent, policy, and geofencing duties that follow. The US state privacy laws hub sets the wider picture across states.
Compliance checklist
- Determine whether you are a HIPAA covered entity or business associate; if you are neither, HIPAA likely does not reach your health-related data.
- If you handle any Washington consumer's health data outside HIPAA, check the MHMDA regulated-entity trigger, which has no revenue or consumer-count threshold.
- Map your data: separate HIPAA protected health information, which MHMDA exempts under RCW 19.373.100, from consumer health data, which MHMDA covers.
- For MHMDA-covered data, publish a consumer health data privacy policy and obtain opt-in consent to collect, with separate consent or a signed authorization to share or sell.
- Do not operate a geofence within 2,000 feet of an in-person health care facility to track consumers or collect their health data.
Sources
- RCW 19.373.100 (My Health My Data Act exemptions; HIPAA and covered-entity data), Washington State Legislature
- U.S. Department of Health and Human Services, Covered Entities and Business Associates (who must comply with HIPAA)
Last verified: 2026-08-07
Informational, not legal advice.