Back to the hub

Does Nevada's consumer health data law apply to your business?

Nevada's consumer health data law (SB 370, effective March 31, 2024) applies to any regulated entity that does business in Nevada or targets Nevada consumers and decides how consumer health data is processed. It sets no revenue threshold, requires opt-in consent to collect that data, and bans geofencing within 1,750 feet of health facilities.

Applies to: Any regulated entity that conducts business in Nevada or targets products or services to Nevada consumers and determines the purpose and means of processing, sharing, or selling consumer health data; there is no revenue or consumer-count threshold to be covered.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Nevada quietly passed one of the strictest consumer health data laws in the country, and it catches companies that assumed HIPAA covered everything health-related. Senate Bill 370 took effect on March 31, 2024, sits in Chapter 603A of the Nevada Revised Statutes, and reaches health information that falls outside HIPAA. Like Washington's law, it turns on opt-in consent and applies no matter how small you are.

Who does SB 370 cover?

The law applies to a "regulated entity," which Section 15 defines as any person who conducts business in Nevada, or targets products or services to Nevada consumers, and who alone or with others determines the purpose and means of processing, sharing, or selling consumer health data. There is no revenue floor and no consumer-count trigger, so a small out-of-state app is covered the same as a large in-state company. Entities already regulated by HIPAA or the Gramm-Leach-Bliley Act, and certain research and government activities, are carved out under Section 20, but the exemptions are for specific data, not a blanket pass.

What is consumer health data in Nevada?

Under Section 8, consumer health data is personally identifiable information, linked or reasonably linkable to a consumer, that a regulated entity uses to identify the consumer's past, present, or future health status. It reaches well beyond diagnoses. It includes health conditions, treatments and procedures, the use or acquisition of medication, bodily functions and symptoms, reproductive or sexual health care, and gender-affirming care. It also covers biometric and genetic data tied to those signals, precise geolocation that indicates an attempt to get health care, and data inferred from non-health information. An app that logs symptoms, a store that infers a pregnancy, or a tool that tracks visits near a clinic can all be handling it.

What must you do before collecting or selling it?

Consent is front-loaded and layered. Under Section 22, you cannot collect consumer health data without the consumer's affirmative, voluntary consent, unless it is strictly necessary to provide something they asked for. Sharing needs a second consent that is separate and distinct from the collection consent. Selling is stricter still: Section 30 requires a signed written authorization, in plain language, that names the buyer and purpose, and you cannot condition goods or services on the consumer giving it. Section 21 also requires you to publish a consumer health data privacy policy and link it on your homepage, and Section 24 gives consumers rights to confirm, list recipients, stop, and delete their data.

Why the geofencing ban and enforcement matter

Two features sharpen the law. Section 31 bans running a geofence within 1,750 feet of a medical facility or other in-person health care provider to track consumers, collect their health data, or send them health-related messages or ads. And under Section 34, a violation is a deceptive trade practice enforced by the Nevada Attorney General, with no private right of action, which distinguishes it from Washington's My Health My Data Act, where individuals can sue. Because health data overlaps with California's rules, review CCPA sensitive personal information if you also serve Californians.

Next step

If you collect anything that hints at health and reach anyone in Nevada, the free 2-minute Obligation Scan checks whether SB 370 applies and lists the consent, privacy-policy, authorization, and geofencing steps you owe, so a missing opt-in does not become a deceptive-trade-practice action. The US state privacy laws hub shows how data-type laws like this one sit alongside the comprehensive state laws.

Compliance checklist

  • Decide whether you are a regulated entity: do you do business in Nevada or target Nevada consumers and determine how consumer health data is processed? There is no size threshold to be covered.
  • Publish a consumer health data privacy policy meeting Section 21, and post a link to it conspicuously on your homepage.
  • Get affirmative, voluntary opt-in consent before collecting consumer health data, and separate, distinct consent before sharing it.
  • Obtain a signed written authorization before selling consumer health data, and never condition goods or services on that authorization.
  • Do not run a geofence within 1,750 feet of a health facility to track consumers, collect their health data, or send health-related messages.

Sources

Last verified: 2026-08-04

Informational, not legal advice.