Compliance Tool · Multi-State Overlay

Multi-State Consumer Health Data Checklist

Washington, Nevada, and Connecticut wrote consumer health data privacy laws that do not care whether you are a HIPAA covered entity. They reach health data that HIPAA never touched, they turn on consent rather than permitted-use analysis, and Washington's carries a private right of action. If you run a digital health product, a patient app, a wellness platform, or a marketing operation that infers health status, these apply to you on their own terms. Check items off as you confirm them; your progress saves in this browser.

Sources: RCW 19.373, My Health My Data Act ↗  ·  Nevada SB 370 (2023) ↗  ·  Connecticut Data Privacy Act ↗  ·  Compiled as of July 19, 2026

Items shown
Checked off
Complete
Current view

Items are grouped by jurisdiction. Common to all three covers the obligations that repeat across every one of these statutes, which is where most of the work is and where a single control can satisfy three laws at once. The Washington, Nevada, and Connecticut lanes carry what is specific to each. Items badged Private right of action are Washington provisions a consumer can sue over directly, which is what makes that statute the one to build to first. The critical structural point: in all three, the HIPAA exemption is data-level, not entity-level. Being a covered entity does not put you outside these laws, it only puts your PHI outside them, and everything else you hold is still in scope.

Washington · My Health My Data

The strictest of the three and the only one with a private right of action, enforced through the Consumer Protection Act. No revenue or volume threshold: it reaches any regulated entity doing business in Washington or targeting Washington consumers.

Nevada · SB 370

Structurally close to Washington, with separate consent for collection and sharing and a distinct authorization for sale. Attorney General enforcement only, no private right of action, which is the practical difference that matters.

Connecticut · CTDPA

A comprehensive privacy law rather than a health-specific one. Consumer health data is sensitive data requiring opt-in consent, and applicability turns on consumer-volume thresholds that the other two do not have.

Washington MHMDA geofencing prohibitionJuly 23, 2023
Washington MHMDA main obligationsMarch 31, 2024 (small business: June 30, 2024)
Nevada SB 370March 31, 2024
Connecticut CTDPAJuly 1, 2023
Washington and Nevada applicability thresholdNone. Doing business in the state is enough
Connecticut applicability thresholdConsumer-volume based. Confirm against current CTDPA text
Geofencing radius, Washington2,000 feet of an in-person health care facility
Geofencing radius, Nevada and Connecticut1,750 feet of a health care facility

California is covered separately and in more depth by the California Health Privacy Checklist, which walks CMIA, the AB 352 and AB 254 sensitive-services rules, and the state breach clocks. If you are assessing an AI or analytics vendor that touches any of this data, the AI Vendor Risk Assessment covers the contract terms. For the federal baseline underneath all of it, start with the HIPAA Privacy Rule Checklist.

This checklist compiles selected requirements from Washington's My Health My Data Act (RCW 19.373), Nevada SB 370 (2023), and the Connecticut Data Privacy Act, for general compliance-learning purposes. These statutes are recent, unevenly interpreted, and largely untested in litigation; several key terms including the scope of "consumer health data" itself remain unsettled, and section-level requirements change with amendment. This checklist is organized by obligation rather than by statutory subsection for that reason, and it is not a complete inventory of any of the three laws, nor of the other states that have enacted or are considering similar measures. This is not legal advice. Brandon Goulter is not an attorney, and using this checklist creates no professional advisory relationship. Verify current requirements against the primary sources linked above and confirm your own program's compliance with a licensed attorney before relying on this checklist. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.