Washington, Nevada, and Connecticut wrote consumer health data privacy laws that do not care whether you are a HIPAA covered entity. They reach health data that HIPAA never touched, they turn on consent rather than permitted-use analysis, and Washington's carries a private right of action. If you run a digital health product, a patient app, a wellness platform, or a marketing operation that infers health status, these apply to you on their own terms. Check items off as you confirm them; your progress saves in this browser.
Items are grouped by jurisdiction. Common to all three covers the obligations that repeat across every one of these statutes, which is where most of the work is and where a single control can satisfy three laws at once. The Washington, Nevada, and Connecticut lanes carry what is specific to each. Items badged Private right of action are Washington provisions a consumer can sue over directly, which is what makes that statute the one to build to first. The critical structural point: in all three, the HIPAA exemption is data-level, not entity-level. Being a covered entity does not put you outside these laws, it only puts your PHI outside them, and everything else you hold is still in scope.
The strictest of the three and the only one with a private right of action, enforced through the Consumer Protection Act. No revenue or volume threshold: it reaches any regulated entity doing business in Washington or targeting Washington consumers.
Structurally close to Washington, with separate consent for collection and sharing and a distinct authorization for sale. Attorney General enforcement only, no private right of action, which is the practical difference that matters.
A comprehensive privacy law rather than a health-specific one. Consumer health data is sensitive data requiring opt-in consent, and applicability turns on consumer-volume thresholds that the other two do not have.
California is covered separately and in more depth by the California Health Privacy Checklist, which walks CMIA, the AB 352 and AB 254 sensitive-services rules, and the state breach clocks. If you are assessing an AI or analytics vendor that touches any of this data, the AI Vendor Risk Assessment covers the contract terms. For the federal baseline underneath all of it, start with the HIPAA Privacy Rule Checklist.
This checklist compiles selected requirements from Washington's My Health My Data Act (RCW 19.373), Nevada SB 370 (2023), and the Connecticut Data Privacy Act, for general compliance-learning purposes. These statutes are recent, unevenly interpreted, and largely untested in litigation; several key terms including the scope of "consumer health data" itself remain unsettled, and section-level requirements change with amendment. This checklist is organized by obligation rather than by statutory subsection for that reason, and it is not a complete inventory of any of the three laws, nor of the other states that have enacted or are considering similar measures. This is not legal advice. Brandon Goulter is not an attorney, and using this checklist creates no professional advisory relationship. Verify current requirements against the primary sources linked above and confirm your own program's compliance with a licensed attorney before relying on this checklist. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.