Washington's My Health My Data Act (MHMDA) lets a consumer who sues over a violation recover up to $25,000 in treble damages per violation, under RCW 19.86.090, since the law's core provisions took effect on March 31, 2024. That private right of action, layered on top of a separate $7,500-per-violation civil penalty the state Attorney General can pursue under RCW 19.86.140, makes MHMDA one of the more aggressive consumer health privacy statutes in the country. Two lawsuits have tested that private right of action so far, and Washington remains one of only three states with a law written specifically around consumer health data. Below is the full set of thresholds, dates, and penalty figures that matter for any business handling Washington residents' health-adjacent information.

Washington's My Health My Data Act caps treble damages at $25,000 per violation $25K in treble damages perMHMDA violation, RCW 19.86.090

What is the penalty for violating Washington's My Health My Data Act?

Washington sets two separate penalty tracks for an MHMDA violation, and they do not share a cap. A consumer harmed by a violation can sue directly and recover actual damages plus treble damages capped at $25,000 per violation, under RCW 19.86.090, since MHMDA violations are enforceable through the Washington Consumer Protection Act. The Washington Attorney General can pursue a parallel, separate civil penalty of up to $7,500 per violation under RCW 19.86.140, and that penalty is not available to private plaintiffs. A single violation touching one consumer could in theory draw both remedies at once, a private suit and a state civil penalty, for combined exposure of up to $32,500 before attorney fees and injunctive relief are added, though the two tracks operate independently rather than as one combined award.

Washington's private right of action is the more unusual piece nationally. State privacy laws in Colorado and Virginia rely on Attorney General enforcement alone, with no equivalent consumer lawsuit right. MHMDA gives Washington residents standing to sue for any violation of the statute's substantive requirements, not just a data breach, which is why legal commentators have flagged it as carrying higher litigation risk than the Colorado Privacy Act or Virginia's CDPA.

Figure 1: Washington's private right of action carries the highest per-violation ceiling among the laws compared here, before its separate Attorney General penalty is even added. Sources: RCW 19.86.090, RCW 19.86.140, Colorado Revised Statutes 6-1-112, Code of Virginia 59.1-584.

Whichever track applies, the ceiling sits well above what most state privacy laws allow per violation.

Who has to comply with MHMDA, and when did it take effect?

MHMDA applies to any "regulated entity" that conducts business in Washington, or that targets products or services to Washington residents, and that alone or jointly determines the purpose and means of collecting, processing, sharing, or selling consumer health data. Unlike most state privacy laws, the statute sets no minimum revenue or consumer-count threshold to trigger coverage in the first place; the only threshold that exists determines when a business must comply, not whether it is covered, according to a Ballard Spahr compliance alert. A "small business" gets extra time under that threshold: a regulated entity processing fewer than 100,000 consumers' health data in a calendar year, or fewer than 25,000 while deriving less than 50 percent of revenue from health data, could wait until June 30, 2024 rather than the earlier March 31, 2024 date. The law's geofencing restriction, which bans setting a virtual boundary around a health care facility to track, collect data from, or send notifications to a consumer, took effect earlier still, on July 23, 2023, ninety days after the 2023 legislative session ended.

Figure 2: MHMDA sets no minimum threshold to be covered at all, only a later compliance date for smaller entities. Source: RCW 19.373, Ballard Spahr compliance guidance, Goodwin Law effective-date alert.

Because there is no size floor, a small clinic-adjacent app or a regional wellness brand can fall inside MHMDA's scope just as easily as a national platform. Businesses reassessing their disclosures for Washington residents can generate a privacy policy built around current state requirements rather than relying on a single multi-state template that skips MHMDA's consumer health data definitions.

MHMDA sits alongside, not inside, Washington's general consumer protection framework; the state has not adopted a broader comprehensive privacy law of the kind tracked in our roundup of state privacy laws now in effect nationwide, which makes MHMDA the primary state-level privacy statute Washington-based and Washington-facing businesses need to watch.

The compliance date already passed for every business currently covered; the open question now is how actively regulators and private plaintiffs enforce it.

How many lawsuits have been filed under MHMDA so far?

Only two class action lawsuits had been filed under MHMDA as of mid-2026, more than two years after the law's core provisions took effect. The first, filed February 10, 2025 in the Western District of Washington, targets Amazon and Amazon Advertising over an advertising software development kit embedded in third-party mobile apps, alleging it collected location and biometric data without the consent MHMDA requires. The second, filed in November 2025 against Uncle Ike's, a Seattle-area cannabis retailer, alleges the company configured website tracking pixels to send visitors' medical marijuana appointment details and purchase data to Google and other third parties without consent, a case privacy attorneys have called a precedent-setting test of whether location and purchase data tied to a health care-adjacent visit counts as consumer health data under the statute.

Figure 3: Two years passed between MHMDA's effective date and its first tested lawsuit. Source: WilmerHale, Hintze Law, Washington State Legislature.

That gap between effective date and first lawsuit is not unusual for a new private right of action; similar delays showed up before litigation began over other health-adjacent privacy complaints, including the ones tracked in our coverage of Hims and Hers' health data privacy complaints.

Two lawsuits in roughly seventeen months is a slow start, but both are still active, and neither has been dismissed.

Which other states regulate consumer health data like Washington?

Washington is one of just three states with a privacy law written specifically around consumer health data, rather than personal data generally, as of 2026. Nevada enacted a similar law, Senate Bill 370, in June 2023, and it took effect March 31, 2024, the same date as MHMDA's core provisions. Connecticut folded consumer health data protections into its existing Connecticut Data Privacy Act through 2023 amendments that took effect July 1, 2023, ahead of both Washington's and Nevada's laws. All three share a common structure: they restrict selling consumer health data without separate written consent and ban geofencing around health facilities, according to comparative analysis from Epstein Becker Green.

Figure 4: A dedicated consumer health data law remains rare among state privacy frameworks. Source: Epstein Becker Green comparative analysis, 2026.

The three laws are not identical, and the private right of action is where they diverge most. Washington's MHMDA gives consumers standing to sue directly for any violation of the statute, while Nevada's SB 370 and Connecticut's health data amendments are enforced by each state's Attorney General only, with no equivalent consumer lawsuit right, according to comparative guidance from Epstein Becker Green and Benesch Law. That difference is the main reason MHMDA, not Nevada's or Connecticut's law, has produced the class actions covered above.

A business already built for MHMDA compliance is close to compliant with Nevada's and Connecticut's health data rules too, but the private lawsuit exposure is a Washington-specific risk.

How has MHMDA's compliance scope grown since 2023?

A business tracking only the headline March 2024 date would miss two other milestones that expanded MHMDA's practical reach. The geofencing ban arrived first, in July 2023, restricting location-based tracking around health facilities regardless of a business's size. The core disclosure, consent, and data-sale provisions followed for regulated entities in March 2024, and the same obligations extended to small businesses three months later, in June 2024, closing the compliance gap the law's own size-based delay had created.

Figure 5: Each milestone added a new, still-active obligation rather than replacing the one before it. Source: RCW 19.373, Goodwin Law effective-date alert, Hunton Andrews Kurth geofencing alert.

That layered rollout mirrors how other state privacy laws have added obligations gradually rather than all at once; our breakdown of Colorado's Privacy Act compliance timeline shows a similar multi-year buildup, with five distinct obligations added between 2023 and 2027.

MHMDA has not added a new statutory layer since June 2024, but two active lawsuits mean its practical scope is still being defined in court rather than by the legislature.

How does Washington's My Health My Data Act compare to Nevada and Connecticut?

Washington's private right of action is the clearest structural difference among the three consumer health data laws, and it is also the newest to be tested in court. A business already handling MHMDA disclosures, consent flows, and geofencing restrictions is doing most of what Nevada's and Connecticut's laws separately require, since all three restrict selling consumer health data without distinct written consent. The gap that remains is litigation exposure: a Washington-facing business faces a private lawsuit risk that a Nevada-only or Connecticut-only business does not currently carry.

LawEffective datePrivate right of actionMax Attorney General penalty
My Health My Data Act (Washington)Mar 31, 2024 (Jun 30, 2024 small business)Yes, treble damages capped at $25,000$7,500 per violation
Senate Bill 370 (Nevada)Mar 31, 2024No, AG enforcement onlyNot separately specified in the statute
CTDPA health data amendments (Connecticut)Jul 1, 2023No, AG enforcement onlySet under general CTDPA penalty authority

Sources: RCW 19.86.090, RCW 19.86.140, Nevada Senate Bill 370, Epstein Becker Green and Benesch Law comparative guidance.

Businesses unsure which of these overlapping state rules actually apply to them can start with our guide to which US state privacy laws apply to your business, which walks through the applicability tests state by state.

The Bottom Line

Washington's My Health My Data Act combines a rare structural feature, a full private right of action for consumer health data violations, with penalty numbers that already sit near the top of the state privacy law landscape: $25,000 in treble damages per violation for private plaintiffs, on top of a separate $7,500-per-violation civil penalty the state Attorney General can pursue independently. Only two lawsuits have tested that private right of action so far, but both remain active, and Washington's structure means more are plausible than under Nevada's or Connecticut's Attorney General-only laws. For any business handling Washington residents' health-adjacent data, whether that is location data near a clinic, fitness tracking, reproductive health information, or a wellness app's usage logs, the practical risk is not the state's enforcement pipeline; it is a single class action complaint. Reviewing consent flows, geofencing configurations, and data-sale disclosures against MHMDA's specific requirements, rather than a generic multi-state privacy policy, is the more defensible starting point given that gap.

Frequently Asked Questions

What is the maximum penalty under Washington's My Health My Data Act? Up to $25,000 in treble damages per violation for a private lawsuit, under RCW 19.86.090, plus a separate civil penalty of up to $7,500 per violation the Washington Attorney General can pursue under RCW 19.86.140.

When did the My Health My Data Act take effect? March 31, 2024 for regulated entities and June 30, 2024 for small businesses, with the law's narrower geofencing ban taking effect earlier, on July 23, 2023.

How many lawsuits have been filed under MHMDA? Two class actions as of mid-2026: one against Amazon, filed February 10, 2025, and one against Uncle Ike's cannabis retailer, filed in November 2025.

Which other states have a law like Washington's MHMDA? Nevada, under Senate Bill 370, and Connecticut, through 2023 amendments to its Connecticut Data Privacy Act, making Washington one of three states as of 2026 with a privacy law written specifically around consumer health data.

Where the Numbers Come From

  1. National Law Review. "What Are the Damages for Violating Washington's My Health My Data Act?" Treble damages capped at $25,000 under RCW 19.86.090; civil penalty up to $7,500 per violation under RCW 19.86.140.
  2. Washington State Legislature. RCW 19.86.090, "Civil action for damages, injunction, other equitable relief." Official statute text for the treble damages provision.
  3. Washington State Legislature. RCW 19.86.140, "Civil penalty." Official statute text for the Attorney General's civil penalty authority.
  4. WilmerHale. (2025). "First Lawsuit Filed Under Washington's My Health My Data Act." Amazon class action filed February 10, 2025, Western District of Washington.
  5. Hintze Law. (2025). "Washington Marijuana Retailer Sued Under My Health My Data Act for Website Pixel Use." Uncle Ike's class action filed November 2025.
  6. Epstein Becker Green. "Nevada Joins Washington and Connecticut to Protect Consumer Health Data Privacy." Three-state comparison, effective dates, and enforcement structure.
  7. Hunton Andrews Kurth. "New Washington State Geofencing Ban Set to Take Effect in July." Geofencing provision effective July 23, 2023.
  8. Ballard Spahr. (2024). "Navigating Privacy Compliance: Will Your Business Be Subject to Washington's My Health My Data Act?" No revenue or consumer-count threshold to trigger coverage; small business thresholds of 100,000 and 25,000 consumers.
  9. Goodwin Law. (2024). "Washington's My Health My Data Act Comes Into Force." Effective dates of March 31, 2024 and June 30, 2024.
  10. Benesch Law. "Nevada Joins Washington With A Consumer Health Data Consent Law Now In Effect." Nevada SB 370 effective date confirmation, March 31, 2024.
  11. Justia, Colorado Revised Statutes. Section 6-1-112, "Civil penalties." $20,000 maximum per-violation civil penalty under the Colorado Privacy Act, used here for comparison.

Note: All figures verified as of August 2026. Only two lawsuits had been filed under MHMDA's private right of action as of this writing, and both remain active; this post's litigation count is refreshed at least twice a year as new filings are reported.