15.2 MHMD, Nevada CHD, GIPA, and Geofencing Bans

Key Takeaways

  • Washington’s My Health My Data Act (RCW 19.373) covers consumer health data that HIPAA does not: consent to collect or share, a separate signed authorization to sell (one-year expiration, six-year retention), a deletion right, and a categorical geofence ban around in-person health-care services
  • RCW 19.373.080 makes it unlawful to implement a geofence around an in-person health-care entity to identify or track consumers seeking care, collect consumer health data, or send health-related notifications, messages, or ads; a geofence is a virtual boundary 2,000 feet or less from the perimeter
  • A My Health My Data Act violation is a per se Washington Consumer Protection Act violation (RCW 19.373.090), enforceable by the Attorney General and by private action; official pages are https://app.leg.wa.gov/RCW/default.aspx?cite=19.373 and https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy
  • Nevada’s Consumer Health Data Privacy Act (SB 370, 2023; NRS 603A.400–550) uses a narrower “consumer” (must have requested a product or service), bans geofences within 1,750 feet of in-person health-care facilities (NRS 603A.540), and creates no private right of action (NRS 603A.550)
  • Illinois GIPA (410 ILCS 513) supplies a private right of action with statutory damages and fueled a 2023–2024 class-action wave against employers that collected family medical history in physicals, fitness-for-duty exams, and wellness programs
Last updated: August 2026

The HIPAA Gap These Laws Close

HIPAA protects protected health information (PHI) held by covered entities and business associates. It does not regulate a period-tracker app, a search-engine advertiser, a data broker that infers pregnancy from shopping, or an employer collecting family medical history as employer. Washington’s legislature said so in RCW 19.373.005: people expect HIPAA to cover their health data, but HIPAA covers only specified health-care entities; health data collected by noncovered entities, including certain apps and websites, is not afforded the same protections. Domain V tests the state statutes that close that app-and-advertiser gap — and the employer-genetic gap HIPAA never occupied.

Washington My Health My Data Act

The My Health My Data Act (MHMD), RCW chapter 19.373 (2023 Wash. Laws 191; HB 1155), is the first U.S. privacy statute built specifically for personal health data outside HIPAA. Official chapter: https://app.leg.wa.gov/RCW/default.aspx?cite=19.373. Official Attorney General FAQ: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy.

A consumer is a natural person who is a Washington resident, or a natural person whose consumer health data is collected in Washington, acting in an individual or household context. Employment-context data is out. The Attorney General has said an entity that only stores data in Washington is not, by that fact alone, a regulated entity; the statute keys off conducting business in Washington or targeting Washington consumers, plus determining the purpose and means of collecting, processing, sharing, or selling consumer health data.

Consumer health data (CHD) is personal information linked or reasonably linkable to a consumer that identifies the consumer’s past, present, or future physical or mental health status. The definition expressly includes conditions, treatment, diagnoses, prescribed-medication use or purchase, vital signs, gender-affirming care, reproductive or sexual health information, biometric data, genetic data, precise location that could reasonably indicate an attempt to acquire health services or supplies, data that identifies a consumer seeking health-care services, and — critically — information derived or extrapolated from nonhealth data (proxy, inferred, or algorithmic data) when a regulated entity uses it to associate the consumer with health status. The Attorney General’s FAQ uses the classic retailer “pregnancy prediction score” as protected CHD even though it was inferred from ordinary purchases. Ordinary toiletry purchases, without a health inference, are not CHD.

Consent to collect or share is a clear affirmative act: freely given, specific, informed, opt-in, voluntary, and unambiguous. Consent may not be obtained by acceptance of a general terms-of-use document, by hovering, muting, pausing, or closing content, or through deceptive design. Sharing and selling are different legal events. Collection and sharing require consent under RCW 19.373.030. A sale additionally requires a valid authorization under RCW 19.373.070, beginning 31 March 2024 (30 June 2024 for small businesses). That authorization must be a separate plain-language document — not bundled with the collection consent — and must name the specific CHD, the seller, the purchaser, and the purpose; state that goods or services may not be conditioned on signing; explain revocation; warn that the purchaser may redisclose the data; expire one year from signature; and carry the consumer’s signature and date. Seller and purchaser retain a copy for six years. A copy goes to the consumer. Compound authorizations and expired forms are invalid.

Consumers also have a deletion right, including archived and backup systems (with a permitted delay for backups). Regulated entities and small businesses must publish a separate consumer-health-data privacy policy and place a prominent homepage link to it. The Attorney General’s FAQ is explicit: the link may not be stuffed with extra, off-statute content.

Effective dates are sectional. Geofence restrictions (section 10) applied to all “persons” beginning 23 July 2023. The rest of the regulated-entity duties applied 31 March 2024, and 30 June 2024 for small businesses.

The Geofence Ban

RCW 19.373.010 defines a geofence as technology that uses global-positioning coordinates, cell-tower connectivity, cellular data, radio-frequency identification, Wi-Fi data, or any other spatial or location detection to establish a virtual boundary around a specific physical location, or to locate a consumer within a virtual boundary. For the Act, that virtual boundary is 2,000 feet or less from the perimeter of the physical location.

RCW 19.373.080 is categorical. It is unlawful for any person to implement a geofence around an entity that provides in-person health-care services where the geofence is used to (1) identify or track consumers seeking health-care services, (2) collect consumer health data, or (3) send notifications, messages, or advertisements to consumers related to their consumer health data or health-care services. Unlike collection (which consent can authorize) and sale (which a signed authorization can authorize), the geofence prohibition has no consent override. An app cannot geofence a clinic “because the user clicked Accept.”

Enforcement is the other exam hook. RCW 19.373.090 declares that a violation is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act and unfair method of competition for purposes of the Washington Consumer Protection Act (CPA), RCW 19.86. The Attorney General’s FAQ calls this a per se CPA violation, enforceable by the Attorney General and through private action. That private right is why MHMD is not “just another attorney-general statute.”

Scenario. An advertising network drops a software-development kit into a weather app and draws a 1,500-foot virtual fence around a Washington fertility clinic. When a device crosses the fence, the network adds the user to a “trying to conceive” audience and serves clinic-competitor ads. That is a geofence used to identify or track consumers seeking care and to send health-related advertisements. Consent in the weather app’s terms of use does not legalize it. The user — and the Attorney General — can proceed under the CPA.

Nevada Consumer Health Data Privacy Act

Nevada’s parallel statute is Senate Bill 370 (2023), codified at NRS 603A.400–550, generally effective 31 March 2024. It is the same family of rules — consumer-health-data policy, consent to collect or share, deletion, a separate written authorization to sell (six-year retention), and a geofence ban — with two exam-critical differences.

First, consumer is narrower. Under NRS 603A.425, a consumer is a natural person who has requested a product or service from a regulated entity and who resides in Nevada or whose consumer health data is collected in Nevada. Washington does not require that product-or-service request. A Nevada plaintiff who never asked the company for anything is a harder fit.

Second, NRS 603A.540 bans implementing a geofence within 1,750 feet of any medical facility, facility for the dependent, or other person or entity that provides in-person health-care services or products, for the purpose of identifying or tracking consumers seeking in-person care, collecting consumer health data, or sending notifications, messages, or advertisements related to that data or those services. The statute defines the geofence itself as a virtual boundary with a radius of 1,750 feet or less. Memorize the footage split: Washington 2,000, Nevada 1,750.

Third, NRS 603A.550 makes a violation a deceptive trade practice and states that the chapter does not create a private right of action. Nevada is Attorney General / deceptive-trade-practice enforcement. Washington is CPA private-right territory. Do not import MHMD’s private right into Nevada.

Connecticut’s comprehensive privacy law also added consumer-health-data and geofence restrictions. Treat geofencing of in-person care as a Body of Knowledge theme, not a one-state novelty. Oregon’s HB 2008 amendments, effective 1 January 2026, separately prohibit sale of precise geolocation data relating to an individual’s location within a 1,750-foot radius — a sale restriction, not the same as MHMD’s implement-a-geofence ban, but the same policy family.

Illinois Genetic Information Privacy Act

The Illinois Genetic Information Privacy Act (GIPA), 410 ILCS 513, is older than MHMD and aims at a different HIPAA hole: employers and insurers using genetic testing and genetic information, including family medical history. Federal Genetic Information Nondiscrimination Act (GINA) enforcement is primarily an Equal Employment Opportunity Commission (EEOC) project. GIPA adds a state-court private right of action. 410 ILCS 513/40 authorizes liquidated damages of $2,500 or actual damages, whichever is greater, for a negligent violation, and $15,000 or actual damages, whichever is greater, for an intentional or reckless violation, plus attorneys’ fees and other relief.

GIPA sat quietly for years. It did not stay quiet. In Bridges v. Blackstone Group, 66 F.4th 666 (7th Cir. 2023), the Seventh Circuit treated an “aggrieved” person as able to seek redress against a party that compelled disclosure of genetic information, including from a non-party that held the data. Starting in 2023, plaintiffs filed a wave of class actions against employers whose pre-employment physicals, return-to-duty exams, or workplace wellness vendors asked about family medical history — classic genetic information — or who requested genetic testing. Those collections are generally not HIPAA PHI when the employer holds them as employer. They are GIPA problems. They can also be GINA problems, but GIPA’s statutory damages are what put the wave on the CIPP/US radar.

Scenario. A national manufacturer’s occupational-health vendor, during a post-offer physical for an Illinois plant, hands every candidate a form that asks whether any parent or sibling has had Huntington’s disease, breast cancer, or diabetes. The manufacturer never sees a sequencing report. GIPA still treats family medical history as genetic information. HIPAA does not save the manufacturer because this is an employment record, not a covered-entity treatment record. The 2023 class-action wave is built on exactly that fact pattern.

LawWho is inSignature extra dutyWho sues
MHMD (RCW 19.373)Entities that conduct business in Washington or target Washington consumers and determine the purpose of CHD processing; “persons” for sale and geofenceConsent to collect/share; signed one-year sale authorization; deletion; 2,000-foot geofence banAttorney General and private CPA action
Nevada CHD (NRS 603A.400–550)Regulated entities targeting Nevada; consumer must have requested a product or serviceParallel consent, sale authorization, deletion; 1,750-foot geofence banDeceptive-trade-practice / Attorney General; no private right
GIPA (410 ILCS 513)Employers, insurers, and others that solicit or use genetic testing or genetic information, including family historyNo employment-conditioned genetic solicitation; limits on use and disclosurePrivate right; $2,500 / $15,000 statutory damages

Exam traps

  • HIPAA does not preempt these statutes just because the data “are about health.” HIPAA’s hole is the point.
  • MHMD sale authorization is not the same document as collection consent.
  • The geofence ban cannot be consented away.
  • Nevada’s 1,750-foot figure and Washington’s 2,000-foot figure are not interchangeable, and Nevada has no private right of action.
  • GIPA’s 2023 wave is an employer / wellness / family-history story, not a hospital-PHI story.
Loading diagram...
Closing the HIPAA App-and-Advertiser Gap
Test Your Knowledge

An advertising platform draws a 1,200-foot virtual boundary around a Washington clinic that provides in-person reproductive-health services and uses device entry into that boundary to build an audience and serve clinic-related ads. The platform’s terms of use include a pre-checked box labeled “I agree to location-based advertising.” Which statement is correct under RCW 19.373?

A
B
C
D
Test Your Knowledge

Which statement correctly distinguishes Nevada’s consumer-health-data statute from Washington’s My Health My Data Act?

A
B
C
D
Test Your Knowledge

An Illinois manufacturer’s post-offer physical, administered by an occupational-health vendor, asks every candidate whether any parent or sibling has had breast cancer or Huntington’s disease. No DNA is sequenced. Which statement best describes the 2023–2024 GIPA risk?

A
B
C
D