Resource
IT compliance for Washington State businesses
Most compliance guidance is written nationally and stops at the federal frameworks. Washington adds two obligations that catch businesses out, and one of them reaches well beyond the healthcare sector into companies that would never think of themselves as handling health data.
What applies, and to whom
Federal and state obligations run in parallel. A single business can carry three or four simultaneously, and the controls overlap heavily, so the work is usually less than the count suggests.
| Obligation | Who it applies to |
|---|---|
| RCW 19.255Notification to affected individuals and, above a threshold, to the Attorney General | Any business holding personal information about Washington residents |
| My Health My Data ActConsent before collection, limits on sharing, and a broad definition of health data | Businesses handling consumer health data outside HIPAA |
| HIPAAFederal. Applies alongside state law rather than instead of it | Covered entities and their business associates |
| FTC Safeguards RuleFederal. Written plan and a named accountable individual | Tax preparers, accountants, some financial firms |
| PCI DSSContractual rather than statutory, and enforced by the card brands | Anyone accepting card payments |
General information, not legal advice. Statutory requirements change and the details matter. Confirm your position with counsel.
The one that surprises people
The My Health My Data Act is unusual because its definition of consumer health data is much wider than HIPAA's, and because it applies to businesses that are not healthcare providers at all.
- A fitness or wellness business recording health related information about clients
- An employer wellness programme collecting health data from staff
- An app or web service inferring health status from user behaviour
- A retailer whose purchase data reveals a health condition
- Any business buying or receiving consumer health data from another party
If any of those resemble your business, the question is worth asking properly rather than assumed away, because the obligations attach to the data rather than to your sector.
Why detection speed is a compliance issue
Nearly every notification requirement, state and federal, starts its clock at discovery. That single design choice turns detection capability into a regulatory matter rather than purely a technical one.
A business with continuous monitoring finds an incident in hours and begins its notification process with the full statutory window available. A business without it finds out weeks later, sometimes from a customer or a bank, and starts the same process with the window already consumed and an investigation to run.
This is the practical argument for monitored detection at businesses that consider themselves too small to need it. The control is not only preventing harm, it is preserving the time you are legally allowed to take.
Common questions
Answered before you ask.
We already comply with HIPAA. Does state law add anything?
It can. HIPAA and Washington State law operate alongside each other rather than one replacing the other, and the state breach notification statute applies to personal information generally rather than to protected health information specifically. A practice can therefore have obligations under both, with different definitions and different notification requirements. The practical approach is to build the notification process once, to the stricter standard, rather than maintaining two.
Does the My Health My Data Act apply to us if we are not a healthcare business?
Possibly, and this is what makes it unusual. Its definition of consumer health data is considerably broader than HIPAA's protected health information, and it reaches businesses that would never consider themselves healthcare. Wellness programmes, fitness businesses, apps that infer health status and retailers whose purchase data reveals a condition can all fall within scope. If you hold anything that indicates a person's physical or mental health, it is worth a conversation with counsel rather than an assumption.
How quickly do we have to notify after a breach?
Washington's statute sets a defined timeframe running from discovery, with additional notification to the Attorney General once a breach affects more than a threshold number of residents. The operative detail is that the clock starts when you discover the breach, not when you finish investigating it. That makes detection speed a compliance matter rather than only a security one, because an organisation that finds an incident in a day is in a materially different position from one that finds it in a month.
What should we actually do about this?
Three things, none of them expensive. Know what personal and health related data you hold and where it lives, because you cannot assess an obligation against data you have not inventoried. Have a written incident response process naming who decides that a breach has occurred and who notifies whom. And make sure your detection is good enough that discovery happens in hours rather than weeks, since every notification clock starts there.
Related
Read next.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
HIPAA IT compliance
Risk analysis, safeguards, audit controls and business associate agreements.
Cyber insurance requirements checklist
What insurers now ask for, and why an optimistic answer is worse than a higher premium.
How to choose an IT provider
The questions to ask, the red flags, and a scoring sheet.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.