Skip to content

Resource

IT compliance for Washington State businesses

Most compliance guidance is written nationally and stops at the federal frameworks. Washington adds two obligations that catch businesses out, and one of them reaches well beyond the healthcare sector into companies that would never think of themselves as handling health data.

What applies, and to whom

Federal and state obligations run in parallel. A single business can carry three or four simultaneously, and the controls overlap heavily, so the work is usually less than the count suggests.

Compliance obligations applying to Washington State businesses
ObligationWho it applies to
RCW 19.255Notification to affected individuals and, above a threshold, to the Attorney GeneralAny business holding personal information about Washington residents
My Health My Data ActConsent before collection, limits on sharing, and a broad definition of health dataBusinesses handling consumer health data outside HIPAA
HIPAAFederal. Applies alongside state law rather than instead of itCovered entities and their business associates
FTC Safeguards RuleFederal. Written plan and a named accountable individualTax preparers, accountants, some financial firms
PCI DSSContractual rather than statutory, and enforced by the card brandsAnyone accepting card payments

General information, not legal advice. Statutory requirements change and the details matter. Confirm your position with counsel.

The one that surprises people

The My Health My Data Act is unusual because its definition of consumer health data is much wider than HIPAA's, and because it applies to businesses that are not healthcare providers at all.

  • A fitness or wellness business recording health related information about clients
  • An employer wellness programme collecting health data from staff
  • An app or web service inferring health status from user behaviour
  • A retailer whose purchase data reveals a health condition
  • Any business buying or receiving consumer health data from another party

If any of those resemble your business, the question is worth asking properly rather than assumed away, because the obligations attach to the data rather than to your sector.

Why detection speed is a compliance issue

Nearly every notification requirement, state and federal, starts its clock at discovery. That single design choice turns detection capability into a regulatory matter rather than purely a technical one.

A business with continuous monitoring finds an incident in hours and begins its notification process with the full statutory window available. A business without it finds out weeks later, sometimes from a customer or a bank, and starts the same process with the window already consumed and an investigation to run.

This is the practical argument for monitored detection at businesses that consider themselves too small to need it. The control is not only preventing harm, it is preserving the time you are legally allowed to take.

Common questions

Answered before you ask.

We already comply with HIPAA. Does state law add anything?

It can. HIPAA and Washington State law operate alongside each other rather than one replacing the other, and the state breach notification statute applies to personal information generally rather than to protected health information specifically. A practice can therefore have obligations under both, with different definitions and different notification requirements. The practical approach is to build the notification process once, to the stricter standard, rather than maintaining two.

Does the My Health My Data Act apply to us if we are not a healthcare business?

Possibly, and this is what makes it unusual. Its definition of consumer health data is considerably broader than HIPAA's protected health information, and it reaches businesses that would never consider themselves healthcare. Wellness programmes, fitness businesses, apps that infer health status and retailers whose purchase data reveals a condition can all fall within scope. If you hold anything that indicates a person's physical or mental health, it is worth a conversation with counsel rather than an assumption.

How quickly do we have to notify after a breach?

Washington's statute sets a defined timeframe running from discovery, with additional notification to the Attorney General once a breach affects more than a threshold number of residents. The operative detail is that the clock starts when you discover the breach, not when you finish investigating it. That makes detection speed a compliance matter rather than only a security one, because an organisation that finds an incident in a day is in a materially different position from one that finds it in a month.

What should we actually do about this?

Three things, none of them expensive. Know what personal and health related data you hold and where it lives, because you cannot assess an obligation against data you have not inventoried. Have a written incident response process naming who decides that a breach has occurred and who notifies whom. And make sure your detection is good enough that discovery happens in hours rather than weeks, since every notification clock starts there.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment