A new category of state privacy laws targets organizations that collect biometric, genetic, location, reproductive or mental health information from consumers. Washington's My Health My Data Act, Nevada SB 370 and Connecticut SB 3 impose consent, disclosure, sale restriction and deletion requirements that go beyond HIPAA and apply to health and wellness apps, fitness platforms, genetic testing services, telehealth providers and femtech companies that previously operated in a less-defined regulatory environment.
These laws share a common structure: broad definitions of consumer health data, affirmative consent before collection, strict limits on sale or disclosure, consumer rights to access and delete, and obligations that attach regardless of whether the organization is a HIPAA-covered entity. The compliance challenge is not technical complexity but organizational: these requirements create accountability for a regulatory outcome without a clear owner, decision sequence or method of measuring progress.
Why Consumer Health Data Laws Matter Beyond HIPAA
HIPAA applies to covered entities—healthcare providers, health plans and clearinghouses—and their business associates. Most consumer-facing health apps, wearables, genetic testing services and wellness platforms fall outside this definition. A fitness tracker manufacturer, a period-tracking app or a direct-to-consumer genetic test typically has no HIPAA obligation.
State consumer health data privacy laws close this gap by regulating the data itself, not the type of organization that holds it. If an app collects information about a consumer's menstrual cycle, physical activity, genetic markers, mental health or geolocation data that could reveal visits to a healthcare facility, it is now subject to consent, transparency and deletion requirements in states where these laws apply.
The consequence is that organizations must now identify where they have regulatory exposure, determine what consent and disclosure practices are legally required, establish processes for consumer access and deletion requests, and document decisions in a way that demonstrates compliance. Without clear ownership, these obligations remain unmet or partially addressed across legal, product, engineering and compliance functions.
What Washington My Health My Data Act Requires
Washington's My Health My Data Act applies to any person or organization that conducts business in Washington or produces products or services targeted to Washington residents and that determines the purpose and means of collecting, processing, sharing or selling consumer health data. The Act became effective in March 2024.
Consumer health data is defined broadly to include data that identifies or is reasonably linkable to a consumer and relates to past, present or future physical or mental health, including biometric data, genetic data, precise location data that could reveal a visit to a healthcare facility, and data identifying gender-affirming care, reproductive healthcare or sexual orientation.
The Act requires affirmative consent before collecting or sharing consumer health data, with exceptions for limited operational purposes such as providing a product or service the consumer requested or complying with legal obligations. Organizations must honour consumer requests to confirm what data has been collected, access that data, and delete it. Sale of consumer health data without valid authorization is prohibited, and organizations may not geofence healthcare facilities to collect or infer health data.
Organizations must also implement reasonable administrative, technical and physical safeguards to protect the confidentiality, integrity and accessibility of consumer health data, and must conduct and document a consumer health data privacy impact assessment for each processing activity that presents a heightened risk of harm.
What Nevada SB 370 and Connecticut SB 3 Require
Nevada SB 370 and Connecticut SB 3 follow a similar structure. Nevada's law applies to operators who conduct business in Nevada or produce products or services targeted to Nevada residents and who collect, process or transfer consumer health data. Connecticut SB 3 applies to persons that conduct business in Connecticut or produce products or services targeted to Connecticut residents and that determine the purposes and means of processing consumer health data.
Both laws define consumer health data to include information that identifies or is reasonably linkable to a consumer and relates to the past, present or future physical or mental health of the consumer, including biometric and genetic data, precise location data that could be used to determine a consumer's attempt to acquire or receive health services or supplies, and data that identifies a consumer seeking healthcare.
Consent is required before collecting or sharing consumer health data, with narrow exceptions for specific operational purposes. Consumers have the right to confirm whether their health data is being collected, to access that data and to request deletion. Sale of consumer health data is prohibited unless the consumer has provided authorization, and geofencing of healthcare facilities is restricted. Organizations must maintain reasonable safeguards and conduct privacy assessments for activities that present heightened privacy risks.
Effective dates vary. Nevada SB 370 took effect in March 2024. Connecticut SB 3 became effective July 2023.
Who These Laws Apply To
These laws apply to any organization that conducts business in, or targets products or services to residents of, the applicable state and that determines the purpose and means of collecting, processing or sharing consumer health data. Covered entities and business associates under HIPAA are generally exempt to the extent they are already regulated under HIPAA, but only for data covered by HIPAA. A telehealth platform that is a HIPAA business associate for certain activities but also collects fitness data outside the scope of HIPAA would be subject to state consumer health data laws for that separate data collection.
Organizations likely to be covered include:
- Health and wellness apps that track physical activity, sleep, nutrition or menstrual cycles
- Genetic testing services that provide ancestry, health risk or trait reports directly to consumers
- Wearable device manufacturers that collect biometric or location data
- Telehealth platforms that operate outside HIPAA or collect data beyond what HIPAA regulates
- Femtech platforms offering reproductive health tracking, fertility monitoring or pregnancy support
- Mental health apps or digital therapy platforms not acting as HIPAA-covered entities or business associates
If an organization collects data that fits the definition of consumer health data and does business in or targets one of these states, it is presumptively subject to the law unless a specific exemption applies.
The Gap Between Legal Obligation and Organizational Readiness
Most organizations subject to these laws have no single executive accountable for the full scope of compliance. Product teams decide what data to collect. Engineering builds systems to store and process it. Legal reviews terms of service and privacy policies. Marketing determines what disclosures are made to consumers. Compliance monitors regulatory change. No one owns the complete chain of decisions that determines whether the organization meets its obligations.
The result is partial compliance: consent mechanisms that do not cover all regulated data types, privacy policies that describe practices inaccurately, consumer request processes that exist but are untested, and security controls that may be reasonable for some purposes but have never been evaluated specifically against the standard these laws impose. Leadership is accountable for an outcome it cannot measure or verify.
This is not a technology problem. It is a governance problem. The organization needs someone with the authority to identify where consumer health data is collected, determine what legal requirements apply, establish a decision framework for consent and disclosure, ensure consumer rights can be honoured, and report to leadership on the state of compliance in terms that support board and executive oversight.
What Adequate Ownership Looks Like
Adequate ownership means a senior leader, typically the General Counsel or a Chief Privacy Officer where one exists, is explicitly accountable for ensuring the organization meets its obligations under applicable state consumer health data privacy laws. That accountability must be supported by a clear decision framework and reporting structure.
Specifically, someone must be able to answer these questions and demonstrate to the board or executive leadership that the answers are current and accurate:
- What consumer health data does the organization collect, and from whom?
- Which state laws apply to that collection based on where the organization does business and where consumers are located?
- What consent is required before collection, and is that consent being obtained in a legally sufficient manner?
- What disclosures are required, and do current privacy policies and terms of service satisfy those requirements?
- Can the organization honour consumer requests to confirm, access and delete data within the timeframes the law specifies?
- Is the organization selling or sharing consumer health data in a way that requires authorization, and if so, is valid authorization in place?
- Are required privacy impact assessments being conducted and documented?
- Are security controls in place that would be considered reasonable given the sensitivity of the data and the processing activities?
These questions cannot be answered once. They must be embedded in product development, vendor management, marketing practices and operational procedures. The person accountable must have the authority to require cross-functional cooperation, the expertise to interpret legal requirements in context, and the visibility to know when practices have changed in ways that create new exposure.
For many organizations, this level of sustained oversight exceeds the capacity of existing roles. General Counsel focuses on contracts, corporate governance and litigation risk. Privacy Officers, where they exist, may lack the authority or resources to drive operational change across engineering and product teams. Information Security leaders are accountable for confidentiality, integrity and availability, but not typically for consent, transparency or consumer rights.
This is the problem [virtual CISO (vCISO) leadership](/vciso/) is designed to solve: strategic ownership of the decisions that determine regulatory posture, supported by governance structures that make compliance measurable and reportable to the board.
Relationship to the NIST Privacy Framework
The NIST Privacy Framework is a voluntary tool intended to help organizations identify and manage privacy risk through enterprise risk management. It provides a common language for discussing privacy objectives and outcomes, organized into five functions: Identify, Govern, Control, Communicate and Protect.
While the Privacy Framework does not create legal obligations, it offers a structured approach to the governance gap these state laws expose. Organizations that adopt the framework establish processes to inventory data processing activities, assess privacy risks, implement controls, communicate transparently with individuals, and protect data appropriately. These are the same capabilities required to demonstrate compliance with state consumer health data privacy laws.
The framework is most useful when an organization has already assigned clear accountability for privacy governance. Without that ownership, the framework becomes a document rather than a decision tool. With it, the framework provides a method for translating legal requirements into operational controls and for reporting progress to executive leadership in a consistent format.
Practical Next Steps for Leadership
Leadership should begin by determining whether the organization is subject to Washington My Health My Data Act, Nevada SB 370, Connecticut SB 3 or similar laws in other states. This requires identifying what data the organization collects, whether that data fits the definition of consumer health data, and whether the organization conducts business in or targets residents of states with these laws in effect.
If the organization is subject to one or more of these laws, the next step is to assign explicit accountability. General Counsel, the Chief Privacy Officer or another senior leader must be made accountable for ensuring compliance and must be given the authority and resources to establish the necessary governance structures. This assignment should be documented and communicated to the board.
The accountable executive should then conduct a gap assessment to determine what policies, processes and controls are required and what currently exists. This assessment should cover:
- Data inventory: what consumer health data is collected, where it is stored, who has access and what it is used for
- Consent mechanisms: whether affirmative consent is obtained before collection and sharing, and whether existing consent flows meet legal requirements
- Privacy policies and disclosures: whether current policies accurately describe data practices and satisfy statutory disclosure requirements
- Consumer rights processes: whether the organization can confirm, access and delete consumer health data in response to requests, and within required timeframes
- Sale and sharing restrictions: whether consumer health data is sold or shared in ways that require authorization, and whether authorization is valid
- Privacy impact assessments: whether assessments are being conducted for processing activities that present heightened risk, and whether they are documented
- Security controls: whether safeguards are in place that would be considered reasonable given the nature of the data
Findings from this assessment should be presented to executive leadership and the board with specific recommendations and a timeline for remediation. Compliance is not a one-time project; it requires ongoing governance, monitoring and reporting. The organization must establish a process for reviewing data practices as products and services change, for monitoring regulatory developments in states where the organization operates, and for reporting the state of compliance to leadership in terms that support oversight.
Where internal resources or expertise are insufficient to establish this governance structure, organizations should consider whether strategic leadership from a [virtual CISO (vCISO)](/vciso/) would provide the executive accountability, regulatory interpretation and governance framework required. A vCISO brings the authority to coordinate cross-functional teams, the expertise to translate legal requirements into operational controls, and the reporting discipline to give leadership confidence that obligations are being met.
The decision point is whether the organization has someone today who can provide a complete, accurate and current answer to the board about the state of compliance with consumer health data privacy laws, and who can sustain that level of visibility as the organization and the regulatory environment continue to change. If the answer is uncertain, that uncertainty is the risk leadership must address.
Heights Consulting Group offers confidential consultations to general counsel, privacy officers and compliance leadership who are evaluating how to establish this level of governance. If you would benefit from a conversation about your organization's specific circumstances and what adequate ownership would look like in your context, reach out directly.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.