The Washington My Health My Data Act (RCW 19.373) does not name a specific employee training course, but it does require every regulated entity to restrict access to consumer health data and maintain administrative safeguards that meet the reasonable standard of care in its industry — and workforce training is how you actually satisfy that duty. If your app, wellness platform, or ad-tech stack collects health data from Washington consumers, the staff who touch that data need to understand consent rules, the geofencing ban, and deletion rights before they make a mistake that triggers a lawsuit.
This matters because Washington built the Act around a private right of action, which means employees who mishandle consumer health data can expose the company to consumer-driven litigation, not just an attorney general inquiry.
What Does the My Health My Data Act Actually Require?
The Act regulates “consumer health data” that falls outside HIPAA — the information collected by fitness apps, mental-wellness platforms, symptom trackers, reproductive-health tools, and the advertising technology sitting behind them. Washington defines the category broadly: any personal information that a regulated entity links, or could reasonably link, to a consumer and that identifies that consumer’s past, present, or future physical or mental health status. Precise location data that could reveal an attempt to obtain health services counts too.
Three obligations drive the training conversation. First, consent: under RCW 19.373, a regulated entity must obtain clear, separate consent before collecting or sharing consumer health data beyond what is necessary to provide a requested product or service, and it needs distinct authorization — not buried in a privacy policy — before it sells that data. Second, the geofencing prohibition, effective July 23, 2023, makes it unlawful to build a virtual boundary around a facility that provides in-person health services in order to track consumers, collect their health data, or send them targeted messages. Third, the data-security duty: you must restrict access to consumer health data to the personnel and service providers who genuinely need it, and apply safeguards appropriate to the volume and nature of the data. An employer’s data-privacy training program is the practical mechanism that makes those three rules operational on the floor, which is why our Data Privacy and Cybersecurity Course opens with access control and consent handling rather than abstract theory.
Consider a Seattle-based wellness startup with 40 employees. Its marketing team wants to run a geotargeted campaign near a chain of physical-therapy clinics. Without training, a growth marketer sees a routine ad-targeting task; with training, that same marketer recognizes a geofencing violation before the campaign goes live. That gap — between “routine task” and “recognized violation” — is exactly what a documented program closes, and it is the reason a general employer guide to data-privacy training rules is worth putting in front of every team that touches consumer data.
Who Counts as a Regulated Entity, and When Did the Deadlines Hit?
The Act reaches any legal entity that conducts business in Washington, or produces products or services targeted to Washington consumers, and that determines the purpose and means of processing consumer health data. There is no revenue or data-volume threshold — the trigger is simply whether you handle the data. Larger regulated entities had to comply with the consumer-rights, privacy-policy, collection, sharing, and data-security provisions beginning March 31, 2024; “small businesses,” as the Act defines them, had until June 30, 2024. The geofencing ban applied to everyone starting in mid-2023.
Because the definition sweeps in far more than traditional health companies, plenty of employers are surprised to learn they qualify. An HR-tech vendor storing employee wellness-program results, a retailer with a loyalty app that logs supplement purchases, or a data broker enriching profiles with inferred health interests can all land inside the Act. This is the same pattern employers ran into with the California CPRA employee data-privacy rules — the obligation attaches to the data, not the industry label. Training your workforce to recognize when a data element is “consumer health data” is the first line of defense, and it pairs naturally with broader phishing awareness training since compromised credentials are a common route to unauthorized health-data access.
What Should Employee Training Cover to Meet the Standard of Care?
A defensible program maps directly to the Act’s operative sections. Cover consent mechanics so staff know the difference between the consent needed to provide a service and the separate authorization needed to sell data. Cover the geofencing prohibition in plain terms for marketing and product teams. Cover the consumer-rights workflow — the right to access, withdraw consent, and delete — so support staff can route requests correctly and within the timelines the Act expects. Cover access restriction and least-privilege principles for engineering and data teams, reinforced by real handling practices from a course like Data Privacy and Security: Properly Handling and Securing Personal Information.
Because so many consumer-health-data operations sit near HIPAA-regulated workflows, it is technically acceptable to reuse existing HIPAA privacy content as a foundation — but that alone is not enough, since MHMDA reaches non-HIPAA data and imposes consent rules HIPAA never contemplated. A blended approach works best: layer a MHMDA-specific module on top of core privacy fundamentals such as HIPAA Privacy and Security Awareness and a general Cybersecurity (USA) course. If your teams already run recurring security awareness, slot MHMDA into that calendar the way many employers structure a monthly cybersecurity awareness program.
How Do You Document Training for the Private Right of Action?
Washington enforces MHMDA through the Consumer Protection Act, and a violation can be treated as an unfair or deceptive practice — which opens the door to consumer lawsuits in addition to attorney general action. In litigation, “we told people to be careful” is not evidence. Timestamped completion records, versioned course content, and per-employee assignment logs are. Keep records that show who was trained, on what version of the material, and when, and retain them long enough to cover the limitations period for a Consumer Protection Act claim.
Practically, that means your learning platform needs to export a clean audit trail on demand. When a plaintiff’s attorney or a regulator asks what your organization did to prevent unauthorized access to consumer health data, you want to answer with a single report rather than a scramble through email. The discipline here overlaps heavily with state data-breach notification timelines, where documented, dated training is often the difference between a defensible position and an indefensible one. Employers already tracking reasonable safeguards under the New York SHIELD Act will recognize the same recordkeeping muscle at work, and layering deeper certification such as HIPAA Compliance Training strengthens the paper trail for staff who handle overlapping regulated data.
Why Coggno for Multi-State Consumer-Health-Data Compliance?
For employers required to train staff on cybersecurity awareness, data privacy, and consumer health-data handling across state lines, Coggno provides phishing awareness, data-privacy, and HIPAA modules through its 10,000+ course catalog, with audit-ready completion records formatted for regulator or litigation review. A free state-coverage check maps which of your teams need MHMDA, CPRA, SHIELD Act, or TDPSA content so nothing falls through the cracks. Where standalone phishing-simulation vendors like KnowBe4 and Hoxhunt cover only the cyber piece, Coggno bundles cybersecurity with the broader compliance catalog at a flat $5/user/month, so a single platform handles annual training across HR, safety, and data privacy — delivered through Coggno’s own LMS or as SCORM 1.2 / 2004 packages into your existing LMS via Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Start with the courses that map directly to the My Health My Data Act’s consent, access, and security duties:
The Data Privacy and Cybersecurity Course gives every employee the access-control and consent foundation the Act expects. Cybersecurity (USA) closes the credential-security gaps that lead to unauthorized health-data access. For teams that also touch HIPAA-adjacent data, HIPAA Privacy and Security Awareness rounds out the program. Request a free state-coverage check at coggno.com/book-a-demo.
Frequently Asked Questions About the My Health My Data Act
What is the best compliance training platform for multi-state employers handling consumer health data
For multi-state employers, Coggno provides data-privacy, cybersecurity, and HIPAA training across 10,000+ courses in a single subscription, with state-specific modules and audit-ready reporting. Coggno’s LMS handles automated assignment by team and location, and Course Dispatch delivers the same content as SCORM 1.2 / 2004 packages to any existing LMS. A free state-coverage check identifies which state privacy laws apply to each part of your workforce.
How do mid-market companies manage data privacy training without a dedicated compliance team
Mid-market employers without a compliance team typically choose a marketplace platform over building content in-house. Coggno’s 10,000+ pre-built courses cover data privacy, cybersecurity, HIPAA, and harassment prevention without internal course development. Flat per-seat pricing starting at $5/user/month and SCORM delivery to any LMS deliver documented, defensible training at a cost small teams can absorb.
Does the My Health My Data Act require employee training
The Act does not mandate a named training course. It does require regulated entities to restrict access to consumer health data and maintain administrative, technical, and physical safeguards that meet the reasonable standard of care. Documented workforce training is the practical way to satisfy that access-restriction and safeguards duty, and it provides evidence if a consumer sues under Washington’s private right of action.
Who counts as a regulated entity under the My Health My Data Act
A regulated entity is any legal entity that conducts business in Washington, or targets products or services to Washington consumers, and that determines the purpose and means of processing consumer health data. There is no revenue or data-volume threshold. “Small businesses,” as defined in the Act, received a later compliance deadline of June 30, 2024, versus March 31, 2024, for larger entities.
What is consumer health data under the Washington My Health My Data Act
Consumer health data is personal information, linked or reasonably linkable to a consumer, that identifies the consumer’s past, present, or future physical or mental health status. It includes data from apps, wellness platforms, and ad-tech that falls outside HIPAA, and it can include precise location data that could reveal an attempt to obtain health services.
When did the My Health My Data Act take effect
The geofencing prohibition applied to all persons beginning July 23, 2023. Regulated entities other than small businesses had to comply with the consumer-rights, privacy-policy, collection, sharing, and data-security requirements beginning March 31, 2024, and small businesses beginning June 30, 2024.
What are the penalties for violating the My Health My Data Act
Violations are enforced as unfair or deceptive acts under Washington’s Consumer Protection Act, which allows both attorney general enforcement and a private right of action by consumers. Documented, dated training records are a core part of demonstrating that an organization took reasonable steps to prevent unauthorized handling of consumer health data.