I'm Mary Ann Kolpasek McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Attorney James Hennessy of the Law Firm, Reid Smith. We're going to be discussing Washington State's New My Health, My Data Act, or MHMD Act, which will take effect on March 31, 2024, as well as some other top health, data privacy, and security issues that organizations should be watching. So James, for starters, what stands out to you about the Washington State My Health, My Data Act, and what should entities not based in Washington State know about this law?
I think the first thing I would flag about this law is that it's new, as you noted, it goes into effect next year, it was passed earlier this year, and so we're kind of in that era right now where, you know, my job as a lawyer is to advise my clients based on, you know, risk assessments and applying facts to law. And we're in that period of time right now, which is kind of the theory part where maybe getting some guidance from the Washington Attorney General, we have some statutory language that we're working with. There's a lot more questions than answers happening right now, which is kind of a song and dance that we're accustomed to doing. So we're in that time period where I've gotten more of a law professor than a lawyer, which frankly, I don't mind doing.
But the reason I say that is we do have a lot to learn. With that said, this law, I think, is notable is because it hits this intersection that at least from Washington, Washington's view, no one had hit before. It's a consumer focus non HIPAA health care data privacy law. Washington, the state of Washington passed it.
They claim that it was, you know, the first of its kind. Whether or not that's true, maybe some people could debate, but there have been others that have come around long since that time. In any event, what I think the hallmark of this law is, is that for a lot of my clients, especially these days, who are doing maybe non-traditional health care companies or companies that provide some type of service, a life science service or something that's associated with health care, but maybe when think of them as a traditional health care entity or health care player and they operate in this new digital evolving digital health space and oftentimes structure their data collection, maintenance, sharing practices such that HIPAA doesn't apply. What this law gets at is trying to regulate that outer space where HIPAA does not apply.
So specifically, the law calls out that the data that they're looking for here is not protected health information as that term is defined under HIPAA. It's everything else. And there's a lot of companies that have been existing in this space. And I think that this law marks an important moment where states, other jurisdictions, regulatory bodies are going to start to look at this space and regulate it more closely and cause companies, especially those in that new evolving digital health space to revisit whether or not it's really a desirable outcome for them to avoid the application of HIPAA versus being regulated under laws like this.
So that's why I've kept, as somebody who works specifically in the health care industry, that's why I've been paying attention to this law. And I guess to answer your other question about companies that are outside of Washington, this is another important point here. The law essentially just requires some nexus to Washington. It's somewhat unusual when I think of a consumer focused law, especially consumer focused privacy law, you generally think of circumstances where the state is trying to protect the interests of its own residents.
The way that this law is drafted, it could apply to Washington residents, maybe non-Washington business that targets or provides services to Washington residents, but also a Washington based business that provides services to potentially non-Washington residents. So if you're touching Washington, if you have data touching Washington, if you have consumers in Washington, but maybe you otherwise are headquartered or your principal based businesses outside Washington, you need to be focused on this law. James, with that said, what should entities be doing at this point? How should they be preparing to comply?
Well, the first step I would say is determine whether it applies to you. As I mentioned, this is really going to impact those non-traditional digital health type businesses, maybe wearable device manufacturers, wellness industry, companies, mobile apps, companies that are engaged in advertising in this space and maybe haven't thought about compliance with laws like this necessarily. So that's the first step. The second step might be to determine whether or not you do anything that could be constitute consumer health data.
And there's a number of operative words there, but I would say that consumer health data is pretty broad. And in the sense that it's any personal information that is linked or reasonably linkable to a consumer and identifies a consumer's past, present, or future physical or mental health status, and then the law provides a non-exhaustive list of what that might be. But it's intensively broad. And then collected is also broad.
It doesn't mean, of course, it just means collected. It means bought, rented, received, inferred, derived. So if you're in any way dealing with this type of information and you're in any way touching Washington, you should definitely consider whether or not this applies to you. And then after that, especially before the law really kicks in in 2024, now is the time to build a compliance program.
Make sure that your policies are sufficient, updating agreements with vendors, work on your internal infrastructure to make sure that, you know, when this a lot goes into effect that you're ready. And I think here's a good point to acknowledge that there are some distinctive features of this law. I mentioned the fact that it could apply potentially to non-Washington residents. It also, I think, one other aspect worth noting is that there's really no minimum number of data subjects or revenue threshold.
You look at, like, the CCPA in California and the state where I live and practice, for example, there are thresholds regarding, you know, there's expansive consumer protection and privacy law, but there are some thresholds that limit the extent to which it applies to all business in particular, smaller ones. That doesn't exist here. Small businesses were given a break, but I don't think that they would call it that three months of additional timeline to get prepared. But it could really apply to some smaller business that are engaged in any type of this regulated activity.
In contrast to other laws, this Washington law has an opt-in consent, you know, so before you start engaging in any of the implicating data collection activities, you have to get a consumer's advanced consent to be able to do that. And then I think this is a big one. Of course, in contrast to HIPAA, these consumers have a private right of action. So a consumer identifies a breach, notes it, is harmed by it in some way.
They can bring a case, you know, the lawsuit under the Washington Consumer Protection Act leading to, you know, significant financial liability. So especially in contrast to HIPAA, which I do a lot with HIPAA, doesn't have a private right of action. This will be a lift, a notable one from a compliance development perspective and an enforcement perspective as well. This law pertains, or this law comes out of Washington State.
But as we know, the federal government in Washington, DC, the FTC in particular, has also been putting more attention lately, or maybe it's been sort of building up on health data, privacy and security issues as well, as it pertains to non HIPAA covered sorts of data. How does this Washington State law sort of jide with the attention that the FTC has also been putting on consumer health data where it might be wearables, might be websites that aren't, you know, HIPAA protected entities websites, but it might deal with health data. Where do you kind of see this Washington State law kind of jiving with what the feds are looking at doing or arguing at this point? Well, certainly an activist, right now, number of levels, antitrust certainly.
But as you noted, the recent enforcement for healthcare, private data, privacy, disclosure, authorization issues is certainly unlike what we've, I've ever seen in my career in the past. And I think they're rooted, frankly, in the same general public policy, which is to ensure that consumers, there's a huge, huge sentiment right now, at least a perceived sentiment from a regulator's perspective, and from state legislative perspective, certainly, that consumers want more control, information, anything related to the empowerment associated with their data. Washington's attorney general, for example, in recent guidance that they released on this law cited a 76% approval rating for this law. And so I think they're both targeting and acknowledging this circumstance where HIPAA, which in many ways has been successful in terms of establishing a uniform across the board, set of rules, requirements, enforcement mechanisms to protect people's healthcare data.
It's not quite cutting it right now in this new world of changing healthcare landscape. Healthcare just isn't delivered in the same way as it was even, you know, five years ago, for example, I think what I've seen, particularly in my practice working in healthcare over the past few years, just due to COVID, there's been all sorts of new developments in the industry regarding how companies look for consumers, how they serve consumers in the healthcare space, and a lot of companies are arranging it, you know, namely ones that don't take any traditional third party payers and just take self pay patients, which is happening all over the place. Those new industry stakeholders are not complying with it because they've structured themselves in a way that they don't have to. So I think it's just the volume of activity that's happening out here out in this space that is causing more focus at every level, federal government, FTC, certainly, as you noted, major enforcement actions in this year alone.
And then I guess the last thing I'll say in Washington is that my understanding is that this Washington law, at least in part, was born out of an interest in protecting the consumer privacy with respect to reproductive health, women's health, particularly with respect. You can see it in these geo-fencing restrictions, which already are in effect in this Washington law. Basically, this idea that where companies use data to create boundaries around a certain geographical area, excuse me, to learn something about somebody or to send a notification to somebody, Washington's really cracking down on that. So I highlight that just to note that there was another public policy that I think Washington was looking at maybe that is at least somewhat distinct from the FTC at the federal level.
But broadly speaking, I think it's all rooted in the same public policy. And finally, James, we were just talking about other sort of important regulatory issues that are sort of emerging. Anything else you're keeping a close eye on when it comes to health data privacy and security regulatory issues that health care related entities should be keeping a close eye on in the months and the year ahead. I think it's probably just more of these state laws.
I mean, certainly we are busy right now. I am tracking this law in Washington, certainly, which it's the area that hits on a number of focus areas of mine. But we've been in an era right now where these new state laws are popping up everywhere. I think it wouldn't be appropriate to say you should focus all your energy on this Washington law.
But from a compliance standpoint, you've got to stay nimble. And I think for this Washington one, I'm keeping my eye on it in particular and noting the potential developments in other states, because I've been in so many different conversations where clients have considered this HIPAA versus non HIPAA regulatory structure, where they're maybe not terribly keen on falling under HIPAA's regulations. But I think this is a time where we're going to see a lot of companies revisit that strategy, because certainly, as I noted, the enforcement mechanisms are different under these laws. And they might find that it might be more predictable, more streamlined to after all, which is not something we would have maybe concluded a few years ago, that they may want to consider arranging or structuring their organization to comply with HIPAA.
So that, especially from my perspective, is an area that I'm keeping my eye on. But certainly, it's the development in these laws. The enforcement, what eventually happens, because we can talk about what risk might look like, of course, might interpret certain things, or what regulations may come out later. But as the enforcement rolls in, that will be the true test.
And as I noted, that's already happening at the federal level. But I would just keep an eye on what type of enforcement has been happening, because there's no shortage of it. I mean, every single day at every level, there's been enforcement related to healthcare privacy issues, as I know, you track very closely as well, Marianne. Well, thank you very much, James.
I've been speaking to Attorney James Hennessy. I'm Marianne Kolbizak-McGee of Information Security Media Group. Thanks for joining us.