Nevada’s Consumer Health Data Privacy Law (SB 370) vs. HIPAA: Key Differences and Who Must Comply
Nevada’s Consumer Health Data Privacy Law (SB 370) vs. HIPAA centers on what data is covered, which organizations are in scope, and how consent and consumer rights work. While HIPAA focuses on Protected Health Information (PHI) handled by medical and insurance ecosystems, SB 370 reaches far beyond clinical walls to capture consumer health data created in everyday digital contexts. Understanding where these regimes overlap—and where they do not—helps you prioritize compliance and reduce risk.
Scope of Application
SB 370 applies to organizations that conduct business in Nevada or target Nevada residents and determine the purposes and means of Consumer Health Data Processing (“regulated entities”), as well as service providers that process such data on their behalf (“processors”). This scope can include telehealth platforms, wellness and fitness apps, fertility and mental health tools, retailers offering health-related products, and adtech or analytics vendors that touch health-related signals.
HIPAA, by contrast, applies to HIPAA Covered Entities—health plans, health care clearinghouses, and certain health care providers—and their business associates when they handle PHI in connection with regulated transactions. Many modern health-adjacent services fall outside HIPAA but may be squarely within SB 370 if they collect, infer, or share consumer health data tied to Nevada residents.
- SB 370 is activity-driven: if you decide how consumer health data is collected, used, or shared regarding Nevada consumers, you may be in scope.
- HIPAA is role- and transaction-driven: you must be a covered entity or business associate handling PHI for regulated purposes.
Definition of Consumer Health Data
Consumer health data under SB 370 broadly covers personal information linked or reasonably linkable to an individual that identifies their past, present, or future physical or mental health status or health-seeking behavior. It can include information you directly collect (e.g., symptom checkers, telehealth intake), data generated by devices or apps (e.g., heart rate, cycle tracking, sleep), and inferences derived from browsing, purchase history, or geolocation around health services.
Protected Health Information (PHI) under HIPAA is narrower. PHI is individually identifiable health information created or received by HIPAA Covered Entities or their business associates and tied to health care delivery, payment, or operations. The same data point can be PHI in a clinical context yet “consumer health data” when a non-HIPAA actor collects it for a wellness app or marketing campaign.
Consent Requirements
SB 370 emphasizes Affirmative Consent. Before collecting or sharing consumer health data beyond what is necessary to provide a requested service, you should present clear, specific disclosures and obtain an unambiguous, opt-in signal. Consent should be unbundled from general terms, easy to understand, and free of dark patterns. Separate, express consent is expected for sensitive uses such as sharing with third parties for unrelated purposes or monetization.
Practical steps include: mapping data categories and purposes; presenting a concise privacy notice focused on consumer health data; capturing and storing verifiable consent records; and ensuring processors follow your documented instructions. HIPAA’s consent mechanics differ and often revolve around authorizations and notices of privacy practices for PHI, which do not automatically satisfy SB 370 for non-PHI contexts.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Consumer Rights Under SB 370
SB 370 grants robust Data Subject Rights tied to consumer health data. Consumers can request to know whether you process their data, access specific data you hold, obtain a list of third-party disclosures, and request deletion of consumer health data you collected from or about them. They must also be able to withdraw previously granted consent without undue friction.
To operationalize these rights, build secure request intake channels, verify identity proportionally to risk, and communicate outcomes transparently. Ensure downstream processors can support access and deletion, and avoid retaliatory treatment when a consumer exercises their rights.
Geofencing Restrictions in Nevada Law
SB 370 imposes strict limits on Health Data Geofencing. You may not use geofences around locations providing in-person health care services to identify or track individuals, collect or infer consumer health data about them, or send targeted messages related to health conditions or services as they enter, visit, or leave those areas.
For compliance, disable geofence-triggered ads, suppression, or analytics tied to clinics, hospitals, pharmacies, or similar sites. Audit SDKs, push-notification workflows, and location partners to ensure they do not engage in prohibited geofence activity.
Exemptions and Overlaps with HIPAA
SB 370 contains Data Privacy Exemptions that reduce conflict with federal regimes. PHI handled by HIPAA Covered Entities or business associates remains governed by HIPAA, and certain de-identified or publicly available data may fall outside SB 370. However, the same organization can still be subject to SB 370 for non-PHI consumer health data—such as website analytics on appointment pages, retail wellness programs, or data from consumer apps not operated as part of HIPAA-regulated operations.
Overlap scenarios are common. A hospital’s EHR data may be PHI under HIPAA, but pixels, cookies, or SDKs tracking health-related web journeys can generate consumer health data under SB 370. Align contracts and technical controls so processors handle each dataset under the correct legal regime, and keep your notices and consent flows specific to the data’s context.
Bottom line: SB 370 vs. HIPAA is not an either–or. HIPAA protects PHI within covered ecosystems, while SB 370 closes gaps for consumer-facing health signals outside those ecosystems. Map your data, tailor consent and rights workflows, and ensure your vendors support both frameworks where they intersect.
FAQs.
What entities must comply with Nevada's SB 370?
Any organization that conducts business in Nevada or targets Nevada residents and determines how consumer health data is collected, used, or shared may be in scope, along with processors that handle such data for them. This can include digital health platforms, wellness and fitness apps, retailers with health-related offerings, and adtech or analytics vendors working with health-related signals.
How does SB 370 define consumer health data differently from HIPAA?
SB 370 defines consumer health data broadly to include information linked or reasonably linkable to a person that reveals health status or health-seeking behavior, including inferences from browsing, purchases, or location. HIPAA focuses on Protected Health Information (PHI) created or received by HIPAA Covered Entities and business associates for health care delivery, payment, or operations.
What consent is required under Nevada's health data law?
SB 370 expects Affirmative Consent before collecting or sharing consumer health data beyond what is necessary to provide a requested service. Consent must be clear, specific, and unbundled, with separate opt-ins for sensitive sharing or monetization. Record how and when consent was obtained and honor withdrawals promptly.
Can consumers withdraw consent under SB 370?
Yes. Consumers must have a simple, accessible way to withdraw consent. Once withdrawn, you should stop the relevant processing, notify processors as needed, and confirm completion without creating barriers or punitive experiences.
What geofencing restrictions does Nevada law impose?
SB 370 prohibits using geofences around places that provide in-person health care services to identify, track, collect, infer, or target individuals with health-related messages based on their presence in or near those locations. Audit advertising, analytics, and SDK configurations to ensure compliance.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.