What Clinics Using Wellness Apps Must Do Under Washington’s My Health My Data Act

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What Clinics Using Wellness Apps Must Do Under Washington’s My Health My Data Act

Kevin Henry

Data Privacy

August 22, 2026

7 minutes read
Share this article
What Clinics Using Wellness Apps Must Do Under Washington’s My Health My Data Act

Clinics that deploy or integrate wellness apps handle sensitive consumer health data. Washington’s My Health My Data Act (MHMDA) sets specific duties that go beyond generic privacy practices, requiring clear notices, tight controls, and patient-centered rights. Use the sections below to operationalize compliance in your clinical and digital workflows.

Publish Consumer Health Data Privacy Policy

What your policy must clearly explain

  • What consumer health data you collect in the wellness app (for example, symptom logs, activity metrics, or appointment details) and why you collect it.
  • How you use, retain, and delete that data, including any personal health information disclosure to vendors, analytics providers, or affiliates.
  • Whether data is combined with other sources, deidentified, or aggregated, and how you prevent reidentification.
  • How consumers can exercise their rights, including access, correction, and data accuracy rights, and how you verify identities.
  • Contact methods for questions and appeals related to consumer health data privacy.

Placement and upkeep

  • Link the policy prominently in the app onboarding flow and within in-app settings; avoid burying it behind multiple taps.
  • Update the policy before any material changes to data use or sharing, and maintain an accessible archive of prior versions.
  • Ensure consistency across your website, patient portal, and wellness app so users receive a unified, accurate picture.
  • Secure affirmative consent with a clear, standalone prompt that specifies the categories of consumer health data collected and the purposes of use.
  • Avoid pre-checked boxes or bundled approvals; make consent granular (e.g., activity tracking separate from mood or reproductive health inputs).
  • Offer an easy way to withdraw consent inside the app and honor the revocation prospectively.

Operational details that matter

  • Use just-in-time notices when collection is context-specific (e.g., enabling location or sensor access).
  • Record consent metadata (time, method, version of notice) and sync it with your patient or consumer profile.
  • Design interfaces for accessibility and plain language so consent truly reflects user intent.

Secure Authorization for Health Data Sales

When “sale” is at issue

If you exchange consumer health data for monetary or other valuable consideration, you must obtain a health data sale authorization separate from general consent. Treat “sale” broadly and evaluate any arrangement where data access drives financial value (including certain partnerships or licensing).

What a valid authorization includes

  • Plain-language description of the data to be sold, the purpose of the sale, and the parties involved.
  • A clear statement that the sale will not occur without the consumer’s authorization and that authorization can be revoked.
  • Duration of the authorization and instructions for revocation that are as easy as granting it.
  • Records management: store signed or electronically captured authorizations and link them to downstream disclosures.

Practical safeguards

  • Never condition app access on agreeing to a sale that is not necessary to provide the requested service.
  • Implement data segmentation so unsold data is not inadvertently included in a transfer.

Implement Comprehensive Data Security Measures

Administrative data security

  • Assign executive ownership for consumer health data privacy and security; maintain policies for access, retention, and incident response.
  • Run periodic risk assessments covering the wellness app, APIs, and vendor integrations; track remediation to completion.
  • Deliver role-based training for staff, clinicians, and developers who touch app data or analytics.

Technical controls

  • Apply least-privilege, multi-factor authentication, and regular access reviews across app backends and admin consoles.
  • Encrypt data in transit and at rest; use strong key management and secret rotation.
  • Harden mobile SDKs, disable unnecessary device permissions, and monitor for anomalous data flows.
  • Adopt secure development practices: code review, dependency scanning, and pre-release privacy testing.

Physical and lifecycle safeguards

  • Protect servers and workstations that process wellness data; restrict removable media and enforce secure disposal.
  • Minimize collection; set retention schedules and automatically purge data that’s no longer needed.

Comply with Geofencing Restrictions

Understand the geofencing prohibition

MHMDA prohibits using a geofence around healthcare facilities to identify or track individuals, to collect or infer consumer health data, or to target messaging based on a person’s visit. For clinics using wellness apps, this means avoiding any location-based targeting that singles out people near care settings.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Practical steps

  • Disable location-triggered ads or notifications tied to visits to clinics, pharmacies, or other care sites.
  • Contractually require marketing and analytics partners to comply with the geofencing prohibition and to avoid proxy techniques that approximate it.
  • Use aggregated, non-identifying insights and coarse location where truly necessary, with strong safeguards against reidentification.

Respect Consumer Rights to Data Access and Correction

Build efficient request workflows

  • Offer in-app and web channels to submit requests, with clear instructions and identity verification that balances security with usability.
  • Provide access in a portable, readily usable format and log disclosures related to the request.
  • Enable correction of inaccuracies quickly, documenting what changed to support data accuracy rights.

Governance and recordkeeping

  • Track request timelines, outcomes, and appeals; monitor for systemic issues that create recurrent inaccuracies.
  • Ensure vendors support access and correction for data they process on your behalf.

Maintain Transparency with Third-Party Data Sharing

Vendor and partner controls

  • Map all third parties touching wellness app data and disclose the categories of recipients in your policy.
  • Use contracts that restrict personal health information disclosure to defined purposes, forbid reidentification, and require breach notice and assistance with rights requests.
  • Review data flows periodically to confirm least-necessary sharing and to retire unused integrations.

Onward sharing and monitoring

  • Prohibit onward transfers without your written approval and equivalent protections.
  • Audit logs of data exports, API calls, and bulk downloads; investigate anomalies promptly.

Conclusion

Clinics using wellness apps can meet Washington’s My Health My Data Act by pairing clear notices and affirmative consent with disciplined security, tight geofencing controls, robust rights workflows, and contract-led transparency. Treat these requirements as a continuous program—review, test, and improve as your app and partners evolve.

FAQs

You must obtain affirmative consent before collecting consumer health data—an explicit, opt-in agreement that specifies the categories collected and the purposes of use. Consent cannot be bundled with unrelated terms, must be as easy to withdraw as to give, and should be documented with time, method, and notice version.

How must clinics handle health data sales?

If a transaction qualifies as a sale, you need a separate health data sale authorization. It should identify the data being sold, the purpose, the parties involved, the duration, and a clear revocation method. Keep records of authorizations, do not proceed without them, and ensure segmentation so only authorized data is transferred.

What data security measures are mandated?

MHMDA expects reasonable safeguards across administrative data security, technical, and physical layers. That includes governance and training, access controls and MFA, encryption in transit and at rest, secure development practices, vendor oversight, monitoring and logging, risk assessments, and retention limits with timely deletion.

Are clinics allowed to use geofencing near healthcare facilities?

No. The Act imposes a geofencing prohibition that bars using geofences around healthcare facilities to identify individuals, collect or infer health data, or target messaging based on visits. Avoid location-triggered marketing or analytics that single out people near care settings, and require partners to do the same.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles