Master HIPAA requirements alongside Washington's My Health My Data Act and Uniform Health Care Information Act to protect patient privacy in the Pacific Northwest.
Seattle healthcare organizations must comply with HIPAA, Washington's My Health My Data Act (effective 2024), the Uniform Health Care Information Act (UHCIA), and additional Washington privacy protections. Failure to comply risks federal penalties, state enforcement, and significant litigation exposure.
Seattle is a major healthcare hub in the Pacific Northwest with a sophisticated healthcare infrastructure and strong emphasis on digital health innovation. The metro area population exceeds 4 million, with over 120,000 healthcare professionals serving the region. Seattle's healthcare sector includes leading academic medical centers, integrated delivery networks, and innovative telehealth providers.
Effective January 1, 2024, Washington's MHMD Act is one of the nation's strongest state-level health privacy laws. It applies to vendors of personal health records and PHR related entities, creating obligations that extend beyond traditional HIPAA covered entities.
The MHMD Act applies to vendors of personal health records (apps, platforms, wearables) and PHR related entities. Traditional HIPAA covered entities (hospitals, physician practices) are exempt when operating as covered entities, but may be covered for secondary services or consumer-facing health data platforms.
Washington's UHCIA (RCW 70.02) predates HIPAA and establishes additional healthcare privacy protections. Key provisions include:
Important: UHCIA and HIPAA overlap. Compliance requires meeting the stricter standard in each area.
Washington's Attorney General has aggressively enforced healthcare privacy laws:
Evaluate whether your organization is subject to the My Health My Data Act. Many healthcare organizations that offer patient portals, health data apps, or partner with health information platforms may fall under MHMD obligations.
Under MHMD, prohibit monetization of patient health data without explicit, separate consent. Audit all data sharing agreements for secondary use language and ensure compliance with MHMD restrictions.
For any data sharing beyond treatment, payment, and healthcare operations, maintain clear evidence of patient consent that specifically describes the secondary use or third party recipient.
Ensure your privacy policies address UHCIA-specific requirements, particularly regarding psychotherapy records and substance abuse treatment information restrictions. These protections exceed HIPAA's scope.
Washington requires breach notification within 60 days of discovery. Maintain relationships with Washington-based legal counsel for breach response coordination and notification compliance.
If you operate as a traditional HIPAA covered entity (hospital, physician practice, dentist), you're exempt from MHMD when providing treatment services. However, if you offer a patient portal app, health data platform, or partner with vendors for consumer health records, you may have MHMD obligations. Conduct an assessment of all patient-facing digital health services to determine applicability.
HIPAA allows disclosure of PHI for treatment, payment, and healthcare operations without explicit consent, requiring patient authorization only for non-standard uses. MHMD requires affirmative opt-in consent for any secondary use or data monetization. MHMD consent must be separate, specific, and can be withdrawn. For MHMD-covered activities, you need both HIPAA authorization and MHMD consent.
UHCIA adds state-level privacy protections including stricter rules for psychotherapy records and substance abuse treatment information. UHCIA requires specific authorization for disclosures that might be permissible under HIPAA's broader categories. Additionally, UHCIA creates a state-level private right of action, meaning patients can sue directly for violations, unlike HIPAA which provides limited private enforcement.
Washington requires notification "without unreasonable delay" and within 60 days of discovering a breach affecting Washington residents. Notice must include: the nature of the breach, the types of data exposed, the organization's response efforts, and steps affected individuals can take. Notification to the Washington Attorney General is required if more than 500 Washington residents are affected.
Navigate HIPAA, My Health My Data Act, and UHCIA requirements with confidence. Medcurity provides specialized assessments for Seattle healthcare organizations.
Get Your Free Risk Analysis