HIPAA applies to covered entities, meaning providers, health plans, and clearinghouses, along with the business associates handling data on their behalf. Health information collected by a fitness app, a period tracker, a telehealth company operating outside insurance billing, or an advertising platform inferring a condition from browsing history generally falls outside it. Washington, Nevada, and Connecticut have each passed laws covering that data since 2023, and Washington's allows individuals to sue directly.

 

Why these laws appeared when they did

Washington passed its My Health My Data Act in April 2023, less than a year after the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization. Location records, app logs, and search histories revealing reproductive health decisions could now carry legal consequences in states restricting abortion, and none of that data sat inside HIPAA's protection.

Goodwin's analysis of the Act describes a statute built around "consumer health data," defined far more broadly than protected health information and applying to organizations in health and non-health industries alike.

 

Washington’s private right of action

Most provisions of the Washington law took effect on March 31, 2024. A violation counts automatically as a violation of Washington's Consumer Protection Act, which lets individuals file a suit directly rather than waiting for the attorney general to act, and that enforcement structure separates it from nearly every other state privacy statute.

Orrick set out the remedies available under that structure, covering actual damages, treble damages up to $25,000, attorney's fees and litigation costs, injunctive relief, and civil penalties of up to $7,500 that the attorney general can pursue separately. The firm anticipated plaintiffs focusing on tracking technologies that collect consumer health data for marketing.

The Electronic Privacy Information Center, which supported the legislation, described it as the first modern privacy law to have a strong private right of action covering the unlawful processing of data rather than only breaches.

 

The first lawsuit

On February 10, 2025, a putative class action was filed against Amazon and Amazon Advertising, the first under the Washington law. The plaintiff alleged that Amazon's advertising software development kits, embedded by numerous mobile app developers, harvested her consumer health data, including location and biometric information, without her consent.

The defendant was an advertising platform rather than a provider or insurer, and the alleged conduct was data collection through code embedded in third-party apps rather than a breach. That combination places the case entirely in territory HIPAA does not reach.

 

Nevada and Connecticut

Nevada's consumer health data law took effect the same day as Washington's and largely mirrors it, with two differences. Enforcement rests with the attorney general, who can seek civil penalties of up to $10,000 per violation, because the law includes no private right of action. It also has no volume threshold, so it applies to any business collecting or processing any amount of consumer health data in the state.

Connecticut amended its existing Consumer Data Privacy Act rather than passing a standalone statute, with the changes taking effect on July 1, 2023. The amendments added consumer health data to the categories treated as sensitive and prohibited geofencing within 1,750 feet of any mental health, reproductive, or sexual health facility, blocking advertisers from targeting people based on their presence near a clinic.

New York's proposed Health Information Privacy Act, Senate Bill 929, would extend similar protections. Delaware's recent expansion of its privacy statute, which Paubox covered here, added new requirements on the vendors organizations share data with.

 

What this means for a HIPAA-covered organization

Several of these statutes carve out HIPAA-covered data rather than exempting covered entities as organizations. Information a healthcare organization collects outside the treatment relationship, through marketing programs, patient engagement campaigns, and website tracking, can therefore fall within their scope.

Campaigns segmented by condition, service line, or appointment history process health-related data, and the tracking embedded in those messages, from open pixels to click tracking, generates records of who engaged with which health topic. Consent under the Washington and Nevada laws is opt-in, which differs from the default posture of most US marketing programs.

 

Where email marketing needs to change

Personalized healthcare email carrying PHI has to be encrypted to satisfy HIPAA, and email carrying consumer health data outside HIPAA increasingly has to rely on documented consent to satisfy state law. A campaign can meet the first obligation while failing the second.

Paubox Marketing delivers encrypted campaigns that open directly in the recipient's inbox, letting healthcare organizations segment by health condition without routing patients through a portal. Robin McKinney, Digital Marketing Strategist at North Mississippi Health Services, ruled out mainstream platforms early, knowing "a Constant Contact or MailChimp was not going to be the solution" for that kind of segmentation.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

In the news

WilmerHale's analysis of the Amazon filing placed it alongside federal enforcement actions against X-Mode Social, InMarket Media, and Avast, each involving inadequate disclosure of location tracking and missing consent for data collected through software development kits.

Location records showing a phone at an oncology center, a fertility clinic, or an addiction treatment facility reveal medical information without any medical record being involved. Regulators and plaintiffs across those cases have treated that inference as health data in its own right, which shifts the compliance question from what an organization stores to what its data allows someone to conclude.

 

FAQs

Does HIPAA cover health data collected by apps and wearables?

Usually not. HIPAA applies to covered entities and their business associates, so a consumer fitness app or period tracker operating independently of a provider or health plan generally falls outside it.

 

Can individuals sue under these state laws?

Only in Washington, where violations are actionable under the state Consumer Protection Act with actual damages and treble damages up to $25,000. Nevada and Connecticut rely on attorney general enforcement.

 

Do these laws apply to HIPAA-covered organizations?

They can. Several carve out HIPAA-covered data rather than exempting covered entities outright, so information collected outside the treatment relationship, including through marketing and website tracking, may fall within scope.

 

What counts as consumer health data?

Definitions vary by state and generally cover information identifying a person's past, present, or future physical or mental health status. Location data revealing visits to health facilities and inferences drawn from browsing or purchasing behavior can qualify.

 

What should a healthcare marketing team check first?

Whether consent for health-related segmentation is documented and opt-in, and whether tracking in emails and web pages collects data allowing health inferences. Encryption covers HIPAA obligations for PHI, and consent covers state requirements for consumer health data.