Skip to content

Evidence request lists

Washington My Health My Data Act (MHMD)

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consent

WAMHMD-2
Consent and Authorization

Per MHMD: Consent for collection of Consumer Health Data + Separate consent for sharing + valid authorization for sale.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-2
Where this commonly fails
  • geofencing + consent partial

Consent, Authorisation and Sale

MHMD-MKT.1
Marketing and advertising governance

Use of Consumer Health Data for advertising, profiling, or targeted communications requires consent, prohibits geofencing of health facilities, and requires governance over ad-tech and analytics vendors.

Artefacts an auditor will ask for
  • Ad-tech vendor inventory with data flow descriptions
  • Consent records covering advertising uses
  • Suppression list integration for consumers who have withdrawn consent
  • Documented review of pixels, SDKs, and tag managers
Where this commonly fails
  • Pixels and tags deployed without privacy review
  • Suppression list not propagated to ad-tech vendors
  • Consent flow misses advertising purposes
MHMD-SAL.1
Valid authorization to sell Consumer Health Data

Sale of Consumer Health Data is prohibited without a written, statute-compliant Valid Authorization that includes specific data, recipient, purpose, expiration not exceeding one year, and consumer right to revoke.

Artefacts an auditor will ask for
  • Valid Authorization template aligned to statutory required elements
  • Signed and dated authorizations on file
  • Revocation handling procedure
  • Recipient register of sales with corresponding authorizations
Where this commonly fails
  • Authorization missing one or more statutory elements
  • Expiration not enforced beyond one year
  • Revocation process undocumented
  • No copy of authorization provided to consumer

Consumer Rights

MHMD-NDR.1
Non-discrimination for exercising rights

Regulated entities must not discriminate against a consumer for exercising rights under the Act, including denial of goods or services, different pricing, or different quality.

Artefacts an auditor will ask for
  • Non-discrimination policy
  • Loyalty programme review demonstrating no penalty for rights exercise
  • Pricing model documentation
  • Training records covering non-discrimination
Where this commonly fails
  • Loyalty programmes implicitly condition benefits on broad data consents
  • Pricing differs for consumers who withdraw consent without statutory basis
  • Training not delivered to frontline staff
MHMD-RTS.1
Consumer right to access Consumer Health Data

Consumers must be able to request and receive, free of charge, confirmation of whether the regulated entity is collecting, sharing, or selling their Consumer Health Data, and a list of third parties and affiliates with whom data has been shared or sold.

Artefacts an auditor will ask for
  • Access request intake channel and procedure
  • Response template including third party and affiliate lists
  • Verification process for identity of requester
  • Service level metrics for fulfilment within statutory timeline
Where this commonly fails
  • Response excludes affiliates
  • Identity verification disproportionately burdensome
  • No tracking of statutory response timeline
  • Lists provided in aggregate without recipient categories
MHMD-RTS.2
Consumer right to withdraw consent and delete data

Consumers may withdraw consent and request deletion of their Consumer Health Data, with the regulated entity required to delete the data, notify downstream recipients, and confirm deletion to the consumer.

Artefacts an auditor will ask for
  • Deletion request workflow
  • Downstream recipient notification log
  • Confirmation messages to consumers
  • Exception register where data is retained under a statutory basis
Where this commonly fails
  • Deletion limited to primary systems and not backups or recipients
  • No proof of downstream notification
  • Exceptions claimed without documented legal basis

Data Minimisation and Minors

MHMD-MIN.1
Data minimisation and purpose limitation

Collection, use, and retention of Consumer Health Data must be limited to what is consented to or necessary for the requested product or service, with retention only for as long as required.

Artefacts an auditor will ask for
  • Data minimisation review for each Consumer Health Data field
  • Retention schedule specific to Consumer Health Data
  • Periodic disposal certificates
  • Purpose statement for each collection event
Where this commonly fails
  • Generic enterprise retention schedule applied without Consumer Health Data specifics
  • Retention indefinite by default
  • Purpose statements broad and not enforceable
MHMD-SMI.1
Special handling of minors

Where Consumer Health Data relates to minors, regulated entities should apply enhanced safeguards consistent with applicable state and federal law, including age-appropriate consent mechanisms.

Artefacts an auditor will ask for
  • Age gate or age estimation controls
  • Parental or guardian consent capture process for under-13 where applicable
  • Documented analysis of overlap with COPPA and other minor-protection laws
  • Training for staff on minor-data handling
Where this commonly fails
  • No age verification on services likely to attract minors
  • Parental consent process absent
  • No analysis of CCPA, COPPA, MHMD overlap for minors

Enforcement

WAMHMD-6
Enforcement (CPA + Private Right of Action)

Per MHMD: Consumer Protection Act enforcement and private right of action.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-6
Where this commonly fails
  • geofencing + consent partial

Incident Detection and Notification

MHMD-INC.1
Incident detection and notification

Regulated entities must detect and respond to security incidents affecting Consumer Health Data and provide breach notifications consistent with Washington state breach notification law and the Act's confidentiality obligations.

Artefacts an auditor will ask for
  • Incident response plan
  • Breach notification templates aligned to RCW 19.255
  • Tabletop exercise reports
  • Recent incident closure records and lessons learned
Where this commonly fails
  • Breach notification templates not updated to include Consumer Health Data category
  • No tabletop exercise in past 12 months
  • Detection focused on perimeter rather than data exfiltration

Notice and Transparency

MHMD-NOT.1
Consumer Health Data Privacy Policy

A regulated entity must maintain a distinct, prominently linked Consumer Health Data Privacy Policy on its homepage that lists categories of data collected, purposes of collection, categories of sources, categories of recipients, and the consumer rights process.

Artefacts an auditor will ask for
  • Published Consumer Health Data Privacy Policy
  • Homepage link audit demonstrating prominent placement
  • Version history of the policy
  • Internal mapping showing each disclosed category traces to processing inventory
Where this commonly fails
  • Policy buried inside general privacy policy rather than distinct
  • Categories disclosed in generic terms without mapping to processing inventory
  • No version history retained

Privacy Notice

WAMHMD-4
Privacy Notice, Geofencing Ban, Sale Restrictions

Per MHMD: privacy notice + Geofencing Ban around healthcare facilities + Sale Restrictions.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-4
Where this commonly fails
  • geofencing + consent partial

Processors and Record Keeping

MHMD-PRO.1
Processor contractual obligations

Regulated entities must enter into written contracts with processors that limit the processor to acting on documented instructions, require equivalent safeguards, prohibit secondary use, and define audit rights and subcontracting controls.

Artefacts an auditor will ask for
  • Standard processor contract clauses
  • Executed processor contracts inventory
  • Subprocessor approval register
  • Processor audit or attestation reports
Where this commonly fails
  • Reliance on general terms of service rather than processor-specific addenda
  • Subprocessors used without approval
  • No audit right exercised in past 24 months
  • Contracts silent on secondary use prohibition
MHMD-PRO.2
Processor compliance support obligations

Processors must assist regulated entities in meeting their obligations under the Act including responses to consumer rights requests, security incidents, and provision of information necessary to demonstrate compliance.

Artefacts an auditor will ask for
  • Processor cooperation clauses
  • Incident notification timelines in contracts
  • Records of processor assistance with consumer rights
  • Processor compliance reports
Where this commonly fails
  • Processor lacks operational capability to respond within required timelines
  • No defined notification window for incidents
  • Compliance reports not requested or reviewed
MHMD-REC.1
Record keeping and demonstrability

Regulated entities should maintain records sufficient to demonstrate compliance with the Act, including processing inventories, consent records, contracts, rights request logs, and policy versions.

Artefacts an auditor will ask for
  • Master compliance evidence index
  • Records retention schedule for compliance evidence
  • Periodic internal compliance assessment reports
  • Management review minutes
Where this commonly fails
  • Evidence held by individuals rather than the programme
  • No internal assessment in past 12 months
  • Records dispersed across tools without an index

Rights

WAMHMD-3
Consumer Rights

Per MHMD: consumer rights including access + deletion + withdraw consent + opt-out.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-3
Where this commonly fails
  • geofencing + consent partial

Scope

WAMHMD-1
Consumer Health Data Scope and Definition

Per Washington MHMD Act: Scope and definition of Consumer Health Data + applicability + small business carve-out.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-1
Where this commonly fails
  • geofencing + consent partial

Security

WAMHMD-5
Security, Training, Service Providers

Per MHMD: security + Training and awareness for personnel + service provider contracts.

Artefacts an auditor will ask for
  • MHMD evidence for WAMHMD-5
Where this commonly fails
  • geofencing + consent partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.