Washington My Health My Data Act (MHMD)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consent
Per MHMD: Consent for collection of Consumer Health Data + Separate consent for sharing + valid authorization for sale.
- MHMD evidence for WAMHMD-2
- geofencing + consent partial
Consent, Authorisation and Sale
Use of Consumer Health Data for advertising, profiling, or targeted communications requires consent, prohibits geofencing of health facilities, and requires governance over ad-tech and analytics vendors.
- Ad-tech vendor inventory with data flow descriptions
- Consent records covering advertising uses
- Suppression list integration for consumers who have withdrawn consent
- Documented review of pixels, SDKs, and tag managers
- Pixels and tags deployed without privacy review
- Suppression list not propagated to ad-tech vendors
- Consent flow misses advertising purposes
Sale of Consumer Health Data is prohibited without a written, statute-compliant Valid Authorization that includes specific data, recipient, purpose, expiration not exceeding one year, and consumer right to revoke.
- Valid Authorization template aligned to statutory required elements
- Signed and dated authorizations on file
- Revocation handling procedure
- Recipient register of sales with corresponding authorizations
- Authorization missing one or more statutory elements
- Expiration not enforced beyond one year
- Revocation process undocumented
- No copy of authorization provided to consumer
Consumer Rights
Regulated entities must not discriminate against a consumer for exercising rights under the Act, including denial of goods or services, different pricing, or different quality.
- Non-discrimination policy
- Loyalty programme review demonstrating no penalty for rights exercise
- Pricing model documentation
- Training records covering non-discrimination
- Loyalty programmes implicitly condition benefits on broad data consents
- Pricing differs for consumers who withdraw consent without statutory basis
- Training not delivered to frontline staff
Consumers must be able to request and receive, free of charge, confirmation of whether the regulated entity is collecting, sharing, or selling their Consumer Health Data, and a list of third parties and affiliates with whom data has been shared or sold.
- Access request intake channel and procedure
- Response template including third party and affiliate lists
- Verification process for identity of requester
- Service level metrics for fulfilment within statutory timeline
- Response excludes affiliates
- Identity verification disproportionately burdensome
- No tracking of statutory response timeline
- Lists provided in aggregate without recipient categories
Consumers may withdraw consent and request deletion of their Consumer Health Data, with the regulated entity required to delete the data, notify downstream recipients, and confirm deletion to the consumer.
- Deletion request workflow
- Downstream recipient notification log
- Confirmation messages to consumers
- Exception register where data is retained under a statutory basis
- Deletion limited to primary systems and not backups or recipients
- No proof of downstream notification
- Exceptions claimed without documented legal basis
Data Minimisation and Minors
Collection, use, and retention of Consumer Health Data must be limited to what is consented to or necessary for the requested product or service, with retention only for as long as required.
- Data minimisation review for each Consumer Health Data field
- Retention schedule specific to Consumer Health Data
- Periodic disposal certificates
- Purpose statement for each collection event
- Generic enterprise retention schedule applied without Consumer Health Data specifics
- Retention indefinite by default
- Purpose statements broad and not enforceable
Where Consumer Health Data relates to minors, regulated entities should apply enhanced safeguards consistent with applicable state and federal law, including age-appropriate consent mechanisms.
- Age gate or age estimation controls
- Parental or guardian consent capture process for under-13 where applicable
- Documented analysis of overlap with COPPA and other minor-protection laws
- Training for staff on minor-data handling
- No age verification on services likely to attract minors
- Parental consent process absent
- No analysis of CCPA, COPPA, MHMD overlap for minors
Enforcement
Per MHMD: Consumer Protection Act enforcement and private right of action.
- MHMD evidence for WAMHMD-6
- geofencing + consent partial
Incident Detection and Notification
Regulated entities must detect and respond to security incidents affecting Consumer Health Data and provide breach notifications consistent with Washington state breach notification law and the Act's confidentiality obligations.
- Incident response plan
- Breach notification templates aligned to RCW 19.255
- Tabletop exercise reports
- Recent incident closure records and lessons learned
- Breach notification templates not updated to include Consumer Health Data category
- No tabletop exercise in past 12 months
- Detection focused on perimeter rather than data exfiltration
Notice and Transparency
A regulated entity must maintain a distinct, prominently linked Consumer Health Data Privacy Policy on its homepage that lists categories of data collected, purposes of collection, categories of sources, categories of recipients, and the consumer rights process.
- Published Consumer Health Data Privacy Policy
- Homepage link audit demonstrating prominent placement
- Version history of the policy
- Internal mapping showing each disclosed category traces to processing inventory
- Policy buried inside general privacy policy rather than distinct
- Categories disclosed in generic terms without mapping to processing inventory
- No version history retained
Privacy Notice
Per MHMD: privacy notice + Geofencing Ban around healthcare facilities + Sale Restrictions.
- MHMD evidence for WAMHMD-4
- geofencing + consent partial
Processors and Record Keeping
Regulated entities must enter into written contracts with processors that limit the processor to acting on documented instructions, require equivalent safeguards, prohibit secondary use, and define audit rights and subcontracting controls.
- Standard processor contract clauses
- Executed processor contracts inventory
- Subprocessor approval register
- Processor audit or attestation reports
- Reliance on general terms of service rather than processor-specific addenda
- Subprocessors used without approval
- No audit right exercised in past 24 months
- Contracts silent on secondary use prohibition
Processors must assist regulated entities in meeting their obligations under the Act including responses to consumer rights requests, security incidents, and provision of information necessary to demonstrate compliance.
- Processor cooperation clauses
- Incident notification timelines in contracts
- Records of processor assistance with consumer rights
- Processor compliance reports
- Processor lacks operational capability to respond within required timelines
- No defined notification window for incidents
- Compliance reports not requested or reviewed
Regulated entities should maintain records sufficient to demonstrate compliance with the Act, including processing inventories, consent records, contracts, rights request logs, and policy versions.
- Master compliance evidence index
- Records retention schedule for compliance evidence
- Periodic internal compliance assessment reports
- Management review minutes
- Evidence held by individuals rather than the programme
- No internal assessment in past 12 months
- Records dispersed across tools without an index
Rights
Per MHMD: consumer rights including access + deletion + withdraw consent + opt-out.
- MHMD evidence for WAMHMD-3
- geofencing + consent partial
Scope
Per Washington MHMD Act: Scope and definition of Consumer Health Data + applicability + small business carve-out.
- MHMD evidence for WAMHMD-1
- geofencing + consent partial
Security
Per MHMD: security + Training and awareness for personnel + service provider contracts.
- MHMD evidence for WAMHMD-5
- geofencing + consent partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.