For years, the privacy question for a practice website was HIPAA. HIPAA covers protected health information held by covered entities and their business associates, and a lot of marketing data doesn't fit that definition: the page someone read about ADHD evaluations, the ad they clicked, the fact that they started a booking and stopped. A group of state laws now covers that data directly.
This guide explains Washington's My Health My Data Act, the model for most of them, then the other states with health-data or geofencing rules, and ends with what a practice website should do everywhere. It is a plain-English summary as of 30 September 2026, not legal advice; your counsel decides what applies to your practice.
What the My Health My Data Act covers
Washington's My Health My Data Act (chapter 19.373 RCW) was signed in 2023 and has applied to most businesses since 31 March 2024, and to small businesses since 30 June 2024. Its ban on geofencing health care facilities has applied since 23 July 2023.
It covers consumer health data: information linked or reasonably linkable to a person that identifies their past, present or future physical or mental health status. That reaches further than HIPAA. Data showing that someone looked for or booked care can count, and so can inferences drawn from other data. Protected health information that HIPAA already governs is exempt, but data from website visitors who aren't yet patients may not be, and that is where most marketing data sits.
The main rules:
- Consent to collect. Consumer health data can only be collected with the person's consent for a specified purpose, or where it is necessary to provide a product or service they asked for.
- A separate consent to share. Sharing it needs a second, distinct consent, with the same necessary-service exception.
- A signed authorization to sell. Selling consumer health data needs a valid authorization signed by the person.
- A consumer health data privacy policy, linked on its own from the homepage, saying what is collected, why, and who it is shared with.
- No geofencing within 2,000 feet of a place that provides in-person health care, to identify or track people seeking care, collect their health data, or send them notifications or ads.
Enforcement is what sets it apart. A violation is a violation of Washington's Consumer Protection Act, which the Attorney General enforces and which also lets individuals sue.
The other states with health-data rules
- Nevada (SB 370, NRS 603A.400 to 603A.550), in effect since 31 March 2024: consent to collect and share consumer health data, authorization to sell it, and no geofencing within 1,750 feet of in-person health care providers. Unlike Washington's, it has no private right of action; the state enforces it.
- Connecticut added consumer health data rules to its privacy act in 2023: no selling consumer health data without consent, and no geofencing within 1,750 feet of mental health, reproductive or sexual health facilities to track people or send them ads. The same act treats health data as sensitive data that needs opt-in consent.
- Maryland's Online Data Privacy Act, in effect since 1 October 2025, bans selling sensitive data, health data included, and bans geofencing within 1,750 feet of mental health, reproductive or sexual health facilities.
- New York has banned geofencing health care facilities since July 2023 (General Business Law 394-g): nobody but the facility may draw a geofence of up to 1,850 feet around it to serve digital ads, build profiles or infer health status. A broader New York Health Information Privacy Act had not become law when we checked.
- California's AB 45, in effect since 1 January 2026, bans geofencing in-person health care facilities within 1,850 feet to track people, collect their data or send them ads, and bars collecting personal information from people at or near family planning centers.
- Virginia amended its Consumer Protection Act in 2025 to require consent before anyone obtains, discloses or sells a person's reproductive or sexual health information.
- Vermont enacted a privacy law in 2026 with consumer health data rules and a geofencing ban around health care facilities. It takes effect on 1 January 2028.
Beyond these, 20 states have comprehensive privacy laws that treat health information as sensitive data needing opt-in consent: California, Colorado, Connecticut, Delaware, Florida (only for very large companies), Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. Most small practices fall below their size thresholds, but the ad platforms and data companies that receive website data usually don't. Oklahoma's and Louisiana's laws take effect in January 2027 and Alabama's in May 2027. Each state's details are on its page under healthcare marketing by state.
What a practice website should do, in every state
The laws differ, but one setup satisfies the spirit of all of them and keeps a practice out of the gray areas:
- Keep health questions off web forms. A booking or contact form needs a name, contact details and a time. Symptoms and history belong in intake, inside your practice-management system.
- Keep health details out of ad platforms. Tell Google and Meta that a booking happened, not what it was for. "Booked a consultation" is a conversion; "booked an ADHD evaluation" is health data.
- Load tracking only after consent where the law asks for it, and make sure the consent banner actually blocks the tags until someone agrees.
- Never geofence clinics, yours or anyone else's. Six states already restrict it around health facilities, and it is hard to defend anywhere else.
- Publish a privacy notice that matches what the site does. In Washington, that includes a separate consumer health data privacy policy linked from the homepage.
- Sign a business associate agreement with any vendor that will handle protected health information, before it does.
That is how we run every account, whatever the state. Our compliance page sets out the details.
Sources
- Washington State Legislature, chapter 19.373 RCW (My Health My Data Act) and Washington Attorney General, protecting Washingtonians' personal health data, checked 30 September 2026
- Nevada Legislature, NRS chapter 603A, checked 30 September 2026
- Connecticut General Assembly, Public Act 23-56, checked 30 September 2026
- Maryland General Assembly, SB 541 (2024), Online Data Privacy Act, checked 30 September 2026
- New York State Senate, General Business Law 394-G, checked 30 September 2026
- California Legislative Information, AB 45 (2025), checked 30 September 2026
- Virginia LIS, SB 754 (2025), checked 30 September 2026
- Vermont General Assembly, S.71 (2026), checked 30 September 2026
- IAPP, US State Privacy Legislation Tracker, checked 30 September 2026