Playbook

Why Washington's My Health My Data Act Can Sue Any Agency

It doesn't ask whether your agency is licensed in Washington. It asks whether a Washington resident's health-adjacent data left your site without the specific, named consent the statute requires.

An insurance agency founder with closely buzzed short hair and light stubble sits at a bright office desk looking intently at a laptop screen. The laptop screen shows a simple outline map of the United States with Washington state highlighted in indigo and a glowing indigo arc line stretching from Washington across the map, representing a state privacy law reaching an agency in another state
The short version

Washington's My Health My Data Act, RCW 19.373, applies to any business that advertises to or takes quotes from Washington residents, not just Washington-based ones1. A violation is a per se unfair practice under the state's Consumer Protection Act6, and a court can award actual damages plus attorney's fees and treble damages capped at $25,000 per case, with no regulator required to act first8. The first private lawsuit under the law was filed in February 202511. This guide covers what the statute actually requires, what it costs, and how to check your own site.

The law that doesn't care where you are

Say your agency is licensed in Ohio, or Texas, or Florida. You've never written a policy in Washington state and have no plans to. A prospect in Tacoma searches "Medicare Advantage plans that cover insulin," clicks your ad, and lands on a comparison page you built for exactly that query. She fills out a quote form. The Meta Pixel on that quote page fires the instant it loads, sending her identity to an ad platform tied to the page she was on, the same mechanism that has already produced federal enforcement action against companies far bigger than a two-person agency.

That's the fact pattern Washington's My Health My Data Act was written to reach. The statute, codified at RCW 19.373 and commonly shortened to MHMDA, defines a "regulated entity" as any legal entity that "conducts business in Washington, or produces or provides products or services that are targeted to consumers in Washington," and that determines the purpose and means of collecting, processing, sharing, or selling consumer health data1. Nothing in that definition asks where your office sits, where you're licensed, or whether you've ever heard of the statute. It asks whether the person on the other end of the quote form was in Washington when they filled it out.

Most agents have never run into a law shaped like this. State insurance regulation is jurisdictional, you're licensed where you're licensed, and TCPA and CAN-SPAM are federal, so the rules are the same everywhere. MHMDA is different. It's a state statute with a reach that follows the visitor, not the business. An agency running a national Meta or Google campaign for ACA or Medicare Advantage plans is, almost by construction, targeting consumers in Washington along with every other state, whether or not that was ever the plan.

This guide is not legal advice

What follows is sourced directly from the Revised Code of Washington and Washington's Attorney General, verified live. It's written to help you understand what the statute actually requires and check your own site. For a specific compliance decision, talk to counsel who knows your state and your book of business.

What "consumer health data" actually covers

RCW 19.373.010 defines consumer health data as "personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status"1. That's a broader definition than HIPAA's protected health information, and it isn't limited to a diagnosis or a medical record. Washington's Attorney General describes the law as applying to "all persons and businesses that conduct business in Washington... and that collect, process, share, or sell consumer health data," a scope that reaches marketing and advertising data as directly as it reaches clinical records10.

For an insurance site, the practical reach is specific. A Medicare Advantage plan search that filters by a condition, an ACA subsidy calculator that returns a result tied to a household's health status, a diabetic supplies coverage page, a quote form that asks about current medications, all of these produce data that "identifies" a health status inside the statute's own definition. So does biometric data, defined separately as data generated from measuring an individual's physiological or behavioral characteristics1, and so does precise location data that places a visitor at a specific clinic or pharmacy.

Here's the detail that trips up agents who've already done a HIPAA review and assume they're covered: RCW 19.373.100 exempts protected health information, but only "for purposes of the federal health insurance portability and accountability act," and only when it's held by "a covered entity or business associate as defined by" HIPAA7. Meta and Google are not HIPAA business associates for their standard advertising products. The data your pixel sends them isn't protected health information moving through a HIPAA relationship, it's consumer health data moving through an advertising relationship, which is exactly the gap MHMDA was built to close.

What triggers it

Data reasonably linkable to a consumer that indicates a health status, condition, or need1.

What doesn't exempt you

Being HIPAA compliant, unless the specific vendor receiving the data is itself a HIPAA business associate7.

Who it reaches

Any entity targeting products or services to Washington consumers, regardless of where the business is based1.

RCW 19.373.030 permits a regulated entity to collect or share consumer health data in exactly two situations: with the consumer's consent for a specified purpose, or to the extent necessary to provide a product or service the consumer actually requested3. A quote form arguably clears the second bar for the quote itself. It does not clear it for whatever an ad platform does with that visitor's data afterward, which is a separate act of sharing that needs its own basis.

The statute is specific about what "consent" has to look like before that sharing happens. The request for authorization must "clearly and conspicuously disclose: (i) The categories of consumer health data collected or shared; (ii) the purpose of the collection or sharing... including the specific ways in which it will be used; (iii) the categories of entities with whom the consumer health data is shared; and (iv) how the consumer can withdraw consent from future collection or sharing"3. A generic "we use cookies" banner names none of that. It doesn't name the categories of data, doesn't name the purpose, doesn't name who receives it, and rarely explains how to withdraw consent for future sharing specifically.

Walk through the timing, because it's the part that actually matters. A standard client-side pixel fires the moment the page loads, before a visitor has scrolled, before they've clicked accept on anything. By the time a cookie banner even renders, the request to Meta or Google has already gone out — the same pre-consent gap that decides whether a consent banner makes tracking pixels legal at all. There is no version of "the visitor consented after the fact" that satisfies a statute requiring the four disclosures above before the sharing occurs. The tag doesn't wait for permission. It was never built to.

The mistake we see most

An agency points to its cookie consent banner and considers the question closed. A banner that says "we use cookies to improve your experience," with an accept button, doesn't name the categories of data, the specific purpose, or the categories of recipients the statute requires. It's consent for a different, much older problem than the one this law is actually asking about.

Why this is worse than a normal privacy statute

Most state privacy laws hand enforcement entirely to the state Attorney General, which means exposure depends on that office choosing to act, with limited staff and limited cases. MHMDA does something most of those laws don't: RCW 19.373.090 states plainly that "a violation of this chapter is not reasonable in relation to the development and preservation of business, and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW"6. That's a per se violation, meaning a plaintiff doesn't have to separately prove the practice was unfair or deceptive. Proving the MHMDA violation happened is enough.

And Washington's Consumer Protection Act, unlike a statute that only the Attorney General can enforce, is enforced "by the Attorney General as well as through private action"10. Any individual Washington consumer whose data was mishandled can bring their own lawsuit, without waiting for a regulator to notice, staff a case, or decide it's worth the office's time. One visitor, one plaintiffs' firm, and a filed complaint is the entire path to litigation. That structural difference, private enforcement stacked on top of a per se violation standard, is what separates MHMDA from a law that mostly lives on paper.

It's worth understanding why a plaintiffs' firm would bother with a case built around a single agency's tracking tag in the first place, because the economics are the actual engine here, not just the statute's text. RCW 19.86.090 lets a prevailing consumer recover a reasonable attorney's fee on top of any damages award8. That fee-shifting is what makes a case with modest actual damages worth filing at all, since the firm's own cost of bringing the claim gets paid by the losing side rather than eaten out of a small individual recovery. Pair that with a per se violation standard that removes the need to separately argue the practice was unfair, and a case that would never pencil out under an ordinary damages-only theory starts to look like a reasonable one to bring.

What the statute actually requires, section by section
Section What it requires What it means for your site
RCW 19.373.010 Defines consumer health data, regulated entity, and small business1 If you target WA consumers and touch health-adjacent data, you're covered
RCW 19.373.020 A published consumer health data privacy policy, linked from the homepage2 Most agency sites have a generic privacy policy, not this specific one
RCW 19.373.030 Specific, named consent before collecting or sharing the data3 A pixel firing before a consent banner loads doesn't clear this bar
RCW 19.373.040 Consumer access and deletion rights, answered within 45 days4 Someone on your team has to own this request, on a clock
RCW 19.373.080 No geofencing around a facility providing in-person health care5 Relevant if your ad platform lets you geotarget near a clinic
RCW 19.373.090 Any violation is a per se Consumer Protection Act violation6 Opens the door to a private lawsuit, not just AG enforcement
Worth a conversation if this is you. Agencies running national Medicare or ACA campaigns are exactly who this statute reaches hardest, and it's the kind of compliant-infrastructure build we scope on a call rather than sell as a fixed package. Book a call.

What it actually costs

Put the mechanism into real numbers and the shape of the exposure gets concrete. Under RCW 19.86.090, a consumer who proves a Consumer Protection Act violation, which MHMDA violations automatically are, can recover actual damages, plus the costs of the suit and a reasonable attorney's fee. A court can also, at its discretion, treble that award, with the trebled increase capped at $25,000 per case8. That's not a flat statutory penalty requiring no proof of harm, it's a real damages claim with a fee-shifting and trebling mechanism layered on top, which is exactly the combination that makes a case worth a plaintiffs' firm's time even when the underlying harm looks modest.

$25,000

Cap on treble damages per case under RCW 19.86.090, on top of actual damages and attorney's fees8

45

Days to answer a consumer's data request, extendable once by another 454

Mar 31, 2024

Date most regulated entities had to be compliant9

$53,088

Current maximum FTC Health Breach Notification Rule penalty per violation, for comparison12

Stat card titled What Washington's Health Data Law Actually Costs, showing four figures: 25,000 dollars, cap on treble damages per case under the Washington Consumer Protection Act, RCW 19.86.090; 45 days, deadline to answer a consumer data request under RCW 19.373.040; March 31, 2024, the date the law took effect under RCW 19.373; 53,088 dollars, the current maximum FTC Health Breach Notification Rule penalty per violation, for comparison. Source line reads app.leg.wa.gov, ftc.gov, verified August 2026
Two separate frameworks, two separate ceilings $25,000 WA CPA treble cap, per case (RCW 19.86.090) $53,088 FTC HBNR max, per violation
Sources: Revised Code of Washington section 19.86.090, current statute8; FTC, "Complying with FTC's Health Breach Notification Rule," updated January 202512.

Neither number is the whole exposure. The WA figure is a cap on the trebled portion of one case, not on attorney's fees, not on actual damages, and not on how many separate visitors could each bring their own claim off the same underlying tracking setup. The FTC figure requires the FTC itself to bring an action, which takes agency resources and only happens at scale. MHMDA needs one Washington resident, one law firm willing to take the case, and a filed complaint. That's the actual comparison worth sitting with, not which number is bigger, but which one requires a regulator to move first.

The lawsuit that proves it's not theoretical

A law with a private right of action and no enforcement history is still mostly a hypothetical. MHMDA isn't in that category anymore. On February 20, 2025, a Washington resident filed the first lawsuit under the statute's private right of action, in the U.S. District Court for the Western District of Washington in Seattle, against Amazon.com and Amazon Advertising11.

The complaint alleged that Amazon's advertising software development kit, licensed to a range of mobile apps, collected biometric data and precise location information that "could reasonably indicate a consumer's attempt to acquire or receive health services or supplies," and that this collection violated MHMDA alongside several federal statutes11. Note what the complaint doesn't allege: a data breach, a hack, or malicious intent. It alleges an advertising SDK doing what advertising SDKs do, collecting location and behavioral signals to improve targeting, applied to data the statute treats as consumer health data because of what that location and behavior can reasonably indicate.

A Washington resident filed the case on behalf of herself and others in a similar position, which is its own signal worth noting. A private right of action paired with a class-style filing means one visitor's claim can become the vehicle for a much larger group of people who interacted with the same tracking mechanism, on the same site, in the same way. An agency running a single national ad campaign isn't looking at one visitor's potential claim in isolation, it's looking at however many Washington residents that same campaign reached, each of whom shares the identical fact pattern a plaintiffs' firm needs to build a group case.

That's the same shape of exposure a quote-page tracking pixel carries. Nobody has to intend a health data disclosure for the statute to apply. The SDK, or the pixel, only has to do what it was built to do, on a page where what it was built to do collides with what the statute defines as consumer health data.

The Washington My Health My Data Act, timeline
Date Event What it means
Apr 27, 2023 Governor Inslee signs House Bill 1155 into law9 MHMDA becomes law, with a delayed compliance date
Mar 31, 2024 Compliance deadline for regulated entities that aren't small businesses9 Most agencies running national ad campaigns fall here
Jun 30, 2024 Compliance deadline for small businesses under the statute's threshold9 The small-business carve-out was extra time, not an exemption
Feb 20, 2025 First private lawsuit filed, against Amazon, in W.D. Washington11 The private right of action moved from theoretical to filed

The privacy policy and geofence rules nobody reads

Two more requirements in the statute are easy to miss because they don't look like a tracking question at all, and both are simple to check on your own site.

RCW 19.373.020 requires a regulated entity to "prominently publish a link to its consumer health data privacy policy on its homepage," and that policy has to disclose the categories of data collected and why, the categories of sources, the categories of data shared, "a list of the categories of third parties and specific affiliates" who receive it, and how a consumer exercises their rights2. A generic privacy policy written for a different purpose, the kind most site templates ship with, almost never contains that specific list. It's a different document than what most agency sites currently link.

RCW 19.373.080 bans geofencing "an entity that provides in-person health care services" for three specific purposes: identifying or tracking consumers seeking health care, collecting their consumer health data, or sending them notifications, messages, or advertisements related to their health data or health care services5. If your agency, or a vendor running your ads, has ever set up a geofenced campaign around a clinic, a hospital, or a pharmacy to catch people walking out, that specific tactic is exactly what this section prohibits.

Generic

What most sites currently have

  • A standard privacy policy written for cookies and general data collection
  • No link specifically labeled as a consumer health data policy
  • No named list of who receives health-adjacent tracking data

StatusDoesn't meet RCW 19.373.020's specific requirements

Compliant

What the statute actually requires

  • A dedicated consumer health data privacy policy, linked from the homepage
  • Named categories of data, sources, and recipients
  • A working process for the access and deletion rights it promises

StatusMeets RCW 19.373.020's disclosure list2

The 45-day clock you didn't know you had

RCW 19.373.040 gives consumers the right to confirm what health data a regulated entity holds about them, access it, including "a list of all third parties and affiliates" it's been shared with, and request deletion4. None of that is unusual among modern privacy statutes. What's easy to miss is the clock: entities "shall comply with the consumer's requests... without undue delay, but in all cases within 45 days of receipt of the request," extendable once for another 45 days when reasonably necessary4.

Deletion carries its own wrinkle. The entity has to delete the data "from all parts of the regulated entity's... network, including archived or backup systems," though that specific part of a deletion request "may be delayed to enable restoration of the archived or backup systems," capped at six months from when the request was authenticated4. Almost no independent agency has a documented process for any of this. If a request landed in your inbox tomorrow, from a name you don't recognize, citing this statute, would anyone on your team know what to do with it inside 45 days?

If you want to know where your own site stands

The free Audit checks a site's technical readiness in under a minute, including whether trackers are firing before consent on health and Medicare-adjacent pages. Run one at strategicaiarchitects.com/audit13.

How to check your own exposure in fifteen minutes

You don't need to hire anyone to get a first real answer. Most of this is checkable in your own browser, on your own site, right now.

01

Watch the network tab on your quote page

Open your Medicare, ACA, or plan comparison page with developer tools open to the Network tab. Filter for facebook.com/tr and google-analytics.com. Reload without clicking anything on a consent banner. If those requests fire before you've accepted anything, the tag is sharing data before any consent RCW 19.373.030 would recognize.

02

Look for a consumer health data privacy policy on your homepage

Scroll your homepage footer for a link specifically about consumer health data, not just a general privacy policy. If it isn't there, or if the linked policy doesn't name categories of data, sources, and recipients, it doesn't satisfy RCW 19.373.020.

03

Check your ad platform for geofenced campaigns

In Meta Ads Manager or Google Ads, look for any location-targeted campaign built around a specific radius. If that radius sits around a clinic, hospital, or pharmacy rather than a general service area, it may run into RCW 19.373.080's geofencing ban.

04

Ask who would actually handle a 45-day deletion request

Name the person on your team who would receive, authenticate, and act on a consumer data request under RCW 19.373.040. If the honest answer is nobody, that's the gap, not a hypothetical one.

05

Confirm whether your national ad spend reaches Washington

If your Meta or Google campaigns aren't geographically restricted, they're almost certainly reaching Washington consumers, which is what triggers RCW 19.373.010's "targeted to consumers in Washington" language in the first place.

What actually fixes it

The fix has a name, and it's the same underlying mechanism that closes the gap on a lot of the health-data tracking exposure agents ask about, not just this specific statute. A standard, client-side pixel runs in the visitor's own browser and sends data straight to Meta or Google the instant the page loads. There's no place to check for consent, name a recipient, or hold the event until it's appropriate to send, because the browser already sent it before your server saw the request.

Server-side, consent-gated tracking moves that step onto infrastructure you control. The event still gets captured, but it routes to your own server first. Your server checks whether the specific, named consent RCW 19.373.030 requires was actually recorded, and only then forwards a cleaned event, if it forwards one at all. The visitor's browser never talks to Meta or Google directly.

The consent banner itself has to change too, not just the plumbing behind it. A banner that says "we use cookies to improve your experience" with a single accept button doesn't do the work RCW 19.373.030 requires. The banner, or the layer behind it, needs to actually name the categories of data involved, state the specific purpose, name the categories of recipients, and give a real path to withdraw consent later, before any health-adjacent event fires anywhere. That's a content problem as much as an engineering one, and it's the piece most off-the-shelf consent management tools don't handle out of the box, because they were built for a general cookie-law standard, not this statute's specific four-part disclosure.

What changes between the two approaches
Question Client-side pixel Server-side, consent-gated
Can it fire before named consent Yes, by default, unless separately gated No, the four disclosures are checked first
Can a health-adjacent field be stripped No, the browser sends the raw event as built Yes, your server controls exactly what forwards
Does it support a 45-day deletion request Not directly, the data already left your systems Yes, the event log lives on infrastructure you hold
Flowchart infographic titled Does Washington's My Health My Data Act Reach Your Site, showing four sequential yes or no questions with a low exposure branch off any no: one, do you advertise or take quotes from consumers in Washington state; two, does your site collect data suggesting a health condition or plan need, like a Medicare or ACA quote page; three, did a tracking pixel or ad tag send that data before the visitor consented; four, was that sharing done without specific opt-in consent naming who would receive it. A yes to all four leads to a box reading exposure under RCW 19.373. Source line reads Revised Code of Washington chapter 19.373, app.leg.wa.gov
The tradeoff, plainly. A consent-gated, server-side setup with a documented deletion process takes more engineering than pasting a pixel snippet into your header. That's the honest cost. What it buys back is a structural answer to the exact question this statute asks: who receives a Washington visitor's health-adjacent data, did anyone name that recipient first, and could you answer a deletion request inside 45 days if one landed tomorrow.

How we build this in

This section sticks to what's on our own live pages, verified this session. The free Audit checks whether a site's trackers are firing before consent on health and Medicare-adjacent pages, so you can see where your current site stands before deciding anything13. Digital Foundation ships with server-side, consent-gated tracking by default rather than a raw client-side pixel, starting at $247 a month with a 14-day free trial14.

For agencies that want the compliant-stack build done end to end, including a BAA-covered infrastructure setup, server-side tracking wired to a documented consent flow, and PHI handled only on HIPAA-eligible AWS or Azure services under a signed Business Associate Agreement, Enterprise builds run on infrastructure you own, with every access to protected health information logged inside your own tenant15. Minimum Enterprise projects start at $2,000 plus a small monthly cloud cost, typically under $200, and every build is scoped to the specific agency rather than sold as a fixed package15.

Neither of those claims is a promise about your specific legal exposure disappearing. What we can say plainly is that a client-side pixel sending health-adjacent form data to an ad platform with no named consent and no deletion workflow is not how we build a site in the first place.

Who this doesn't reach as hard

This guide concentrates on health-adjacent pages: Medicare, ACA, and anything tied to a specific condition or benefit. If your book is life insurance, final expense, or property and casualty, and your site never asks about a health condition or returns a result tied to one, your exposure under this specific statute is meaningfully lower. The definition of consumer health data is keyed to health status, not to insurance broadly.

Geography matters too. RCW 19.373.010's reach depends on conducting business in Washington or targeting products to Washington consumers1. A single-county agency running no digital ads outside its own state, with no national campaign and no organic traffic from Washington worth mentioning, carries a genuinely different exposure than an agency running national Meta and Google campaigns for Medicare Advantage or ACA plans. You can run the check in this guide yourself and reasonably conclude your specific site is low risk. A lot of agents will, and that's a legitimate outcome, not a failure to take the law seriously.

Where it applies almost without exception is any agency running national or multi-state digital advertising for Medicare Advantage, Medicare Supplement, or ACA products, because the ad spend itself is what makes the campaign "targeted to consumers in Washington" in the statute's own language, whether or not writing business there was ever part of the plan.

Questions agents ask

What is Washington's My Health My Data Act?

It's a Washington state law, codified at RCW 19.373 and generally effective March 31, 2024, that regulates any entity collecting, sharing, or selling "consumer health data" tied to a Washington resident. It applies based on the data and the consumer's location, not on whether the business is a healthcare provider or a HIPAA covered entity.

Does the law apply to my agency if I'm not based in Washington?

Yes, if you advertise to or take quotes from Washington residents. RCW 19.373.010 defines a "regulated entity" as one that conducts business in Washington, or produces or provides products or services targeted to consumers in Washington, with no exception for out-of-state agencies.

Is my agency exempt because it's a small business?

No. RCW 19.373.010's small-business threshold, fewer than 100,000 consumers' health data collected a year, or fewer than 25,000 if over half of revenue comes from that data, only delayed a small business's compliance deadline to June 30, 2024. Every substantive requirement in the statute still applies, and that deadline passed more than two years ago.

Doesn't being HIPAA compliant already cover this?

Only for the specific data RCW 19.373.100 exempts: protected health information actually handled by a HIPAA covered entity or business associate. An ad platform receiving pixel data from a quote page is not typically a HIPAA business associate for that data, so the exemption usually doesn't reach the exact flow this law targets.

What actually counts as consumer health data on an insurance website?

RCW 19.373.010 defines it as data linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status, which reaches a Medicare Advantage plan search tied to a condition, an ACA subsidy result based on a household's health status, or biometric or precise location data suggesting someone visited a clinic.

How much can a violation actually cost?

A violation is a per se unfair or deceptive act under Washington's Consumer Protection Act, RCW 19.373.090. Under RCW 19.86.090, a court can award actual damages, add attorney's fees and costs, and treble the award, with that trebled increase capped at $25,000 per case, all without a regulator having to bring the case first.

What's the fastest way to check my own exposure?

Open your quote or plan-comparison page, watch your browser's network tab for tags firing before any consent interaction, and check whether your homepage links a consumer health data privacy policy naming who receives the data, which RCW 19.373.020 requires. The free Audit at strategicaiarchitects.com/audit checks the tracking half of that in under a minute.

Sources

  1. Washington State Legislature. RCW 19.373.010, "Definitions," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  2. Washington State Legislature. RCW 19.373.020, "Consumer health data privacy policy," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  3. Washington State Legislature. RCW 19.373.030, "Collection or sharing of consumer health data," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  4. Washington State Legislature. RCW 19.373.040, "Consumer rights and requests," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  5. Washington State Legislature. RCW 19.373.080, "Geofence restrictions," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  6. Washington State Legislature. RCW 19.373.090, "Application of consumer protection act," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  7. Washington State Legislature. RCW 19.373.100, "Exemptions," current statutory text, verified live 2026-08-14. app.leg.wa.gov.
  8. Washington State Legislature. RCW 19.86.090, "Civil action for damages, Attorney's fees and costs," current statutory text, treble damages increase capped at $25,000, verified live 2026-08-14. app.leg.wa.gov.
  9. Washington State House Democrats. "Governor Inslee Signs WA My Health, My Data Act into Law," published 2023-04-27, compliance dates of 2024-03-31 and 2024-06-30, verified live 2026-08-14. housedemocrats.wa.gov.
  10. Washington State Office of the Attorney General. "Protecting Washingtonians' Personal Health Data and Privacy," geographic and entity scope, Consumer Protection Act enforcement, verified live 2026-08-14. atg.wa.gov.
  11. HIPAA Journal. "Lawsuit Filed Against Amazon Alleging Unlawful Collection of Health & Location Data," published 2025-02-27, lawsuit filed 2025-02-20 in the U.S. District Court for the Western District of Washington, verified live 2026-08-14. hipaajournal.com.
  12. Federal Trade Commission. "Complying with FTC's Health Breach Notification Rule," civil penalty of up to $53,088 per violation, edited January 2025 for inflation-adjusted maximums, verified live 2026-08-14. ftc.gov.
  13. Strategic AI Architects. "Free Audit," HIPAA and consent tracking scan feature, verified live 2026-08-14. strategicaiarchitects.com.
  14. Strategic AI Architects. "Digital Foundation," pricing and server-side tracking, verified live 2026-08-14. strategicaiarchitects.com.
  15. Strategic AI Architects. "Enterprise," HIPAA-eligible AWS and Azure infrastructure and Business Associate Agreement terms, minimum project pricing, verified live 2026-08-14. strategicaiarchitects.com.

See whether your own site would clear this bar

Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.

Related reading: why your insurance website's pixel could get you sued · can your AI follow-up get your agency sued

← All guides