Washington MHMDA Privacy Policy Gap Checker
Most consumer-health-data privacy policies I see are a generic privacy policy with a sentence about health data dropped in. That is not the separate Consumer Health Data Privacy Policy that RCW 19.373.020 requires. This checker walks the disclosure elements in RCW 19.373.020, the consumer-rights mechanism in RCW 19.373.040, the consent rules in RCW 19.373.030, and the data-security baseline in RCW 19.373.050, and returns a gap list with statutory citations.
MHMDA compliance score
Gap list (with statutory citations)
Recommended next step
Send these inputs to me for policy reviewThis is a triage tool, not legal advice. Confirm against the live statutory text and your specific product before relying on this output.
How the score is calculated
The score weighs the most-violated MHMDA policy elements. Weights total 100 points.
- Separate Consumer Health Data Privacy Policy: up to 30 points. This is the single most-violated MHMDA requirement.
- Prominent homepage link: up to 20 points. Footer-only links score partial credit; no link scores zero.
- Disclosure completeness (categories, sources, purposes, sharing): up to 30 points across four elements.
- Two-layer affirmative opt-in consent: up to 10 points.
- Policy last reviewed within 12 months: up to 10 points.
The four verdict bands are 80 to 100 (Strong: minor language tightening), 60 to 79 (Moderate: a documented gap-closing pass needed), 40 to 59 (Weak: substantial rewrite needed), and 0 to 39 (Poor: rebuild the policy from a compliant template).
Authority notes
Statutory citations come from RCW 19.373.020 (privacy policy and homepage link, disclosure elements), RCW 19.373.030 (separate consents for collection and sharing), RCW 19.373.040 (consumer rights and 45-day response window), and RCW 19.373.050 (data security). For sale of consumer health data, see RCW 19.373.070. For per-se CPA exposure on any violation, see RCW 19.373.090.
For background on Washington MHMDA, see my Washington My Health My Data Act resource. The companion MHMDA Scope Analyzer determines whether you are in scope.