Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View
Veeam

The Funniest Evening at RSA with Hasan Minhaj

Hasan Minhaj Request ticket
View

Healthcare Privacy Laws & Regulations Around the World

Author

Anas Baig

Product Marketing Manager at Securiti

Published December 25, 2023

Listen to the content

In the digital era, health data, such as genetic information or biometric information, is equally valuable and crucial as other types of sensitive personal information of individuals across the globe. Hence, apart from ensuring compliance with general data protection and privacy laws, organizations must also comply with health data privacy laws to protect consumers' health data and prevent legal consequences.

This tracker contains a list of healthcare data privacy laws around the world.

Global Healthcare Data Privacy Laws

Health data privacy laws are designed to govern the collection, processing, and protection of general health-related data. It includes all types of health information, including genetic, biometric, physical, mental, and general patient data. The Health Insurance Portability and Accountability Act (HIPAA) is one of the best examples of a comprehensive federal health data privacy law in the US. Let’s take a look at some of the other general health data protection laws across the US states.

Nevada Health Data Privacy Law

Status

The Nevada Governor approved Senate Bill 370 (Nevada’s Consumer Health Data Privacy Law), which aims to impose certain requirements on collecting, using, and selling consumer health data. It will come into effect on March 31, 2024.

Applicability

The law applies to any persons who operate in the state of Nevada or provide their products or services to consumers in Nevada. Regulated entities also include persons who are, alone or in partnership with another person, determining the purpose and means of processing, sharing, or selling consumer health data. However, the law is not applicable to:

  • any person or entity subject to the HIPAA;
  • information created for compliance with the Healthcare Quality Improvement Act of 1986;
  • patient data, including substance use disorder records;
  • research, public health activities, and state-authorized data collection;
  • personally identifiable information under specific federal laws (Gramm-Leach-Bliley Act, Social Security Act, Fair Credit Reporting Act, Family Educational Rights and Privacy Act);
  • entities processing consumer health data on behalf of governments or tribes.

Data Subject Rights

Under the law, consumers have been provided with several rights. These include the right to request a regulated entity to confirm if it collects, processes, or sells consumer’s health data, access to third parties to whom the consumer health data is sold or shared, right to request to cease collection, processing, or selling consumer’s health data, and the right to request the regulated entity to delete consumer’s health data.

Obligations of Regulated Entities

Privacy Policy/Notice

The law requires regulated entities to create, maintain, and display a privacy notice on their main internet website while including specific information, such as categories of consumer health data, sources from which it is collected, third parties, and affiliates with which the data is shared, the purpose of data collection, consumers’ privacy rights, and the process of notifying the consumer whose health data is collected by the regulated entity.

Consent

The regulated entity should not collect consumer health data except with affirmative and voluntary consent of the consumer, or the health data is to be collected only to the extent necessary to provide the product and service requested by the consumer.

Restrict Access to Data

The regulated entity must restrict access to consumer health data to only authorized employees and processors. Access can only be provided where it is reasonably necessary to either further the process for which the consumer's consent is acquired or to provide products or services requested by the consumer.

Sharing/Sale

The law prohibits offering to sell or selling a consumer’s health data if there is no written authorization from the consumer or if the authorization is written in a manner that is outside the scope of or inconsistent with the written authorization. The authorization must be provided in plain language while including specific descriptions. Moreover, the regulated entity can share health data with the consumer’s consent or when necessary for a requested service or required by law. The consent for sharing consumers' health data must be obtained separately from the consent for collecting the health data.

Security Measures

Regulated entities are required to implement appropriate technical, security, and administrative controls to protect consumer health data. These controls must meet the security standards of the industry in which the regulated entity operates to protect the accessibility, integrity, and confidentiality of consumer health data and be reasonable, taking into account the volume and nature of the consumer health issue.

Geofencing Restriction

The law prohibits any person from implementing geofencing within 1,750 feet of any medical facility that provides health care services for the purpose of tracking consumers seeking in-person health care services, collecting consumer health data, or sending notifications to consumers related to their health care services.

Regulatory Authority

The Nevada Attorney General has the exclusive right to enforce and implement the provisions of the law.

Penalties for Non-Compliance

This law does not provide any private right of action. However, any violations of the law are to be considered deceptive trade practices and hence enforceable by the state Attorney General. The court may impose a penalty of not more than $12,500 for each violation.

Washington My Health My Data Act

Status

Washington’s House Bill 1155, commonly known as My Health, My Data Act (MHMDA), was signed into law on 27 April 2023. The law aims to govern the regulated entities and small businesses and have respective implementation deadlines. The prohibition on geofencing does not include any specific effective date; therefore, as per the Washington legislative convention, this prohibition goes into effect 90 days from the end of the current legislative session on July 22, 2023. All other requirements related to Regulated Entities shall be effective from March 31, 2024. However, small businesses have been given a year to comply with the MHMDA provisions. Hence, they are required to be compliant starting June 30, 2024.

Applicability

The MHMDA broadly applies to all ‘regulated entities’, which include all the legal entities conducting business in Washington or producing or providing products or services targeted to consumers in Washington that, alone or jointly with others, determine the purpose or means of collecting, processing, sharing, or selling of consumer health data. An entity that only stores data in Washington is not a regulated entity. MHMD creates blanket exemptions for three categories of organizations: government agencies, tribal nations, and “contracted service providers when processing consumer health data on behalf of a government agency”.

In addition, MHMDA applies to small businesses if they satisfy either of the following conditions:

  • Collects, processes, sells, or shares consumer health data of less than 100,000 consumers during a calendar year; or
  • Derives less than 50 percent of gross revenue from the collection, processing, selling, or sharing of consumer health data, and controls, processes, sells, or shares consumer health data of less than 25,000 consumers.

Data Subject Rights

Under MHMDA, consumers can exercise their right to confirm if the entity collects, processes, or shares consumer health data, access a list of the third parties with which the data is shared or sold, withdraw consent from the entity’s collection, sharing of consumer health data, and request to delete consumers’ health data. Consumers are also entitled to access a list of the names and email addresses (or other online mechanisms for contact) of third parties and affiliates with whom the data was “shared” or “sold.”

Obligations of the Regulated Entities

Privacy Policy/Notice

All the regulated entities must create and maintain a privacy policy that “clearly and conspicuously” communicates categories of consumer health data collected, the purpose of collection, categories of sources from where it is collected, categories of data shared, list of third parties with which it is shared, and consumers’ privacy rights. The regulated entities and small businesses shall publish a link to their privacy policy on their homepage.

Consent

Consent is one of the essential components of MHMDA. Consent must be collected before collecting and sharing consumers’ health data. It must also be noted that the consent for collecting consumer health data must be distinct and separate from the consent obtained for sharing consumer health data. Where collection or sharing of consumer health information is necessary to provide a product or service that a consumer has requested, consumer consent is not required. However, there is no ‘necessity’ exception for secondary uses of consumer data or the “sale” of such information.

Sharing/Sale

MHMDA requires all persons to obtain a valid authorization from the consumer before selling or offering to sell the consumer health data. The authorization must be separate and distinct from the consent obtained for selling consumer data. The authorizations are only valid for one year, and the seller and buyers must retain a copy of the authorization for six years.

Restricted Access to Data

Regulated entities and small businesses must restrict access to consumer health data to only those employees, processors, and contractors for whom the access is necessary to further the purpose for which the consent is obtained.

Security Measures

Regulated entities and small businesses must implement technical and physical data security measures that, at a minimum, satisfy reasonable industry standards to protect health data appropriate for the volume and nature of the data to ensure the confidentiality, integrity, and accessibility of consumer health data.

Geofencing Restriction

It is illegal for any person to implement a geofence around an entity providing healthcare facilities to identify or track a consumer seeking healthcare services, collect health data from consumers, and send notifications, messages, or advertisements to consumers based on their health data or healthcare services.

Regulatory Authority

The Attorney General of Washington is responsible for enforcing and implementing the provisions of MHMDA.

Penalties for Non-Compliance

Violations of MHMDA provisions will be deemed as unfair or deceptive trade practices under Washington’s Consumer Protection Act.

Compliance with applicable global data privacy laws is obligatory for businesses.
Failure to comply can result in huge loss such as consumer trust, class-action lawsuits, and hefty fines.
orange hammer icon
Is your organization ready to comply with the existing as well as upcoming data privacy laws?

Watch the demo to see how Securiti is helping organizations with global privacy regulatory compliance.

Watch the demo

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
View More
Introducing Agent Commander
The promise of AI Agents is staggering— intelligent systems that make decisions, use tools, automate complex workflows act as force multipliers for every knowledge...
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About View More
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About
Boards are tuned in to the AI conversation, but there’s a blind spot many organizations still haven’t named: risk silos. Everyone agrees AI governance...
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
California’s Delete Request and Opt-out Platform (DROP) and the Delete Act View More
California’s Delete Request and Opt-out Platform (DROP) and the Delete Act
Understand California’s DROP platform and the Delete Act, including compliance timelines, the 45-day cycle, broker obligations, and how to operationalize compliance.
Building A Secure AI Foundation For Financial Services View More
Building A Secure AI Foundation For Financial Services
Access the whitepaper and discover how financial institutions eliminate Shadow AI, enforce real-time AI policies, and secure sensitive data with a unified DataAI control...
Emerging AI Security Trends For 2026 View More
Emerging AI Security Trends For 2026
Securiti’s latest infographic provides security leaders with a walkthrough of all the emerging AI security trends for 2026 to help them assess and plan...
Safe AI, Accelerated: View More
Safe AI, Accelerated: Securing Data & AI Across the Lifecycle
Securiti’s latest infographic dives into the issue organizations face when scaling their AI projects safely, and how best they can address those challenges.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New