Between May 13 and May 15, 2024, an unauthorized party accessed the systems of Okanogan Behavioral HealthCare in Omak, Washington, a community provider of counseling, crisis response, and substance use treatment. The files taken included psychiatric diagnoses and substance use treatment records. A class action followed, and a settlement was reached; the Okanogan breach settlement post walks through it. The point for every other Washington provider is the calendar: under state law the letters to patients were due within 30 days of discovery, and the Attorney General had to hear about it in the same window.
Federal enforcement runs on its own track. OCR (the HHS Office for Civil Rights) settled with Lifespan for $1,040,000 over an unencrypted stolen laptop breach (July 27, 2020), and its recent titles include a $950,000 settlement over Security Rule failures (July 1, 2024). The federal rules apply in Seattle, Spokane, and Yakima exactly as they apply anywhere else. Washington adds three things on top: a faster breach clock, a health records act with its own deadlines and consent form, and a consumer health data law that starts where HIPAA stops.
HIPAA Compliance Washington State: How the Federal and State Rules Interact
HIPAA (the Health Insurance Portability and Accountability Act) sets a floor. 45 CFR 160.203 states the general rule: a HIPAA standard "that is contrary to a provision of State law preempts the provision of State law," then lists the exceptions. Paragraph (b) preserves state law that "relates to the privacy of individually identifiable health information and is more stringent than" the federal Privacy Rule. 45 CFR 160.202 defines "more stringent" to include state law that "permits greater rights of access" and law that provides "for the retention or reporting of more detailed information or for a longer duration." Washington's 15-working-day access rule and its hospital retention rule are both that kind of law.
Where Washington is stricter, Washington wins. Where HIPAA is stricter, HIPAA wins.
Who Is a Covered Entity in Washington
The definition is federal. 45 CFR 160.103 defines a covered entity as "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." The Uniform Health Care Information Act uses its own terms, "health care provider" and "health care facility" (RCW 70.02.010), whether or not the provider bills electronically.
Who Is a Business Associate in Washington
Also federal. A business associate under 160.103 is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter," including billing, practice management, data analysis, and the other listed services. Each needs a signed B.A.A. (Business Associate Agreement). Washington's breach statute adds its own vendor duty: a business that holds data it does not own "shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery" (RCW 19.255.010(2)).
Washington Statutes That Stack on Top of HIPAA
The Uniform Health Care Information Act (RCW 70.02)
Chapter 70.02 governs day-to-day records handling. Four sections matter most:
- Access in 15 working days (RCW 70.02.080). On a written request, a provider "as promptly as required under the circumstances, but no later than fifteen working days after receiving the request shall" make the information available or provide a copy, inform the patient if it does not exist, or, if the record is in use or unusual circumstances apply, "specify in writing the reasons for the delay and the earliest date, not later than twenty-one working days after receiving the request." HIPAA's clock at 45 CFR 164.524(b)(2) is 30 days with one extension; Washington's is shorter and wins.
- The authorization form (RCW 70.02.030). A valid disclosure authorization must "Be in writing, dated, and signed by the patient," identify the information, the recipient, the disclosing provider, and the patient, and "Contain an expiration date or an expiration event." The elements overlap HIPAA's 45 CFR 164.508(c) but are not identical; one form should satisfy both lists.
- Sexually transmitted disease and HIV records (RCW 70.02.220). "No person may disclose or be compelled to disclose the identity of any person who has investigated, considered, or requested a test or treatment for a sexually transmitted disease," and related records go without authorization only to the listed recipients.
- Mental health records (RCW 70.02.230). "The fact of admission to a provider for mental health services and all information and records compiled, obtained, or maintained in the course of providing mental health services" may not be disclosed except as the section allows or under a valid RCW 70.02.030 authorization. Substance use disorder programs may also be under 42 CFR Part 2.
The act has teeth of its own. Under RCW 70.02.170, a person who has complied with the chapter "may maintain an action" against a provider who has not; relief "may include actual damages," and "The court shall award reasonable attorneys' fees and all other expenses reasonably incurred to the prevailing party." Actions must be brought within two years of discovery.
Hospital Record Retention: 26 Years (RCW 70.41.190)
HIPAA sets no retention period for the chart; it requires that policies and required documentation be kept "for 6 years from the date of its creation or the date when it last was in effect, whichever is later" (45 CFR 164.316(b)(2)(i) and 164.530(j)(2)). Washington's hospital licensing statute, as amended in 2025, requires that "A hospital shall retain and preserve all medical records for a minimum period of 26 years from the date the record was created," applying to records created on or after July 27, 2025 and to earlier records still held on that date. Retention rules for non-hospital providers sit in Department of Health regulations and were not reviewed for this article; check the rule for each license type. The record retention guide covers the federal-versus-state split.
The My Health My Data Act (RCW 19.373)
Passed in 2023, the act is described by the Attorney General's office as "the first privacy-focused law in the country to protect personal health data that falls outside the ambit of" HIPAA. It regulates "consumer health data," defined in RCW 19.373.010(8) as "personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status," which reaches diagnoses, medications, biometric and genetic data, and "precise location information that could reasonably indicate a consumer's attempt to acquire or receive health services."
The exemptions in RCW 19.373.100 are what a practice needs. The chapter "does not apply to" information that meets the definition of "Protected health information for purposes of" HIPAA, "Health care information collected, used, or disclosed in accordance with chapter 70.02 RCW," or patient identifying information under 42 CFR Part 2, along with data intermingled with that information and held by a covered entity, business associate, or 70.02 provider. That is a data exemption, not an entity exemption. A marketing website, an email list of non-patients, or an advertising pixel can generate consumer health data that is not P.H.I. (Protected Health Information) and is not 70.02 information. The Attorney General's FAQ notes the requirement that a regulated entity "prominently publish a link to its consumer health data privacy policy on its homepage." Compliance dates were March 31, 2024 for regulated entities and June 30, 2024 for small businesses. Under RCW 19.373.090, a violation "is an unfair or deceptive act in trade or commerce" under the Consumer Protection Act. Counsel should map which data falls where.
Washington Breach Notification: 30 Days, and the Attorney General at 500
The federal rule first. 45 CFR 164.404(b) requires notice to affected individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." A breach involving 500 or more individuals goes to HHS "contemporaneously" with the individual notice (164.408(b)); smaller breaches are logged and reported "not later than 60 days after the end of each calendar year" (164.408(c)); a breach involving "more than 500 residents of a State or jurisdiction" also goes to prominent media serving that state (164.406(a)).
Washington's statute, RCW 19.255.010, is faster. Notice to affected residents "must be made in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered," with delay allowed only for law enforcement or for measures to determine the scope of the breach. A business that must notify "more than five hundred Washington residents as a result of a single breach shall notify the attorney general of the breach no more than thirty days after the breach was discovered," with the contents the section lists; the Attorney General accepts the filing through an online web form and publishes the notices. The state definition of personal information in RCW 19.255.005 is broad: a name linked to a Social Security number, a full date of birth, a health insurance identification number, "Any information about a consumer's medical history or mental or physical condition or about a health care professional's medical diagnosis or treatment of the consumer," or biometric data, among others. Notice is not required "if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm."
Now the HIPAA clause, RCW 19.255.030(1). A HIPAA covered entity "is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal health information technology for economic and clinical health act," the statute behind the federal Breach Notification Rule. The same subsection keeps one state duty alive: "Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402," that is, on the federal timeline rather than the state's 30 days. In practice: a covered entity that follows 45 CFR 164.404 to 164.408 for P.H.I. satisfies the state's individual-notice rule, but still files with the Washington Attorney General when more than 500 residents are affected. Business associates are not named in the clause.
| Obligation | Federal HIPAA | Washington (RCW 19.255) |
|---|---|---|
| Trigger | Breach of unsecured P.H.I. (164.402) | Unauthorized acquisition of unsecured personal information, including medical and health insurance data |
| Individual notice deadline | No later than 60 calendar days after discovery | No more than 30 calendar days after discovery (covered entities deemed compliant for P.H.I. via 19.255.030) |
| Government notice | HHS: contemporaneous if 500 or more; annual log if fewer | Attorney General if more than 500 residents; within 30 days, or on the federal timeline for covered entities |
| Media | Prominent outlets if more than 500 residents of a state | Only as substitute notice when direct notice is impractical |
| Vendor to client | No later than 60 days (164.410) | Immediately following discovery |
| Waiver | Not applicable | Void and unenforceable (19.255.040(1)) |
The working rule for a Washington practice: run the federal process from the breach notification guide, treat 30 days as the operational target anyway, and add the Attorney General filing at 500 residents.
HIPAA Penalties in Washington
Federal OCR Penalty Tiers
45 CFR 160.404 sets four culpability tiers, and the amounts are inflation-adjusted each year at 45 CFR 102.3. Under the 2025 adjustment, the per-violation ranges are: $145 to $73,011 where the entity did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect not corrected. The calendar-year cap for identical violations is $2,190,294. OCR has applied a Notice of Enforcement Discretion with lower annual caps for the first three tiers; those figures are not quoted here. The penalty amounts post tracks the numbers.
Washington Attorney General and Private Enforcement
Under RCW 19.255.040, "The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter," and a violation "is an unfair or deceptive act in trade or commerce" under the Consumer Protection Act. The same section adds that "Any consumer injured by a violation of this chapter may institute a civil action to recover damages." The My Health My Data Act carries the same Consumer Protection Act hook under RCW 19.373.090. The Uniform Health Care Information Act is enforced by patients directly under RCW 70.02.170, with attorneys' fees to the prevailing party. A privacy failure in Washington can be litigated three ways at once, none of them requiring OCR.
HIPAA Compliance for Washington Healthcare Providers
Washington Hospitals and Health Systems
The Washington layer for a system lands in health information management: the 26-year retention rule, the 15-working-day access clock, and the 70.02.220 and 70.02.230 release lists. The incident response plan should carry the Attorney General filing at 500 residents and the 30-day target, and the marketing team needs a consumer health data privacy policy if any site collects health-related data from non-patients.
Washington Dental Practices
A dental office is a covered entity with its first electronic claim; the dental compliance page covers the federal program. Washington adds the 15-working-day access rule, the 70.02.030 authorization elements, and a breach clock of 30 days for any file that includes insurance identification numbers. OCR's dental enforcement runs to patient access and social media, including a $10,000 case over social media disclosures of patients' P.H.I. (October 2, 2019).
Washington Behavioral Health Providers
The Okanogan case is the sector's local lesson: psychiatric and substance use records carry RCW 70.02.230 and, often, 42 CFR Part 2 on top of HIPAA, and a breach of them lands in both class action court and the Attorney General's public breach directory. OCR's federal pattern is patient access: a $100,000 penalty against a mental health center for failure to provide timely access to patient records (November 19, 2024). The behavioral health compliance page covers the program.
Washington Home Health and Long-Term Care
Home health agencies and long-term care facilities move P.H.I. on phones and paper across large counties. The $3 million settlement over failure to encrypt mobile devices (November 5, 2019) is the sector's warning. Encryption keeps a lost device out of the federal definition of unsecured P.H.I. and out of Washington's "not secured" trigger.
Washington HIPAA Compliance Checklist
| Requirement | Source | Timing | Evidence to keep |
|---|---|---|---|
| Security risk analysis and risk management plan | Federal, 164.308(a)(1) | Documented; reviewed at least annually in practice | Risk analysis report, remediation plan |
| Workforce training | Federal, 164.530(b), 164.308(a)(5) | New hires; when policies change; annual in practice | Training log with dates and names |
| Signed B.A.A. with every P.H.I. vendor | Federal, 164.504(e), 164.314(a) | Before access; add the state "immediately" notice term | Executed agreement per vendor |
| Breach procedure with a 30-day target and Attorney General filing | Federal 164.402 to 164.410; RCW 19.255.010, 19.255.030 | Letters within 30 days; Attorney General web form if more than 500 residents | Incident log, risk assessment memo, filing confirmation, notice copies |
| Records request workflow | RCW 70.02.080; federal 164.524 | 15 working days; written delay notice to 21 working days | Request log with dates |
| Retention schedule | RCW 70.41.190 (hospitals, 26 years); Department of Health rules for other license types | Ongoing | Written schedule, destruction log |
| Consumer health data privacy policy, if non-patient health data is collected | RCW 19.373 | Before collection | Published policy, counsel data map |
One note on timing. The proposed update to the HIPAA Security Rule, published in January 2025, would add express requirements such as encryption and multifactor authentication. It is a proposal, not current law, and OCR is not enforcing it. Nothing in this guide depends on it.
---
FAQ
How fast must a Washington practice notify patients after a breach?
RCW 19.255.010(8) requires notice in the most expedient time possible and no more than 30 calendar days after discovery. A HIPAA covered entity that complies with the federal Breach Notification Rule for protected health information is deemed compliant under RCW 19.255.030, but the federal rule's 60-day ceiling is a ceiling, and 30 days is the safer operational target.
Does a Washington covered entity have to notify the Attorney General?
Yes, when more than 500 Washington residents are affected. RCW 19.255.030(1) keeps the Attorney General notice in RCW 19.255.010(7) in force for covered entities, on the federal notification timeline. The filing is made through the Attorney General's online web form.
How quickly must a Washington provider give a patient a copy of the record?
No later than 15 working days after a written request under RCW 70.02.080, or, if the record is in use or unusual circumstances delay handling, a written explanation and a date not later than 21 working days. That is shorter than HIPAA's 30 days and controls.
Does the My Health My Data Act apply to HIPAA covered entities?
Its exemptions cover protected health information, information handled under RCW 70.02, and 42 CFR Part 2 records, so a practice's patient data is outside the act. Health-related data collected from people who are not patients, for example through a marketing website or an advertising pixel, can be consumer health data under RCW 19.373 and should be mapped with counsel.
Who enforces HIPAA in Washington?
OCR enforces the federal rules. The Washington Attorney General enforces the breach statute and the My Health My Data Act under the Consumer Protection Act, both of which also allow private suits, and patients can sue directly under the Uniform Health Care Information Act (RCW 70.02.170) with attorneys' fees to the prevailing party.
Conclusion
The federal program comes first: risk analysis, written policies, workforce training, and signed B.A.A.s. The Washington layer is a breach procedure with the 30-day Attorney General step, a records-request workflow built on 15 working days, and a retention schedule that matches the state rule for each facility type. One Guy Consulting's Full-Scope plan builds the federal program and documents the state overlay alongside it. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- RCW 19.255.010, Personal information, notice of security breaches, Washington State Legislature
- RCW 19.255.005, Definitions
- RCW 19.255.030, Federal law, covered entities, financial institutions
- RCW 19.255.040, Consumer protection
- RCW 70.02.080, Patient's examination and copying, requirements
- RCW 70.02.030, Patient authorization of disclosure
- RCW 70.02.220, Sexually transmitted diseases, permitted and mandatory disclosures
- RCW 70.02.230, Mental health services, confidentiality of records
- RCW 70.02.170, Civil remedies
- RCW 70.41.190, Medical records of patients, retention and preservation
- RCW 19.373.010, Definitions (My Health My Data Act)
- RCW 19.373.100, Exemptions (My Health My Data Act)
- RCW 19.373.090, Application of consumer protection act
- Washington Attorney General: Washington's Data Breach Notification Laws
- Washington Attorney General: My Health My Data Act FAQ
- Washington Attorney General: Data Breach Notifications Directory
- 45 CFR 160.203 (preemption of state law)
- 45 CFR 164.404 (breach notification to individuals)
- 45 CFR 164.524 (access of individuals to protected health information)
- 45 CFR 102.3 (civil money penalty amounts)
- HHS: Breach Notification Rule
Related Reading