Back to Blog
Best Practices February 24, 2025 4 min read

The First Health Data Privacy Lawsuit Is Here. Health Publishers, Audit Now

A class action filed Feb. 10 is the first under Washington's My Health My Data Act, and New York just passed a stricter bill. Here is what health and wellness publishers should review.

HR
HBDR Research
February 24, 2025

What happened

On February 10, 2025, a Washington state resident filed a proposed class action against Amazon, the first lawsuit brought under the private right of action in Washington's My Health My Data Act (MHMDA). The complaint alleges that an advertising SDK embedded in third-party mobile apps collected precise, time-stamped location data and mobile advertising IDs without the consent the law requires, and that location data can reveal health information, such as visits to clinics. These are allegations, and the case is at its earliest stage. Law firm Byte Back's summary lays out the claims.

Two weeks earlier, on January 22, New York's legislature passed the New York Health Information Privacy Act. As of this writing it still awaits the governor's action. As passed, it would bar selling regulated health information and require a separate authorization before processing it for many purposes, with regulated health information defined broadly as information reasonably linkable to an individual or a device and collected or processed in connection with physical or mental health. WilmerHale's overview covers the details.

Why this matters beyond apps and retailers

MHMDA took effect March 31, 2024. It is unusual among state privacy laws because it covers consumer health data held by companies outside HIPAA, applies regardless of company size, and lets consumers sue directly. Its definition of consumer health data is broad and can include inferences drawn from non-health data. The first lawsuit shows plaintiffs' firms are now testing it.

For health and wellness publishers, the risk is not that your content is illegal. It is that the ad and analytics stack on a page about diabetes, pregnancy, mental health or cancer can turn a page view into health-related data about an identifiable browser or device, and then pass it to partners. A symptom-checker page with a dozen third-party tags looks very different through this lens than it did two years ago.

A practical audit for health publishers

1. Map where health signals are created

List the sections and templates that could reveal a condition or treatment: condition hubs, symptom tools, medication pages, quizzes, newsletters by topic and appointment or provider finders. These are your sensitive surfaces.

2. Inventory what fires on those surfaces

For each sensitive template, record every script: bidders, identity modules, audience data providers, retargeting pixels, analytics and embedded video. Note which ones receive the page URL, keywords or content categories, because a URL like /conditions/depression/treatment is itself a health signal.

3. Decide what should never leave

Common, defensible choices include:

  • Removing audience-building and retargeting pixels from sensitive templates entirely.
  • Stopping user syncs and identity modules on those pages.
  • Passing generalized content categories to bidders (for example, a broad health category) rather than specific condition keywords or full URLs.
  • Excluding sensitive sections from any audience segments you build or sell.

4. Check consent where the law requires it

MHMDA requires consent before collecting and sharing consumer health data, with separate consent for sharing. If any tag on your sensitive pages could fall within that definition for Washington users, your consent flow has to reflect it, and the default before consent should be off.

5. Review apps and SDKs

If you have a mobile app, list every SDK and its data access. The Washington case centers on location data collected through an ad SDK in someone else's app. Your app's location permission should not become a pipeline to partners you have not vetted.

6. Don't forget analytics and on-site tools

Ad tags get the attention, but analytics platforms, session replay tools, chat widgets and A/B testing scripts often capture full URLs, search terms and form inputs. On a health site, an on-site search for a medication or a completed symptom quiz can be more revealing than any ad request. Check what these tools collect on sensitive templates, where it is stored and who can access it. Disable URL query capture and form field recording where they are not strictly needed, and review retention settings so data is not kept longer than its purpose requires.

What about revenue?

Health is a strong vertical for advertisers, and much of its value is contextual. Pharmaceutical, insurance and wellness brands want to appear next to relevant, trustworthy content. That demand does not depend on tracking individuals across the web. Publishers who keep rich, accurate contextual signals while cutting individual-level data flows on sensitive pages usually preserve most of the value that matters to those buyers, and they are far easier to sell to brand-conscious advertisers.

Practical steps that protect both sides:

  • Package contextual deals by condition area and content type for direct and private marketplace buyers.
  • Set floors by section so high-value health content is not sold at run-of-site prices.
  • Keep ad quality controls tight. Block categories that erode trust on medical content, and review creative for misleading health claims.

What to watch

More states are moving on sensitive data. Maryland's Online Data Privacy Act, effective October 1, 2025, prohibits the sale of sensitive data, which includes consumer health data. Nevada has its own consumer health data law. New York's bill, if signed, would take effect a year later. The direction is consistent: health-related data used for advertising will face tighter rules, not looser ones.

On health content, the safest data is the data you never send. Build monetization on context and trust, not on following readers.

If your stack is managed by a partner, ask for a page-level tag report on your most sensitive templates. It should take hours, not weeks, to produce.

Tags: health privacy sensitive data sdk compliance

Ready to maximize your ad revenue?

Get Started