Skip to main content

How does Cyber Crucible support Washington's My Health My Data Act?

Short answer: Washington's My Health My Data Act regulates "consumer health data" broadly and carries a private right of action, so vendors that touch such data face real exposure. Cyber Crucible does not collect consumer health data — it analyzes process and memory behavior on the endpoint and never ingests customer content — so it does not create the collection-and-consent surface the Act is written to govern.

Why there is little surface

  • No consumer health data collected. Cyber Crucible does not gather health-related content, identifiers, or inferences.
  • Local processing. Analysis stays on the device; there is no vendor-held health data set.
  • No sale or sharing of personal information of any kind.

Vendor-selection notes

The Act's private right of action makes health-data vendors a scrutiny focus; Cyber Crucible is simply not in that category. This can be confirmed in the data governance documentation available on request. This is not legal advice — a covered entity should assess its own obligations with counsel.