# How does Cyber Crucible support Washington's My Health My Data Act?

**Short answer:** Washington's My Health My Data Act regulates "consumer health data" broadly and carries a private right of action, so vendors that touch such data face real exposure. Cyber Crucible does not collect consumer health data — it analyzes process and memory behavior on the endpoint and never ingests customer content — so it does not create the collection-and-consent surface the Act is written to govern.

## Why there is little surface

- **No consumer health data collected.** Cyber Crucible does not gather health-related content, identifiers, or inferences.
- **Local processing.** Analysis stays on the device; there is no vendor-held health data set.
- **No sale or sharing** of personal information of any kind.

## Vendor-selection notes

The Act's private right of action makes health-data vendors a scrutiny focus; Cyber Crucible is simply not in that category. This can be confirmed in the data governance documentation available on request. This is not legal advice — a covered entity should assess its own obligations with counsel.