← Back to all articles

What Small Businesses in Washington State Need to Know About IT Compliance in 2026


Washington State has some of the strictest data breach and health data privacy laws in the country. This guide breaks down which compliance frameworks apply to small businesses, what cyber insurers are actually asking for, and how to figure out where your gaps are before an auditor or attacker does it for you.

Most Small Businesses Do Not Know Which Compliance Rules Apply to Them

There is a common assumption among small business owners that compliance is something only hospitals and banks need to worry about. That assumption is wrong, and it is getting more expensive every year.

If your business stores customer names and email addresses, processes credit cards, handles employee health plan data, or collects any form of personal health information, you almost certainly fall under at least one regulatory framework. In Washington State specifically, the rules are stricter than the national baseline, and enforcement is picking up.

The problem is not that business owners are careless. The problem is that nobody has explained this clearly without trying to sell them something first. This article attempts to fix that.

Washington State Breach Notification: The 30-Day Clock

Washington's data breach notification law (RCW 19.255.010) requires businesses to notify affected individuals within 30 calendar days of discovering a breach. That is significantly shorter than what most other states require, and it catches a lot of businesses off guard.

The law applies to any business that owns or licenses computerized data containing personal information about Washington residents. Personal information under this statute includes Social Security numbers, driver's license numbers, financial account numbers, and health information when combined with a person's name.

If a breach affects more than 500 Washington residents, you must also notify the state Attorney General. The notification must include specific details about what happened, what data was involved, and what you are doing about it.

Thirty days sounds like enough time until you realize that most small businesses do not have an incident response plan. Without one, the first several days after discovering a breach are spent figuring out what happened, who to call, and what to do. By the time you have answers, the deadline is already close.

The My Health My Data Act Is Broader Than You Think

Washington's My Health My Data Act took effect in 2024, and it applies to far more businesses than the name suggests. This is not limited to healthcare providers or companies covered by HIPAA.

The law covers any entity that collects, shares, or sells health data from Washington consumers. Health data under this law includes fitness information, reproductive health data, biometric data, mental health information, and data related to bodily functions or vital signs. If your business runs a wellness program, collects health screening data for employees, or operates any kind of health-adjacent app or service, this law likely applies to you.

The Act requires businesses to obtain opt-in consent before collecting health data, maintain a consumer health data privacy policy, and honor deletion requests. Violations carry enforcement by the state Attorney General and a private right of action, meaning individuals can sue directly.

HIPAA Is Not Just for Hospitals

HIPAA's Security Rule applies to covered entities and their business associates. If your company provides any service that involves accessing, transmitting, or storing protected health information on behalf of a healthcare provider, health plan, or clearinghouse, you are a business associate and HIPAA applies to you.

This catches a lot of small businesses by surprise. IT companies that support medical practices, billing services, document storage providers, cloud service vendors, and even janitorial companies with access to areas where patient records are stored can qualify as business associates.

The Security Rule requires administrative safeguards like workforce training and access controls, physical safeguards like facility security, and technical safeguards like encryption and audit logging. It also requires a formal risk assessment, which is the single most common item that small businesses are missing.

Penalties for HIPAA violations start at $141 per violation and can reach over $2 million per violation category per year. The Office for Civil Rights has been increasing enforcement against small providers and business associates, not just large health systems.

What Cyber Insurers Are Actually Asking For

Cyber insurance questionnaires have gotten significantly more detailed over the past two years. Insurers are no longer satisfied with "do you have antivirus" as a checkbox item. Current applications routinely ask about multi-factor authentication coverage, endpoint detection and response deployment, backup and recovery procedures, email filtering, privileged access management, and employee security awareness training.

The critical detail that many businesses miss is that cyber insurance applications are legally binding documents. If you state on your application that you have MFA deployed across all remote access and email, and then a breach occurs because an account without MFA was compromised, the insurer can deny your claim. This has already happened in multiple court cases.

The baseline controls that most insurers now expect include MFA on all external-facing services and email, endpoint detection and response software on all workstations and servers, regular patched and updated systems, encrypted and tested backups stored offline or in immutable storage, email filtering with anti-phishing capabilities, and a documented incident response plan.

If you do not have these controls in place, getting a cyber insurance policy is either going to be very expensive or impossible. If you do have them and you document that fact accurately, your premiums will reflect the reduced risk.

PCI-DSS: If You Take Credit Cards

The Payment Card Industry Data Security Standard applies to any business that accepts, processes, stores, or transmits credit card data. For most small businesses, this means completing a Self-Assessment Questionnaire annually and maintaining a set of security controls.

The most common compliance gap for small businesses is not having a documented process for how card data flows through their systems. If you use a point-of-sale terminal that connects to the internet, if you take payments over the phone, or if you process online orders, PCI-DSS applies.

The standard requires network segmentation, access controls, encryption of card data in transit, regular vulnerability scanning, and maintaining a security policy. Noncompliance can result in fines from your payment processor and increased transaction fees, along with liability exposure if a breach occurs.

How to Figure Out Where You Stand

The first step is identifying which frameworks apply to your business. This depends on your industry, what kind of data you handle, whether you take credit cards, and whether you do business with healthcare organizations.

Once you know which rules apply, conduct a gap assessment. Compare what the framework requires against what you actually have in place. Be honest about this. The goal is not to pass a test but to find the gaps before someone else finds them for you.

Common gaps for small businesses include no formal risk assessment documentation, no written incident response plan, MFA not deployed on all accounts, no endpoint detection and response software, backups that exist but have never been tested, no employee security awareness training, and no encryption on laptops or portable devices.

Each of these gaps is fixable. Most of them do not require massive budgets. They require attention, documentation, and follow-through.

Where to Start

Pick the framework that carries the highest risk for your business and start there. For most Washington State businesses, that means getting your breach notification response plan in order first, since 30 days is not a lot of time if you are starting from zero.

From there, address the controls your cyber insurer requires, since those overlap heavily with most compliance frameworks anyway. MFA, endpoint protection, backup testing, and employee training cover a large percentage of requirements across HIPAA, PCI-DSS, and general security best practices.

Document everything. Compliance is not just about having controls in place. It is about being able to prove you have them in place. Written policies, configuration records, training logs, and test results are what auditors and insurers want to see.

If you need a starting point, Rain City Techworks built a free compliance readiness checker that walks you through a few questions about your business and tells you which frameworks apply and where your gaps are. It takes about two minutes and does not require an email address or account.


Rain City Techworks provides managed IT services for businesses throughout the Seattle, Tacoma, and Puget Sound region. Learn more at rain-city.tech.





Author: Todd, Founder and Lead Engineer at RainCity Techworks


rain-city.tech
RainCity Techworks
https://rain-city.tech Flip