Nevada SB 370 Compliance for Consumer Health Data

Nevada SB 370 is a consumer health data privacy law, in effect since March 31, 2024. It covers health information collected by businesses that are not subject to HIPAA, such as med spas, gyms, wellness coaches and health apps. It requires consent, a health data privacy policy, limited access and reasonable security. Our managed security plans support the security side for Reno, Sparks and Carson City businesses.

A quick check.

SB 370 may apply if all of these are true:1

  • You do business in Nevada or market to Nevada consumers.
  • You collect, use, share or sell information that identifies a person's past, present or future physical or mental health status. That can include data derived from purchases, app activity or location near health facilities.
  • You are not a HIPAA covered entity or business associate for that information, and the data is not otherwise exempt (for example, GLBA, FCRA or FERPA data).

There is no revenue threshold, so a five-person med spa can be covered.

Businesses HIPAA does not cover.

  • Med spas and aesthetics clinics
  • IV therapy and wellness clinics
  • Gyms, fitness studios and personal trainers
  • Nutrition, wellness and health coaches
  • Supplement and wellness product sellers
  • Health, fitness and period-tracking apps

Practices that are covered by HIPAA should start with our HIPAA security compliance page instead.

What SB 370 asks of regulated businesses.

Summary of Nevada SB 370 obligations (not legal advice)
RequirementWhat it meansWho handles it or how we support it
Consumer health data privacy policyPublish how you collect, use and share health dataYour attorney
Affirmative consentSeparate, voluntary consent to collect and to share health data, with limited exceptionsYour attorney and website team
Authorization to sellWritten authorization from the consumer before any sale of health dataYour attorney
Consumer rightsHonor requests to access, delete and withdraw consentYour team, with process support
Limited accessOnly people who need health data can reach itYour business; our plans support it with zero trust access controls
Reasonable securityPolicies and practices that protect health dataYour business; our plans support it with monitoring, MFA, training and vCISO guidance
Processor contractsVendors that process health data for you must be under contractYour attorney, with vCISO guidance on vendor risk
No geofencingNo virtual fences within 1,750 feet of health facilities to track people or send them health-related messagesYour marketing team

SB 370 vs HIPAA vs NRS 603A.

Three Nevada-relevant rules for personal and health information
Nevada SB 370HIPAANRS 603A
CoversConsumer health data outside HIPAAProtected health information held by covered entities and business associatesPersonal information of Nevada residents as the law defines it, such as names with SSNs or account numbers
Main dutiesConsent, privacy policy, access limits, reasonable securityPrivacy, Security and Breach Notification RulesReasonable security and breach notification
Enforced byNevada Attorney GeneralHHS Office for Civil Rights, and state attorneys generalState of Nevada

The security side of SB 370.

SB 370 is mostly a privacy law, and your attorney should own the consent, policy and authorization pieces. Our plans support the security pieces, protecting health data and limiting who can reach it:

Many of these businesses sit close to healthcare, so our healthcare cybersecurity page may also help.

This page is general information about Nevada SB 370 and is not legal advice. Consult your attorney about how the law applies to your business.

Nevada SB 370 FAQ

Generally no. Information covered by HIPAA, and entities subject to HIPAA such as covered health care providers and their business associates, are exempt. SB 370 is aimed at health data collected outside HIPAA.
It can. The law covers businesses that conduct business in Nevada or target Nevada consumers and that collect, use or share consumer health data. Many med spas, fitness studios, wellness coaches, supplement sellers and health apps are not HIPAA covered entities and may fall under SB 370. Your attorney can confirm.
No. Unlike many state privacy laws, SB 370 does not set a revenue or data-volume threshold, so small businesses are not automatically excluded.
SB 370 does not create a private right of action. Violations are treated as deceptive trade practices, which the Nevada Attorney General can enforce. Other legal remedies may still exist, so ask your attorney.
The two laws are similar in scope and structure, but Washington's law allows consumers to sue, while Nevada's is enforced by the state. Businesses operating in both states should review both.
SB 370 requires regulated entities to limit access to consumer health data to the people who need it and to maintain reasonable security policies and practices to protect it. The law does not list specific controls, but reasonable security commonly includes access controls, MFA, monitoring, staff training and vendor contracts, which our managed security plans and vCISO guidance support.

Find out where your business is exposed.

Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.