Data at HCA

Data is one of the Health Care Authority's (HCA) most valuable assets, helping strengthen our ability to make decisions based on reliable, timely, and accurate information.

Core principles

  • Integrity: Data should be as accurate, complete, consistent, valid, and reliable as possible.
  • Security and privacy: Data should be properly handled and protected from unauthorized access, disclosure, and destruction.
  • Standardization: Data should be handled in a way that allows for predictability and controlled variation.
  • User experience: Data should be usable and add value.

How does HCA use data?

Data strategy

Read our data strategy overview to learn more about how we manage our data for accuracy, reliability, security, and best user experience. The full data strategy details how we aim to accomplish our goals.

Data Governance

Data Governance serves to organize and implement structures that support HCA’s ability to create, protect, and share quality data. These structures include policies, procedures, standards, and roles that enable the effective use of HCA’s data assets.

It operates within an ecosystem consisting of several committees and workgroups designed to ensure that everyone plays their part and is heard. Each group serves a distinct purpose in supporting HCA’s comprehensive data strategy.

Data requests

Before requesting data, please review our list of dashboards and reports. The data you're looking for may already be available.

Start a request for data by contacting HCA's Data Governance Team.

We process requests in the order received. Requests are prioritized based on many factors including the type of request:

  • HCA's required reporting to authorizing environments
  • Partner agency requests
  • Program evaluation and research
  • As-needed requests

HCA will offer to discuss your request with you within one month of receiving it. This discussion is to help with refinements, estimate timelines, and discuss costs.

Request considerations

We consider data requests based on:

  • Our governance committee schedule
  • How the request aligns with our mission, vision, and values
  • How the request complies with laws and regulations
  • Our staff capacity to fulfill the request
  • Subject matter expertise availability

Public disclosure requests

Data is not a public record and data requests do not follow Washington’s public records act. Read more about HCA's public records request process.

Data request fees

Effective July 1, 2026, HCA may charge fees as part of the request process. The minimum fee for each request is $2,000 plus $100 for each staff hour spent fulfilling the request. Costs apply to new requests and to modifying existing data products. Examples of existing data products are on our dashboards and reports page

Category 1 data

Static reports containing only category 1 data may not require a data request. These reports must meet the following conditions:

  • Category 1 data, containing:
    • No protected health information (PHI)
    • No direct or indirect identifiers, such as dates of service or client ZIP code
    • Small numbers are suppressed
  • Nonrepeatable (one-time)
  • Will not require a contract or data sharing agreement

Static reports such as these can be found under Reports on our Data and reports page.

Public disclosure requests

Public disclosure requests and data required as part of an audit are handled by our Public Disclosure and Audit and Accountability offices. They may not require a Data Request Form. To learn more, visit our Public Records Center.

Data request process

Various groups at HCA support this effort. The data type and sensitivity determine what level of review and vetting is required for the data to be released.

  • Data Governance Team: Will facilitate the review process and communicate with applicants on the process and feedback.
  • Privacy Office: Review request to ensure compliance with HIPAA, other federal and state laws, and data categorization.
  • Security Office: Review request to ensure contractor can comply with State practices for securely storing and accessing information.
  • Data Utilization Committee (DUC): Reviews requests for new contracts, research, and external publishing of data products.
  • Data Utilization Subcommittee (SubDUC): Reviews requests for contract modifications, renewals, and consults on potential data shares.
  • Contracts: Ensures data share agreement and contractual terms are up to date.

Contact