, 8 min read
Does HIPAA protect the health data in your apps?
HIPAA covers doctors, hospitals and insurers, not most apps you download yourself. What does apply, eight questions to ask any app, and how Lifelong answers.

Co-founder & CEO, Lifelong
HIPAA usually does not protect the health data in an app you download yourself. It applies to doctors, hospitals, insurers and the companies working for them. Most consumer health apps answer to other laws instead: the FTC Act, the FTC's Health Breach Notification Rule and state health data laws. This post is general information, not legal advice.
Who does HIPAA cover?
HIPAA covers two groups: covered entities and their business associates. The US Department of Health and Human Services (HHS) says that only health plans, health care clearinghouses and most health care providers are covered entities. A business associate is a company that handles identifiable health information on behalf of one of them, such as a firm a hospital pays to run its patient portal.
Everyone else is outside. HHS: "If an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA Rules."
So HIPAA follows the holder of the data. A blood test result is protected by HIPAA while it sits in your hospital's system. Type the same result into an app you chose, and HIPAA has nothing to say about that copy.
Does HIPAA cover a health app I download myself?
HIPAA usually does not cover a health app you download and fill in yourself. HHS published worked examples for app developers, and three of them settle most cases:
- A person downloads an app and enters her own blood glucose and blood pressure readings. The developer is not a business associate.
- A person downloads her records from her doctor's patient portal and uploads them into an app. The developer is still not a business associate, because nothing indicates the provider hired the developer.
- A provider contracts with a developer for patient management services and directs the patient to download the app. That developer is a business associate.
The test is who the app works for. If your clinic or insurer hired the developer, HIPAA probably reaches the app. If you found it yourself, or your doctor only recommended it, HIPAA probably does not.
A HIPAA badge on a consumer app deserves a second look. The FTC tells businesses not to make false or misleading claims that they are "HIPAA Compliant", "HIPAA Secure" or "HIPAA Certified".
What protects health data in a US app that HIPAA does not cover?
A US health app that HIPAA does not cover is still subject to the FTC Act. If it holds a personal health record it is also subject to the FTC's Health Breach Notification Rule, and in some states to a consumer health data law.
The FTC Act. The FTC Act prohibits unfair or deceptive acts or practices, and the FTC says its obligations apply to "companies that collect, use, or share health information that aren't required to comply with HIPAA". The agency reads "health information" widely: anything that enables an inference about your health counts, including location data showing a visit to a cancer center.
The Health Breach Notification Rule. This FTC rule requires vendors of personal health records that HIPAA does not cover to notify the people affected, the FTC and, in some cases, the media after a breach of unsecured identifiable health data. People must be told without unreasonable delay and within 60 calendar days of the breach being discovered. A breach includes a company's own unauthorized disclosure of your data, as well as a break-in. The FTC finalized changes to the rule in April 2024, and in September 2026 described that update as covering "health apps and connected devices like fitness trackers".
State laws. Washington's My Health My Data Act is, in the words of the Washington Attorney General, "the first privacy-focused law in the country to protect personal health data that falls outside the ambit of" HIPAA. The Act lets a consumer find out whether a business is collecting, sharing or selling their health data, withdraw consent, and have the data deleted. Selling it requires a separate authorization signed by the consumer. Both the Attorney General and a consumer can enforce it.
Nevada's Senate Bill 370, passed in 2023, is now part of the Nevada Revised Statutes. A business it regulates may not collect or share consumer health data without the consumer's affirmative, voluntary consent, with limited exceptions such as providing a product or service the consumer asked for. The Connecticut Data Privacy Act applies to every business that controls consumer health data and operates in the state, whatever its size, and prohibits selling that data without the consumer's consent.
What has the FTC done about health apps sharing data?
The FTC brought three cases in 2023 over health data shared for advertising. Each summary below is the FTC's account of its own allegations.
- BetterHelp. The FTC finalized an order in July 2023 requiring the online counseling service to pay $7.8 million and banning it from sharing consumers' health data for advertising. It had alleged that BetterHelp shared health questionnaire information with Facebook, Snapchat and others after promising to keep it private.
- GoodRx. In February 2023, in its first enforcement action under the Health Breach Notification Rule, the FTC said GoodRx shared users' prescription medications and health conditions with Facebook, Google and others, and displayed a seal falsely suggesting it complied with HIPAA. GoodRx agreed to a $1.5 million civil penalty and a ban on sharing user health data for advertising, in an order a federal court entered that month.
- Premom. In May 2023 the FTC charged that Easy Healthcare, the fertility app's developer, disclosed users' health data to AppsFlyer and Google. The proposed order, which needed a federal court's approval, set a $100,000 civil penalty and barred the company from sharing personal health data for advertising.
In the GoodRx and Premom cases, the breach the FTC alleged was the company's own disclosure of its users' data, followed by a failure to tell them.
What should you ask a health app before you trust it?
Ask a health app these eight questions before you put a family's records into it. The answers should be in writing, in its privacy policy or on its security page.
- Are you covered by HIPAA, and do you say so plainly? A consumer app that says "HIPAA compliant" without saying which hospital or insurer it works for has not answered the question.
- Do you sell my data or share it for advertising? Search the policy for "sell", "advertising" and "partners". Look on the homepage for a separate consumer health data privacy policy, which the Washington Attorney General says a business covered by the Act must link there.
- Which other companies receive my data? Look for a section on service providers or processors, and read the analytics and advertising tools closely.
- Is my data used to train AI models? Search for "train" and "improve our services", and check that the answer covers the app's AI vendors as well as its own models.
- Who at the company can read my records? Look for how data is encrypted and for who has access to production data.
- Has anyone independent checked your security? Look for a named audit or certification with a date. "Bank-grade" and "military-grade" are adjectives.
- Can I get a copy of everything, and delete everything? Look under "your rights". A good answer includes a number of days.
- What happens after a breach, a sale or a shutdown? Look for "breach", "business transfer" and "discontinue". The terms of service often hold the shutdown answer.
If a policy does not answer one of these, write to the privacy address it lists and ask.
How does Lifelong handle your family's health data?
Lifelong's answers are in our Privacy Policy, our Consumer Health Data Privacy Policy and our security page. The short version:
- The laws that apply. You bring your own health information to Lifelong, so the rules that apply to us are the consumer ones above. Our Privacy Policy lists them, including the FTC Act, the FTC Health Breach Notification Rule and Washington's My Health My Data Act.
- Selling and advertising. Lifelong does not sell personal information and does not share it for cross-context behavioral advertising. We do not disclose your information to insurers, employers, credit agencies, data brokers or advertising platforms.
- Other companies. Lifelong uses service providers for cloud hosting, AI processing, authentication, payments, communications and analytics. The Consumer Health Data Privacy Policy lists what each category receives, and on request we will send you the list of third parties your health data has been shared with.
- AI training. Lifelong does not train AI models on your identifiable health data, and our AI vendors are contractually prohibited from training on what we send them.
- Encryption and access. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Staff access to production data is limited to need-to-know and logged.
- Copy and delete. You can get a copy of your data in a structured, machine-readable format by emailing privacy@trylifelong.com. Deletion from our live systems is completed within 45 days of a verified request, and copies in encrypted backups expire within 7 days after that.
- Breach, sale, shutdown. If a breach affects your health information, we will notify you and the appropriate regulators as the FTC Health Breach Notification Rule, the GDPR and applicable state laws require. An acquirer would be bound by our Privacy Policy, and we will notify you before a different one applies, with the chance to delete your account first. If we shut Lifelong down, our Terms give you at least 30 days to export your data.
The longer versions are in the FAQ.
Sources
- US Department of Health and Human Services: Covered Entities and Business Associates
- US Department of Health and Human Services, Office for Civil Rights: Health App Use Scenarios & HIPAA (February 2016)
- Federal Trade Commission: Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule
- Federal Trade Commission: Complying with FTC's Health Breach Notification Rule
- Federal Trade Commission: FTC Finalizes Changes to the Health Breach Notification Rule (26 April 2024)
- Federal Trade Commission: FTC Withdraws Obsolete Policy Statement (9 September 2026)
- Federal Trade Commission: FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising (14 July 2023)
- Federal Trade Commission: FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising (1 February 2023)
- Federal Trade Commission: Ovulation Tracking App Premom Will be Barred from Sharing Health Data for Advertising Under Proposed FTC Order (17 May 2023)
- Federal Trade Commission: GoodRx Holdings, Inc. (case file, with the stipulated order entered by the court on 17 February 2023)
- Washington State Attorney General: Protecting Washingtonians' Personal Health Data and Privacy
- Washington State Legislature: Chapter 19.373 RCW, Washington My Health My Data Act
- Nevada Revised Statutes, Chapter 603A: Security and Privacy of Consumer Health Data (NRS 603A.400 to 603A.550, added by Senate Bill 370 of 2023)
- Connecticut Office of the Attorney General: The Connecticut Data Privacy Act
Lifelong is a health information tool, not medical care. Nothing here is medical advice; for a decision about someone’s health, talk to their doctor. Medical disclaimer.
