A period tracker, a symptom checker, a fitness app that syncs to your doctor — none of these are bound by HIPAA in the way most people assume. Here's what actually protects that data.
The Common Misconception: HIPAA Doesn't Cover Most Health Apps
HIPAA applies to "covered entities" — doctors, hospitals, health plans, and their business associates — and the data they hold as part of providing or paying for care. A period-tracking app, a symptom checker, a fitness tracker, or a direct-to-consumer health app you downloaded yourself generally is not a HIPAA-covered entity, even though the data it collects feels just as sensitive. This gap is exactly what the FTC's Health Breach Notification Rule (HBNR) was built to address.
What Changed in 2024, and Why It Matters Now
The FTC finalized amendments to the HBNR that took effect July 29, 2024, explicitly clarifying that health apps, connected devices, and similar technologies not covered by HIPAA fall under this rule if they draw personal health information from multiple sources. The amendments also broadened what counts as a "breach" — it's not limited to a hacking incident. An unauthorized disclosure, such as an app sharing your health data with a third-party advertiser without your permission and contrary to its own stated privacy policy, counts as a breach under this rule, triggering the same notification obligations as a data hack would.
This distinction has real teeth. In prior enforcement actions that established the FTC's approach before the 2024 amendments, the agency took action against GoodRx, a prescription discount app, and Easy Healthcare, maker of the fertility-tracking app Premom, for sharing users' health information with advertising platforms without proper authorization — cases the FTC has pointed to directly as the model for how it will apply the updated rule going forward.
What the Rule Actually Requires
If a covered health app or service experiences a breach — including an unauthorized disclosure — of your identifiable health information, it must notify you, and if the breach affects 500 or more people, it must also notify the FTC and, in some cases, the media. The rule extended the deadline for notifying the FTC of larger breaches to give companies more time to investigate before reporting, but the obligation to notify affected individuals remains a core requirement.
What This Means Practically
- Don't assume a health or fitness app is bound by HIPAA just because it deals with sensitive health data — check its privacy policy for what it actually says about data sharing.
- An app sharing your data with an advertiser without your clear authorization is treated as a "breach" under federal law, not just a privacy policy violation — you're entitled to notification if this happens.
- If you receive a breach notification from a health app, take it seriously — this rule exists specifically because this category of company sits outside HIPAA's normal protections.
- You can report a suspected violation directly to the FTC.
Related Kibbo Tools
Sources
- Federal Trade Commission — Complying with FTC's Health Breach Notification Rule. ftc.gov
- Federal Register — Health Breach Notification Rule final amendments, May 2024. federalregister.gov