Healthcare & Medical · United States

Your Health App Isn't Covered by HIPAA — But It Might Be Covered by This

A period tracker, a symptom checker, a fitness app that syncs to your doctor — none of these are bound by HIPAA in the way most people assume. Here's what actually protects that data.

The Common Misconception: HIPAA Doesn't Cover Most Health Apps

HIPAA applies to "covered entities" — doctors, hospitals, health plans, and their business associates — and the data they hold as part of providing or paying for care. A period-tracking app, a symptom checker, a fitness tracker, or a direct-to-consumer health app you downloaded yourself generally is not a HIPAA-covered entity, even though the data it collects feels just as sensitive. This gap is exactly what the FTC's Health Breach Notification Rule (HBNR) was built to address.

What Changed in 2024, and Why It Matters Now

The FTC finalized amendments to the HBNR that took effect July 29, 2024, explicitly clarifying that health apps, connected devices, and similar technologies not covered by HIPAA fall under this rule if they draw personal health information from multiple sources. The amendments also broadened what counts as a "breach" — it's not limited to a hacking incident. An unauthorized disclosure, such as an app sharing your health data with a third-party advertiser without your permission and contrary to its own stated privacy policy, counts as a breach under this rule, triggering the same notification obligations as a data hack would.

This distinction has real teeth. In prior enforcement actions that established the FTC's approach before the 2024 amendments, the agency took action against GoodRx, a prescription discount app, and Easy Healthcare, maker of the fertility-tracking app Premom, for sharing users' health information with advertising platforms without proper authorization — cases the FTC has pointed to directly as the model for how it will apply the updated rule going forward.

What the Rule Actually Requires

If a covered health app or service experiences a breach — including an unauthorized disclosure — of your identifiable health information, it must notify you, and if the breach affects 500 or more people, it must also notify the FTC and, in some cases, the media. The rule extended the deadline for notifying the FTC of larger breaches to give companies more time to investigate before reporting, but the obligation to notify affected individuals remains a core requirement.

What This Means Practically

Related Kibbo Tools

Sources