You entered your symptoms into an app. You tracked your period. You logged your weight. You bought a test. But who else can see that information?
"Not Covered by HIPAA" Doesn't Mean "Unregulated"
Most consumer health apps — period trackers, symptom checkers, weight-loss and telehealth platforms, prescription discount apps — are not HIPAA-covered entities. That doesn't mean they operate in a legal vacuum. The FTC has been explicit that these companies remain subject to the FTC Act's prohibition on unfair and deceptive practices, and to the Health Breach Notification Rule specifically when they draw personal health data from multiple sources and experience an unauthorized disclosure.
A Pattern of Real Enforcement, Not a Hypothetical Risk
Over the past several years, the FTC has taken action against a consistent pattern of health apps sharing user data with advertising platforms, contrary to their own privacy promises:
- GoodRx — the prescription discount and telehealth platform paid a $1.5 million penalty and was banned from sharing user health data for advertising, after sharing data with Facebook, Google, and other companies for years despite its own privacy promises.
- BetterHelp — the online therapy platform was ordered to pay $7.8 million in consumer refunds over sharing sensitive mental health information with advertising platforms.
- Premom — the fertility-tracking app paid $100,000 for disclosing users' health data to third parties including Google.
- Cerebral — the telehealth provider disclosed sensitive data belonging to about 3.2 million consumers, including medical and prescription histories, to LinkedIn, Snapchat, and TikTok via tracking tools, resulting in a proposed order barring most use or disclosure of that data for marketing.
In every case, the mechanism was largely the same: tracking pixels and software development kits embedded in the app or website that quietly passed user activity — sometimes including specific health conditions or search terms — to advertising and analytics platforms.
What "Private" Actually Needs to Mean in a Privacy Policy
A privacy policy stating your data is "private" or "secure" is a specific, enforceable claim under the FTC Act — not a vague marketing statement. If the company's actual practices contradict that stated promise, that gap is exactly what the FTC has repeatedly pursued as a deceptive practice. The presence of a privacy policy is not, by itself, evidence that your data is being handled the way the policy describes.
What This Means Practically
- Don't assume a health app is covered by HIPAA just because it deals with sensitive health information — most consumer-facing apps aren't.
- Read what a privacy policy actually says about third-party data sharing, not just whether one exists.
- Treat "unauthorized disclosure to an advertiser" as a real, enforceable violation if it happens to you — it's exactly what's been fined repeatedly, not just a theoretical concern.
- If you receive a data breach notification from a health app, take it seriously — this is precisely the category of company the Health Breach Notification Rule exists to cover.