---
title: "Does HIPAA Cover Health Apps? The Honest Answer"
description: "Most people assume HIPAA protects the data in their health apps. It usually does not. Here is what actually protects you, and what to check before signing up."
keywords: "does hipaa cover health apps, hipaa health apps, does hipaa protect health app data, are health apps private, health app privacy laws"
date: "2026-09-18"
---


![Smartphone and smartwatch showing a health app hero](/images/does-hipaa-cover-health-apps-hero.webp)

Most people assume that anything health-related is protected by HIPAA. It feels obvious. Your doctor's records are protected, so your heart rate data should be too.

**It is not. HIPAA almost never covers the health apps on your phone.** If you download an app from the App Store to track your sleep, your workouts, or your diet, that data usually sits outside HIPAA's reach entirely. It does not matter how sensitive the data is. It matters who holds it.

HIPAA is a 1996 law that protects information handled by doctors, hospitals, and health insurance companies. It was written before a single fitness tracker existed. When you hand your health data to a consumer app, you are handing it to a company the law never mentions. Other rules apply instead, some strong and some weak. This post explains the difference, plus a five-item checklist to use before you sign up for any health app.

## The short answer

- **HIPAA covers doctors, hospitals, and health insurance companies.** It does not cover apps you download yourself, even apps that store your medications, moods, or symptoms.
- **Your doctor's office is protected. The app that syncs with your doctor's office may not be.** What matters is who holds the data, not what kind of data it is.
- **The FTC's Health Breach Notification Rule is the main law that does apply.** It forces non-HIPAA companies to tell you when they have a breach of your health data.
- **The FTC enforces that rule.** In 2023 it fined GoodRx $1.5 million for sharing users' health data with advertisers, and ordered BetterHelp to pay $7.8 million for sharing mental health data with Facebook and Snapchat.
- **A 2024 update made the rules stricter for apps.** It confirmed that health apps and connected devices are covered by the FTC rule.

## Does HIPAA cover health apps?

In nearly every case, no.

HIPAA's rules apply to what the law calls "covered entities." The Department of Health and Human Services, or HHS, lists three groups: health care providers like doctors and clinics, health plans like insurance companies and Medicare, and health care clearinghouses. Clearinghouses convert health data between formats. HIPAA also covers "business associates," companies that handle health data for those three groups under contract.

A health app you download on your own is none of these things. You are not its patient. You are not its insurance customer. The app is not working under contract for your doctor. So HIPAA does not apply.

The FTC says this plainly in its guidance for businesses. HIPAA governs health records for most hospitals, doctors' offices, and insurance companies. Many companies that collect health information, whether it is a fitness tracker, a diet app, or a connected blood pressure cuff, are not covered by HIPAA.

This surprises people for a good reason. Apps often display seals that imply medical-grade privacy. In the GoodRx case, the FTC said the company displayed a seal on its website falsely suggesting it complied with HIPAA. A badge is not a law. A "HIPAA compliant" label in an app's marketing means nothing unless HIPAA actually applies to that company, and for a consumer app, it usually does not.

One more nuance. If your doctor's office shares your records with an app through a formal arrangement, the provider still carries HIPAA duties for its own side of that exchange. But the app's own use of the data, its advertising partners, and its security practices are governed by other rules, or by nothing at all.

## What protects your health app data instead?

Two federal rules do most of the work.

The first is the FTC Act. It is a general consumer protection law. Section 5 of the act makes it illegal for companies to mislead consumers or to engage in practices that harm them unfairly. If a health app promises in its privacy policy that it will never sell your data, and then sells your data, the FTC can take action for deception. That is true even though no specific health privacy law covers the app.

The second is the Health Breach Notification Rule, also from the FTC. Congress directed the FTC to create it in 2009. It applies to companies that are not covered by HIPAA. That includes vendors of personal health records. The FTC describes these as apps that collect identifiable health information from multiple sources and let the individual manage and share it. If a covered company has a breach of unsecured health data, it must notify every affected person, the FTC, and in some cases the media. The deadline is 60 calendar days from discovery. The FTC's guidance puts the civil penalty at up to $53,088 per violation as of 2025.

The rule has a feature people often miss. The FTC's own FAQ says a "breach" is not limited to hackers. If a company shares your identifiable health information without your authorization, that counts as a breach. Sending your prescriptions and mobile identifiers to an ad network is one example. Disclosure without consent triggers the same duties as a hack.

## What did the FTC do about GoodRx and BetterHelp?

These two cases show what happens when apps misuse health data. Both are from 2023, and both were the first of their kind.

**GoodRx, February 2023.** GoodRx offers prescription drug discounts and telehealth visits. According to the FTC's complaint, the company shared users' health information with advertising platforms since at least 2017. The platforms included Facebook, Google, and Criteo. The shared data included prescription medications and health conditions. The FTC said GoodRx had promised users it would never share personal health information with advertisers, then broke that promise. In one example from August 2019, GoodRx uploaded the email addresses, phone numbers, and mobile advertising IDs of users who had bought medications for heart disease and blood pressure to Facebook. Facebook then targeted those users with ads. The FTC said GoodRx also failed to report these disclosures as required by the Health Breach Notification Rule. It was the FTC's first enforcement action under that rule. GoodRx paid a $1.5 million civil penalty and agreed to a permanent ban on sharing user health data for advertising.

**BetterHelp, March 2023.** BetterHelp is an online counseling service. To sign up, users filled out a questionnaire asking about depression, suicidal thoughts, and medications. Despite promises to keep that data private, the FTC said BetterHelp shared users' email addresses, IP addresses, and health questionnaire answers with Facebook, Snapchat, Criteo, and Pinterest for advertising. It even instructed Facebook to find people similar to its users, targeting ads at people who had been in therapy. The proposed order required BetterHelp to pay $7.8 million, which went back to consumers as partial refunds, the first time the FTC had returned money to consumers whose health data was compromised. BetterHelp was also banned from sharing health data for advertising and ordered to direct third parties to delete the data it had shared.

The lesson from both cases is the same. Neither company was covered by HIPAA, but both still broke the law by lying about privacy and failing the FTC rules.

## What did the 2024 rule update change?

In April 2024, the FTC finished an update to the Health Breach Notification Rule, its first major revision since 2009. The changes matter for anyone using consumer health apps. Four stand out.

First, the updated rule makes it explicit that health apps and connected devices are covered. The FTC amended definitions so that makers of health apps, wearables, and similar products fall under the rule, not just the personal health record websites of 2009.

Second, the definition of a breach now includes unauthorized disclosures, not just data security incidents. If an app shares your health data without permission, that alone can be a reportable breach.

Third, breach notices must include more detail. Companies must tell you which third parties received your health data in the breach and what kinds of health information were involved, such as diagnoses, lab results, medications, or your use of a health app. Notices must be clear and reasonably understandable, and the FTC now allows email, text, in-app messages, or website banners instead of only paper mail.

Fourth, the timing rules were tightened. For breaches involving 500 or more people, a company must notify the FTC at the same time it notifies the affected individuals, within 60 calendar days of discovery.

The update took effect 60 days after it appeared in the Federal Register in 2024. The practical result for you: if a health app shares or loses your data without your consent, the company owes you a faster, clearer, more complete explanation than it did before 2024.

## What are the gaps left over?

Even with the FTC rules, health app privacy has real holes.

The Health Breach Notification Rule tells you after a breach. It does not stop a company from selling your health data, as long as the policy disclosed that possibility. Some states fill part of that gap. Washington's My Health My Data Act, for example, requires consent before collecting or selling consumer health data and gives people a right to delete it. But many states have no equivalent law.

De-identification is another gap. Companies sometimes claim shared data is anonymous. Researchers have shown it can often be traced back to a person with statistical methods, because a few data points like location, age, and sleep patterns point to one individual. Treat "anonymized" as a spectrum, not a guarantee.

Finally, the CNET reporting on AI health coaches makes a current-technology point. These chatbots get real-time access to your biometric data. Many do not cite sources or explain where their advice comes from. The privacy terms often allow your history, location, and chat logs to train future models. HIPAA does not apply, so it would never catch that use.

## What are the 5 things to check before you hand over your data?

Read the privacy policy with these five questions in mind. It takes about ten minutes.

1. **Does the app sell or share health data with third parties, especially advertisers?** Search the policy for the words "share," "sell," "partners," and "advertising." A policy that says data is shared with "trusted partners" for "improving services" is leaving the door open. If the app is free and shows ads, assume your data is the payment.

2. **Is the claim "HIPAA compliant" meaningful here, or decorative?** For a consumer app, HIPAA usually does not apply, so the claim may just be marketing. What you want instead is a plain statement of what the company collects, who it goes to, and how long it is kept.
3. **Where is the data processed and stored, and on device or in the cloud?** An app that computes scores on your iPhone or Apple Watch never has to ship raw health data to a server. Cloud-processed data can be breached, subpoenaed, or used for research. This is the single biggest architectural difference between health apps, and it is often stated in one sentence in the policy.
4. **Does the company say what happens after a breach?** Under the FTC rule, a covered app must notify you within 60 days and say which third parties got your data. That only applies if the app is actually covered. Look for a security page or breach commitment. If there is nothing, treat that as an answer.
5. **Can you get your data out and have it deleted?** Look for an export feature and a deletion request in the settings. If the policy describes deletion but the app offers no way to trigger it, that mismatch is a red flag.

Two quick habits round this out. Check the App Store privacy label, which lists data linked to you and data used to track you. And search the company's name plus "FTC" or "privacy complaint" before signing up.

## FAQ

**Is Apple Health HIPAA compliant?**
Apple Health is not a HIPAA covered entity, so the question is a bit off. HIPAA does not apply to Apple for data you generate on your own, just as it does not apply to any consumer app. What Apple does promise is that much of your Health data is encrypted and processed on your device, and Apple publishes detailed platform privacy documentation. That is a company policy backed by its platform design, not a federal health privacy law covering the data.

**Can health apps sell my data?**
Yes, some can, and some have. Outside HIPAA, selling health data can be legal if the privacy policy discloses it. The FTC has punished companies for sharing health data after promising not to, under the FTC Act and the Health Breach Notification Rule. The rule limits what a covered app can do, but the practical protection is the policy itself. Read it before signing up.

**What happens if a health app gets breached?**
If the app is covered by the FTC's Health Breach Notification Rule, and most consumer health apps are after the 2024 update, it must notify affected people within 60 calendar days, notify the FTC, and in some cases notify the media. The notice must describe what happened, what kinds of health data were involved, and which third parties received data. Companies face civil penalties of up to $53,088 per violation for failing to comply.

**Does HIPAA protect my data when I use a telehealth app?**
Sometimes. If the telehealth company delivers care under contract with a health plan or provider, parts of the interaction can fall under HIPAA. If you sign up on your own as a consumer, the company may still not be a HIPAA covered entity, and the FTC rules apply instead. GoodRx and BetterHelp were both telehealth-adjacent companies that HIPAA did not protect.

**What is the difference between HIPAA and the FTC's rules?**
HIPAA protects health data held by health care providers, health plans, and clearinghouses, and it gives patients rights like access to their records. The FTC's rules apply to companies outside HIPAA. The FTC Act bans deceptive practices, so a health app that lies about privacy can face action. The Health Breach Notification Rule requires non-HIPAA companies to report breaches of health data. Think of it this way: HIPAA covers the data, and the FTC rules cover everyone HIPAA forgot.

## Sources

1. [Complying with the FTC's Health Breach Notification Rule](https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0), Federal Trade Commission, July 2024.
2. [Updated FTC Health Breach Notification Rule puts new provisions in place to protect users of health apps and devices](https://www.ftc.gov/business-guidance/blog/2024/04/updated-ftc-health-breach-notification-rule-puts-new-provisions-place-protect-users-health-apps), FTC Business Blog, April 30, 2024.
3. [FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising](https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising), Federal Trade Commission, February 1, 2023.
4. [FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising](https://www.ftc.gov/news-events/news/press-releases/2023/03/ftc-ban-betterhelp-revealing-consumers-data-including-sensitive-mental-health-information-facebook), Federal Trade Commission, March 2, 2023.
5. [Covered Entities and Business Associates](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html), U.S. Department of Health and Human Services, reviewed August 21, 2024.
6. [AI Health Coaches: The Next Frontier in Wearables or Privacy Nightmare?](https://www.cnet.com/tech/mobile/ai-health-coaches-the-next-frontier-in-wearables-or-privacy-nightmare/), CNET, by Vanessa Hand Orellana.

## Related reading

- [Health Apps That Don't Sell Your Data: A Privacy Guide](/blog/health-apps-that-dont-sell-your-data)
- [Can You Trust AI Health Coaches?](/blog/ai-health-coaches-can-you-trust-them)
- [The Best AI Health Coach for Apple Watch](/blog/best-ai-health-coach-for-apple-watch)

Ness was built with these questions in mind. Ness turns your Apple Watch and Apple Health data into health scores, with its AI coach running anonymized, zero-data-retention queries and scores computed on your device rather than a server. It costs $12.99/mo monthly or $79.99/yr yearly, and you can download it on the [App Store](https://apps.apple.com/us/app/ness/id6758977081). Read our privacy policy before you sign up. We wrote it to pass the checklist above.

*Nothing here is medical advice. Health apps and wellness scores are tools, not diagnoses; if you have symptoms or a health condition, see a physician.*
