Do Medical Privacy Laws Cover Health Tracking Apps?
Understanding when HIPAA and other privacy rules protect your data in fitness, wellness, and health tracking apps.
Health and wellness apps now track everything from steps and heart rate to sleep, fertility, and mental health. Many people assume these apps are protected by the same medical privacy laws that apply to hospitals and clinics. In most cases, that assumption is wrong.
This article explains when laws like the Health Insurance Portability and Accountability Act (HIPAA) apply to health tracking apps, when they do not, and what other rules may govern how your data is used and shared. It also offers practical tips and answers common questions so you can make more informed choices about your digital health tools.
Why Health Tracking Apps Raise New Privacy Questions
Traditionally, health data lived in paper charts or in electronic health record systems controlled by doctors, hospitals, and insurers. Today, vast amounts of sensitive information are generated and stored on personal devices, cloud servers, and third-party platforms.
Examples of popular apps and devices include:
- Fitness trackers that log steps, heart rate, and exercise routines
- Diet and weight management apps that record calories, weight, and body measurements
- Period and fertility apps that track menstrual cycles, sexual activity, and pregnancy status
- Sleep and stress monitoring tools that collect biometric data, mood ratings, or journal entries
- Remote monitoring apps prescribed by providers to track chronic conditions, medications, or symptoms
Some of these tools are directly connected to healthcare organizations. Others are purely consumer products available in app stores and never integrated into your formal medical record. That distinction is crucial for understanding whether medical privacy laws apply.
HIPAA Basics: What the Law Actually Covers
HIPAA is the main U.S. federal law governing the privacy and security of certain health information. To understand when it applies to apps, you need to know three core concepts:
- Covered entities
These are health plans, most healthcare providers (like doctors and hospitals), and healthcare clearinghouses. HIPAA directly regulates how they use, disclose, and protect certain health information. - Business associates
These are companies that perform specific services for covered entities involving protected health information (PHI), such as cloud hosts, billing services, or certain health IT vendors. - Protected health information (PHI)
PHI is individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate in connection with care, payment, or operations.
HIPAA does not automatically cover all health-related data. Instead, it protects information only when it meets the legal definition of PHI and is handled by covered entities or their business associates in the context of healthcare activities.
When Health Apps Are Subject to HIPAA
Some apps fall squarely inside HIPAA because they are integrated into clinical care or health plan programs. These typically involve a formal relationship with a healthcare organization and a written Business Associate Agreement (BAA) between the app provider and the covered entity.
Common situations where HIPAA applies include:
- An app provided by your hospital or physician practice for secure messaging, appointment scheduling, or viewing your medical records
- A health plan’s app for claims, benefits, and managed care programs that display identifiable member health data
- A remote monitoring app prescribed by a provider to track blood pressure, glucose, or other vitals, where the app vendor acts as a business associate
- A portal or mobile interface to an electronic health record (EHR), used under the control of a covered entity
In these arrangements, the app’s handling of PHI must comply with HIPAA’s privacy and security rules. For example, if the app uses online tracking technologies on authenticated pages that process PHI, those technologies must be configured so any collected data is used and disclosed consistent with HIPAA and kept secure as electronic PHI (ePHI).
Key features of HIPAA-covered apps
If an app is truly HIPAA-covered, you can expect:
- Formal privacy and security safeguards designed to meet HIPAA standards
- Restrictions on how PHI can be used for marketing or analytics without your authorization
- Rights to access and obtain copies of your PHI, request corrections, and receive a notice of privacy practices
- Obligations to notify you and regulators in case of certain data breaches
However, these protections only exist within the scope of the covered entity–business associate relationship and apply specifically to PHI.
When Health Apps Are Not Covered by HIPAA
Most consumer health and wellness apps fall outside HIPAA, even when they collect highly sensitive data such as fertility, weight, mental health, or exercise patterns.
According to official guidance and legal analyses:
- HIPAA rules generally do not apply to health information created or stored directly on personal cell phones, tablets, or consumer devices when handled outside of covered entities and business associates.
- Apps that users download on their own for fitness, period tracking, or general wellness are typically not covered entities and do not become business associates unless they formally act on behalf of a healthcare organization with a BAA.
- Even if data in the app originally came from a provider (for example, a patient requests their record and then uploads it to a third-party app), once the information is received by an app that is neither a covered entity nor a business associate, HIPAA protections generally do not apply to that app’s subsequent use or disclosure of the data.
In practice, this means many popular apps can collect, combine, and share health-related information with marketers, analytics services, or other partners, subject mainly to their own privacy policies and to applicable consumer protection and state privacy laws—not to HIPAA.
Illustrative comparison: HIPAA vs non-HIPAA apps
| Scenario | Example app | HIPAA likely applies? |
|---|---|---|
| Hospital-prescribed remote monitoring | Blood pressure app integrated with your clinic’s system, under a BAA | Yes, the app vendor is a business associate handling PHI. |
| Consumer fitness tracker | Step-counting, heart rate tracker you downloaded from an app store | Generally no; not a covered entity or business associate. |
| Health plan member portal | Insurer’s official app showing claims and benefits | Yes, the health plan is a covered entity. |
| Period-tracking app | Independent menstrual cycle tracker with social or analytics features | Typically no, unless operated for a covered entity under a BAA. |
| Personal health record chosen by consumer | Standalone app where you manually enter your health history | Generally no, if not acting for a covered entity. |
Other Laws That May Govern Health Apps
Even when HIPAA does not apply, health app developers and platforms are not operating in a legal vacuum. Several other laws and regulatory tools can affect how health data is handled.
Federal Trade Commission (FTC) enforcement
The U.S. Federal Trade Commission enforces consumer protection laws that prohibit unfair or deceptive practices. It has published tools and guidance specifically for mobile health app developers.
The FTC focuses on issues such as:
- Whether a company’s privacy policy or marketing claims accurately describe how data is collected, used, and shared
- Whether reasonable security measures are in place to protect sensitive user information
- Whether companies comply with specialized rules, such as the Health Breach Notification Rule, when certain personal health records are compromised
Children’s Online Privacy Protection Act (COPPA)
Health apps targeting children may be subject to COPPA. Before collecting children’s data—such as contact information, persistent identifiers, photos, videos, or geolocation—operators must provide parental notice and obtain verifiable parental consent. They must also maintain reasonable procedures to protect the confidentiality, security, and integrity of children’s information.
State privacy and data breach laws
Many U.S. states have enacted privacy statutes and data breach notification laws that apply to a wide range of consumer data, including health-related information handled outside HIPAA. These laws may:
- Require disclosure of certain data practices
- Mandate safeguards for sensitive personal information
- Specify notice obligations in the event of a security incident
As a result, a non-HIPAA app may still have legal obligations, but those obligations differ from HIPAA and vary across jurisdictions.
Common Risk Patterns in Non-HIPAA Apps
Legal analyses and investigative reporting have highlighted several recurring privacy risks in consumer health apps, especially period trackers and fitness tools.
- Extensive data sharing
Some apps share health-related data with advertising networks, analytics providers, or social media platforms, sometimes in ways users might not expect. This can include cycle data, exercise patterns, or location information. - Broad or vague privacy policies
Policies may allow wide use and disclosure of user data, including for marketing or research, without clearly explaining specific partners or purposes. - Limited user control
Users may have few options to limit certain types of data sharing or to fully delete their data from company systems. - Lack of strong security requirements
Where HIPAA does not apply and no equivalent security framework is adopted, safeguards may vary significantly between apps.
In some situations, providers may send PHI to a third-party app at the patient’s request. Guidance indicates that if the transmission is made under the individual’s explicit direction to a non-covered app, the healthcare provider generally is not liable for what happens to the data after it reaches that app. That reality places much of the risk on individuals.
Practical Steps for Users to Protect Their Data
Although the legal landscape is complex, users can take concrete steps to reduce privacy risks when using health tracking apps. Many digital rights advocates and regulators recommend focusing on a few key areas.
1. Check who operates the app
- Look for clear identification of the app developer and whether the app is affiliated with a healthcare provider or health plan.
- If an app is offered directly by your clinic or insurer, it is more likely to fall under HIPAA, but you should still review their notices of privacy practices.
2. Read privacy policies—critically
- Search for statements about data sharing with advertisers, analytics firms, or third parties.
- Note how long data is retained and whether you can delete it.
- Check whether location data, device identifiers, or other tracking technologies are used and for what purposes.
3. Adjust settings and permissions
- Turn off location services for apps that do not genuinely need your precise location.
- Limit sharing features that send your health metrics to social networks or public leaderboards.
- Use in-app privacy controls to opt out of certain data uses where available.
4. Separate clinical and consumer tools
- Use official provider or health plan apps for tasks involving diagnoses, test results, or clinical messaging, where HIPAA protections are more clearly defined.
- Consider what you choose to duplicate into non-HIPAA consumer apps, particularly highly sensitive information.
5. Be cautious with “free” apps
- Recognize that if you are not paying money, your data may be part of the business model.
- Balance convenience against the potential long-term sensitivity of the information being collected.
FAQ: Medical Privacy Laws and Health Tracking Apps
Does HIPAA apply to my fitness tracker?
In most cases, no. Consumer fitness trackers and wellness apps that you download on your own are typically not HIPAA-covered entities and do not become business associates unless they formally perform services for a provider or health plan involving PHI under a BAA.
Are period-tracking apps protected by HIPAA?
Generally no. Investigations and legal analyses have found that most period tracking apps are outside HIPAA because they are not operated by covered entities or business associates. Their data practices are instead governed by their privacy policies and applicable consumer and state laws.
If my doctor sends my data to an app I chose, is the doctor responsible?
Guidance indicates that when a patient directs their healthcare provider to transmit PHI to a third-party app that is neither a covered entity nor a business associate, HIPAA’s protections do not extend to that app, and the provider generally does not bear responsibility for any misuse by the app.
What other laws protect my health app data?
Depending on the app and context, your data may be protected by FTC consumer protection rules, COPPA for children, state privacy and data breach laws, and platform policies. These laws differ from HIPAA and provide varying levels of protection.
How can I tell if an app is HIPAA-compliant?
Look for clear indications that the app is operated by or on behalf of a healthcare provider or health plan, and whether it is described as part of clinical care or benefits management. Developers working as business associates often reference HIPAA compliance and BAAs, but such claims should be weighed against how the app actually handles data.
References
- Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates — U.S. Department of Health and Human Services. 2022-12-01. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
- Mobile Health App Interactive Tool — Federal Trade Commission. 2016-04-01 (tool updated periodically). https://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool
- Healthcare Apps and Data Privacy/Security Risks — American Institute of Healthcare Compliance. 2019-07-01. https://aihc-assn.org/healthcare-apps-and-data-privacy-security-risks/
- Federal Patient Privacy Law Does Not Cover Most Period-Tracking Apps — ProPublica. 2022-07-08. https://www.propublica.org/article/period-app-privacy-hipaa
- New Health Apps May Pose Challenges to Patient Privacy — Neurology Advisor. 2016-02-19. https://www.neurologyadvisor.com/features/new-health-apps-may-pose-challenges-to-patient-privacy/
- Do Fitness Apps Need to Be HIPAA Compliant? When It Applies and When It Doesn’t — Accountable. 2023-06-15. https://www.accountablehq.com/post/do-fitness-apps-need-to-be-hipaa-compliant-when-it-applies-and-when-it-doesn-t
- Health Data Not Covered by HIPAA — Florida Coastal School of Law Library Guide. 2020-01-01. https://fclawlib.libguides.com/HIPAA/notHIPPAA
Read full bio of medha deb





