PRIV-10 Privacy, Cyber & AI Data Under Duty Federal + state overlay
Health Data Outside HIPAA: Apps, Wearables, and Consumer Health Rules
HIPAA follows the entity, not the data. This brief maps the rules that reach health information held by apps, wearables, and consumer services, and where the private-suit risk sits.
Briefing in 60 seconds
- HIPAA applies to covered entities and business associates, so most apps, wearables, and consumer health services fall entirely outside it.
- The FTC reaches that data through Section 5 and the Health Breach Notification Rule, amended in 2024 to cover health apps and connected devices explicitly.
- Washington's My Health My Data Act carries a private right of action, which makes it the highest-exposure consumer health statute in the country.
- State comprehensive privacy laws classify health data as sensitive, requiring opt-in consent and a documented assessment before processing begins.
Controlling variables
- Status
- Whether the organization is a covered entity or business associate at all, since that single question decides whether HIPAA or the consumer regimes apply.
- Facts
- Whether the data identifies or could reasonably be linked to a consumer and relates to past, present, or future physical or mental health status.
- Jurisdiction
- Whether Washington residents are reached, because that statute's private right of action changes the exposure profile more than any other single variable.
- Documents
- Whether separate, purpose-specific consent and, for any sale, a separate signed authorization exist and predate the collection or disclosure at issue.
- Timing
- When tracking technologies were deployed relative to the consent flow, since pixel and SDK disclosures are usually continuous rather than one-time events.
General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.
HIPAA follows the entity, not the data. It reaches health plans, health care clearinghouses, and health care providers that transmit certain transactions electronically — plus the business associates that serve them. A blood pressure reading in a hospital chart is protected. The identical reading in a consumer app, synced from a watch the person bought themselves, generally is not.
That gap is not unregulated. It is regulated by a different stack: the FTC Act, the Health Breach Notification Rule, state consumer health statutes, and the sensitive-data provisions of the comprehensive state privacy laws. One of those statutes carries a private right of action, which is where the money risk concentrates.
Who is actually covered, and who only thinks they are
| Who holds it | HIPAA? | What governs instead |
|---|---|---|
| Hospital, clinic, or health plan | Yes, as a covered entity | Privacy, Security, and Breach Notification Rules; state medical confidentiality law layered on top. |
| Vendor processing data for a covered entity | Yes, as a business associate | The business associate agreement plus direct statutory liability for defined obligations. |
| Direct-to-consumer app or wearable | Generally no | FTC Act Section 5; Health Breach Notification Rule; state consumer health statutes; sensitive-data rules. |
| Employer wellness program | Depends on structure | Group health plan components may be covered; the employer's own records generally are not, and separate employment statutes apply. |
| Life, disability, or property insurer | Usually no | State insurance privacy regimes and general consumer protection law. |
| Ad tech and analytics vendors | No, unless serving a covered entity under an agreement | Consumer health statutes, sensitive-data consent rules, and unfairness and deception theories. |
Two structural notes. HIPAA does not preempt stricter state law, so a covered entity is not exempt from state consumer health statutes for every activity it conducts. And a business can be partly covered — a telehealth arm inside a broader consumer product is a common structure — which means the analysis has to be run per data flow rather than per company. The current framework as administered by HHS is the starting point, but concluding "we are not a covered entity" ends only the HIPAA question.
The federal stack: Section 5 and the Health Breach Notification Rule
The Federal Trade Commission operates on two tracks here. Section 5 reaches misrepresentations about how health information is handled and practices that cause substantial unavoidable consumer injury. The Commission has brought a series of actions against consumer health services alleging that data was shared with advertising platforms contrary to promises made in privacy policies and in-app statements, with orders imposing monetary relief, bans on sharing health data for advertising, and requirements to direct third parties to delete data already received.
The second track is the Health Breach Notification Rule, which applies to vendors of personal health records and related entities that are not HIPAA-covered. The FTC amended the rule in 2024 to make its application to health apps and connected devices explicit, and the amendments matter more than they sound. A "breach of security" under the rule includes an unauthorized disclosure — not only a security failure — so routine data sharing without authorizing consent can itself be a reportable breach. Notice obligations run to affected individuals, to the FTC, and, above a threshold, to media.
The enforcement record predates the amendments. The Commission's first action under the rule, resolved in 2023, involved a prescription discount service alleged to have shared health information with advertising platforms; a second followed months later involving a fertility-tracking app. Both were framed as unauthorized disclosures rather than intrusions.
Read the trigger carefully: under this rule, "breach" does not require a hacker. Deploying an advertising pixel that transmits health-related events without valid authorization can be the reportable event, which is why tag inventories belong in the compliance program and not only in the marketing backlog.
State consumer health statutes, and the one with teeth
Washington's My Health My Data Act is the statute that changed the risk calculus. It defines consumer health data broadly — data linked or reasonably linkable to a consumer that identifies past, present, or future physical or mental health status, which by its terms sweeps in inferences, precise location near health facilities, and purchases of health-related goods. It requires disclosure through a separate consumer health data privacy policy, consent for collection and sharing that is separate from other consents, and a distinct signed authorization before any sale. It restricts geofencing around facilities providing health services. And it is enforceable by consumers through the state's consumer protection act.
That private right of action is the operative fact. As of mid-2026 the statute's outer boundaries — how broadly "reasonably linkable" reaches, what counts as a sale, how damages are measured — are being worked out in litigation rather than settled, so an organization sizing exposure should treat the scope as contested and moving. Nevada enacted a comparable statute without a private right of action, and Connecticut amended its comprehensive law to add consumer health data provisions, so the design pattern is spreading even where the remedy is not.
Underneath these sit the comprehensive state privacy laws, which classify health data as sensitive. That classification carries three consequences: opt-in consent before processing, a documented assessment before the processing begins, and heightened scrutiny of any sharing. The assessment mechanics are set out in privacy and data protection assessments, and the consent must survive the interface analysis in dark patterns and consent interfaces — a bundled acceptance of a general privacy policy does not carry opt-in consent for sensitive data. California's requirements are described through the state's CCPA resources.
Tracking technologies, the recurring failure
Nearly every enforcement action and class filing in this area traces to the same technical fact: a pixel, SDK, or analytics tag installed on a page or screen where the user's activity itself reveals health information. Appointment booking flows, symptom searches, condition-specific landing pages, and prescription refill screens all transmit meaning even when no diagnosis field is sent.
Federal health regulators issued guidance addressing tracking technologies on the sites of HIPAA-covered entities, and a portion of that guidance was vacated by a federal district court in 2024 in litigation brought by hospital groups. The practical effect is narrower than it is often described: the vacatur addressed the agency's guidance as applied to covered entities, and it did not disturb the FTC's authority over non-covered businesses, the Health Breach Notification Rule, or the state consumer health statutes. As of mid-2026 the covered-entity position on tracking guidance remains unsettled while the consumer-side rules continue to operate unchanged.
- Inventory every tag
List each pixel, SDK, session replay tool, chat widget, and analytics library, per page and per screen. Include tools added by marketing without engineering review, which is where most of them come from.
- Classify the surfaces
Mark any surface where the visit itself signals a health condition. Treat URL paths, page titles, form field names, and button labels as data, because they are transmitted as data.
- Trace what leaves
Capture the actual network traffic rather than reading the vendor's documentation. Identifiers commonly leave through referrer headers and query strings that no one intended to send.
- Fix consent or remove the tag
Where the surface is health-revealing, either obtain separate, specific consent that meets the applicable state standard or remove the tag from that surface. Server-side tagging changes the transport, not the legal analysis.
- Paper the downstream
Bind vendors to purpose limits, deletion on request, and a training-data clause preventing model training on the data, using the framework in contracting with AI vendors.
- Keep the evidence
Retain dated tag configurations and traffic captures. When a demand arrives about conduct two years old, the archive decides whether the company can describe what happened.
Two adjacent categories travel with health data and carry their own rules. Health-adjacent identity verification and access systems often derive a biometric identifier, discussed in biometric privacy laws. And any service that may reach minors triggers a separate consent architecture requiring verifiable parental consent before collection.
Questions the desk gets
Our app is not HIPAA-covered. Does that reduce our obligations?
It changes them rather than reducing them. HIPAA brings a detailed rulebook and a regulator that works through investigation and corrective action. The consumer stack brings broader definitions of health data, a breach rule that can be triggered by ordinary sharing, and at least one statute allowing consumers to sue directly. Many teams find the consumer regime harder to satisfy, not easier, because the definitions reach inferences.
Is a step count or sleep record health data?
Frequently yes under the broader state definitions, which reach data that identifies past, present, or future physical or mental health status, including inferences. Fitness metrics alone may sit at the edge, but combined with app usage, purchases, or location near a treatment facility they land inside. The safer working rule is to classify by what the data can reveal about a person's condition, not by the label on the field.
Does a business associate agreement solve the problem?
Only for the HIPAA relationship it governs. A BAA does not authorize sharing with advertising platforms, does not satisfy a state consumer health consent requirement, and does not apply at all to data collected outside the covered-entity relationship. Companies with both a covered arm and a consumer arm should map the data flows separately and avoid letting the BAA stand in for the consumer-side analysis.
If we de-identify, are we outside these rules?
Sometimes, and the standard is stricter than the practice. HIPAA sets defined de-identification methods, while the state statutes require that data not be reasonably linkable, that controls prevent reidentification, and that the business commit publicly not to attempt it and bind recipients likewise. Hashed identifiers shared with advertising platforms have repeatedly been treated as identifying, because the recipient can match them.
What happens to this data in an acquisition?
It travels with constraints attached. Consent obtained for one purpose does not automatically support a buyer's different purposes, and several state statutes treat a change of use as requiring fresh consent even where the transfer itself is permitted. Diligence should confirm what was disclosed, what consent was captured, and whether the data was ever shared in ways that create an unresolved liability.
Where the exposure concentrates
Three things drive nearly all of the risk. What the marketing and analytics stack transmits from health-revealing surfaces. Whether consent for sensitive data was collected separately and specifically rather than bundled into a terms acceptance. And whether Washington residents are in the user base, since that is the jurisdiction where a consumer can bring the claim directly.
Work in that order: inventory the tags, fix the consent, then size the state footprint. Set retention deliberately for anything health-related, because these categories are the ones where excess retention converts into breach population and litigation scope, using the approach in data retention schedules and deletion obligations. Structuring the program against the NIST Privacy Framework and the FTC's privacy and security guidance gives the record a shape regulators recognize. Related material sits on the Privacy, Cyber & AI desk.
Sources
Atlas Research Desk
ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.