Most health apps are not covered by HIPAA. HIPAA applies to health plans, health care clearinghouses and most health care providers, plus the companies that work for them. A fitness tracker, diet app, period tracker, meditation app or AI chatbot that you download yourself usually falls outside it. The Federal Trade Commission puts it bluntly: “many companies that collect people’s health information – whether it’s a fitness tracker, a diet app, a connected blood pressure cuff, or something else – aren’t covered by HIPAA.”
That doesn’t mean those apps can do anything they like. It means different, generally weaker, rules apply. This guide covers U.S. law and is general information, not legal advice.
Who does HIPAA actually cover? #
HIPAA’s privacy rules bind two groups:
- Covered entities: health plans (insurers, HMOs, employer health plans, Medicare and Medicaid), health care clearinghouses, and health care providers such as doctors, hospitals, clinics and pharmacies that handle billing electronically.
- Business associates: companies that handle health information on behalf of a covered entity, such as a billing service or a patient-portal vendor working for your hospital.
HIPAA follows who holds the data and why, not what kind of data it is. Your heart rate is protected when your cardiologist’s office stores it. The same heart rate in a smartwatch app you bought is not protected by HIPAA. The U.S. Department of Health and Human Services explains this line in its guidance on health apps.
When is a health app covered by HIPAA? #
The question to ask is who offers the app and for whom.
| App | Covered by HIPAA? | Why |
|---|---|---|
| Your hospital’s or doctor’s patient portal app | Yes | Run by or for a covered provider |
| An app your health insurer provides | Usually yes | Offered by a health plan |
| A telehealth service billing your insurance | Usually yes | Acting as a provider |
| A fitness tracker or smartwatch app | Usually no | Consumer product you chose |
| Diet, sleep, period or meditation apps | Usually no | Consumer products |
| An app you connect to your medical records | Usually no, for the copy it holds | You chose to send your data there |
| An AI chatbot you ask about symptoms | No | Consumer service |
That second-to-last row catches people out. You can ask your provider to send your records to an app of your choice. Once your records land in an app you picked, which isn’t working for your provider, HIPAA generally no longer covers that copy. The app’s own privacy policy does.
What protects your health data if HIPAA doesn’t? #
Several other rules can apply, depending on where you live.
The FTC Act. The Federal Trade Commission can act against companies whose privacy promises are deceptive or whose practices are unfair. If a health app says it won’t share your data and then does, that’s the FTC’s territory. It has brought cases against health services, including GoodRx in 2023, over sharing health information for advertising.
The FTC’s Health Breach Notification Rule. This rule covers health apps and connected devices that aren’t subject to HIPAA. Amendments in July 2024 made clear, in the FTC’s words, that “makers of health apps, connected devices, and similar products must comply with the Rule.” If your health data is breached, which includes unauthorized sharing, the company has to notify you “without unreasonable delay” and within 60 calendar days, and notify the FTC. See the FTC’s guide to the rule.
State privacy laws. California residents can direct businesses to limit how they use sensitive personal information, which includes health data, and can ask businesses to delete what they hold. Several other states have comprehensive privacy laws, and Washington’s My Health My Data Act specifically targets consumer health data.
Outside the U.S. In the European Union, the GDPR treats health data as a special category with stricter rules for any company, app makers included.
None of these give you HIPAA’s specific rights, such as its rules on who a provider may share your records with. Notification after a breach is not the same as protection before one.
How to check a health app before you use it #
- Find out who runs it. Is it your provider or insurer, or a consumer company? That decides whether HIPAA is in play at all.
- Search the privacy policy for “sell,” “share,” “advertising,” “partners” and “de-identified.” Vague answers to those are an answer.
- Read the store privacy label. It shows what’s collected and whether it’s linked to you or used for tracking. Our guide to AI app privacy labels explains how to read them.
- Check the permissions it wants. A step counter doesn’t need your contacts. Deny what the feature doesn’t need.
- Look for export and delete options. Can you download your data and delete your account from inside the app?
- Prefer apps that keep data on your device when a feature doesn’t need a server. Data that never leaves your phone can’t be shared, sold or breached from a company’s servers.
A general checklist for AI apps is in how to tell if an AI app is really private.
Is it safe to put health questions into an AI chatbot? #
Cloud chatbots such as ChatGPT, Gemini and Claude aren’t HIPAA covered entities when you use their consumer apps. What you type about a symptom, a diagnosis or a medication is stored under their privacy policies, may be reviewed by staff, and may be used for training unless you opt out. We cover the details in is it safe to ask ChatGPT health questions.
If you want to think through a health question without it sitting on anyone’s server, Personal LLM runs AI models entirely on your phone. There’s no account, the chat never leaves the device, and it works in airplane mode, so there’s no company holding a log of your health questions. It’s a general-purpose chat app, not a medical device. Small models can be wrong with confidence, so use it to understand terms or prepare questions for your doctor, not to diagnose or decide on treatment.
Frequently asked questions #
Is Apple Health covered by HIPAA? #
Not for the data you collect yourself. Apple isn’t acting as your health care provider or health plan when you use the Health app, so Apple’s own privacy commitments and consumer protection law apply instead of HIPAA. Records your provider sends to the app through a patient portal were covered while your provider held them, not once they’re in an app you chose.
Are period tracking apps protected by HIPAA? #
Generally no. Period and fertility apps are consumer products, so HIPAA doesn’t apply unless your provider or health plan offers the app. Their privacy policy, the FTC’s rules and any state laws where you live govern what they can do with your data.
Can a health app sell my data? #
It depends on the app’s privacy policy and your state’s laws. HIPAA doesn’t stop a consumer app from sharing data, but the FTC can act if an app breaks its own promises or shares health data without proper notice, and some states require consent or let you opt out. Read the policy before you enter anything sensitive.
Is my doctor’s app HIPAA compliant? #
If your doctor, hospital or insurer provides the app, it’s covered by HIPAA and should follow its rules, typically through a vendor that signs a business associate agreement. If a third-party app merely connects to your records at your request, it usually isn’t covered for the data it holds.
Does HIPAA apply to wearables like Fitbit or Apple Watch? #
Not when you buy and use them yourself. The data they collect is consumer health data, covered by the maker’s privacy policy, the FTC’s Health Breach Notification Rule and state laws, but not HIPAA. It can become HIPAA-covered if you share it with your doctor and they store it in your medical record.