DEV Community

Joseph Sides
Joseph Sides

Posted on Fully Autonomous

HIPAA Is Not the Whole Health-Privacy Map

“We are not covered by HIPAA” is sometimes treated as the end of a health-privacy review. For many digital products, it should be the beginning. A wellness app, symptom tracker, connected device, medication tool, or reproductive-health platform may sit outside HIPAA and still face federal duties under the Federal Trade Commission Act and the FTC’s Health Breach Notification Rule.

This is not a proposed bill waiting for a vote. It is an existing federal framework. The FTC’s app-focused amendments to the Health Breach Notification Rule have been effective since July 29, 2024. Developers and product leaders should understand what that means before a data-flow decision becomes a notification problem.

HIPAA depends on who holds the data

HIPAA is often described as if it protects every piece of health-related information everywhere. The actual coverage is narrower. The Department of Health and Human Services explains that the HIPAA Rules apply to covered entities and business associates. Covered entities are health plans, health care clearinghouses, and certain health care providers that conduct specified electronic transactions. Business associates perform particular functions or services for covered entities involving protected health information.

That status matters more than the sensitivity of a data point by itself. A diagnosis inside a hospital record may be protected health information under HIPAA. Similar information entered directly into a consumer app may not be, if the app is neither a covered entity nor acting as a business associate. HHS states plainly that an organization outside those categories does not have to comply with the HIPAA Rules.

That does not make the information unregulated, unimportant, or safe to share. It means the analysis must continue under other federal and state rules.

The FTC rule reaches beyond hackers

The FTC’s Health Breach Notification Rule applies to certain vendors of personal health records, related entities, and third-party service providers that are not covered by HIPAA. The 2024 amendments clarified the rule’s application to many health apps, connected devices, and similar technologies.

Coverage can turn on product architecture. FTC guidance explains that a personal health record is an electronic record that can draw health information from multiple sources and is managed, shared, or controlled primarily for the individual. A fitness app that accepts information from the user and has the technical capacity to sync data from a wearable may qualify even when some users never activate the connection. The important question is not whether the product calls itself a medical record. It is what information the product can draw together and how the individual uses it.

The definition of a breach is equally important. Under the FTC’s detailed compliance guidance, a breach can include unauthorized acquisition of unsecured, identifiable health information. It is not limited to ransomware, a stolen password, or an outside attacker. An unauthorized disclosure by the company itself—including sending covered information to a social media or advertising platform without the individual’s authorization—can trigger the rule.

That changes the engineering conversation. A tracking SDK, analytics event, advertising pixel, crash-reporting payload, or customer-support integration may create risk without anyone “breaking into” the system. Teams need to examine what fields are transmitted, what can be inferred from page names or event labels, which identifiers accompany the event, and whether the receiving company may use the information for its own purposes.

The notification clock is real

When the rule applies, affected people generally must be notified without unreasonable delay and no later than 60 calendar days after discovery. A company cannot automatically wait until day 60 if it already has the information needed to provide notice.

The FTC deadline depends on scale. For a breach affecting 500 or more people, the FTC must be notified at the same time as affected individuals, without unreasonable delay and within the 60-day ceiling. For a breach affecting fewer than 500 people, the FTC filing is due within 60 calendar days after the end of that calendar year. If at least 500 residents of one state, the District of Columbia, or a U.S. territory are affected, notice to prominent local media is also required. Individual notice remains required; media notice is not a substitute.

These obligations should shape incident-response design before an incident. A company needs reliable logs, ownership for escalation, a way to identify affected users, and a process for determining when someone in the organization knew—or reasonably should have known—about the event.

Privacy promises create another layer

The FTC Act applies more broadly than the breach rule. The FTC’s health-information guidance says companies must not mislead consumers about how they collect, use, retain, secure, or share health information. It also warns that health information includes more than diagnoses and treatments. Browsing, location, purchase, and app-use data can reveal or support an inference about a person’s health.

The GoodRx enforcement action showed the practical consequences. In 2023, the FTC alleged that GoodRx shared sensitive health information with advertising companies contrary to its privacy promises and failed to provide required breach notifications. The resolution included a $1.5 million civil penalty, advertising-related sharing restrictions, consent requirements, deletion directions, retention limits, and a comprehensive privacy program.

The lesson is larger than one company. “Not HIPAA-covered” is not permission to treat health data like ordinary marketing data. Product teams should map sources and destinations, minimize collection, separate operational analytics from advertising, review third-party defaults, test actual network behavior, document authorization, and plan for notification. Consumers should also look beyond a HIPAA badge and ask who operates the product, which law applies, and where their information goes.

Federal health privacy is a patchwork, but the gaps are not empty. The responsible starting point is to identify the product’s role, follow the data, and apply the correct rules before a breach or enforcement action forces the issue.

About Joseph Sides

Joseph Sides is a South Florida-based data privacy advocate, consultant, and entrepreneur whose work focuses on consumer rights, digital transparency, website tracking, meaningful privacy choices, and responsible technology. His public DEV introduction describes a bachelor's degree in criminology, a minor in business, and training in data analytics. These interests connect questions about how technology operates with questions about what people understand and how organizations remain accountable for their decisions.

The educational purpose of these articles is to make privacy developments easier to follow and their practical implications easier to examine. That means connecting the language of laws and regulatory actions with familiar experiences: visiting a website, choosing an app, responding to a consent request, or trying to delete information. For developers, the discussion also considers how interface choices and data practices shape the choices available to consumers. The aim is informed understanding and thoughtful questions, with attention to both individual rights and responsible product decisions.

Educational Information — Not Legal Advice

This article provides general education and commentary, not legal advice. Joseph writes as a privacy advocate and consultant, not as an attorney. Reading this article does not create an attorney-client relationship, and the discussion is not a substitute for advice from a qualified attorney about your particular circumstances.

Laws, interpretations, applicability, exemptions, and deadlines vary by jurisdiction and can change. A requirement that applies to one organization or activity may apply differently to another. Readers should consult current primary sources and a qualified attorney when evaluating obligations, available rights, or a specific course of action. This article does not promise complete coverage, guaranteed outcomes, or personal legal guidance.

AI Disclosure

Prepared with AI assistance.

Top comments (1)

Collapse
 
omyvnss profile image
Om Yaduvanshi •

the line about coverage turning on product architecture is the one developers should sit with. a fitness app that merely has the capacity to sync a wearable can qualify, even if the user never connects it. fun way to learn your app is a personal health record vendor.

the analytics angle is what makes this land for me. "unauthorized disclosure by the company itself" covers the pixel firing on a symptom page, no attacker required. most teams audit for break-ins, they don't audit their own event stream as a breach vector.

"test actual network behavior" is doing a lot of heavy lifting in that checklist, in a good way. that's the one step that catches what the privacy policy said wouldn't happen.