AI & Digital Health

Health Data Privacy Does Not Begin and End With HIPAA

Not every health app or wellness service is covered by HIPAA. Consumers and product teams need to examine what data is collected, where it goes, and which rules actually apply.

People often use HIPAA as shorthand for all health privacy. In the United States, the HIPAA Privacy Rule applies to covered health plans, health care clearinghouses, and many health care providers, plus their business associates. A consumer app can collect highly sensitive health information without being covered by HIPAA when it operates outside those relationships.[1]

That does not mean the data is unregulated or that privacy is optional. It means the applicable protections may come from a different mix of federal and state laws, contractual commitments, platform rules, and enforcement authority.

Follow the data, not the label

A wellness label does not explain whether an app collects heart rate, sleep, symptoms, medications, location, contacts, advertising identifiers, or precise timestamps. It also does not show whether information stays on the device, moves to a cloud service, is shared with an analytics vendor, or is used to train a model.

A useful privacy review asks what is collected, why it is needed, how long it is retained, who receives it, how consent works, whether the user can correct or delete it, and what happens after account closure.

Breach obligations can reach consumer health apps

The Federal Trade Commission’s Health Breach Notification Rule can apply to certain vendors of personal health records and related entities that are not covered by HIPAA. The FTC finalized amendments in 2024 that clarify the rule’s application to health apps and connected devices.[2][3]

A privacy policy should therefore be more than a general promise. Product teams need a data inventory, access controls, vendor oversight, incident response, and a way to honor user choices.

Consent should be specific and revisable

One broad acceptance screen can hide several decisions: storing information, linking a wearable, generating a summary, sharing with another person, or using de-identified data for improvement. Separating those choices makes consent easier to understand and change.

A user-directed export should make the recipient and included information visible before sending. The safest default is not to imply that a clinician has received, reviewed, or endorsed information unless that actually occurred.

The RTH takeaway

Health privacy begins with a map of the data and the parties that touch it. HIPAA status is one question, not the entire answer. For SuperstarIQ, trust requires minimization, source visibility, user correction, clear sharing choices, and claims that match a consumer-directed general-wellness information tool in development. It should not promise provider integration or clinical review that has not been established.

Educational note

This article provides general education and does not provide medical advice, diagnosis, or treatment. Call 911 for a medical emergency and consult a qualified professional about personal symptoms, diagnoses, medication, or care decisions.

Explore more

SuperstarIQ  |  Privacy Policy

Sources and further reading

  1. U.S. Department of Health and Human Services. Health Apps and HIPAA. accessed 2026.
  2. Federal Trade Commission. FTC Finalizes Changes to the Health Breach Notification Rule. 2024.
  3. Federal Trade Commission. Complying With the FTC Health Breach Notification Rule. accessed 2026.