Medical Data Privacy: What HIPAA Covers and How to Review Health-App Data (2026)
Evidence-first guide to HIPAA scope, health-app and pharmacy data flows, de-identification risk, state health-data rules, and scoped privacy requests.
You may share health information with a hospital, a period-tracking app, a pharmacy-discount service, a wearable, or a mental-health platform. Those services do not all operate under the same legal framework.
HIPAA protects protected health information held by HIPAA covered entities and their business associates. It is not a universal privacy law for every health-related app or website. At the same time, saying that non-HIPAA data has “no protection” is also inaccurate: the FTC, state privacy laws, contractual promises, and sector-specific rules may apply depending on the service, the data, and the use.
This guide explains those boundaries, what documented enforcement actions do and do not show, how de-identification works under HIPAA, and how to review a service’s current privacy and deletion options. It is educational information, not legal or medical advice.
Key Takeaways
- HIPAA has a defined scope. The HHS Privacy Rule generally applies to covered entities—health plans, health care clearinghouses, and certain health care providers—and their business associates. A consumer app is not automatically a HIPAA covered entity or business associate merely because it handles health-related information. HHS explains the covered-entity and business-associate definitions.
- De-identification is not one simple deletion switch. HIPAA recognizes an expert-determination method and a Safe Harbor method. HHS says properly de-identified information is no longer PHI under the Privacy Rule, while also noting that residual identification risk is not zero. Read HHS’s de-identification guidance.
- Re-identification research needs careful framing. A 2019 Nature Communications study modeled uniqueness using 15 demographic attributes and reported a headline result that 99.98% of Americans would be correctly re-identified under its model. That is not a universal accuracy rate for medical records, every dataset, or every attack.
- The FTC has acted against specific health-data practices. The GoodRx and BetterHelp matters are documented cases; they do not establish that every pharmacy-discount service, health app, or tracking pixel handles data the same way. The FTC also administers a Health Breach Notification Rule for certain non-HIPAA personal-health-record vendors, related entities, and service providers; the FTC says its 2024 amendments clarify coverage for health apps and similar technologies.
- State laws are conditional. Washington’s My Health My Data Act and Nevada’s 2023 SB 370 create health-data duties and consumer processes within defined scopes and exemptions. California’s CCPA also has covered-business rules and exceptions. Do not treat one state’s route as a nationwide deletion right.
HIPAA Is Not a Universal Medical-Privacy Law
HIPAA’s Privacy Rule protects most individually identifiable health information held or transmitted by a covered entity or its business associate. HHS defines covered entities as health plans, health care clearinghouses, and health care providers that conduct certain standard electronic transactions. A business associate performs specified functions or services for a covered entity that involve protected health information.
Tired of dealing with data exposure?
Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.
That means the same type of health detail can be treated differently depending on who holds it and why. A hospital’s patient record may be PHI under HIPAA. A symptom entered into a consumer app may instead be governed by the app’s privacy notice, the FTC Act, a state health-data statute, or another rule. The answer requires examining the entity and the data flow; it cannot be determined from the word “health” alone.
There is also no sound basis for saying that a Google search, a fitness tracker, or a commercial app has “zero federal protection.” HIPAA may not apply, but the FTC can address deceptive privacy promises, and the FTC’s Health Breach Notification Rule can apply to certain vendors of personal health records, related entities, and service providers. Other federal laws may apply to particular products or users.
Covered Entities, Apps, and De-Identified Data
The following comparison is a starting point, not a classification of any named company:
| Question | HIPAA covered entity or business associate | Consumer health app or other commercial service |
|---|---|---|
| Primary question | Is the entity a covered entity or performing a covered function as a business associate? | What entity controls the data, what does its privacy notice say, and which other laws apply? |
| Main federal framework | HIPAA Privacy, Security, and Breach Notification Rules, when applicable | Potentially the FTC Act, FTC Health Breach Notification Rule, state law, contract, and sector-specific rules |
| Use and disclosure | Limited by the Privacy Rule, authorizations, and applicable exceptions | Depends on the service, consent, notice, contract, and applicable law; no blanket permission or prohibition should be assumed |
| De-identification | HIPAA recognizes expert determination and Safe Harbor methods | A service may use a different technical or contractual standard; do not call data anonymous without evidence |
| Deletion | HIPAA provides defined access and amendment rights; it is not a universal deletion right for all PHI | A deletion or opt-out route may come from state law, the service’s policy, an account control, or a voluntary process |
HIPAA also does not make every disclosure or sale of PHI automatically a felony. The Privacy Rule regulates uses and disclosures, and some disclosures require written authorization while others are permitted or required by the rule. Read the current HHS guidance and the service’s role before drawing a legal conclusion.
How Health Information Can Move Through Commercial Services
Health-data flows vary widely. The examples below describe documented possibilities, not a claim about every provider.
1. Pharmacy discounts and prescription services
Some prescription-discount services receive information connected with a coupon or medication transaction. In its GoodRx enforcement action, the FTC said GoodRx collected information from users and pharmacy-benefit managers, and shared sensitive health information with advertising companies contrary to its privacy promises. The matter resulted in a court-entered stipulated order with a $1.5 million civil penalty and provisions addressing future disclosures. See the FTC’s GoodRx case page and enforcement release.
That case does not show that every discount card records the same fields or shares them for the same purpose. Review the service’s current privacy notice, cookie controls, account settings, and any separate pharmacy or benefit-provider relationship.
2. Health websites, apps, and advertising technologies
A website or app may use analytics, advertising, or measurement tools. Whether a tool receives health-related information depends on the implementation, the fields sent, the service’s settings, and the provider’s disclosures. A tracking-pixel label alone is not proof that a particular diagnosis or questionnaire answer was sent.
The FTC’s BetterHelp matter is another specific example. The FTC case materials say the online counseling service disclosed sensitive data to third parties for advertising after promising to keep it private; the July 2023 final order required payment of $7.8 million and restricted future practices. See the FTC case record.
3. Aggregated and de-identified health products
Research, analytics, and life-sciences companies may offer products built from aggregated, de-identified, or otherwise processed information. A company’s marketing description does not by itself establish that it holds identifiable patient records, acts as a data broker, or can locate a particular person.
Before naming a company or requesting removal, identify the actual controller, product, record, and current privacy route. Do not infer a person-specific profile from a general statement that an organization works with health data.
What De-Identification Does—and Does Not—Prove
Under HIPAA, the Safe Harbor method removes specified identifiers and also requires the covered entity not to have actual knowledge that the remaining information could identify someone, alone or in combination with other information. The alternative expert-determination method requires a qualified person to document that the risk is very small for the anticipated recipient.
HHS states that properly de-identified information is no longer PHI under the Privacy Rule. HHS also says that de-identification reduces but does not make identification risk zero. Other laws, contracts, research rules, or promises may still matter.
What the 99.98% study actually found
The often-repeated 99.98% figure comes from the 2019 paper “Estimating the success of re-identifications in incomplete datasets using generative models”. The paper’s headline result says its model would correctly re-identify 99.98% of Americans in a dataset using 15 demographic attributes; its population and sampling assumptions matter. The finding is useful evidence that quasi-identifiers can create risk, but it is not a guarantee that an attacker can identify 99.98% of patients in any medical database.
The practical lesson is narrower and more useful: a dataset’s risk depends on its attributes, population, sampling, controls, intended recipient, and available auxiliary information. “De-identified” is not a reason to assume either perfect anonymity or automatic unlawfulness.
State Health-Data Rules to Review
Washington’s My Health My Data Act
Washington’s Chapter 19.373 applies to defined regulated entities and small businesses, with exemptions. Among other provisions, it gives covered consumers a right to request deletion of consumer health data, requires a response generally within 45 days with a possible additional 45-day extension, and addresses authentication and appeals. See RCW 19.373.040.
The Act separately regulates selling consumer health data without valid authorization and prohibits certain geofences around in-person health-care services. See RCW 19.373.070 and RCW 19.373.080. Its exemptions and definitions matter, so do not describe it as a universal deletion rule for every health record.
Nevada’s SB 370
Nevada’s 2023 SB 370 addresses consumer-health-data privacy policies, consent, consumer requests, sale authorizations, security, and certain geofences. Its sections have different effective dates: the enacted text includes provisions effective on passage, July 1, 2023, October 1, 2023, and January 1, 2024. Read the official Nevada session-law text and the service’s current privacy route before relying on a provision.
California and other jurisdictions
California’s CCPA can provide rights to qualifying California residents in relation to covered businesses, subject to definitions, exceptions, verification, and other limits. The California Attorney General’s CCPA guidance is a better starting point than a generic template.
Other states and countries use different definitions and request types. A deletion request, correction request, sale opt-out, sharing opt-out, preference signal, and account closure are not interchangeable. For a cross-border request, review the applicable regulator or statute and the provider’s current notice.
A Practical, Evidence-First Review Process
Step 1: Identify the service and the record
Write down the product name, account or profile URL, the health fields involved, the source of the data, and the date you observed it. Distinguish the app, an ad network, a pharmacy or provider, a research product, and a public source. They may require different requests.
Step 2: Review the current first-party controls
Use the service’s current privacy center, account deletion control, “privacy choices” tool, or rights-request channel. Save the page and confirmation. If the service is integrated with a health-care provider, insurance plan, employer, or pharmacy, confirm which organization controls the relevant record before deleting an account or revoking an integration.
Step 3: Reduce future collection where appropriate
Review permissions for location, health data, contacts, microphone, camera, and advertising or analytics features. Apple and Android menu names change across versions; use the current settings on the device and the app’s own controls. Disabling an advertising identifier or a permission can reduce future collection or linkage, but it does not necessarily delete historical records.
Step 4: Make a scoped request
Where a law applies, request the right that matches the record: access, deletion, correction, withdrawal of consent, or an opt-out from sale or sharing. Ask the provider to explain any verification, exception, retention, or downstream-notification step. Do not send more health information or identity documents than the current route requires.
You can adapt this neutral starting point:
Hello,
I am reviewing personal information associated with [account, profile, or URL].
Please identify the privacy request options that apply to this record and tell me:
- what information you hold about me and the source or category of source;
- whether deletion, correction, withdrawal of consent, or an opt-out is available;
- what verification is required and how the information will be used; and
- whether any exception, retention rule, or downstream notice applies.
If the applicable law gives me a right to make a request, please treat this as a request under that law and confirm the applicable response process. I am not asking you to send sensitive health information by unencrypted email.
Name: [name]
Account or profile URL: [URL]
Preferred contact: [contact]Step 5: Record the result separately
Keep the submission date, exact scope, verification step, response, and any source or third-party copy. A response from one app does not prove that a pharmacy, ad network, research product, search engine, or other broker changed its own record.
Frequently Asked Questions
Can an employer buy my health-data profile?
The answer depends on the employer, vendor, data, purpose, contract, and applicable law. The ADA and GINA address particular employment and genetic-information practices, but they are not a blanket rule that every health-data purchase or vendor arrangement is illegal. Review the vendor’s disclosures and seek qualified advice if an employment decision appears to involve protected information.
Does an app deletion request affect my medical care?
Usually, an account or advertising preference for a commercial app is separate from a hospital’s electronic health record. But integrated services can have different account, clinical, billing, or legal-retention effects. Confirm the scope before deleting an account or revoking a connection.
Are direct-to-consumer DNA services covered by HIPAA?
Do not assume either answer for every provider. Many direct-to-consumer genetic-testing services are not HIPAA covered entities for all of their activities, while a provider may have separate relationships or products with covered entities. Review the provider’s privacy notice, terms, and current rights route.
What is the HIPAA Safe Harbor method?
It is one of HIPAA’s two de-identification methods. It requires removing the listed identifiers—including names, geographic subdivisions smaller than a state subject to the rule’s limited ZIP-code exception, and many date elements—and requires that the covered entity have no actual knowledge that the remaining information could identify the person. The expert-determination method is separate. See HHS’s current guidance.
Medical-Data Privacy Action Plan
- [ ] Identify the actual service, controller, record, and source before submitting a request.
- [ ] Read the current first-party privacy notice and account or rights-request options.
- [ ] Review app, device, location, health, and advertising permissions.
- [ ] Use the request type that matches the applicable law and record.
- [ ] Minimize sensitive information and identity documents during verification.
- [ ] Save confirmations and re-check separate downstream copies when appropriate.
Official and primary sources
- HHS: Covered entities and business associates
- HHS: De-identification guidance
- HHS: Access to medical records
- HHS: HIPAA Breach Notification Rule
- FTC: Health Breach Notification Rule compliance
- FTC: GoodRx case page
- FTC: BetterHelp case record
- Nature Communications: Re-identification study
- Washington Chapter 19.373
- Nevada SB 370 session law
- California Attorney General CCPA guidance
- EEOC: GINA fact sheet
Related Health and Privacy Guides
- What is HIPAA?: Analysis of HIPAA coverage limits and non-covered health data.
- Location Data Brokers Guide: How location aggregators may use location signals and why source-specific review matters.
- Opt-Out Credit Header Data Brokers: Why credit-report, prescreening, and people-search controls are separate.
- Complete Data Broker Removal Guide: A source-first framework for reviewing personal-data records.
- Explore more educational articles in the Privacy Education Category Hub or use the OfflistMe Opt-Out Directory.
Related Guides
- Complete 2026 Data Broker Directory & Opt-Out List: A snapshot-based guide to recorded provider routes.
- OfflistMe Data Removal Plans & Pricing: Review recorded browser-local workflows and decide which requests to send yourself.
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
