Fitness trackers, symptom checkers, cycle trackers, and mental-health apps can be genuinely useful — but many people assume the personal information they enter is protected by HIPAA. Often, it isn't. Understanding that gap helps you make smarter choices about what you share and with whom. The convenience these apps offer is real, but so is the value of the information you feed into them — and once it leaves your phone, it can be hard to get back.
Why many apps aren't covered by HIPAA
HIPAA applies to "covered entities" — most providers, health plans, and the business associates that handle data on their behalf. A health app you download directly and use on your own is usually not a covered entity. That means the information you put into it is generally governed by the app's own privacy policy and by broader consumer-protection laws, rather than by HIPAA's specific protections.
What this means in practice
- Depending on its policy, the app may share or even sell data to advertisers or data brokers.
- You may have fewer formal rights to access or correct what the app holds about you.
- Security practices vary widely from one app to the next, with no single standard.
Other protections that may still apply
Even without HIPAA, some safeguards exist. The Federal Trade Commission (FTC) can take action against unfair or deceptive data practices, and a specific FTC rule — the Health Breach Notification Rule — requires certain health apps and connected devices to notify users when there's a breach of identifiable health information. Some state privacy laws add further protections on top of these.
How to protect yourself
- Read the privacy policy before sharing sensitive data, and look specifically for whether your data is sold or shared with third parties.
- Limit permissions such as location, contacts, and microphone to only what the app truly needs.
- Use strong, unique passwords and turn on two-factor authentication where available.
- Share the minimum information necessary to get value from the app.
- Delete data and accounts for apps you stop using, and disconnect them from any provider records you previously linked.
| Source of your app | Likely HIPAA status |
|---|---|
| Provided by your doctor or health plan | May be covered |
| Downloaded by you directly | Usually not covered |
Questions to ask before you trust an app
Before relying on any health app for something sensitive, it's worth pausing to ask a few questions. Does the privacy policy say whether your data is sold or shared with advertisers? Can you delete your data and account entirely, and does deleting actually remove it? Is the company clear about where data is stored and who can access it? Does the app explain what happens to your information if the company is sold or shut down? You won't always get perfect answers, but an app that's transparent and gives you real control is a better bet than one that's vague. The most sensitive categories — reproductive, mental-health, and substance-use information — deserve the most scrutiny.
Bottom line
Health apps can genuinely support your wellbeing, but treat the data you put into them as valuable and worth protecting. Before you hand it over, know who is — and isn't — protecting it on the other side.