Is This Health App HIPAA Compliant?
Most consumer health apps are not covered by HIPAA at all. HIPAA applies to covered entities — health plans, most health care providers, and clearinghouses — and to the business associates working on their behalf. An app you found yourself, downloaded, and typed your own information into is usually none of those. Which means the phrase “HIPAA compliant” on a marketing page is a self-assertion rather than a certification. No government body certifies apps. There is no registry, no badge, no audit that confers the label. What does apply to a non-covered app is its own privacy policy, which becomes enforceable once published, the FTC’s authority over deceptive practices and its Health Breach Notification Rule, and a growing set of state privacy laws — some of which reach further than HIPAA does for consumer health data. The more useful question is not whether an app is HIPAA compliant. It is who can see this, and what are they allowed to do with it.
Does HIPAA even apply to this app?
Only if the app is offered by, or works on behalf of, a covered entity.
Here is the distinction that catches nearly everyone. Your doctor’s patient portal app shows you records held by a covered entity, so those records are protected health information under HIPAA. The symptom tracker you downloaded last Tuesday holds the same kind of information about the same body, and it generally is not — because the data did not come from a covered entity and the developer is not acting for one.
Same information. Same person. Entirely different legal regime, determined by how the data got there. When a hospital or an insurer offers an app to its patients or members, that app is usually inside the perimeter. When you go and find one yourself, it usually is not.
What does “HIPAA compliant” on a website actually mean?
It is a claim the company is making about itself. Nobody issues HIPAA compliance certificates.
There is no federal certifying body for HIPAA compliance, no approved-vendor list, and no government seal. A company can be genuinely rigorous, or genuinely careless, and put the same three words in the same footer.
Third-party audits and attestations do exist and they are meaningful evidence — an independent assessor examined the controls and wrote down what they found. That is worth more than a badge. It is still not government approval, and it is worth knowing the difference so you can weigh the claim properly rather than either trusting it completely or dismissing it entirely.
If HIPAA doesn’t cover it, what does?
The app’s own privacy policy, plus the FTC, plus your state.
A published privacy policy is a promise, and the Federal Trade Commission has authority over companies that break their stated promises — that is the deceptive-practices power, and it has been used against health apps. The FTC also enforces a Health Breach Notification Rule that reaches health apps outside HIPAA and requires them to tell you when your data is exposed. Several states have passed consumer health privacy laws that in some respects go further than HIPAA for exactly this category of data.
So the honest summary is: less protection than most people assume, considerably more than nothing. The gap is real and it is not a lawless void.
What should I actually check before trusting an app?
Five things, all findable in about ten minutes.
Does the privacy policy say the data is sold, or shared with advertisers or unnamed “partners”? Does the app carry third-party analytics or advertising code? Can you export everything you put in, in a format you can read? Can you delete your account, and does that actually delete the data or just close the door? And how does the company make money — because an app with no visible revenue is being paid by someone, and it is worth working out who.
Those five questions do more work than any compliance badge. Apply them to everything, including us.
What are the real warning signs?
Vague language, no export, and a business model that does not explain itself.
“We may share information with trusted partners” without naming a single partner is the one to watch for, because it is doing a great deal of quiet work in a short sentence. A policy with no deletion path. A policy last updated four years ago. A free app, with no subscription, no advertising you can see, and no explanation of where the money comes from.
None of these prove anything on their own. Together they tell you what kind of company you are dealing with, which is usually what you were actually trying to find out.
Where does Organized.health sit?
We would rather you run the five questions on us than take our word for anything, and we will answer them in writing when you ask.
The same test in this post applies to us, and it should. We are an app you would find and download yourself, which puts us in the same category as most of what we have described here rather than inside a hospital’s HIPAA perimeter. That is a reason to check us carefully, not a reason to relax.
Our own policy is at our privacy policy and how we think about handling health information is on our HIPAA and security page. If something there is unclear or does not answer one of the five questions properly, that is a problem with our writing and we would like to know about it.
The companion to this post is what “secure” should actually mean for a health app, which is the practical question underneath the legal one — because an app can sit entirely outside HIPAA and still be careful with your information, and an app can sit inside it and still lose your data.
Organized.health helps you organize your health information. It does not provide medical advice, diagnosis, or treatment. Always talk to a qualified healthcare provider about your care.
Related: What should “secure” mean for a health app? · What are my rights to my own medical records? · HIPAA and security at Organized.health