What Should "Secure" Mean for a Health App?

What Should "Secure" Mean for a Health App?

Joshua Ford
August 31, 2026

For a health app holding your medical history, secure should mean four things, and encryption is only the first: that your health data is encrypted in transit and at rest, that employee access to it is limited and logged, that the company’s business model does not depend on selling or sharing it, and that you can export it and delete your account whenever you want. Encryption is the part every app advertises because it is the cheapest to claim and the most straightforward to implement. It protects your information from interception and from theft. It does exactly nothing about what the company itself chooses to do with it. The business model is the security question almost nobody asks, and it is the one that predicts behaviour over years. Exportability is a security property too — data you cannot get out is data you have already partly lost.

Is encryption enough?

No. Encryption protects your data from outsiders and does nothing about insiders or about the company’s own decisions.

Two phrases get used and they mean different things. Encrypted in transit means the data is scrambled while travelling between your phone and the server, so somebody on the same coffee-shop network cannot read it. Encrypted at rest means it is scrambled while sitting on the server, so somebody who steals the hard drive gets noise.

Both are genuinely necessary and both are table stakes. Neither addresses the far more likely scenario, which is not a thief but a company deciding — legally, in accordance with its own posted policy — to do something with your information you would not have chosen. “Bank-level encryption” is marketing language rather than a specification, and it should be read as such.

Who at the company can see my data?

Ask, because the honest answer is rarely nobody and rarely everybody.

A reasonable answer sounds like this: a small number of people can access customer data for support and debugging, that access is limited by role, and every access is logged. That is how a careful company actually operates, and someone who tells you that is being straight with you.

An app claiming that literally nobody can ever see anything is either using end-to-end encryption — which is real, and carries a trade-off worth understanding, because if the company genuinely cannot read your data then they also cannot recover it when you lose your key — or it is overstating. Both answers are fine. Not knowing which one you are being given is the problem.

What happens to my data if the app shuts down?

Usually nothing good, and almost nobody asks before signing up.

Three things happen to software companies: they shut down, they get acquired, or they go bankrupt. In a shutdown you may get an export window, and you may not be reading your email that week. In an acquisition, data is an asset, and many privacy policies explicitly permit transferring your information to a buyer — read the section headed something like “business transfers,” because it is in there and it is usually one sentence long.

This is the likeliest route by which consumer health data actually changes hands, and it is not a breach. It is the plan, disclosed in advance, in a document nobody read. The defence is the same as the answer to the next question: get your data out and keep your own copy.

How can I tell if an app is tracking me?

Read the sharing section of the privacy policy, check the app store’s data-collection label, and pay attention to what the policy does not say.

App store privacy labels are useful and they are self-reported by the developer, so treat them as a starting point rather than an audit. In the policy itself, look for named categories of recipient. “We share with service providers who help us operate the app” is normal and describes hosting and email. “We may share with trusted partners” without naming anyone, in a section that also mentions marketing, is a different sentence doing different work.

Analytics and advertising code embedded in an app is the common route by which information leaks somewhere you did not expect, and it is invisible from the outside. That is precisely why the question belongs in writing, addressed to the company, before you commit your medical history to it.

Does HIPAA compliance make an app secure?

It sets a floor rather than a ceiling, and most consumer apps are not under it in the first place.

Where HIPAA does apply, its Security Rule requires administrative, physical, and technical safeguards, and that is a meaningful constraint on how an organization operates. It is also a baseline, not a guarantee — breaches happen inside covered entities routinely, and being subject to a rule is not the same as being good at following it.

Whether a given app is covered at all is the prior question, and we worked through it in is this health app HIPAA compliant. Short version: probably not, and that matters less than people think, because a careful company outside HIPAA will treat your data better than a careless one inside it.

What should I ask before I trust an app with my medical history?

Six questions. Any company worth trusting will answer all six in writing, and the ones that will not have told you something.

How do you make money? Who inside the company can access my data, and is that access logged? Do you use third-party analytics or advertising code, and which? Can I export everything in a format I can read? Can I delete my account, and does that delete the data? And what happens to my information if you are acquired or you shut down?

You should be able to answer most of those from the privacy policy alone. Where you cannot, ask, and treat the quality of the reply as part of the answer.

We build a health app, which means we should be held to those same six questions and we would rather you asked them than assumed. Ours are answered at our privacy policy and HIPAA and security at Organized.health. And the deeper reason we keep pushing you toward keeping your own copy of everything — covered in what a personal health record is — is that a record you hold yourself survives any company’s decisions, including ours.


Organized.health helps you organize your health information. It does not provide medical advice, diagnosis, or treatment. Always talk to a qualified healthcare provider about your care.

Related: Is this health app HIPAA compliant? · What is a personal health record? · HIPAA and security at Organized.health

About the Author

Joshua Ford

A contributor to this blog.

You May Also Like