Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Privacy
Privacy

Health app privacy: why your fitness tracker isn't covered by HIPAA

HIPAA binds doctors and insurers — not the fitness, period-tracking, and meditation apps harvesting your most intimate data, which is why FTC enforcement, not health law, is where the action is.

Malik Johnson, · July 3, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Runner checking a fitness tracking app on a park path

Your period tracker, fitness app, and meditation log are not covered by HIPAA in most cases: the health privacy law binds healthcare providers, insurers, and their business associates — not consumer app makers selling or indefinitely retaining intimate data. Period and fertility tracking, mental-health journaling, diet and symptom logs, and medication reminders all sit in the regulatory gap, governed instead by FTC consumer-protection enforcement, platform policies, and state privacy laws. That gap is not theoretical: the FTC has taken repeated action against health apps — including a landmark 2021 order against Premom for sharing fertility data with advertisers and a first-ever 2024 action against BetterHelp over therapy-seekers' data, plus a 2023 enforcement policy warning the whole category that health-claim violations will be pursued.

What is HIPAA, exactly?

The Health Insurance Portability and Accountability Act of 1996 protects "protected health information" held by covered entities — doctors, hospitals, insurers, clearinghouses — and their business associates. Your cardiologist's portal: covered. A heart-rate app on your phone: not covered, unless it contracts with a covered entity. The popular shorthand "my health data is private by law" collapses exactly here — most consumer health data is legally food, in most of the U.S., for exactly the practices HIPAA forbids in clinics: sharing with advertisers, selling to brokers, retention without limits. Sensitive-health provisions in the newer state privacy laws (California, Colorado, Washington's My Health My Data Act) tighten this gradually, with Washington's 2024 law the most aggressive reach into consumer health data.

Why does the data matter so much?

Because health-adjacent data is identity-defining and permanent. A period-tracking history reveals pregnancy, fertility treatment, or contraception; mental-health entries reveal diagnoses; a fitness log reveals disability, surgery recovery, or cardiac conditions. This data feeds ad segmentation — the FTC's Premom case documented fertility data flowing to advertising intermediaries via the developer's analytics SDK — and in the post-Dobbs legal landscape it has acquired a harder edge: reproductive-health data has been subpoenaed in criminal proceedings, which turned period-tracker privacy from an abstract concern into a widely reported news story from 2022 onward.

What do the apps actually do?

The documented patterns, from FTC actions and researcher audits: third-party advertising and analytics SDKs embedded in the app receiving event data that can include health context; "anonymous" profiles that persist across sessions and link to device or advertising identifiers; data brokers receiving identifiable health-labeled segments; and vague retention — data held indefinitely, surviving account deletion in some documented cases. None of this requires malice; default SDK integrations do it as plumbing. But the effect is that a category of data most users assume is confidential travels through an advertising economy the user never saw or approved in any meaningful sense.

How do you protect yourself?

  1. Read the two pages that matter: the app's privacy policy sections on third-party sharing and retention. Vague is an answer — treat it as one. Health-specific policies from the app stores (Apple's and Google's health-data rules restrict sharing for apps declaring health categories) add a backstop.
  2. Prefer device-local storage where the app offers it, and decline cloud sync for the most sensitive logging unless you need it.
  3. Block ad tracking at the OS level: Apple's App Tracking Transparency off / deny, and Android's ad ID deletion, cut the identifier linkage that makes leaked data valuable.
  4. Audit permissions per our guide — health apps rarely need contacts, location, or full photo access.
  5. For genuinely sensitive tracking, consider apps that store only locally or use a notebook; the convenience calculus is yours, but it should be an actual calculation.
  6. Delete what you stop using — with a follow-up data-deletion request under state privacy laws where you qualify, since account deletion does not always mean data deletion.

What should change — and is slowly

The policy direction is clear: FTC enforcement now treats health-data misuse as its own priority, state sensitive-data laws are expanding definitions of health data beyond clinic walls, and platform rules have tightened. What does not exist yet is a general federal consumer-health-privacy law closing the gap HIPAA never covered. Until then, the operating assumption for any health app should be: this data is protected by nothing by default, and by everything I configure myself — which makes the checklist above, not the law, the actual privacy policy.

Frequently Asked Questions

Is my fitness app covered by HIPAA?
Almost certainly not. HIPAA covers healthcare providers, insurers, and their business associates — not consumer app makers. Your tracker's data is governed by FTC consumer-protection rules, platform policies, and state privacy laws instead.
Why did period trackers make privacy news?
After Dobbs in 2022, reproductive-health data gained criminal-legal significance — subpoenas for such data became a reported concern — while most period apps fell outside HIPAA and some shared data with advertisers, as FTC actions documented.
How do I check if a health app shares my data?
Read its privacy policy's third-party sharing and retention sections, check whether it offers local-only storage, and note that vagueness is an answer in itself. Then deny ad tracking at the OS level and audit its permissions.
Has the FTC acted against health apps?
Yes — Premom in 2021 and the BetterHelp order in 2024 over shared therapy-seekers' data are the leading cases, alongside a 2023 policy putting the entire health-app category on notice under health-claim breach rules.