Launching soon — not yet accepting new client matters.
Interactive · Health data · Privacy

You're outside HIPAA. That's not the relief you think it is.

Most AI health, telehealth, and wellness apps are not HIPAA covered entities — and founders read that as "privacy rules don't apply to us." The opposite is true: stepping outside HIPAA drops you into the FTC Health Breach Notification Rule and a wave of state consumer-health-data laws, the exact regime the FTC used against BetterHelp, GoodRx, Cerebral, and Premom. Mark what applies to your product and see where you're exposed, flagged by severity.

0 flagged
Mark each item below.
Your health-data exposure

Mark the items above.

Being outside HIPAA is not a shield — it's a different rulebook. Each item you flag is something the FTC or a state regulator (or a plaintiff's lawyer) can act on. Most are fixable with consent design, a tracking-tech audit, and a separate consumer-health-data notice, before an enforcement letter or a class complaint arrives.

Get your health-data exposure mapped →

Why "not HIPAA" stopped being a safe harbor

HIPAA only reaches covered entities (providers, plans, clearinghouses) and their business associates. A direct-to-consumer app, a wellness tool, or a telehealth brand that contracts with affiliated medical groups often sits outside that perimeter for much of its consumer data. For years that felt like freedom. Three things closed the gap.

First, the FTC Health Breach Notification Rule, expanded in 2024, now covers most health apps and connected tools that aren't HIPAA-regulated, and it treats an unauthorized disclosure — including sharing data with an advertiser without consent — as a reportable "breach." Second, the FTC's Section 5 enforcement against BetterHelp, GoodRx, Cerebral, Premom, and others established that funneling health-related signals to Meta, Google, or analytics SDKs without clear consent is an unfair or deceptive practice, with real money attached. Third, a new tier of state consumer-health-data laws — Washington's My Health My Data Act, Nevada's SB 370, Connecticut's amendments — define "consumer health data" broadly, require a separate privacy notice and explicit consent to collect or share it, and in Washington's case carry a private right of action that has already driven a wave of pixel-and-SDK class filings.

For AI-native health products there's an extra layer: when you use a model to infer or predict a health condition or treatment response, you're generating sensitive data and making an automated decision about a person — which pulls in Colorado's ADMT rules, the CPPA's automated-decision regime, and EU AI Act transparency duties on top of the consumer-health-data rules. The inference itself is regulated, not just the data you were handed.

This scan is general educational information, not legal advice, and using it does not create an attorney-client relationship. Whether a given law actually applies turns on specific facts about your data, your corporate structure, and where your users are. Treat a result here as orientation, and have your actual posture reviewed before you rely on it or represent it to a partner or regulator.