Most AI health, telehealth, and wellness apps are not HIPAA covered entities — and founders read that as "privacy rules don't apply to us." The opposite is true: stepping outside HIPAA drops you into the FTC Health Breach Notification Rule and a wave of state consumer-health-data laws, the exact regime the FTC used against BetterHelp, GoodRx, Cerebral, and Premom. Mark what applies to your product and see where you're exposed, flagged by severity.
Being outside HIPAA is not a shield — it's a different rulebook. Each item you flag is something the FTC or a state regulator (or a plaintiff's lawyer) can act on. Most are fixable with consent design, a tracking-tech audit, and a separate consumer-health-data notice, before an enforcement letter or a class complaint arrives.
HIPAA only reaches covered entities (providers, plans, clearinghouses) and their business associates. A direct-to-consumer app, a wellness tool, or a telehealth brand that contracts with affiliated medical groups often sits outside that perimeter for much of its consumer data. For years that felt like freedom. Three things closed the gap.
First, the FTC Health Breach Notification Rule, expanded in 2024, now covers most health apps and connected tools that aren't HIPAA-regulated, and it treats an unauthorized disclosure — including sharing data with an advertiser without consent — as a reportable "breach." Second, the FTC's Section 5 enforcement against BetterHelp, GoodRx, Cerebral, Premom, and others established that funneling health-related signals to Meta, Google, or analytics SDKs without clear consent is an unfair or deceptive practice, with real money attached. Third, a new tier of state consumer-health-data laws — Washington's My Health My Data Act, Nevada's SB 370, Connecticut's amendments — define "consumer health data" broadly, require a separate privacy notice and explicit consent to collect or share it, and in Washington's case carry a private right of action that has already driven a wave of pixel-and-SDK class filings.
For AI-native health products there's an extra layer: when you use a model to infer or predict a health condition or treatment response, you're generating sensitive data and making an automated decision about a person — which pulls in Colorado's ADMT rules, the CPPA's automated-decision regime, and EU AI Act transparency duties on top of the consumer-health-data rules. The inference itself is regulated, not just the data you were handed.