What Actually Has to Stay Private
HIPAA protects specific information handled by specific organizations — not every health-adjacent fact, and not every company that touches it. Knowing that boundary is what tells you what a breach actually triggers.
Most people assume HIPAA means “anything about my health is legally private.” It doesn't. HIPAA protects specific information, handled by specific kinds of organisations — and the fitness app on your phone almost certainly falls outside both boundaries, no matter how personal the data it holds feels.
HIPAA protects specific information, not all of it
HIPAA — the Health Insurance Portability and Accountability Act — covers Protected Health Information: data created or held by a covered healthcare provider, health plan, or their business partners, tied to an identifiable patient. A doctor's note about your diagnosis is squarely inside that boundary. A lot of health-adjacent data people assume is covered is not.
Who is actually bound by it
The law binds covered entities — hospitals, clinics, insurers, pharmacies — and their business associates, companies those entities hire to handle patient data on their behalf, like a billing service or a cloud storage provider. Step outside that specific relationship and HIPAA typically has nothing to say, even about data that looks exactly like medical information.
This is Protected Health Information, created by a covered entity about an identifiable patient. Its handling, storage, and any breach of it fall directly under HIPAA.
The organisation and the data both sit inside the boundary the law was written for.
Unless that app was built by, or contracted to, a covered healthcare provider or insurer, HIPAA does not apply to it — even though the data is arguably more detailed than what your doctor sees in a single visit. The app is instead governed by its own privacy policy and general consumer-protection law, which offer weaker guarantees.
This is the single most common misunderstanding people bring to this topic — the sensitivity of the data does not determine whether HIPAA applies; who is holding it does.
What a breach actually triggers
When a covered entity has a breach — a hacked hospital database, a lost laptop with patient files on it — HIPAA requires notifying every affected patient, notifying the federal government, and in large breaches notifying the media, all within a fixed number of days. Fines follow, and they can run into the millions for a large or negligent breach.
None of those specific obligations apply to a consumer wellness app leaking the same kind of data. It might violate its own privacy policy, and general data-protection or state consumer law might apply — but not the specific machinery HIPAA sets in motion, because the app was never a covered entity to begin with.
Key takeaways
- HIPAA protects Protected Health Information handled by covered entities and their business associates — not every piece of health-adjacent data everywhere.
- A consumer wellness app is usually outside HIPAA entirely, even when its data is more detailed than what a doctor's office holds.
- What determines HIPAA coverage is who is holding the data, not how sensitive the data feels.
- A real HIPAA breach triggers fixed notification deadlines and potential fines running into the millions — obligations a non-covered app simply doesn't have.