Your period tracker knows things about you that your mother doesn’t. Your fitness app knows your resting heart rate, your sleep patterns, and possibly your exact location every morning at 6 a.m. when you go for a run. And here’s the part that catches most people off guard: almost none of that is protected by HIPAA.
You’ve probably assumed otherwise. HIPAA, the Health Insurance Portability and Accountability Act, sounds like it should cover anything medical. It doesn’t. It was written in 1996, back when “health data” meant a folder in your doctor’s filing cabinet, not a river of biometric information flowing out of your phone 24/7. That gap between what people assume is protected and what’s actually protected is exactly where a lot of health apps are quietly operating.
Does HIPAA Actually Cover Your Period Tracker? (Spoiler: No.)

Most period-tracking, fitness, and wellness apps aren’t protected by HIPAA at all, because HIPAA only applies to “covered entities”: hospitals, doctors, insurers, clearinghouses, and their business associates. An app you downloaded yourself, with no connection to a healthcare provider, is neither.
That’s not a technicality. Because healthcare providers don’t own most third-party cycle-tracking apps, those apps simply don’t have to follow HIPAA rules, which means the data inside them can be used with none of the medical-privacy protections you’d expect. Flo, one of the biggest period trackers on the market, is the clearest example of how far that gap can stretch; more on that shortly.
The same logic applies to your smartwatch. Apple, Google, and Fitbit’s parent company Alphabet aren’t healthcare providers; they’re tech companies, and unless there’s a specific business associate agreement with a covered entity, the health data these devices collect sits entirely outside HIPAA’s reach. Your smart ring doesn’t need a warrant to be searched. It just needs a subpoena, a data broker willing to sell, or a privacy policy vague enough to allow it.
The Real Difference Between “Medical-Grade” and “App Store” Health Software
Here’s the direct answer: a medical-grade app is built for or contracted by a licensed healthcare provider and is either FDA-regulated as a device or bound to HIPAA as a business associate; a consumer wellness app is neither, even if it tracks identical data.
The distinction isn’t about how sophisticated the app looks. It’s about who commissioned it and what it claims to do. A health application sold directly to consumers may operate entirely outside HIPAA, but that same application can become subject to HIPAA the moment a hospital contracts with the developer to process protected health information. Nothing about the code changes. Just the ownership.
The FDA draws its own, separate line based on intent rather than data sensitivity. A fitness tracker that counts your steps and estimates calories burned is treated as a wellness tool, while an app that analyzes your heart rhythm and flags a potential arrhythmia is treated as a medical device, even though both live on the same phone and collect similarly personal information. One gets FDA oversight. The other gets a terms-of-service page nobody reads.
Even when an app is technically a business associate on paper, that status is narrower than people assume. A smartwatch app that a patient downloads on their own, without being commissioned by a hospital and without ever touching an electronic health record, isn’t a business associate at all; HIPAA simply doesn’t apply, regardless of how sensitive the data inside it is.
How Your Data Actually Gets Out the Door

It’s rarely a hack. That’s the uncomfortable part. Most of this is just business as usual.
Independent research keeps landing on the same conclusion, even if the exact numbers vary by category. A JAMA-published study of 578 mental health apps found that 44% shared data they collected with third parties. Mozilla’s own review of reproductive-health apps found that 18 of 25 popular period and fertility trackers failed to meet even its minimum privacy bar. Whichever study you pick, the pattern holds: a meaningful share of the apps people trust with their bodies are quietly routing that data somewhere else.
Devices like Whoop alone collect heart rate, heart rate variability, skin temperature, blood oxygen, respiratory rate, sleep stages, strain scores, and recovery metrics, an extraordinarily detailed physiological profile, all generated passively, all potentially shareable under a privacy policy most users never read past the “Accept” button.
And this data doesn’t stay theoretical once it exists. Fitness-tracker data has been used in court since 2014, when a Calgary personal injury lawyer became the first known attorney to introduce a client’s Fitbit data as evidence, using her activity levels to demonstrate that an injury had measurably reduced her physical capacity. It didn’t stay a plaintiff’s tool for long; insurance companies can request the same data through a court order, and if it shows more activity than the claimed injury should allow, it can be used to reduce or deny a payout entirely. No breach required. Just a subpoena.
The Flo Health Case That Changed Everything
If you want the clearest cautionary tale in this space, it’s Flo Health. The FTC alleged that Flo Health shared users’ health information with outside data analytics providers, including Facebook and Google, after promising that information would stay private. The company settled with the FTC in 2021; that settlement required Flo to obtain users’ affirmative consent before sharing health data going forward, to notify affected users about the earlier disclosures, and to instruct any third party that had received the data to destroy it.
That wasn’t the end of it. A related class action, covering everyone who used the app and entered menstruation or pregnancy data between November 2016 and February 2019, went considerably further. Flo Health settled mid-trial on July 31, 2025, and the very next day, a jury found Meta liable for its role in the unauthorized collection and commercial use of that health data. Google and Flurry, an analytics firm, had already settled separately. Flo, Google, and Flurry’s combined settlement totals $59.5 million, still pending final court approval as of this writing. Meta, meanwhile, didn’t settle; the jury found it liable under California’s wiretapping-era privacy law, and plaintiffs are seeking $5,000 in statutory damages per class member across a subclass of roughly 1.6 million people, with total exposure still undetermined.
The kicker: Flo wasn’t doing anything HIPAA prohibited. HIPAA never applied to Flo to begin with.
Is Anyone Closing the Gap?
Slowly, yes, but unevenly, and mostly at the state level. Washington moved first. State lawmakers explicitly noted that residents expect their health data to be protected the way HIPAA protects it, but HIPAA only covers data collected by specific healthcare entities, leaving apps and websites that collect the same kind of information with no equivalent safeguard. The resulting My Health My Data Act makes it unlawful to sell or even offer to sell consumer health data without first obtaining valid, specific authorization from the consumer, and gives consumers a sweeping right to demand deletion of their health data, one that, unlike most privacy laws, doesn’t even carve out an exception for data companies are otherwise required to retain.
Federally, the FTC has leaned on a different tool: the Health Breach Notification Rule, originally written in 2009 for personal health record vendors HIPAA never touched. 2024 amendments to that rule clarified that it expressly covers health apps, fitness trackers, and other wearables, precisely the category of products that HIPAA and, increasingly, the FDA’s general wellness guidance leave unregulated. It’s not HIPAA-level protection, but it does mean unauthorized disclosures, even by the company itself, can now trigger mandatory breach notifications.
Still, if you don’t live in a state with its own law, you’re mostly relying on a company’s privacy policy and its own definition of “consent.”
How to Protect Yourself Without Deleting Every App
You don’t need to throw your smartwatch in a drawer. A few habits go a long way:
- Read the data-sharing section, not the whole policy. Look specifically for “third parties,” “analytics partners,” or “advertising.” That’s where the sharing lives.
- Check for end-to-end encryption on sensitive trackers, especially period and fertility apps; some now advertise this specifically, meaning even the company can’t hand your data over on request.
- Turn off ad personalization and analytics permissions inside the app’s own settings, not just your phone’s.
- Favor apps built for or by healthcare providers when the data is genuinely sensitive: reproductive health, mental health, chronic conditions. That’s your best shot at actual HIPAA coverage.
- Know your state’s law. If you’re in Washington, Connecticut, Nevada, or a handful of others, you have deletion and consent rights that HIPAA never gave you.
The Bottom Line on Health App Privacy
The uncomfortable truth is that most health apps were never built inside HIPAA’s walls; they were built entirely outside them, on purpose, because operating outside those walls is cheaper and more profitable. That’s not a bug in the system. It’s a gap the system never closed. Until federal law catches up, and there’s no clear sign it will anytime soon, the burden of protecting sensitive health data sits with you: reading the fine print, checking your state’s protections, and picking your apps with the assumption that HIPAA isn’t watching, because it probably isn’t.