Part 2 of 6 · Chapter 4 of 4

What Actually Has to Stay Private

HIPAA protects specific information handled by specific organizations — not every health-adjacent fact, and not every company that touches it. Knowing that boundary is what tells you what a breach actually triggers.

Beginner8 min read

Most people assume HIPAA means “anything about my health is legally private.” It doesn't. HIPAA protects specific information, handled by specific kinds of organisations — and the fitness app on your phone almost certainly falls outside both boundaries, no matter how personal the data it holds feels.

HIPAA protects specific information, not all of it

HIPAA — the Health Insurance Portability and Accountability Act — covers Protected Health Information: data created or held by a covered healthcare provider, health plan, or their business partners, tied to an identifiable patient. A doctor's note about your diagnosis is squarely inside that boundary. A lot of health-adjacent data people assume is covered is not.

Who is actually bound by it

The law binds covered entities — hospitals, clinics, insurers, pharmacies — and their business associates, companies those entities hire to handle patient data on their behalf, like a billing service or a cloud storage provider. Step outside that specific relationship and HIPAA typically has nothing to say, even about data that looks exactly like medical information.

What a breach actually triggers

When a covered entity has a breach — a hacked hospital database, a lost laptop with patient files on it — HIPAA requires notifying every affected patient, notifying the federal government, and in large breaches notifying the media, all within a fixed number of days. Fines follow, and they can run into the millions for a large or negligent breach.

None of those specific obligations apply to a consumer wellness app leaking the same kind of data. It might violate its own privacy policy, and general data-protection or state consumer law might apply — but not the specific machinery HIPAA sets in motion, because the app was never a covered entity to begin with.

Key takeaways

  • HIPAA protects Protected Health Information handled by covered entities and their business associates — not every piece of health-adjacent data everywhere.
  • A consumer wellness app is usually outside HIPAA entirely, even when its data is more detailed than what a doctor's office holds.
  • What determines HIPAA coverage is who is holding the data, not how sensitive the data feels.
  • A real HIPAA breach triggers fixed notification deadlines and potential fines running into the millions — obligations a non-covered app simply doesn't have.