What Actually Has to Stay Private
HIPAA protects specific information handled by specific organizations — not every health-adjacent fact, and not every company that touches it. Knowing that boundary is what tells you what a breach actually triggers.
Most people assume HIPAA means “anything about my health is legally private.” It doesn't. HIPAA protects specific information, handled by specific kinds of organisations — and the fitness app on your phone almost certainly falls outside both boundaries, no matter how personal the data it holds feels.
HIPAA protects specific information, not all of it
HIPAA — the Health Insurance Portability and Accountability Act — covers Protected Health Information, or PHI: data created or held by a covered healthcare provider, health plan, or their business partners, tied to an identifiable patient. A doctor's note about your diagnosis is squarely inside that boundary. A lot of health-adjacent data people assume is covered is not.
PHI is not just the diagnosis itself. It is any of a defined list of identifiers — name, address, birth date, and more — attached to health information, held by one of those specific organisations. Strip every identifier from that same data and, under the rules covered later in this chapter, it can stop being PHI entirely. The identifiers are doing almost all of the legal work, which is worth seeing spelled out rather than taken on faith.
The eighteen identifiers that actually define PHI
HIPAA's regulations name eighteen specific identifiers. Health information tied to any one of them, held by a covered entity, is PHI. A representative slice of the list:
- •Name
- •Any geographic subdivision smaller than a state — street address, county, or ZIP code
- •All dates directly tied to an individual, other than the year — birth date, admission date, discharge date
- •Telephone and fax numbers, email addresses
- •Social Security number, medical record number, health plan beneficiary number
- •Biometric identifiers, including fingerprints and voiceprints
- •Full-face photographs
- •Any other unique identifying number, characteristic, or code
That last line does most of the quiet work — it is a catch-all, not a loophole. A hospital-assigned patient ID that looks meaningless to an outsider still counts, because it can be traced back to one specific person inside that hospital's own systems.
Treatment, payment, and operations need no extra authorisation
HIPAA is often pictured as requiring a fresh signature every time PHI moves between two people. It doesn't. The law carves out three broad purposes — usually shortened to TPO — where a covered entity can use or share PHI without asking the patient again each time: treatment (a specialist pulling your primary care notes before an appointment), payment (a hospital sending your claim details to your insurer), and healthcare operations (a hospital reviewing its own case outcomes to improve quality).
An emergency room doctor at a hospital you have never visited before can request your records from your regular clinic in the middle of treating you, without a new consent form, because that request falls inside treatment. The one blanket document you sign — the Notice of Privacy Practices, usually on a clipboard at a first visit — is what covers all three going forward. Anything outside TPO, like selling PHI to a marketer, needs the patient's specific authorisation instead.
Who is actually bound by it
The law binds covered entities — hospitals, clinics, insurers, pharmacies — and their business associates, companies those entities hire to handle patient data on their behalf, like a billing service or a cloud storage provider. Step outside that specific relationship and HIPAA typically has nothing to say, even about data that looks exactly like medical information.
That relationship with a business associate is not informal. The law requires a Business Associate Agreement, or BAA, before PHI can be shared at all — a signed contract that obligates the vendor to use appropriate safeguards, to report a breach on its end back to the covered entity, and to limit its use of the data to exactly what the contract permits. A cloud provider hosting patient records without a BAA in place is not a grey area; it is a compliance failure on both sides of the contract, regardless of how good that provider's actual security is.
This is Protected Health Information, created by a covered entity about an identifiable patient. Its handling, storage, and any breach of it fall directly under HIPAA.
The organisation and the data both sit inside the boundary the law was written for.
Unless that app was built by, or contracted to, a covered healthcare provider or insurer, HIPAA does not apply to it — even though the data is arguably more detailed than what your doctor sees in a single visit. The app is instead governed by its own privacy policy and general consumer-protection law, which offer weaker guarantees.
A common misunderstanding is that data sensitivity determines whether HIPAA applies; who is holding the data does.
De-identifying data, and how re-identification can undo it
Once PHI has every one of those eighteen identifiers stripped out — the Safe Harbor method — HIPAA no longer treats it as PHI at all, and a hospital can share it freely for research without patient authorisation. The alternative, Expert Determination, lets a qualified statistician certify a smaller, more tailored set of removals as sufficiently low-risk instead of following the fixed list.
The gap in Safe Harbor is that “identifier removed” is not the same guarantee as “person unidentifiable.” Researcher Latanya Sweeney showed that ZIP code, birth date, and sex alone — none of them a full identifier on their own — uniquely identify roughly 87% of the U.S. population when combined with an outside, publicly available list like a voter roll. De-identified data can be re-identified by cross-referencing it against a second dataset that was never covered by HIPAA in the first place.
What a breach actually triggers
When a covered entity has a breach — a hacked hospital database, a lost laptop with patient files on it — HIPAA requires notifying every affected patient, notifying the federal government, and in large breaches notifying the media, all within a fixed number of days. Fines follow, and they can run into the millions for a large or negligent breach.
None of those specific obligations apply to a consumer wellness app leaking the same kind of data. It might violate its own privacy policy, and general data-protection or state consumer law might apply — but not the specific machinery HIPAA sets in motion, because the app was never a covered entity to begin with.
Key takeaways
- HIPAA protects Protected Health Information handled by covered entities and their business associates — not every piece of health-adjacent data everywhere.
- PHI is defined by eighteen specific identifiers attached to health data, including a catch-all for any other unique identifying code — strip all eighteen and the legal category can disappear.
- Treatment, payment, and healthcare operations need no fresh authorisation each time; one signed notice at the first visit covers all three going forward.
- A business associate can only touch PHI under a signed agreement obligating it to safeguard the data and report its own breaches — sharing without one is a compliance failure regardless of actual security.
- De-identified data is a legal category, not a guarantee of anonymity — ZIP code, birth date, and sex alone re-identify most Americans once cross-referenced against an outside dataset.
Quick check
Answer these to unlock the next chapter — 3 of 4 to pass. You can retake it anytime.
Answer every question to check.
Make a free account to read on
Every chapter is free — an account is how your progress, XP, and streak follow you from your laptop to your phone, and how you show up on the leaderboard. No payment, no trial.