The Higher Floor: Why Patients Gain Protection, Not Lose It, When Their Health Data Moves Beyond HIPAA

INTRODUCTION

At b.well, we believe patients deserve clarity about how their health data is protected. As a platform built to connect the 350 million people in the US market to their own health information, we’ve watched a misconception take hold in recent coverage of conversational AI and consumer health tools: the idea that once data leaves HIPAA’s jurisdiction, it enters a lawless, less secure space. We think patients deserve a complete understanding of consumer privacy protections surrounding their health data. This brief lays out, in plain terms, what actually happens to a patient’s data when it moves from a HIPAA-covered entity into an app or platform they’ve chosen and why, in most cases, that data ends up under stronger protections, not weaker ones. We offer it as a resource for our partners, for policymakers, and for anyone trying to separate what’s being said from what’s actually happening.

I. A False and Recurring Narrative

A recurring misconception keeps surfacing across recent coverage of conversational AI and consumer health platforms. This misconception centers on the claim that a patient’s health information is less protected once it leaves HIPAA’s jurisdiction.  The implication is either that consumers should not use apps from non-HIPAA entities, or that consumer app and wearable device developers should be (or become) HIPAA-regulated entities.

Three recent examples of this misconception are described below

  • On January 8, 2026, the Electronic Privacy Information Center, a privacy advocacy organization, published a blog warning that connecting medical records to ChatGPT Health would “remove the HIPAA protection from those records, which is dangerous,” adding that the platform “is only bound by its own disclosures and promises,” with no “meaningful limitation on that, like regulation or a law.” 
  • On June 25, 2026, the news outlet Axios published an article telling readers that “the moment someone pulls data from their doctor’s office, it’s no longer covered by HIPAA.” While true, the article goes on to describe how consumer apps are regulated by a patchwork of conflicting standards and protections that depend on what are contained in the related terms and privacy notices which is not a complete picture.
  • On July 23, 2026, the news outlet Tech Times published an article, stating that connecting records to a consumer AI tool “permanently strips them of their federal privacy protections”. It also stated, once data leaves a provider’s system, only a company’s own terms of service and “weaker and changeable” state laws remain.

Each of these articles contains a similar fact-conclusion pattern, where the conclusion does not follow from the fact. 

Fact: Data does indeed leave HIPAA’s regulatory jurisdiction once a covered entity securely transmits a patient’s health data to the patient through his or her choice of application, under their HIPAA right of access (except when the app is offered by a HIPAA regulated entity). 

The Myth: After leaving HIPAA’s regulatory jurisdiction, it doesn’t necessarily follow that patient’s privacy protections are weak or changeable, or that this loss of HIPAA’s privacy protections is dangerous for consumers and their health data, especially for apps that have been approved for listing on the Medicare App Library or have otherwise voluntarily agreed to or been certified to follow the CARIN Alliance’s Code of Conduct, the industry-defined privacy and data best practices for consumer-facing applications involved in helping patients retrieve their medical records from HIPAA covered entities.

The Reality: The combination of FTC enforcement plus 23 states with comprehensive consumer privacy laws sets a higher floor of privacy rights and protections than are available to patients under HIPAA today.  This is even more so when the developers of consumer health apps publicly attest that they follow the CARIN Code of Conduct and apply for listing on the Medicare App Library. The reality is that patients actually gain more privacy protections once their data moves outside of HIPAA, not when it stays in HIPAA.  The rest of this brief explains why.

II. Facts Disputing this False Narrative

1. HIPAA was not built as a consumer privacy law.

It was enacted to let hospitals, health plans, and their business associates move clinical and payment data within and across the health care system without seeking permission every time. Most of HIPAA is not relevant to consumer apps. It’s entirely inappropriate for consumer apps to follow the Privacy Rule’s instructions for reporting information to public health authorities, to coroners, or to healthcare oversight agencies. Moreover, HHS’ Office of Civil Rights, which has regulatory and enforcement jurisdiction for HIPAA, has no authority and little experience with regulating these apps.  Its sister agency, the Federal Trade Commission already does. Applying HIPAA to consumer apps simply doesn’t make sense because the HIPAA framework is built for protecting PHI in the specific context of entities involved in the delivery and payment of healthcare services. If HIPAA applied to consumer apps, they would find themselves conflicted between inconsistent regulatory frameworks.

2. De-identification provides an example where HIPAA protections conflict with state consumer privacy laws.

A good example of that conflict is demonstrated by HIPAA’s handling of de-identified data derived from PHI. Under HIPAA, as long as 18 enumerated identifiers are removed from PHI, the resulting data is no longer regulated by HIPAA. As a result, de-identified clinical data is routinely sold and traded by HIPAA covered entities, without patient notice or choice, fueling a multi-billion dollar secondary use data economy. A consumer app that did the same without disclosure would be scrutinized by the Federal Trade Commission and the attorneys general for different states, either as a potential undisclosed data practice, unfair or deceptive act, or both. Moreover, any app launching into the CMS Health Tech Ecosystem must adopt and certify to the CARIN Code of Conduct, which requires a transparent disclosure about the app’s use and sharing of de-identified data. The claim that HIPAA has more protections ignores the dark data flows occurring every day inside HIPAA without acknowledging that these practices would not pass muster outside of HIPAA.

3. For apps, consent is the legal basis for data collection, use and sharing. Most of HIPAA allows collection, use and sharing without consent.

It is a common assumption that HIPAA requires a patient’s permission before a covered entity uses or shares protected health information. It does not, by deliberate policy choice, so that consent could never become a barrier to care. A consumer platform cannot rely on the same policy basis without upending their entire business. For these businesses, plain-language privacy notices built on fair information practice principles is the default. Moreover, to comply with most state laws, which provide added protections for sensitive data categories, they must treat consumer health data as a distinct, sensitive category requiring affirmative authorization before it is collected, used, or shared. A patient whose data moves from a covered entity into a well-built consumer app is, in a meaningful number of states, moving from a regulatory framework that does not ask for consent into one that always does.

5. The floor doesn’t fall when the data crosses HIPAA’s boundary; it floats ever upward to where the de facto national standard lives.

HIPAA sets a floor in a specific and narrow sense: it preempts state laws that would restrict a patient’s right of access below HIPAA’s own standard. That narrow function has been mistaken for a broader claim, that HIPAA represents the floor of consumer privacy protection generally. It does not. 

In fact, HIPAA patient rights are significantly curtailed, in order not to impose technical burdens on HIPAA covered entities. As an example, HIPAA grants patients a right to an accounting of disclosures made by covered entities; however, this accounting  need not include PHI shared between covered entities for treatment, payment, or operations.

By contrast, all but a handful of the 23 states with comprehensive consumer privacy laws give consumers, as a matter of course, the right to know what is collected and how it is used, rights of access and, with varying support, portability rights, the right to deletion, and the right to withdraw consent already given, typically alongside a requirement that regulated entities obtain consent before sensitive data is used for marketing or shared with data brokers. These protections demonstrate the higher floor, and how that floor reflects an emerging national consensus over time. For most consumer apps, it makes more sense to build products with privacy standards that meet the higher floor than to create different products for residents of different states. This actually turns the variability of state consumer privacy laws into a strength over HIPAA.

6. In some states, patients can enforce that floor themselves, a power HIPAA has never given them.

A patient cannot sue a covered entity directly for a HIPAA violation; enforcement runs exclusively through the Department of Health and Human Services and, in limited circumstances, state attorneys general. Many states, like Washington’s My Health My Data Act, does the opposite. It makes any violation a per se violation of the state Consumer Protection Act, which carries its own private right of action, and the first lawsuit under that provision was filed in February 2025. When a privacy advocate says a platform is bound only by its own promises, the accurate answer,  in some states at least, is that the platform is bound by a statute that consumer can personally enforce in court, a legal position no HIPAA covered entity has ever occupied with respect to its own patients.

7. Apps built into the CMS Health Tech Ecosystem stand on a second, higher floor still.

The floor rises again for consumer apps that choose to participate in the CMS Health Tech Ecosystem. To be listed in the Medicare App Library, a developer must adopt the CARIN Code of Conduct, a voluntary trust framework, and pass an independent compliance assessment conducted by DirectTrust. The Code codifies protections that predate most state comprehensive privacy laws and, in several respects, exceeds them. It requires that any material change to a privacy notice be disclosed in plain language and accepted by the user, and that a user who declines retains the right to take their data with them and be forgotten by the app rather than being bound by a term they never agreed to. This is the direct answer to the claim that a platform can change its terms at will: under the Code, it cannot, not without the user’s informed acceptance or the user’s exit. The Code also protects consumer data through a change in business ownership in a way HIPAA does not. The concern raised when 23andMe’s genetic data set became subject to sale in its 2025 bankruptcy could not arise under an app that follows the Code, since that data must be deleted rather than transferred without the same protections attaching.

8. None of this depends on taking a company’s word for it.

A voluntary standard matters only if something enforces it, and the enforcement architecture around non-HIPAA consumer health data is deeper than the coverage suggests. The Federal Trade Commission has brought and settled enforcement actions under Section 5 of the FTC Act and its Health Breach Notification Rule against GoodRx, BetterHelp, and Easy Healthcare Corporation, publisher of the Premom fertility tracking application, in each case for sharing consumer health data with third parties inconsistent with the company’s own stated practices. State attorneys general enforce their own consumer protection and, increasingly, comprehensive health data statutes independent of HIPAA status. DirectTrust and DiME perform independent, continuing conformance reviews of CARIN-accredited apps and can revoke accreditation for noncompliance. The Centers for Medicare and Medicaid Services can remove an app from the Medicare App Library if that accreditation lapses, a public and commercial consequence with no real counterpart in HIPAA’s enforcement structure, where the Office for Civil Rights has long operated with resources outpaced by the size of the industry it oversees.

III. Comparing the Coverage to the Facts

Read against this record, the three articles that opened this brief each rest on an incomplete premise. For example, the suggestion that Frontier models in health are bound only by their own disclosures and promises overlooks the FTC Act, the amended Health Breach Notification Rule, and, for consumers in some states, privacy protections that users can personally enforce in court. 

The suggestion that data leaving a provider’s system enters a patchwork of conflicting standards describes something real, since the nation’s privacy law is not uniform, but it omits that the trend of that patchwork is toward more protection, not less, now covering more than half the population, and that the CARIN Code of Conduct exists precisely to give consumers assurance about apps that promise to follow it. The suggestion that leaving HIPAA permanently strips a patient of federal privacy protection is inaccurate on its face. Federal protection does not end at HIPAA’s border. It changes form, from a statute built around covered entities to an enforcement regime, run by the Federal Trade Commission, built around the promises a company actually makes to the people who trust it.

IV. Conclusion

Patients are not standing in an unregulated space when their data moves beyond HIPAA. They are standing in one governed by state statutes that, across most of the country, ask more of the companies that hold their data than HIPAA ever has. For apps that join the CMS Health Tech Ecosystem, their privacy commitments are reinforced by their promise to follow the CARIN Code of Conduct.  These commitments make them accountable under the FTC enforcement authorities and the states attorney general of comparable jurisdiction. 

The question worth asking about any platform that touches a patient’s health data is not whether HIPAA applies to it. It is whether the platform has made enforceable commitments, and whether someone other than the platform is positioned to hold it to them. On that question, the record examined here gives a clear answer, the FTC, state laws and quite frankly the patient are the best suited to hold apps accountable for the use of our most coveted and personal data.

Sources

EPIC / The Record, “ChatGPT Health Feature Draws Concern From Privacy Critics Over Sensitive Medical Data,” January 8, 2026, epic.org
Axios, “The Perils of Connecting Wearables with Medical Records,” June 25, 2026, axios.com
Tech Times, “ChatGPT Health Goes Nationwide: Your Medical Records Lose HIPAA Protection,” July 23, 2026, techtimes.com
U.S. Department of Health and Human Services, Proposed Modifications to the HIPAA Privacy Rule to Support, and Remove Barriers to, Coordinated Care and Individual Engagement, Federal Register, 2021, with 2026 tribal consultation update
Washington My Health My Data Act, RCW 19.373, private right of action via RCW 19.86 (Consumer Protection Act)
Federal Trade Commission, In the Matter of BetterHelp, Inc. (2023) and press releases on GoodRx and Easy Healthcare Corporation (Premom) settlements, ftc.gov
CARIN Alliance, Code of Conduct, carinalliance.com/code-of-conduct
DirectTrust, CARIN Code of Conduct Accreditation Program, accreditation.directtrust.org/programs/carin-code-of-conduct
Centers for Medicare & Medicaid Services, Medicare App Library, cms.gov/priorities/health-technology-ecosystem/overview/medicare-app-library

Join us on our mission to simplify healthcare, one person at a time.