Many of us carry a health app in our pocket – in fact, most of us carry several.

We can log our steps, monitor our heart rate, view our medical records and connect wearable devices that capture a steady stream of personal health information. But how often do we stop to ask, “where does all that data actually go?”

Most people assume health data is protected simply because it is health data. Yet the same information that is safeguarded under HIPAA in a doctor’s office may be subject to entirely different rules once it is shared with a wellness app, wearable device or AI-powered health platform.

As the line between healthcare and consumer technology continues to blur, patients are increasingly moving their information between traditional healthcare organizations and digital tools that promise convenience, insight and personalized care. While these innovations come with many benefits, they also raise just as many questions about how health information is protected once it leaves the traditional healthcare ecosystem.

In recent years, federal regulators signaled a greater willingness to apply privacy and breach-reporting expectations to health apps and connected technologies. However, that approach seems to have shifted based on the Federal Trade Commission (FTC) recission of its 2021 policy statement in September 2026.

This decision has reignited debate around a longstanding challenge in healthcare privacy: what happens to sensitive health information when it moves beyond HIPAA-covered entities and into consumer technology platforms?

Why Does the Same Health Data Have Different Rules?

One of the most misunderstood realities in healthcare privacy is that HIPAA follows the data itself. Instead, HIPAA generally applies to specific organizations, such as healthcare providers, health plans and their business associates.

This distinction can be confusing, so let’s clear the muddy waters of healthcare regulation.

Consider a patient’s blood pressure reading; if the reading is collected and maintained by a hospital, physician practice or any other type of covered entity, HIPAA protections apply. But if that same reading is collected through a consumer health app or wearable device and stored outside the healthcare system, HIPAA may no longer govern how the information is used or disclosed.

Adding to the confusion, a patient’s blood pressure reading may be protected by HIPAA when it’s collected at their provider’s office. But if that same information is later downloaded into an app, it is likely no longer covered by HIPAA protections.

The data is identical, so why aren’t the rules that govern it?

As consumer health technologies become more integrated into daily life, having protections in place feels increasingly important for healthcare organizations, HIM professionals and patients alike.

Why Does the FTC Health App Policy Recission Matter?

The now-rescinded FTC policy statement clarified that certain consumer health apps and connected devices could be subject to the FTC’s Health Breach Notification Rule when unauthorized disclosures of health information occurred. It “place(d) entities on notice of their ongoing obligation to come clean about breaches.”

However, the FTC’s recent decision to withdraw that guidance creates uncertainty about how aggressively those protections will be enforced moving forward. At the same time, federal agencies continue to encourage beneficiaries and consumers to adopt digital health tools, including apps designed to manage conditions, access health information and receive health-related recommendations.

For provider organizations, the issue isn’t just about the law – it’s also about encouraging trust between patients and those in charge of protecting their health information.

Patients often assume that health information receives the same safeguards, regardless of where it is recorded or stored. In reality, the rules governing a hospital EHR and a consumer wellness application are often very different.

The Case for Stronger Consumer Health Privacy Protections

The FTC policy recission arrives amid ongoing discussions surrounding proposed legislation, such as HIPRA, which seeks to establish more consistent protections for consumer health information.

The question at the core of this discussion is straightforward: Should sensitive health data receive different protections simply because it is held by a consumer application rather than a healthcare provider?

Regardless of where policymakers ultimately land, healthcare organizations should pay close attention to this debate.

As patients exercise their right to access and direct their information, providers increasingly encounter scenarios where records are sent to third-party applications that may operate under entirely different privacy standards than those patients expect.

When a patient later questions how their information was used, shared or exposed, healthcare organizations often find themselves helping explain a reality many consumers never realized existed.

Where is the Missing Trust Layer?

Healthcare data exchange depends on trust:

  1. Providers need confidence that disclosures are made appropriately and in accordance with legal obligations.
  2. Patients need confidence that their information is being shared only as intended.

But trust becomes harder to maintain when health information moves into ecosystems where privacy obligations, consent practices and breach notification requirements are different than the laws that govern PHI in a traditional clinical setting.

This is where HIM professionals entrusted with stewarding patient data play an important role.

Beyond processing requests, HIM teams help ensure:

  • Disclosures are reviewed
  • Authorizations are validated
  • Patient intent is understood
  • Information is shared through processes designed to protect both access and privacy

As new technologies emerge, that expertise becomes more important – not less.

What Should You Do Next?

Healthcare privacy and data governance are becoming increasingly complex – and the FTC’s policy recission only widens the legal confusion. As patients continue to use consumer health apps and digital platforms, healthcare organizations should be prepared to navigate an evolving landscape where not all health data is protected the same way.

Provider organizations should consider:

  • Educating staff on the distinction between HIPAA-covered and non-HIPAA-covered health data
  • Preparing teams to answer patient questions about third-party health apps and consumer platforms
  • Reviewing workflows for patient-directed disclosures to consumer applications
  • Evaluating how patient education materials explain the risks and responsibilities associated with directing data outside the healthcare system
  • Continuing to prioritize trusted, well-governed processes for managing health information exchange

A trust layer doesn’t stop patients from getting their data where they want it; it just ensures that patients are fully informed of what happens to their data.

Looking Ahead: The Future of Health App Privacy

The broader debate over consumer health privacy is far from over.

As healthcare data becomes more portable and digital health technologies continue to expand, regulators, legislators, providers and patients alike will all be forced to grapple with the same question: How do we preserve innovation in data exchange without sacrificing trust?

For us in HIM, the answer begins with understanding where privacy protections start, where they end and why the distinction matters more than ever.

The ability to move health information is valuable and ensuring that it remains protected throughout that journey is essential to the integrity and safety of patient health data.

Sources:

  1. Federal Trade Commission. FTC Withdraws Obsolete Policy Statement (September 9, 2026). https://www.ftc.gov/news-events/news/press-releases/2026/09/ftc-withdraws-obsolete-policy-statement
  2. Health Breach Notification Rule. https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule
  3. Health Breach Notification Rule Final Amendments. https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule
  4. U.S. Senate Committee on Health, Education, Labor and Pensions. Health Information Privacy Reform Act (HIPRA). https://www.help.senate.gov/rep/newsroom/press/chair-cassidy-introduces-bill-to-protect-americans-private-health-data
  5. Centers for Medicare & Medicaid Services. Medicare App Library. https://www.medicare.gov/health-apps
  6. American Hospital Association. FTC Rescinds Policy Statement Extending Breach Notification Rule to Apps and Devices That Collect Health Information. https://www.aha.org/news/headline/2026-09-10-ftc-rescinds-policy-statement-extending-breach-notification-rule-apps-devices-collect-health

Where do you want to start?

Tell us a little bit about yourself, and we’ll match you with the right expert to help you optimize your patient information.