Privacy policies are unilateral disclosures, which means they are statements of current practice that companies can revise as their practices change. Most privacy policies include language reserving the company's right to modify the policy at any time, often with a clause like "we may update this policy periodically, and continued use of the service constitutes acceptance of the changes." This is standard practice across tech, not just healthtech.

 

Why health data is different

Consumer data such as shopping preferences, browsing history etc is treated with less restrictions than health data under U.S. law. Health data exposure can lead to employment discrimination, insurance denial, reproductive privacy violations, mental health stigma, and personal safety risks.

A few things limit how freely a healthtech company can change how it treats data that's already been collected:

HIPAA-covered entities

If a healthtech company qualifies as a "covered entity" or "business associate" under HIPAA, retroactive changes to data use are limited. HIPAA doesn't let a covered entity update its Notice of Privacy Practices and start using previously collected data for a new purpose, like marketing, without new authorization from the patient.

 

Most consumer health apps aren't HIPAA-covered

Fitness trackers, period-tracking apps, mental wellness apps, and direct-to-consumer genetic testing services sometimes fall outside HIPAA because they aren't providers, insurers, or clearinghouses, and they don't process claims through covered entities. These companies are instead governed by their own privacy policy and by general consumer protection law.

A 2017 analysis in the Catholic University Journal of Law & Technology pointed out that the U.S. has no single comprehensive statute governing personal data collection, leaving health apps that fall outside HIPAA to be regulated by a patchwork of FTC enforcement, FDA guidance, and inconsistent state law. As the author puts it, there is "not a single comprehensive law regulating the collection of personal data" in the U.S. That structural gap, identified nearly a decade ago, is the same one still driving the FTC's and states' more recent efforts to police retroactive policy changes.

 

There may be no such thing as 'non-health' data

The HIPAA regulatory gap described above assumes there's a difference between apps that handle "health data" and apps that don't. A 2020 qualitative study in JAMA Network Open suggests that difference is non-existent. The researchers interviewed 26 experts across privacy law, data science, health policy, and consumer advocacy, and asked them to distinguish health-related digital data from everyday digital exhaust such as shopping records, toll-pass logs, frequent-flyer accounts, etc. The experts couldn't do it. Their consistent view was that any data can become health data once it's aggregated across sources and over time, even when a single data point looks ordinary on its own.

The study grouped the resulting privacy risks into five characteristics of what the authors call a person's "digital health footprint": it's invisible to the person it describes, often inaccurate in ways that generate false inferences, permanent since there's no real deletion mechanism once it's dispersed across platforms, marketable to data brokers and advertisers, and easier to re-identify than most consumers assume. On that last point, the researchers found that supposedly anonymized location data is not much of a shield, one expert noted that 85 percent of people can be re-identified based on three GPS points, since a home, a workplace, and a child's school are usually enough to narrow a dataset down to one person.

This matters for the retroactive-policy-change. If a wellness app, a period tracker, or a fitness platform can be re-identified and cross-referenced with other datasets regardless of how "anonymized" or "aggregated" its data is claimed to be, then a policy change that broadens who the data gets shared with, or what it gets used for, carries real-world risk than the plain language of the update might suggest, even for data the company never labeled as sensitive in the first place. The study's authors conclude that HIPAA and similar sector-specific laws, built around a narrower definition of "health information," are out of touch with how modern data function.

The Federal Trade Commission has taken the position that materially changing how you use data collected under an earlier, more restrictive privacy promise, without getting affirmative consent from the people whose data it is, can constitute an unfair or deceptive practice under Section 5 of the FTC Act.

In a February 2024 blog on the FTC's Technology Blog, staff from the agency's Office of Technology and Division of Privacy and Identity Protection framed the issue as a structural conflict of interest. AI companies have a business incentive to feed user data into their models, but many of those same companies have made prior privacy commitments that restrict that kind of use. The blog warns that if a company only discloses a shift toward more permissive data practices, like sharing data with third parties or using it for AI training, through a quiet, retroactive change to its terms of service, that pattern can itself amount to an unfair or deceptive practice.

The FTC blog also establishes this in enforcement in prior cases. Nearly twenty years ago, the agency pursued Gateway Learning Corporation, the company behind "Hooked on Phonics," after it altered its privacy policy to permit sharing consumer data with third parties without notifying users or securing their consent. More recently, in 2023, the FTC took action against a genetic testing company for retroactively broadening the categories of third parties it could share consumer data with, again without new notice or consent from the people whose data was already on file. The FTC's own framing of the throughline between these cases is that, "there's nothing intelligent about obtaining artificial consent."

The FTC blog also flags a market-structure problem worth noting for healthtech specifically, because switching between digital health products can be difficult once someone's data and history live inside one app, users may have little practical recourse if a company uses a privacy promise to win them as a customer and then loosens that promise later. In these enforcement matters, the FTC required companies to delete data or algorithms that had been built using data obtained under different terms than the ones applied.

 

State health privacy laws

States like Washington (with its My Health My Data Act) and others have passed laws specifically targeting consumer health data collected outside HIPAA. These often require affirmative, opt-in consent for new uses of health data, not just passive notice-and-continued-use.

Read also: Can de-identified data be used to train AI under HIPAA?

 

Whatmaterial changeactually means in practice

Not every policy update triggers these concerns. A change to who the data protection officer is, or a clarification of existing practice, is different from:

  • Starting to sell or share health data with new categories of third parties
  • Using health data to train an AI model when the original policy didn't disclose this
  • Changing data retention periods in ways that extend how long sensitive data is kept
  • Repurposing data collected for one clinical or wellness purpose into a different use case

These are the kinds of changes regulators and courts identify as "material," and material changes are where affirmative consent is legally and ethically required.

 

Practical steps for healthtech companies

Companies that want to change their data practices without regulatory or reputational problems should consider:

  • Notifying users directly (email, in-app banner) rather than relying on a buried policy page update
  • Getting affirmative opt-in consent for any new use of previously collected data, rather than opt-out
  • Segmenting data so that data collected under old terms isn't merged with data collected under new terms without consent
  • Offering a choice to delete data rather than just an option to stop using the service going forward
  • Avoiding retroactively applying broader terms to historical data

 

FAQs

Is a privacy policy legally binding?

Yes, but courts generally treat it as a policy the company can amend rather than a fixed contract, as long as users get reasonable notice of changes.

 

What's the difference between a privacy policy and terms of service?

A privacy policy governs how a company collects and uses your data, while terms of service govern your broader rights and obligations in using the product.

 

Do startups need to worry about this as much as large healthtech companies?

Yes, since FTC enforcement and state health privacy laws apply regardless of company size.