The Health Insurance Portability and Accountability Act was built around a relationship between patients and "covered entities." Covered entities include doctors, hospitals, insurers, and the vendors that process claims or handle records on their behalf.

When health data leaves that relationship, HIPAA generally does not protect that information. A fitness tracker that logs heart rates, a period-tracking app that logs a cycle, a wellness app that logs mood fluctuations, and a direct-to-consumer genetic testing company that logs ancestry and health markers, are generally not covered entities because they aren't providing treatment or billing insurance.

 

So what fills the gap?

First, the FTC Act’s section five outlines some requirements for fair business practices. The Federal Trade Commission has authority to police "unfair or deceptive" business practices. If a health app promises in its privacy policy that it won't sell data and then does exactly that, the FTC can act. The agency has brought enforcement actions against companies that misrepresented how they used health information. However, section 5 punishes broken promises, not the practice of collecting and monetizing sensitive data. If a company discloses that it may share data with "partners," that disclosure alone can satisfy the law.

The FTC also has a breach notification rule that requires certain health apps and connected devices to notify users if there's a breach of unsecured health data. It was updated in 2024 to apply to health apps, following enforcement actions against companies like GoodRx and BetterHelp for sharing sensitive health data with advertisers without adequate disclosure. It addresses breaches and improper disclosures, not data collection and sale that a company discloses upfront.

 

State privacy laws

A number of states have passed consumer privacy laws that treat health information as protected or "sensitive", generally requiring opt-in consent before it's processed. These laws are not interchangeable, thresholds, consent standards, and enforcement mechanisms differ by state:

  • California: The CCPA/CPRA framework defines "sensitive personal information" to include health data alongside government IDs, precise geolocation, and account credentials, and giving residents the right to limit its use in addition to standard access and deletion rights.
  • Virginia: The Consumer Data Protection Act (VCDPA) established the template most other states have followed, requiring opt-in consent for processing sensitive data including health information. It was later amended to add specific protections for reproductive and sexual health data, effective July 2025.
  • Colorado and Connecticut: Both classify health data as "sensitive data" requiring affirmative consent, and both were among the earliest states, alongside Virginia, to build out the now-common state privacy law template.
  • Indiana, Kentucky, and Rhode Island: All three brought new privacy laws into effect on January 1, 2026. Rhode Island has low applicability thresholds, covering businesses that process the data of as few as 35,000 residents.
  • Alabama: Alabama enacted its own privacy law in April 2026 (effective May 2027), making it one of the newest states to require opt-in consent for processing health-related sensitive data.
  • Vermont: Enacted the Data Privacy and Online Surveillance Act in June 2026, notable for applying its consumer health data provisions with no minimum data-volume threshold.

For organizations, the fact is that "sensitive data" includes health information across these laws, even though none of these companies are HIPAA-covered entities.

 

State-specific health data laws

Alongside privacy statutes, a separate category of laws targets "consumer health data," largely written in response to the Supreme Court's 2022 Dobbs decision and the resulting concerns about reproductive health data tracking. These laws are broader than privacy laws in what counts as covered data, and carry more enforcement:

  • Washington: The My Health My Data Act (MHMDA), effective March 2024, defines "consumer health data" broadly enough to include inferences about health status, requires consent or necessity for collection and separate consent for sharing, bans geofencing around health facilities, and includes a private right of action. A class action was filed against Amazon in 2025 alleging its advertising SDKs harvested consumer health data without consent.
  • Nevada: SB 370, effective March 2024, is similar to Washington's approach but is enforced by the state Attorney General and Commissioner of Consumer Affairs, without a private right of action.
  • Connecticut: The state added consumer health data as a distinct sensitive-data category via amendments to the Connecticut Data Privacy Act (CTDPA), effective July 2023, including a geofencing restriction (1,750 feet around health facilities) than Washington's.

 

State genetic privacy laws

More than a dozen states have now passed laws governing direct-to-consumer (DTC) genetic testing companies. Requirements differ, but common things include consent for collection and secondary use, consumer rights to access or delete data, mandatory destruction of biological samples on request, and restrictions on foreign-adversary access to genomic data.

  • California: The Genetic Information Privacy Act (GIPA) was among the first laws of its kind, requiring express consent before a DTC company collects, uses, or discloses genetic data, and giving consumers the right to request deletion of their data and destruction of biological samples.
  • Florida: State law restricts the use of genetic information by life, disability, and long-term care insurers.
  • South Dakota: The Genetic Data Privacy Act (SB 49), effective July 1, 2026, requires consent revocation to be honored with sample destruction within 30 days, mandates a security program for genetic data, and grants the state Attorney General authority to seek civil penalties of up to $5,000 per violation.
  • Connecticut: SB 4, effective October 1, 2026, grants consumers rights to access, delete, and revoke consent for genetic data, requires "express consent" under standards aligned with the federal Common Rule for research disclosures, and is enforceable by the state Attorney General as an unfair trade practice.
  • Alabama: Its genetic privacy law is notable for defining "deidentified data" with a carve-out tied to HIPAA's deidentification standard.

 

What this means for organizations

Companies that collect health-adjacent data outside a HIPAA-covered relationship should not assume that they do not need to be compliant. State privacy laws, health-specific statutes like Washington's My Health My Data Act, and genetic privacy laws can independently apply based on where users are located, not where the company is headquartered. Marketing a product as "HIPAA compliant" when it isn't actually subject to HIPAA is itself a potential FTC Section 5 exposure, since it's a claim that can be deceptive if untrue.

Read also: Why ‘HIPAA-ready AI’ isn't always HIPAA compliant

 

FAQs

Is HIPAA compliance the same as having a health privacy law's protection?

No, HIPAA only applies to covered entities and their vendors, so being "HIPAA compliant" doesn't mean a company is covered by HIPAAl.

 

If a company is based outside a state, do that state's health privacy laws still apply?

Generally yes, since these laws are normally triggered by where the user or resident is located, not where the company is headquartered.

 

Are all types of "health data" treated the same under these laws?

No, definitions differ, with some laws covering only clinical-type data and others reaching inferences drawn from unrelated behavior.

 

Who enforces these laws?

Usually a state Attorney General or a specific consumer protection agency.