Skip to content
AFAIFitnessAPI
Compliance

Does My Fitness App Need to Be HIPAA Compliant?

Updated July 14, 2026

Usually no. HIPAA binds only covered entities (providers, health plans, clearinghouses) and their business associates, so a direct-to-consumer fitness app that collects data for its own users generally falls outside it. HIPAA does apply if you build or run the app on behalf of a covered entity under a Business Associate Agreement. But being outside HIPAA is not being unregulated: the FTC Health Breach Notification Rule, GDPR, and state consumer-health laws usually apply instead. This is general guidance, not legal advice, so confirm your status with a qualified professional.

If you are building a direct-to-consumer fitness or wellness app, the honest answer is usually no — you are most likely not subject to HIPAA. HIPAA binds only "covered entities" (health providers, health plans, clearinghouses) and their "business associates," so an app that collects data directly from and for consumers generally falls outside it. The catch: "not HIPAA" does not mean "unregulated" — your real obligations usually come from the FTC Health Breach Notification Rule, GDPR (for EU users), and state consumer-health laws. This is general engineering guidance, not legal advice; confirm your own status with a qualified professional.

Does HIPAA apply to your app?

HIPAA applies only to two kinds of entities. If you are neither, you do not have to comply with the HIPAA Rules.

  • Covered entities — health care providers who transmit health information electronically for covered transactions, health plans, and health care clearinghouses.
  • Business associates — a person or company that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity, under a signed Business Associate Agreement (BAA).

Per HHS guidance, if you offer services directly to and collect information for or on behalf of consumers — and not on behalf of a provider, health plan, or clearinghouse — you are not likely subject to HIPAA as either a covered entity or a business associate. Data a user downloads or enters into an app for personal use is generally not protected by HIPAA, regardless of where it originally came from, unless the app was provided by a covered entity or its business associate. In fact, once a covered entity sends PHI to a consumer app at the individual's direction, that data is no longer subject to HIPAA in the app's hands.

The deciding factor is the relationship and purpose — are you doing a covered entity's work? — not the sensitivity of the data. A heart-rate reading is only "PHI" when a covered entity or business associate holds it; the identical reading in a standalone consumer app is not PHI. For the full breakdown of PHI versus other data labels, see is fitness data PHI?.

When a fitness app does fall under HIPAA

HIPAA can pull your app in when you step into a covered entity's shoes. Typical triggers:

  • You build or offer the app on behalf of a covered entity (or that entity's contractor or business associate) — you may be a business associate.
  • B2B2C deployments where a hospital, provider, or health plan sponsors or offers the app to its patients or members.
  • The app is contracted to handle PHI for the covered entity, and you sign a BAA.

Rule of thumb: if a provider or plan is paying you to handle their patients' data, assume HIPAA is in scope and get advice.

What HIPAA requires if you are covered

If you are a covered entity or business associate, these are the obligations at a high level. This is not a compliance checklist — HIPAA compliance is contextual and should be confirmed with a qualified professional.

RequirementWhat it means for your app
Privacy RuleLimits uses and disclosures of PHI, applies "minimum necessary," and grants individual rights (access, amendment, accounting of disclosures).
Security RuleFor electronic PHI: administrative, physical, and technical safeguards — access controls, audit controls, risk analysis, and encryption (currently "addressable").
Breach Notification RuleThe HIPAA breach rule (distinct from the FTC rule below).
Business Associate AgreementsA BAA with every downstream vendor that touches PHI.

Two cautions: penalty amounts are inflation-adjusted annually, so verify current figures at HHS before relying on any number. And there is no official HHS "HIPAA certification" — any vendor claiming one is a red flag.

What applies instead for consumer apps

This is the part most builders miss. "Not HIPAA" does not mean "unregulated." For a typical consumer fitness app, these usually matter more than HIPAA:

  • FTC Health Breach Notification Rule (HBNR). For consumer health apps not covered by HIPAA, this is often the operative breach law. A 2024 update (effective July 29, 2024) made explicit that makers of health apps, connected devices, and similar products are covered. It reaches vendors of personal health records and their service providers — precisely the non-HIPAA world. A "breach of security" is read broadly, and can include unauthorized disclosures such as sharing health data with third-party ad tech, not just outside hacks (verify exact phrasing against the final rule). When triggered, you must notify affected individuals, the FTC, and — for large breaches — the media.
  • FTC Act Section 5. Unfair or deceptive practices are a baseline for all US consumer apps — a broken privacy promise is an enforcement risk independent of HIPAA or the HBNR.
  • GDPR for EU users. Fitness and wearable metrics are generally treated as special-category "data concerning health," and GDPR applies to non-EU companies that offer services to or monitor people in the EU. See GDPR for fitness apps.
  • State consumer-health laws such as Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's amendments. These use deliberately broad "consumer health data" definitions that capture the wearable and workout data HIPAA leaves untouched, and often require opt-in consent — Washington even adds a private right of action. Treat the state landscape as fast-moving and verify the current roster as of 2026.
  • App-store policy. Apple and Google impose their own health-data requirements (consent, disclosure, and bans on selling health data) that often bite before any statute does. See Apple's health-data rules and Google Play's health-data policy.

What this means for your fitness app

  • Do not market a standalone consumer app as "HIPAA compliant." It is usually inapplicable and can mislead users.
  • Do not assume that being outside HIPAA leaves you unregulated — map your real obligations to the FTC HBNR, GDPR, and state laws.
  • Remember an OS permission grant (a HealthKit or Health Connect prompt) is a device access control, not automatically a legal consent basis.
  • The safe engineering posture — consent, data minimization, encryption, access control, and deletion — satisfies GDPR and state consumer-health laws even where HIPAA does not apply. See storing health data securely.

A note on limits

Whether HIPAA, the FTC rule, GDPR, or a state law applies turns on your specific relationships, users, and jurisdictions — and several of these rules are actively changing in 2026. Use this as a starting map, verify the current text of any rule you rely on, and get advice from a qualified professional for your particular case.

Frequently asked questions

Is a consumer fitness app automatically covered by HIPAA because it handles health data?
No. HIPAA is tied to covered entities and business associates, not to the sensitivity of the data. Per HHS guidance, an app that collects information directly from and for consumers is not likely subject to HIPAA. The same heart-rate reading is PHI only when a covered entity or business associate holds it.
When would my fitness app actually fall under HIPAA?
Typically when you build or offer the app on behalf of a covered entity, or in B2B2C deployments where a provider or health plan sponsors the app to its patients or members and you sign a Business Associate Agreement to handle PHI for them. The relationship and purpose decide it, not the data type.
If HIPAA doesn't apply, is my app unregulated?
No. Non-HIPAA health apps still face the FTC Health Breach Notification Rule (updated in 2024 to cover health apps and connected devices), the FTC Act's ban on deceptive practices, GDPR for EU users, state consumer-health laws like Washington's My Health My Data Act, and app-store policies. These often matter more than HIPAA for consumer apps.
Can I advertise my consumer app as HIPAA compliant?
It is usually the wrong claim for a standalone consumer app and can mislead users, since HIPAA typically does not apply. There is also no official HHS HIPAA certification, so any vendor claiming one is a red flag. Focus on the rules that do apply to you and verify current requirements with a professional.

Keep reading

General engineering guidance, last reviewed July 14, 2026. This is not legal, medical, or regulatory advice. Health-data laws (HIPAA, GDPR, state privacy laws) and platform policies vary by jurisdiction and change often, and how they apply depends on your specific product, users, and data. Confirm your obligations with a qualified attorney or compliance professional and check the current official sources before you ship.

← All compliance · by AIFitnessAPI