No—HIPAA does not automatically cover all online health data. Whether data from texting, wellness apps, fitness trackers, fertility apps, prescription discount platforms, or online therapy tools is protected by HIPAA depends on who collects it, why they collect it, and whether the organization is acting as a HIPAA covered entity or business associate. Companies handling this information should not assume HIPAA applies, but they should still protect sensitive health data using strong privacy, security, and contracting practices.
When does HIPAA apply to online health data?
HIPAA applies only to specific organizations and their partners. The HIPAA Privacy, Security, and Breach Notification Rules govern the use and disclosure of protected health information by covered entities and their business associates. Covered entities include health plans, healthcare clearinghouses, and most healthcare providers that transmit health information electronically in connection with standard transactions. See 45 CFR 160.103.
If an app, platform, or messaging tool is used by or on behalf of a covered entity to create, receive, maintain, or transmit protected health information, it may fall under HIPAA. If the same type of app is offered directly to consumers outside that relationship, it often does not.
In other words, the technology itself is not what determines HIPAA coverage. The legal role of the company and the data flow do.
What counts as protected health information online?
Under HIPAA, protected health information, or PHI, is individually identifiable health information that is transmitted or maintained in any form or medium by a covered entity or business associate, subject to certain exceptions. See 45 CFR 160.103.
Online PHI can include:
- Names linked to diagnoses, symptoms, medications, or treatment plans
- Appointment reminders sent by text or email
- Therapy notes or patient portal messages
- Insurance, billing, and claims data
- Device or app data when tied to an identifiable patient in a covered relationship
By contrast, health-related data collected directly by a consumer app may be sensitive but not regulated as PHI under HIPAA if no covered entity or business associate relationship exists.
Are wellness, fitness, and fertility apps covered by HIPAA?
Usually, consumer wellness, fitness, and fertility apps are not covered by HIPAA when they collect information directly from users for the app company’s own purposes. For example, a step tracker, calorie counter, cycle-tracking app, or symptom journal may hold highly sensitive information, but HIPAA generally does not apply unless the app is operating on behalf of a covered entity.
The U.S. Department of Health and Human Services has long distinguished between consumer health apps and HIPAA-regulated services. If a hospital offers a patient-facing app through a vendor and that vendor handles PHI for the hospital, HIPAA may apply. If a consumer independently downloads a similar app from an app store and uses it outside any provider relationship, HIPAA usually does not.
Why this distinction matters
Many users assume all health apps have HIPAA protections. That is incorrect. In non-HIPAA settings, data practices are often controlled by the company’s privacy policy, terms of use, Federal Trade Commission oversight for unfair or deceptive practices, state privacy laws, and, in some cases, reproductive or consumer health privacy laws.
Is texting covered by HIPAA?
Texting can be covered by HIPAA if PHI is being sent by a covered entity or business associate. HIPAA does not ban texting, but it requires appropriate safeguards. The Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI. See 45 CFR Part 164, Subpart C.
Basic SMS texting is often risky because messages may be stored on personal devices, forwarded, misdirected, or transmitted without encryption. If an organization uses texting for patient communication, it should assess the risks and implement controls such as:
- Secure messaging platforms instead of standard SMS when PHI is involved
- Access controls, unique user IDs, and device management
- Policies on minimum necessary use
- Workforce training and sanctions for improper disclosure
- Retention and audit capabilities where appropriate
Patients may request unencrypted communications in some cases, but organizations still need clear policies and documented processes under the HIPAA Privacy Rule.
Are online therapy platforms and telehealth tools covered by HIPAA?
Often yes, but not always. If an online therapy platform or telehealth vendor provides services for a licensed provider or healthcare organization that is a covered entity, the vendor will often be a business associate and must sign a business associate agreement, or BAA. That relationship triggers HIPAA obligations.
However, a mental wellness app offering self-guided coaching directly to consumers may fall outside HIPAA if it is not acting on behalf of a covered entity. The fact that the service relates to mental health does not by itself create HIPAA coverage.
Organizations should be especially careful in behavioral health because the data is highly sensitive and may also implicate stricter state confidentiality rules. In some settings, 42 CFR Part 2 may apply to substance use disorder records maintained by federally assisted programs.
What about prescription discount cards, pharmacy platforms, and online prescribing services?
These arrangements vary. A pharmacy that is a covered entity is subject to HIPAA. A vendor operating a prescription management or refill tool for the pharmacy may be a business associate. But a standalone discount card company or consumer marketplace may not be covered by HIPAA if it is collecting data for its own commercial purposes rather than on behalf of a covered entity.
This is one reason healthcare organizations should map data flows carefully. A consumer may move between HIPAA-covered and non-covered environments without realizing it—for example, from a provider portal to a third-party coupon or marketplace site.
What should companies do to protect PHI and other sensitive health data?
Even when HIPAA does not apply, companies should treat health-related data as high risk. For covered entities and business associates, the following steps are essential:
- Determine your legal role. Confirm whether you are a covered entity, business associate, or neither under 45 CFR 160.103.
- Identify PHI and map data flows. Document what data is collected, where it goes, who can access it, and whether any third parties receive it.
- Use business associate agreements where required. If a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity, a BAA is generally required under 45 CFR 164.502(e) and 164.504(e).
- Perform a risk analysis. The HIPAA Security Rule requires an accurate and thorough assessment of risks and vulnerabilities to electronic PHI. See 45 CFR 164.308(a)(1)(ii)(A).
- Implement reasonable safeguards. Encryption, access controls, multifactor authentication, audit logging, secure configuration, and device management are common baseline measures.
- Review tracking technologies and pixels. Websites, apps, and portals that send health-related data to analytics or advertising vendors can create major HIPAA and privacy risks if identifiers and health context are disclosed improperly.
- Train the workforce. Staff should know when PHI can be texted, emailed, uploaded, or shared with vendors, and when it cannot.
- Maintain breach response procedures. If unsecured PHI is breached, notification obligations may apply under 45 CFR 164.400-414, including notice to affected individuals without unreasonable delay and no later than 60 days after discovery.
What if HIPAA does not apply?
If a company is outside HIPAA, that does not mean it can ignore privacy and security. Other laws and regulators may still apply, including the Federal Trade Commission, state consumer protection statutes, state health privacy laws, biometric laws, breach notification laws, and contractual commitments made in privacy notices.
Best practices for non-HIPAA health data include:
- Collect only the data needed for the service
- Provide clear and truthful privacy disclosures
- Avoid sharing sensitive health data for advertising without informed authorization where required
- Limit retention and delete data when no longer needed
- Vet software development kits, analytics tools, and ad tech embedded in apps
- Apply strong security controls and incident response planning
Why healthcare organizations should not rely on assumptions
The biggest compliance mistake in digital health is assuming that all health data is either fully protected by HIPAA or entirely outside regulation. Neither assumption is safe. The same type of information may be PHI in one workflow and non-HIPAA consumer data in another, depending on the parties and purpose.
Healthcare organizations, vendors, and digital health companies should evaluate each tool, app, and communication channel individually. Clear role definitions, documented risk assessments, and consistent safeguards are the best way to protect patients and reduce compliance exposure.
HIPAA covers some online health data, but not all of it. Companies should first determine whether they are operating as a covered entity or business associate, then apply the right privacy and security controls. Where HIPAA does not apply, sensitive health data still deserves careful protection under sound governance, security, and transparency practices.

