The App That Knows Your Diagnosis: Health Data Outside HIPAA and the Rules That Fill the Gap
By Casey Scott McKay ·
Most health data in the United States is not governed by the statute everyone names. This article maps the actual boundary of HIPAA — which reaches covered entities and their business associates and nothing else — and then works through the regimes that have grown up to fill the space outside it: the health breach notification rule now applied to consumer apps, general consumer protection enforcement against undisclosed data sharing, and a fast-moving set of state statutes that define consumer health data far more broadly than the federal rules ever did. It covers the tracking technology problem on patient portals, which has produced the most litigation of any issue in the field, and the de-identification standards that determine whether a data set can lawfully be licensed. The second half addresses research consent, information blocking and interoperability, regulated software, and the contract architecture a digital health product actually needs.
IP and Technology > Privacy Data Security | Article | Published 11 January 2026 - Updated 27 January 2026 | Casey Scott McKay - marksy.us
Summary. Most health data in the United States is not governed by the statute everyone names. This article maps the actual boundary of HIPAA — which reaches covered entities and their business associates and nothing else — and then works through the regimes that have grown up to fill the space outside it: the health breach notification rule now applied to consumer apps, general consumer protection enforcement against undisclosed data sharing, and a fast-moving set of state statutes that define consumer health data far more broadly than the federal rules ever did. It covers the tracking technology problem on patient portals, which has produced the most litigation of any issue in the field, and the de-identification standards that determine whether a data set can lawfully be licensed. The second half addresses research consent, information blocking and interoperability, regulated software, and the contract architecture a digital health product actually needs.
Keywords: health data privacy · HIPAA scope · covered entities · business associates · consumer health apps · health breach notification rule · tracking pixels on patient portals · state health privacy statutes · consumer health data · de-identification · expert determination · real world evidence licensing · information blocking · interoperability APIs · software as a medical device · clinical decision support · substance use disorder records · genetic testing privacy · telehealth licensure · research consent
This is premium Marksy content — the full document is available to subscribers.