Digital Health Data Checklist: Regulatory Classification, Business Associate Terms, Consent and Tracking, Breach Analysis, and Vendor Diligence
By Casey Scott McKay ·
This checklist builds a digital health data position starting from the determination that governs everything else: covered entity, business associate, or neither. Phase one settles that question per legal entity and per line of business, in writing, with reasoning. Phase two builds the data inventory from production systems rather than from interviews. The middle phases handle the third-party tracking code that has produced more litigation in this sector than any other practice, the state consumer health data statutes whose definitions reach far beyond the federal rules, business associate terms and the data use permissions buried in them, and the de-identification strategy that determines what can lawfully be licensed. The closing phases cover research consent scope, information blocking, the device boundary, vendor management, incident readiness, and the diligence pack buyers now expect to see prepared.
IP and Technology > Privacy Data Security | Checklist | Published 22 December 2023 - Updated 13 October 2024 | Casey Scott McKay - marksy.us
Summary. This checklist builds a digital health data position starting from the determination that governs everything else: covered entity, business associate, or neither. Phase one settles that question per legal entity and per line of business, in writing, with reasoning. Phase two builds the data inventory from production systems rather than from interviews. The middle phases handle the third-party tracking code that has produced more litigation in this sector than any other practice, the state consumer health data statutes whose definitions reach far beyond the federal rules, business associate terms and the data use permissions buried in them, and the de-identification strategy that determines what can lawfully be licensed. The closing phases cover research consent scope, information blocking, the device boundary, vendor management, incident readiness, and the diligence pack buyers now expect to see prepared.
Keywords: digital health checklist · status determination · covered entity analysis · business associate terms · data use permissions · tag inventory · tracking pixels · consumer health data statutes · separate consent · geofencing prohibition · de-identification strategy · expert determination · research consent scope · information blocking exceptions · device classification · health system contracting · vendor register · incident playbook · log preservation · diligence pack
How to use this checklist
| Field | Detail | |---|---| | Who runs it | Privacy counsel with engineering, marketing, regulatory affairs, and commercial | | When | Before launch; on any change of business model; on any enterprise deal; annually | | Time required | Six to eight weeks for a first pass | | Gates | Status determined in writing; tags inventoried; consents separated; agreements executed | | Output | A status memo, a data inventory, a tag scan record, a vendor register, and an incident playbook | | Companion documents | Building a Digital Health Product and The App That Knows Your Diagnosis |
The matter. A company operates a symptom-tracking app with eight million consumer users and has just signed its first two contracts with hospital systems. Its privacy policy was written for the consumer product and describes data sharing with "analytics partners". The website and the app both carry advertising and analytics tags added by marketing through a tag manager. The company plans to license a de-identified data set to a pharmaceutical sponsor and has commissioned no expert determination. Its research arm holds records from an academic collaboration whose consent form mentions research only. Marketing has begun describing the app as "detecting early signs" of a condition. Neither hospital contract has an executed business associate agreement, and the security questionnaire from the second hospital is overdue.
Phase 1. Determine status
-
[ ] Do it per legal entity and per line of business. Why. Enterprise groups routinely find three subsidiaries handling apparently identical data have three different answers. Trap. One determination for the whole group.
-
[ ] Test covered entity status against the definitions. Health plan, clearinghouse, or provider transmitting electronically in connection with covered transactions — 42 U.S.C. § 1320d and 45 C.F.R. § 160.103. Trap. Assuming that holding clinical data makes an entity covered. It does not.
-
[ ] Test business associate status separately. Creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity. Why. Direct statutory obligations attach, not merely contractual ones. Trap. A consumer business that signs its first provider contract and does not notice it has changed category.
-
[ ] Record the reasoning, not just the conclusion. Why. It is the first document a regulator, buyer, or enterprise customer requests, and a bare conclusion reads as an assumption. Trap. A one-line answer in a policy document.
-
[ ] [Gate] Re-run the determination whenever the business model changes. Why. A wellness app contracting with providers becomes a business associate, and the whole compliance architecture must change. Trap. A determination dated at incorporation.
Phase 2. Build the data inventory from systems
-
[ ] Query production rather than interviewing teams. Why. Engineering enables flows for debugging and forgets them; the inventory has to describe what happens, not what was designed. Trap. An inventory assembled from a data mapping questionnaire.
-
[ ] Record per flow: what is collected, where stored, retention, internal access, external recipients, legal basis. Why. Every later step is a query against this table. Trap. Recording systems rather than flows.
-
[ ] List every external recipient and the agreement governing it. Analytics, advertising, mapping, chat, testing, payments, and enterprise integrations. Why. Most are governed by framework agreements with no data terms. Trap. Assuming a vendor agreement covers a flow that postdates it.
-
[ ] Flag flows carrying inferences as well as raw data. Why. State consumer health data definitions reach inferences, and they are usually undocumented. Trap. Inventorying inputs only.
-
[ ] Set retention periods and enforce them. Why. Data not held cannot be breached, produced, or misused, and indefinite retention is the most common aggravating factor in this sector. Trap. Retention decided by storage cost.
Phase 3. Inventory and remove the tracking code
-
[ ] Scan every health-related page and screen for third-party tags. Analytics, advertising, session replay, chat, testing, consent tools. Why. This is the single largest exposure in the sector. Trap. Scanning the marketing site and not the portal.
-
[ ] Determine what each tag transmits. Why. A page address alone frequently reveals condition, provider, or appointment type; combined with an identifier it is a disclosure about a named person. Trap. Assessing tags by vendor rather than by payload.
-
[ ] For a covered entity, treat transmission as a Privacy Rule disclosure unless an exception applies. Why. Regulatory guidance has addressed this directly. Trap. Relying on a vendor's assurance that data is "de-identified in transit".
-
[ ] For everyone else, expect wiretap and privacy claims. Why. The federal Wiretap Act and state analogues with statutory damages, as in In re Facebook Internet Tracking Litigation. Trap. Relying on standing defences; Spokeo v. Robins and TransUnion v. Ramirez require concrete harm but intrusion analogies are available.
-
[ ] Remove the unnecessary and reconfigure the rest so page addresses and identifiers are not transmitted. Why. Technical remediation is the only durable answer. Trap. A consent banner presented as the fix.
-
[ ] Restrict tag manager access. Why. Tags reappear through campaign integrations and vendor updates. Trap. Marketing retaining deployment rights after remediation.
-
[ ] [Gate] Re-scan quarterly and record the date. Why. A one-off remediation decays within months, and buyers now run their own scan and compare. Trap. An undated remediation memo.
Phase 4. Map the state consumer health data statutes
-
[ ] Map the definitions against actual data, including inferences and location. Why. Consumer health data may include purchases, search behaviour, proximity to a health facility, and biometric measurements. Trap. Mapping against the company's own concept of health data.
-
[ ] Separate collection consent from sharing consent. Why. Several statutes require distinct affirmative consents with prescribed content. Trap. A single acceptance covering both.
-
[ ] Check for geofencing prohibitions. Why. At least one statute prohibits virtual boundaries near health facilities for data collection or advertising, with penalties not requiring any showing of harm. Trap. Location-based marketing designed without a health-facility exclusion.
-
[ ] Identify jurisdictions with a private right of action. Why. It changes the risk profile and the litigation exposure substantially. Trap. Treating all state statutes as regulator-enforced.
-
[ ] Build to the strictest applicable standard. Why. Fifty implementations is not maintainable and the direction of travel is toward the stricter position. Trap. State-by-state feature flags that drift out of alignment.
Phase 5. Negotiate and audit business associate agreements
-
[ ] Execute before any data moves. Why. A covered entity disclosing protected health information without one has violated the Privacy Rule regardless of the vendor's behaviour. Trap. Data flowing during a pilot while the agreement is "in legal".
-
[ ] Read clause four of every vendor template. Why. Permission for the vendor's own product improvement, benchmarking, and de-identification is where the value moves, and it is granted in standard forms. Trap. Signing a template because the required content looks compliant.
-
[ ] Price de-identification rights rather than conceding them. Why. A vendor permitted to de-identify and retain has acquired an asset from the covered entity. Trap. Treating it as a technical permission.
-
[ ] Set notification in days, not the regulatory maximum. Why. The covered entity's own clocks run from discovery, and a vendor using the outer limit consumes most of the available time. Trap. Mirroring the regulatory period into the contract.
-
[ ] Verify subcontractor flow-down rather than reciting it. Why. Every downstream processor is a business associate with direct obligations. Trap. A flow-down clause with no audit right behind it.
-
[ ] Test the infeasibility answer on return or destruction. Why. It is the standard vendor position and it is frequently untrue. Trap. Accepting it in the template.
-
[ ] Reconcile the agreement with the services contract. Why. The two are negotiated by different people and routinely contradict each other on data rights. Trap. Assuming the later document governs.
Phase 6. Settle the de-identification strategy
-
[ ] Choose the route deliberately. Safe harbour under 45 C.F.R. § 164.514 removes eighteen identifiers and destroys analytic value; expert determination preserves utility and produces a document. Trap. Assuming safe harbour because it appears simpler.
-
[ ] Commission and retain the expert determination, with methods, results, and date. Why. It is the artefact a licensee will diligence. Trap. A determination performed once for a data set that has since changed.
-
[ ] Refresh it when the data set changes. Why. Added fields change re-identification risk. Trap. Treating the determination as permanent.
-
[ ] Prohibit re-identification and combination in every licence. Why. Neither route survives re-identification, and the recipient's conduct is what takes the data back into scope. Trap. Absence of these terms in an inbound licence, which is a defect in what you bought.
-
[ ] Check state law separately. Why. Several statutes treat de-identification as a factual question about re-identifiability, and some restrict sale of consumer health data outright. Trap. Federal compliance presented as clearance.
-
[ ] Draft against Dinerstein v. Google. Why. It is the case every hospital data-sharing arrangement is now written against, whatever its procedural disposition. Trap. Reading only the holding and ignoring the market response.
Phase 7. Research consent and secondary use
-
[ ] Read the original consent, not the approval. Why. Its scope decides what the data set can become; a study may be exempt from review and still constrained by what participants agreed to. Trap. Treating ethics approval as commercial permission.
-
[ ] Check for commercialisation, industry sharing, and sequencing. Why. Most historical consents contemplate none of them. Trap. Repurposing an academic data set as a commercial asset.
-
[ ] Apply 45 C.F.R. Part 46 where the activity is human subjects research, including the broad consent conditions for future unspecified research. Trap. Classifying commercial product development as quality improvement to avoid review.
-
[ ] Handle substance use disorder records under 42 C.F.R. Part 2. Why. Consent requirements are stricter and the redisclosure prohibition follows the record. Trap. Treating them as ordinary protected health information.
-
[ ] Address return of results and incidental findings. Why. They create obligations as well as permissions. Trap. A consent silent on them and a finding that requires action.
Phase 8. Information blocking
-
[ ] Advise on it in the same memo as privacy. Why. 45 C.F.R. Part 171 prohibits practices likely to interfere with access, exchange, or use of electronic health information, and a conservative refusal can be a violation. Trap. A privacy-only analysis that creates exposure.
-
[ ] Identify which exception is relied on and document its conditions at the time. Why. Eight exceptions exist and each has conditions that must be satisfied and evidenced. Trap. An exception asserted retrospectively.
-
[ ] Review fees and licensing terms for interoperability elements. Why. The conditions constrain what may be charged and licensed, so an intellectual property position cannot be used to defeat access. Trap. Standard licensing terms applied to certified interfaces.
-
[ ] Tell patients what happens when data reaches a third-party app. Why. It leaves the framework, and saying so plainly is both good practice and the honest answer. Trap. A reassurance the covered entity cannot support.
Phase 9. The device boundary
-
[ ] Assess classification against the marketing copy, not the internal memo. Why. Copy determines the regulatory posture in practice. Trap. A classification analysis performed once at launch.
-
[ ] Test any clinical decision support exclusion carefully. Display and analysis, support rather than direction, and independent review of the basis. Why. These conditions are asserted more often than satisfied. Trap. A recommendation the clinician cannot practically interrogate.
-
[ ] Give the boundary an owner with authority over copy. Why. Without one, claims drift toward the device side incrementally. Trap. Ownership assigned to someone who reports to marketing.
-
[ ] Prepare a predetermined change control plan for adaptive models. Why. It replaces a submission for each update. Trap. Continuous deployment on a regulated product with no plan.
-
[ ] Hold evidence of performance across populations. Why. Regulators, plaintiffs, and hospital purchasers each ask. Trap. Aggregate performance metrics with no subgroup analysis.
Phase 10. Vendors, incidents, and the diligence pack
-
[ ] Maintain a vendor register keyed to data flows. Who receives what, under what agreement, for what purpose, with what retention and security commitments. Why. Most incidents originate with a vendor. Trap. A procurement list with no data mapping.
-
[ ] Diligence security before contracting, using certification reports and incident history rather than questionnaires. Trap. A completed questionnaire accepted as assurance.
-
[ ] Write the breach risk assessment template now. Why. Under 45 C.F.R. § 164.400 an impermissible use or disclosure is presumed a breach unless a documented assessment shows low probability of compromise. Trap. Drafting the template during the incident.
-
[ ] Map every clock. Federal, state, contractual, and — outside the framework — 16 C.F.R. Part 318, which has been applied to intentional disclosures as well as security incidents. Trap. Sequencing notifications as if the clocks were consecutive.
-
[ ] Stop log rotation in the first hour. Why. It is the single most useful instruction and the one most often given too late. Trap. A playbook that begins with legal analysis.
-
[ ] Notify insurers before instructing counsel. Why. Cyber policies carry short notice periods and consent-to-counsel requirements. Trap. Preferred counsel instructed first, forfeiting cover.
-
[ ] Assemble the diligence pack before it is requested. Status memos, business associate agreements with data permissions highlighted, the de-identification file, consent documents, a dated tag scan, incident history including non-breaches, regulatory correspondence, device classification with copy attached, and insurance details. Why. The diligence discount for an unclear data position is substantial. Trap. Assembling it under time pressure, which produces answers that read as concealment.
Phase 11. Working the example matter
-
[ ] Stop the two hospital deals until the business associate agreements are executed. Why. Data flowing to a business associate without an executed agreement is a Privacy Rule violation by the covered entity and a direct statutory exposure for the vendor. Two live contracts without agreements is the most urgent item on the list. Trap. Allowing a pilot to proceed on the basis that no patient data has moved yet, when integration testing usually means it has.
-
[ ] Re-run the status determination immediately. Why. The company was outside the framework as a consumer app and became a business associate the moment it contracted with providers. Its entire compliance architecture was built for the wrong regime. Trap. Assuming the consumer programme scales into a business associate programme. It does not.
-
[ ] Scan the app and website for tags, and remove them from any health-related surface. Why. Advertising and analytics tags deployed through a tag manager on a symptom-tracking product transmit condition information with identifiers, and eight million users is a class. Trap. Removing them from the website and leaving the in-app software development kits in place.
-
[ ] Rewrite the privacy policy, and do not apply it retroactively. Why. A policy describing sharing with "analytics partners" does not disclose what is happening, and applying a new policy to data already collected has been treated as an unfair practice. Fresh consent is the cure. Trap. Updating the policy and treating the update as sufficient.
-
[ ] Stop the pharmaceutical licensing conversation until the expert determination exists. Why. There is no de-identification file, so the data set is not outside the framework and cannot lawfully be licensed as though it were. Trap. Licensing on the strength of an internal view that identifiers were removed.
-
[ ] Read the academic collaboration consent before touching those records. Why. A consent mentioning research only does not support commercialisation, industry sharing, or inclusion in a licensed data set. Trap. Treating institutional approval as commercial permission.
-
[ ] Stop the "detecting early signs" copy today. Why. A detection claim moves the product into the device framework regardless of the company's internal classification, and it also requires competent and reliable scientific evidence as an advertising claim. Trap. Negotiating the wording rather than removing it while the classification analysis runs.
-
[ ] Answer the overdue security questionnaire honestly. Why. An inaccurate questionnaire response to an enterprise customer is a misrepresentation with contractual and, potentially, regulatory consequences. Trap. Answering aspirationally to keep the deal moving.
-
[ ] [Gate] Sequence the work: agreements, then tags, then policy, then the licensing and marketing questions. Why. The first two are live violations; the rest are exposures that can be managed on a plan. Trap. Starting with the licensing revenue because it is the commercially interesting item.
Phase 12. Telehealth and clinical delivery
-
[ ] Enforce licensure in the booking flow. Why. The practitioner must generally be licensed where the patient is located, and a flow that ignores geography creates unlicensed practice at scale. Trap. A compliance policy that the product does not implement.
-
[ ] Design prescribing workflows to accommodate change. Why. Controlled substance prescribing requirements have shifted repeatedly, and encoding a snapshot creates a rebuild each time. Trap. Hard-coded rules with no configuration layer.
-
[ ] Check corporate practice of medicine constraints per state. Why. Lay ownership of medical practices is restricted in many states, which drives the management services structure. Trap. A single national entity model.
-
[ ] Execute the agreement between the professional entity and the management company. Why. The professional entity is the covered entity and the management company is usually a business associate; this agreement is signed late in a great many businesses. Trap. Treating the affiliated structure as a single organisation for data purposes.
-
[ ] Review fee arrangements for splitting and referral constraints. Why. A percentage-of-revenue management fee is ordinary in technology and problematic in several states. Trap. A pricing model designed by finance without a state-by-state review.
-
[ ] Apply professional advertising rules to clinical marketing. Why. They differ by state and by profession and sit on top of general consumer protection. Trap. One national marketing review.
-
[ ] Reconcile retention policy with professional record obligations. Why. Retention periods set by state law and professional boards are obligations, and a data minimisation policy that ignores them creates a different violation. Trap. Aggressive deletion presented as privacy best practice.
Phase 13. Marketing claims
-
[ ] Hold competent and reliable scientific evidence for every outcome claim. Why. Health claims are held to a higher substantiation standard than ordinary advertising. Trap. A study of a component offered for a product claim.
-
[ ] Treat testimonials as claims. Why. A user describing a health outcome makes a representation the advertiser must substantiate, and typicality evidence or clear disclosure is required. Trap. Testimonials used to say what the company would not say directly.
-
[ ] Disclose material connections under 16 C.F.R. § 255 at the point of the endorsement. Why. Disclosure does not cure an unsubstantiated claim but its absence adds a separate violation. Trap. Disclosure in a profile biography.
-
[ ] Review subscription and cancellation flows. Why. Negative option practices attached to a health service have attracted specific enforcement and are treated as aggravating. Trap. A cancellation path that requires a telephone call.
-
[ ] Check insurance and reimbursement representations regularly. Why. They are factual claims that change frequently, and a claim true at launch may be false within a quarter. Trap. Coverage statements written once.
-
[ ] Avoid equivalence claims against clinical care. Why. Suggesting equivalence to a physician visit, a laboratory test, or a prescribed therapy invites regulatory attention and a competitor claim from an entity inside the regulated framework. Trap. Comparative copy written by a growth team.
-
[ ] Maintain a claim register with expiry dates and a clinician in the review. Why. Health claims decay as evidence and coverage change. Trap. A legal-only review of clinical assertions.
Phase 14. Intellectual property
-
[ ] Separate four asset classes in the inventory. The data, which nobody owns. The software, which is copyright and trade secret. The models, which are trade secret and sometimes patentable. The clinical evidence, which has no natural legal category. Why. Each is protected differently and neglecting the fourth is the common failure. Trap. A single "IP" line in the asset register.
-
[ ] Protect the data set by contract and access control. Why. Facts are not copyrightable, compilation copyright is thin, and trade secret under 18 U.S.C. § 1839 requires reasonable measures that must be evidenced. Trap. A claim of data ownership in a term sheet that no legal theory supports.
-
[ ] Audit open source before an enterprise sale. Why. Copyleft components in clinical software delivered to a hospital may constitute distribution triggering source disclosure. Trap. A bill of materials produced for the first time during customer diligence.
-
[ ] Decide patent or secret on detectability. Why. A model whose behaviour cannot be inferred from outputs is better kept secret; one evident from the product is a patent candidate, subject to eligibility constraints favouring claims tied to concrete clinical intervention. Trap. Filing on a scoring method and disclosing it for a claim that will not survive.
-
[ ] Build a controlled repository for clinical evidence. Protocols, analysis plans, data, regulatory correspondence. Why. It is the asset with the longest useful life and the least legal protection, and access control is the only thing protecting it. Trap. Study files on a shared drive with organisation-wide access.
-
[ ] Allocate training data, architecture, weights, and improvements separately in every contract where customer data trains anything. Trap. A single foreground clause.
-
[ ] File marks early and check the regulatory interaction. Why. A mark implying diagnostic capability the product lacks faces a deceptive misdescriptiveness refusal and a regulatory question at once. Trap. A product name chosen for clinical resonance and cleared for nothing.
-
[ ] Plan escrow before the first enterprise sale. Why. Hospital procurement will require it, and release conditions negotiated during a deal can be triggered by a routine dispute. Trap. Agreeing to "material breach" as a release condition.
Phase 15. Governance and cadence
-
[ ] Name a privacy owner and a device boundary owner, both with authority to stop a release. Why. The second is unusual and the one most companies omit. Trap. Boundary ownership assigned inside marketing.
-
[ ] Maintain four registers. Data flows, vendors keyed to those flows, marketing claims, and consents for research and clinical data sets. Trap. Registers owned by four functions with no shared identifiers.
-
[ ] Gate four moments. New data flow enabled; new third-party tag added; outcome claim published; data use permission granted or accepted. Trap. Gates that a programme manager can waive.
-
[ ] Report five measures. Flows with documented purpose and retention; tags on health pages and date of last scan; vendors with executed agreements and current assessments; open incidents and near misses; claims live and expiring. Trap. Reporting policies written.
-
[ ] Rehearse the incident annually with the people who would run it. Why. The playbook's value is in the rehearsal, not the document. Trap. A tabletop attended by legal alone.
-
[ ] Refresh the state law map twice a year. Why. Consumer health data statutes are moving faster than any other area touching this sector. Trap. An annual review that assumes the map is stable.
Phase 16. Employers, insurers, and plan structures
-
[ ] Separate the group health plan from the employer. Why. The plan is a covered entity; the employer as employer is not, and the Privacy Rule requires plan documents restricting what the sponsor receives and firewalls between plan administration and employment functions. Trap. Human resources staff with access to plan data in an unsegregated system.
-
[ ] Classify wellness programmes by delivery route. Why. Run through the plan they are inside the framework; run directly by the employer with a vendor they are generally outside it and governed by employment law and, for genetic information, 42 U.S.C. § 2000ff. Trap. One privacy notice covering both.
-
[ ] Treat insurer status line by line. Why. Health lines are covered; life, disability, and property lines are generally not, and the same corporate group holds identical information under different regimes. Trap. A group-wide privacy programme built on the health line's obligations.
-
[ ] Read the data use rights granted to benefit vendors. Why. Pharmacy benefit managers, care management vendors, and analytics providers are business associates whose agreements are frequently more permissive than the plan intended. Trap. A vendor building a commercial data asset from plan member data.
-
[ ] Map each flow separately. Why. "We are in healthcare" is not a compliance position; the answer differs by entity, by line, and by flow. Trap. A single enterprise-wide determination.
Phase 17. Cross-border operation
-
[ ] Treat health data as a special category in every other market. Why. Consent, purpose limitation, and assessment obligations are generally stricter than the domestic baseline. Trap. Exporting a domestic consent design.
-
[ ] Assess every cross-border flow with a documented basis. Why. Centralised infrastructure means the architecture decision is a compliance decision made by engineers. Trap. A single global data store adopted before the legal review.
-
[ ] Check localisation requirements for health data. Why. They exist in several markets and cannot be satisfied by contract. Trap. Contractual safeguards offered where localisation is required.
-
[ ] Handle clinical research data under its own transfer rules. Why. They overlap with but are not identical to the general regime, and sponsor obligations follow the data. Trap. Research data treated as ordinary product data.
-
[ ] Plan separate device assessments per market. Why. Clearance is not harmonised; classification rules and clinical evidence expectations differ. Trap. A global launch plan built on one clearance.
-
[ ] Apply labelling and language obligations to the interface. Why. For software the interface carries the instructions for use. Trap. Localisation treated as a translation exercise.
-
[ ] Stage market entry to match approvals to infrastructure. Why. Retrofitting either is materially more expensive than sequencing them. Trap. Simultaneous global launch, the expensive instinct in this sector.
Phase 18. Documents this checklist should produce
-
[ ] A status memorandum per legal entity, with reasoning and a review date. Why. It is the first document anyone asks for and the foundation of everything else. Trap. A conclusion without an analysis.
-
[ ] A data inventory by flow, built from production systems, with purpose, retention, internal access, external recipients, and legal basis. Why. Every question in this checklist queries it. Trap. An inventory describing intended architecture.
-
[ ] A dated tag scan record covering website, portal, and application, with remediation actions and residual configuration. Why. Buyers now run their own scan and compare. Trap. A remediation email with no artefact.
-
[ ] A business associate agreement register with data use permissions and notification periods extracted into columns. Why. The permissions are the commercially significant term and they are invisible inside the documents. Trap. A contract repository with no extraction.
-
[ ] A de-identification file containing the expert determination, its date, the data set it covers, and the licences relying on it. Why. It is what makes a licensing model lawful. Trap. A determination for a data set that has since grown.
-
[ ] A consent register for research and clinical data sets, recording scope rather than approval. Why. Scope decides what the data can become. Trap. Approval letters filed instead of consent forms.
-
[ ] An incident playbook, rehearsed, with the log-preservation instruction first and the insurer notification before counsel instruction. Why. The sequence matters more than the content. Trap. A playbook written and never run.
-
[ ] A standing diligence pack, maintained rather than assembled. Why. The discount for an unclear data position is substantial and the questions are identical in every deal. Trap. Assembly beginning when the term sheet arrives.
Phase 19. Sequencing and proportion
-
[ ] Do the status determination and the tag scan first, whatever else is pending. Why. They cost days, they prevent most of what goes wrong, and every other item depends on the first. Trap. Beginning with the privacy policy because it is the visible artefact.
-
[ ] Fix live violations before managing exposures. Unexecuted agreements and transmitting tags are the first category; licensing structure and marketing copy are the second. Why. The distinction determines the order and the urgency. Trap. Sequencing by commercial interest.
-
[ ] Scale the programme to the entity. An early-stage company should do the status determination, the tag scan, a policy that describes reality, a correct consent architecture, and a first enterprise contract that does not concede data rights — and defer the rest. Why. A programme designed for an incumbent is abandoned within a year by a company of twenty. Trap. A compliance framework adopted whole from a template.
-
[ ] Ask the publication test. Would a plain description of every data flow surprise anyone? Why. A programme that survives that question survives most of what follows. Trap. Treating the answer as a communications problem rather than a design one.
- [ ] Book the follow-up before the first pass ends. Why. Every input to this checklist moves: state statutes, tag deployments, vendor architecture, marketing copy, and the product's own regulatory position. A first pass with no scheduled second pass decays into a document. Trap. Treating completion of the checklist as completion of the work.
- [ ] Record who owns each open item and by when. Why. Findings without owners and dates are observations, and this checklist generates enough of them to disappear without a tracker. Trap. A report circulated for information.
Outcome. A written status determination per entity; a data inventory built from production systems; a dated tag scan with unnecessary code removed and tag manager access restricted; business associate agreements whose data use permissions were negotiated rather than inherited; a current expert determination supporting whatever is licensed; and an incident playbook that has been rehearsed.
The five things people get wrong
One. Assuming health data is protected because it is health data. Protection attaches to who holds it. A wellness app, a wearable, and a testing service are generally outside HIPAA entirely, and building a HIPAA-shaped compliance programme for an entity outside the framework produces both over-compliance in the wrong places and no coverage of the regimes that actually apply.
Two. Leaving the third-party tags in place. This has generated more litigation in the sector than every other practice combined. The evidence is the company's own page source, the damages are statutory, and the fix costs an afternoon of engineering time plus an argument with marketing.
Three. Signing the vendor's business associate agreement template. The required content looks compliant, and clause four grants product improvement, benchmarking, and de-identification rights that convert a service relationship into a data acquisition. It is the most valuable term in the document and the least read.
Four. Treating a research data set as a commercial asset without reading the consent. Ethics approval is not commercial permission, and most historical consents contemplate neither commercialisation nor industry sharing. The defect is found in diligence and is frequently not curable.
Five. Letting the marketing copy determine the regulatory status by accident. Claims drift from wellness toward detection incrementally, nobody reviews the increment, and the product becomes a device without any decision having been taken. Naming an owner with authority over copy is the entire fix.
Key Authorities at a Glance
| Authority | Proposition | |---|---| | 42 U.S.C. § 1320d | HIPAA administrative simplification | | 42 U.S.C. § 2000ff | Genetic information non-discrimination | | 21 U.S.C. § 360 | Device registration and listing | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 15 U.S.C. § 1125 | False advertising | | 18 U.S.C. § 1836 | DTSA civil action | | 18 U.S.C. § 1839 | Trade secret definition | | 18 U.S.C. § 2511 | Interception of communications | | 45 C.F.R. § 160.103 | Status definitions | | 45 C.F.R. § 164.306 | Security Rule | | 45 C.F.R. § 164.502 | Uses and disclosures | | 45 C.F.R. § 164.514 | De-identification | | 45 C.F.R. § 164.400 | Breach notification | | 45 C.F.R. § 46 | Common Rule | | 45 C.F.R. § 171 | Information blocking | | 42 C.F.R. § 2 | Substance use disorder records | | 16 C.F.R. § 318 | Health breach notification | | 16 C.F.R. § 255 | Endorsements | | Sorrell v. IMS Health | Data restrictions and speech | | Spokeo v. Robins | Concrete injury | | TransUnion v. Ramirez | Concrete harm | | Van Buren v. United States | Authorised access | | Carpenter v. United States | Location records | | Riley v. California | Devices are different | | Dinerstein v. Google | De-identified clinical data | | In re Facebook Internet Tracking Litigation | Tracking claims | | State consumer health data statutes | Health data outside HIPAA | | Online tracking guidance | Pixels on health sites | | Clinical decision support policy | Device boundary | | Predetermined change control | Adaptive models | | Real world data licensing | Data licensing practice |
Related Documents
Articles
Guides
Checklists
Toolkits
- Digital Health and Health Data Toolkit
- Biometric and Sensitive Data Toolkit
- Incident Response and Breach Notification Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Digital health positions depend on the entity's regulatory status, the data actually held, the consents obtained, and the jurisdictions in which individuals are located. Marksy is not a law firm.