Digital Health Data Checklist: Regulatory Classification, Business Associate Terms, Consent and Tracking, Breach Analysis, and Vendor Diligence

By ·

This checklist builds a digital health data position starting from the determination that governs everything else: covered entity, business associate, or neither. Phase one settles that question per legal entity and per line of business, in writing, with reasoning. Phase two builds the data inventory from production systems rather than from interviews. The middle phases handle the third-party tracking code that has produced more litigation in this sector than any other practice, the state consumer health data statutes whose definitions reach far beyond the federal rules, business associate terms and the data use permissions buried in them, and the de-identification strategy that determines what can lawfully be licensed. The closing phases cover research consent scope, information blocking, the device boundary, vendor management, incident readiness, and the diligence pack buyers now expect to see prepared.

IP and Technology > Privacy Data Security | Checklist | Published 22 December 2023 - Updated 13 October 2024 | Casey Scott McKay - marksy.us

Summary. This checklist builds a digital health data position starting from the determination that governs everything else: covered entity, business associate, or neither. Phase one settles that question per legal entity and per line of business, in writing, with reasoning. Phase two builds the data inventory from production systems rather than from interviews. The middle phases handle the third-party tracking code that has produced more litigation in this sector than any other practice, the state consumer health data statutes whose definitions reach far beyond the federal rules, business associate terms and the data use permissions buried in them, and the de-identification strategy that determines what can lawfully be licensed. The closing phases cover research consent scope, information blocking, the device boundary, vendor management, incident readiness, and the diligence pack buyers now expect to see prepared.

Keywords: digital health checklist · status determination · covered entity analysis · business associate terms · data use permissions · tag inventory · tracking pixels · consumer health data statutes · separate consent · geofencing prohibition · de-identification strategy · expert determination · research consent scope · information blocking exceptions · device classification · health system contracting · vendor register · incident playbook · log preservation · diligence pack


How to use this checklist

| Field | Detail | |---|---| | Who runs it | Privacy counsel with engineering, marketing, regulatory affairs, and commercial | | When | Before launch; on any change of business model; on any enterprise deal; annually | | Time required | Six to eight weeks for a first pass | | Gates | Status determined in writing; tags inventoried; consents separated; agreements executed | | Output | A status memo, a data inventory, a tag scan record, a vendor register, and an incident playbook | | Companion documents | Building a Digital Health Product and The App That Knows Your Diagnosis |

The matter. A company operates a symptom-tracking app with eight million consumer users and has just signed its first two contracts with hospital systems. Its privacy policy was written for the consumer product and describes data sharing with "analytics partners". The website and the app both carry advertising and analytics tags added by marketing through a tag manager. The company plans to license a de-identified data set to a pharmaceutical sponsor and has commissioned no expert determination. Its research arm holds records from an academic collaboration whose consent form mentions research only. Marketing has begun describing the app as "detecting early signs" of a condition. Neither hospital contract has an executed business associate agreement, and the security questionnaire from the second hospital is overdue.


Phase 1. Determine status


Phase 2. Build the data inventory from systems


Phase 3. Inventory and remove the tracking code


Phase 4. Map the state consumer health data statutes


Phase 5. Negotiate and audit business associate agreements


Phase 6. Settle the de-identification strategy


Phase 7. Research consent and secondary use


Phase 8. Information blocking


Phase 9. The device boundary


Phase 10. Vendors, incidents, and the diligence pack

Phase 11. Working the example matter


Phase 12. Telehealth and clinical delivery


Phase 13. Marketing claims


Phase 14. Intellectual property


Phase 15. Governance and cadence


Phase 16. Employers, insurers, and plan structures


Phase 17. Cross-border operation


Phase 18. Documents this checklist should produce


Phase 19. Sequencing and proportion




Outcome. A written status determination per entity; a data inventory built from production systems; a dated tag scan with unnecessary code removed and tag manager access restricted; business associate agreements whose data use permissions were negotiated rather than inherited; a current expert determination supporting whatever is licensed; and an incident playbook that has been rehearsed.


The five things people get wrong

One. Assuming health data is protected because it is health data. Protection attaches to who holds it. A wellness app, a wearable, and a testing service are generally outside HIPAA entirely, and building a HIPAA-shaped compliance programme for an entity outside the framework produces both over-compliance in the wrong places and no coverage of the regimes that actually apply.

Two. Leaving the third-party tags in place. This has generated more litigation in the sector than every other practice combined. The evidence is the company's own page source, the damages are statutory, and the fix costs an afternoon of engineering time plus an argument with marketing.

Three. Signing the vendor's business associate agreement template. The required content looks compliant, and clause four grants product improvement, benchmarking, and de-identification rights that convert a service relationship into a data acquisition. It is the most valuable term in the document and the least read.

Four. Treating a research data set as a commercial asset without reading the consent. Ethics approval is not commercial permission, and most historical consents contemplate neither commercialisation nor industry sharing. The defect is found in diligence and is frequently not curable.

Five. Letting the marketing copy determine the regulatory status by accident. Claims drift from wellness toward detection incrementally, nobody reviews the increment, and the product becomes a device without any decision having been taken. Naming an owner with authority over copy is the entire fix.


Key Authorities at a Glance

| Authority | Proposition | |---|---| | 42 U.S.C. § 1320d | HIPAA administrative simplification | | 42 U.S.C. § 2000ff | Genetic information non-discrimination | | 21 U.S.C. § 360 | Device registration and listing | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 15 U.S.C. § 1125 | False advertising | | 18 U.S.C. § 1836 | DTSA civil action | | 18 U.S.C. § 1839 | Trade secret definition | | 18 U.S.C. § 2511 | Interception of communications | | 45 C.F.R. § 160.103 | Status definitions | | 45 C.F.R. § 164.306 | Security Rule | | 45 C.F.R. § 164.502 | Uses and disclosures | | 45 C.F.R. § 164.514 | De-identification | | 45 C.F.R. § 164.400 | Breach notification | | 45 C.F.R. § 46 | Common Rule | | 45 C.F.R. § 171 | Information blocking | | 42 C.F.R. § 2 | Substance use disorder records | | 16 C.F.R. § 318 | Health breach notification | | 16 C.F.R. § 255 | Endorsements | | Sorrell v. IMS Health | Data restrictions and speech | | Spokeo v. Robins | Concrete injury | | TransUnion v. Ramirez | Concrete harm | | Van Buren v. United States | Authorised access | | Carpenter v. United States | Location records | | Riley v. California | Devices are different | | Dinerstein v. Google | De-identified clinical data | | In re Facebook Internet Tracking Litigation | Tracking claims | | State consumer health data statutes | Health data outside HIPAA | | Online tracking guidance | Pixels on health sites | | Clinical decision support policy | Device boundary | | Predetermined change control | Adaptive models | | Real world data licensing | Data licensing practice |


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Digital health positions depend on the entity's regulatory status, the data actually held, the consents obtained, and the jurisdictions in which individuals are located. Marksy is not a law firm.

Read this article on Marksy