Most guides skip this question. It is the first one, and for a large share of health-app founders the answer is no, which does not mean unregulated.
Part 2 of 8 in the HIPAA Engineering Series. Previous: How to Develop a HIPAA-Compliant Application: The 12 Engineering Steps. Next: What Is PHI? The 18 HIPAA Identifiers and How De-identification Works (coming soon).
Before any of the engineering work, settle who regulates you. Getting this wrong in either direction is expensive: teams build to HIPAA when the FTC is their actual regulator, or assume that being outside HIPAA means being outside the law. Neither holds.
Who HIPAA actually applies to
Most guides skip this. It is the first question, and for a large share of health-app founders the answer is no.
It is also the question people most often get wrong, in two specific ways. Both come from the same mistake, so it is worth taking them together before the categories.
Two questions people collapse into one
• Who are you? A covered entity, a business associate, or neither. This decides which rules apply: HIPAA, or the FTC rule and state law.
• Where does the data live and flow? Device, server, backup, vendor, model. This decides which controls you must build, and how much work that is.
The first is a legal relationship. It is settled by who your customer is and what you agreed to do for them, usually before a single byte moves. The second is architecture.
The second only matters once the first says HIPAA applies. Collapsing them produces the two misconceptions below, and they point in opposite directions: one makes a team think they are covered when they are not, the other makes them think they are safe when they are not.
Who you are decides whether HIPAA applies. Where the data lives decides how much work that means.
The three organizations HIPAA reaches
Covered entities. Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with a covered transaction: a claim, an eligibility check, a referral authorization. A cash-only wellness clinic that never bills insurance electronically may genuinely fall outside this.
Business associates. Anyone who creates, receives, maintains or transmits PHI on behalf of a covered entity. If you build and host the patient portal for a hospital, you are a business associate. Since the 2013 Omnibus Rule, business associates are directly liable to OCR, not merely contractually liable to their customer.
Subcontractors of business associates. Your hosting provider, your queue, your analytics vendor, your model provider. The chain of BAAs runs all the way down, and it is your job to sign with each link below you.
If you are none of the three, HIPAA does not apply to you. Skip to the section below titled “If HIPAA does not apply, you are still regulated,” which is the part that catches people.
Misconception 1: “our app has PHI, so HIPAA applies”
A consumer fitness, diet or symptom-tracking app does not have PHI. It has identifiable health information, which is not the same thing.
PHI is not a property of the data. It is a property of the data plus who holds it. The regulation defines protected health information as individually identifiable health information held by a covered entity or a business associate. Remove that relationship and the same bytes are still sensitive, still valuable and still regulated, but they are not PHI, and the Security Rule has nothing to attach to.
A resting heart rate, a weight log, a cycle-tracker entry and a symptom diary are all PHI in a clinic’s record system and not PHI in an app somebody downloaded for themselves. Same data, different legal object.
This matters in both directions. Teams that believe they hold PHI build to the wrong rulebook and still miss the FTC obligations that actually bind them. Teams that believe they do not hold PHI, while sitting under a hospital contract, miss HIPAA entirely.
Misconception 2: “HIPAA applies once the data reaches our server”
It does not. There is no point in a data flow where HIPAA switches on.
The definition carries four verbs: PHI is information created, received, maintained or transmitted by a covered entity or business associate. Transmission is one of four. Data created on a phone and kept there, never sent anywhere, is squarely covered if you are a business associate. So is a paper chart that never touches a computer: the Privacy Rule covers PHI in any form, and the Security Rule governs the electronic subset, which is what “ePHI” means.
Here are five scenarios, in order:
• Consumer fitness app (no relationship, data on your servers): No. FTC and state law apply.
• Consumer fitness app (no relationship, data on the device only): No. FTC and state law apply.
• App white-labeled for a hospital (business associate, data on your servers): Yes.
• App white-labeled for a hospital (business associate, data on the device only): Yes.
• A clinic’s on-premise records system with no internet at all (covered entity, data in their server room): Yes.
The fourth scenario is the one that catches engineering teams. “We never send it to our servers” reduces your exposure; it does not change your status. If you are a business associate, PHI in the app’s local database, the Keychain or Keystore, a WebView cache or an iCloud backup is governed, which is exactly what the physical safeguards at §164.310 exist for, and why the mobile chapter of this guide is as long as it is.
The fifth scenario is the mirror image: an entirely air-gapped system with no server anywhere is fully in scope.
When a consumer app becomes a business associate
This is the answer to “so we are fine, then?” because the trigger is not the product getting more medical. It is a relationship, and one contract is enough.
• You sell into an employer’s group health plan as a benefit. Health plans are covered entities, so you are a business associate.
• A hospital or clinic white-labels you for their patients. You are a business associate.
• You integrate with a provider’s EHR and receive records from them. You are a business associate.
• A provider uses you to deliver care and bills for it, remote monitoring for example. You are a business associate.
• You perform any function or service on behalf of a provider, plan or clearinghouse. You are a business associate.
None of those requires a line of product code to change. One signed agreement and the full Security Rule applies, along with a BAA chain down to every subprocessor and direct liability to OCR.
One exception worth knowing, because teams usually assume the opposite. If a patient exercises their right of access and directs their provider to send their records to your app, you do not generally become a business associate on that basis. The data was delivered at the individual’s direction, and the provider is not responsible for what happens to it afterwards. You hold identifiable health data with FTC obligations, not PHI. That changes the moment you also start doing something for the provider.
Two things that do not change the answer
• “We never look at the data.” OCR’s 2016 cloud computing guidance is explicit: a service provider that merely stores encrypted PHI, with no ability to view it, is still a business associate and still needs a BAA. The narrow “conduit exception” covers transmission-only services like an ISP or a courier, not storage.
• “It never leaves the device.” Covered above, and worth repeating because it is offered as a defense so often. Architecture decides how much work you have. It does not decide whether the rules apply.
If HIPAA does not apply, you are still regulated
This is the part that surprises people, and it has produced more enforcement against app companies in recent years than HIPAA has.
The FTC Health Breach Notification Rule. The FTC’s amendments, effective July 29, 2024, make it explicit that the rule reaches health apps, connected devices and similar consumer products that are not covered by HIPAA. Two things about it matter to engineers:
• A “breach of security” under the amended rule includes any unauthorized disclosure of identifiable health information, not just a hack. A voluntary disclosure the consumer did not authorize counts. This is precisely how an advertising SDK becomes a reportable breach.
• Notification is due without unreasonable delay and no later than 60 days from discovery.
The FTC’s actions against GoodRx and Premom both turned on health data flowing to advertising platforms. Neither company was a HIPAA covered entity. That was not a defense.
State consumer health privacy laws. Washington’s My Health My Data Act is the one to design against, because it covers “consumer health data” broadly, requires separate consent for collection and for sharing, and, unusually, carries a private right of action. Nevada has a similar law. Most comprehensive state privacy laws now treat health data as sensitive, requiring opt-in consent.
Sector rules that sit on top of HIPAA. If you touch substance use disorder treatment records, 42 CFR Part 2 applies in addition to HIPAA, and its compliance deadline landed on February 16, 2026, with civil and criminal penalties and its own breach-notification requirement now in force. If you touch student health records, FERPA may apply instead of HIPAA. If your product makes clinical recommendations, you may be in FDA territory; the AI features post later in this series covers that.
None of these care where the data lives either. The FTC rule reaches a health app whose data never leaves the phone, exactly as HIPAA would reach a business associate in the same position. The axis that changes is which rulebook, never whether there is one.
The practical upshot. Design to the HIPAA Security Rule technical safeguards even if HIPAA does not apply to you. It is the most detailed and best-documented baseline available, the FTC has never faulted anyone for exceeding it, and the day a health system wants to buy your product, you will need it anyway.
There is a sharper version of that last point. Everything in the list of business-associate triggers above happens on a contract’s timescale, not a release’s. A team that has already built to the Security Rule signs the deal and starts work. A team that has not spends the next two quarters retrofitting a record-level audit log, unpicking patient data from two years of retained analytics, and replacing a vendor who will not sign a BAA, while the customer waits.
Frequently asked questions
Does HIPAA apply to my health app?
Only if you are a covered entity (a health plan, clearinghouse, or provider billing electronically), a business associate handling PHI on behalf of one, or a subcontractor of a business associate. A direct-to-consumer wellness, fitness or symptom-tracking app with no covered entity behind it is usually none of these. It is still regulated by the FTC Health Breach Notification Rule, whose July 2024 amendments explicitly reach health apps and connected devices, and by state consumer health privacy laws such as Washington’s My Health My Data Act.
Is a fitness or wellness app covered by HIPAA?
Usually not, and the reason matters more than the answer. A direct-to-consumer fitness, diet or symptom-tracking app with no covered entity behind it is neither a covered entity nor a business associate, so HIPAA has nothing to attach to. Note that such an app does not “have PHI” either: PHI is individually identifiable health information held by a covered entity or business associate, so the same heart-rate log is PHI in a clinic’s records and is not PHI in a consumer app. What does apply is the FTC Health Breach Notification Rule, whose amendments effective July 29, 2024 explicitly reach health apps and connected devices, and state consumer health privacy laws. The FTC’s actions against GoodRx and Premom both involved companies that were not HIPAA covered entities.
Does HIPAA apply once patient data reaches our server?
No. HIPAA applicability is not a technical event, and there is no point in a data flow where it switches on. It is decided by a relationship (covered entity, business associate, or neither), which is settled by who your customer is and what you agreed to do for them. The definition of PHI carries four verbs: information created, received, maintained or transmitted by a covered entity or business associate. Transmission is one of four. Data created on a phone and kept there is covered if you are a business associate, an air-gapped records system with no internet at all is fully in scope, and a paper chart that never touches a computer is PHI under the Privacy Rule. Where the data lives decides how much work you have, not whether the rules apply.
Does keeping data only on the device avoid HIPAA?
No. If you are a business associate, PHI in the app’s local database, the Keychain or Keystore, a WebView cache or an iCloud backup is governed. That is what the physical safeguards at 45 CFR 164.310 and the mobile controls in this guide are for. Client-side-only storage genuinely reduces your exposure and is often a good design, but it changes the amount of work, not your status.
Can a consumer health app become a business associate later?
Yes, and one contract is enough, because the product need not change at all. Selling into an employer’s group health plan, being white-labeled by a hospital, integrating with a provider’s EHR, or being used by a provider to deliver care they bill for all make you a business associate, with the full Security Rule, a BAA chain down to every subprocessor and direct liability to OCR. One exception runs the other way: if a patient exercises their right of access and directs their provider to send records to your app, you do not generally become a business associate on that basis alone.
What is the HIPAA conduit exception?
A narrow exception for services that only transmit PHI without storing it, such as an internet service provider or a courier. It does not cover a cloud provider that stores PHI, even encrypted PHI it cannot read. OCR’s 2016 cloud computing guidance is explicit on this: a “no-view” storage provider is still a business associate and still needs a BAA.
Does a business associate need its own BAAs?
Yes. A business associate must sign a BAA with each of its own subcontractors that can touch PHI: hosting, database, email, error tracking, analytics, support desk, model provider. Business associates have also been directly liable to OCR since the 2013 Omnibus Rule, not merely contractually liable to their customer.
Where Bitsol fits
We build healthcare software on AWS and do the compliance engineering as part of building it, not as a phase at the end. What we can honestly offer is a read of your codebase and cloud account against the technical safeguards with a file-and-line citation for every control we find and a plain statement of every gap; design and build for web, mobile and AI on a PHI boundary written down before the first table is created; a launch gate verified against the running system before the first real patient record; and the evidence pack a hospital security reviewer will ask for, with the open items named.
What we will not offer is a statement that your application is HIPAA compliant, or a certification. Those do not exist, and a vendor who offers them is telling you something useful about themselves. Get in touch.
The HIPAA Engineering Series
1. How to Develop a HIPAA-Compliant Application: The 12 Engineering Steps
2. Does HIPAA Apply to Your App? And What Applies If It Does Not (you are here)
3. What Is PHI? The 18 HIPAA Identifiers and How De-identification Works
4. HIPAA Technical Safeguards: BAAs, Encryption, Identity and Audit Logs
5. Where PHI Leaks, and How to Stay Compliant After Launch
6. HIPAA Compliance for Web Applications
7. HIPAA Compliance for Mobile Apps
8. HIPAA Compliance for AI Features: LLMs, RAG and PHI
Sources
• 45 CFR Part 164: Security and Privacy (eCFR)
• HHS: Guidance on HIPAA and Cloud Computing
• FTC: Complying with the Health Breach Notification Rule
• FTC: Health Breach Notification Rule final amendments (Federal Register, May 2024)
• HHS: Substance Use Disorder (Part 2) records
This guide describes engineering practice. It is not legal advice, and several of the questions it raises (whether HIPAA applies to your organization, whether a feature is a regulated medical device, what your state’s retention period is, and what any customer-facing document may claim) need a qualified healthcare attorney rather than an engineer.



