Does HIPAA Cover My Fitness Tracker or Health App?
No. For almost everyone, HIPAA does not apply to the Apple Watch, Oura Ring, Garmin, Fitbit, or health app on their phone. HIPAA only covers specific entities: health care providers, health plans, and the vendors who process data on their behalf. A separate federal rule, run by the FTC, covers most consumer health apps and wearables instead.
Why doesn't HIPAA cover my wearable data?
HIPAA's privacy and security rules apply to "covered entities" and their "business associates," a legal category defined narrowly as health care providers, health plans, health care clearinghouses, and the vendors those entities hire to handle protected health information (HHS, Covered Entities and Business Associates). A company that makes a fitness tracker or a wearable-data app is not a doctor, an insurer, or a clearinghouse, and in the vast majority of cases has no HIPAA business associate agreement with one. Buying a smartwatch from an app store and connecting it yourself does not bring that data under HIPAA, no matter how sensitive the numbers look.
This surprises people because "HIPAA compliant" gets used in consumer marketing as a general seal of trustworthiness. It is not that. It is a specific legal status tied to a specific relationship with the health care system, and most wearable and app companies simply do not have that relationship.
If HIPAA doesn't apply, what does?
The Federal Trade Commission's Health Breach Notification Rule exists to close exactly this gap. In 2024 the FTC finalized amendments making explicit that the rule applies to health apps, connected fitness devices, and similar technologies that are not covered by HIPAA (FTC, Health Breach Notification Rule final amendments, 2024). Under this rule, a company that experiences an unauthorized disclosure of your identifiable health information, including a data breach or sharing your data without your permission, has to notify you and, in serious cases, the FTC and the media. The updated rule also clarified that this includes apps that pull data from multiple sources, which describes most wearable-data aggregators.
The practical difference matters. HIPAA is a detailed set of operational requirements: access controls, audit logs, breach response procedures, and specific technical safeguards, enforced by the Department of Health and Human Services. The FTC rule is narrower: it is primarily a breach notification requirement, not a full operational security standard, enforced by the FTC under its general consumer protection authority. A company can genuinely say "the FTC rule applies to us" without that meaning the same thing as "we are HIPAA compliant," and a company that says "HIPAA compliant" about a consumer wearable app when it has no covered relationship is making a claim that does not hold up.
HIPAA vs. the FTC Health Breach Notification Rule
| HIPAA | FTC Health Breach Notification Rule | |
|---|---|---|
| Who it covers | Health care providers, health plans, clearinghouses, and their business associates | Health apps, connected devices, and vendors of personal health records not covered by HIPAA |
| What it requires | Detailed privacy, security, and breach rules with ongoing compliance obligations | Notification to users, and in some cases the FTC and media, after a breach or unauthorized disclosure |
| Enforced by | HHS Office for Civil Rights | Federal Trade Commission |
| Applies to a typical wearable app | Almost never, unless it has a direct contract with a covered entity | Yes, if it collects identifiable health information from multiple sources |
Does this mean my wearable data has no protection at all?
No, but it means the protection looks different than people assume. Outside HIPAA and the FTC rule, most protection for wearable data comes from a company's own privacy policy, state privacy laws where they exist, and general consumer protection law against deceptive practices. That is a real gap compared to the strict operational requirements HIPAA imposes on a hospital or insurer, which is exactly why it is worth reading a privacy policy for what it actually commits to, rather than trusting a badge on a landing page. We covered the specific questions worth asking any wearable-data app, including MotionSync, in our earlier piece on connecting wearables to one health app.
What should I actually check before trusting an app with this data?
Skip the HIPAA badge and look for three things instead. First, a plain statement of whether the company sells data or uses it for advertising. Second, a real self-service way to delete your account and your data, not a support ticket. Third, clarity on who processes your data to generate any AI-driven insights and what that processor can see. None of these require a law degree to evaluate, and all three tell you more than a compliance label would.
MotionSync is not a HIPAA covered entity, and we do not claim to be. What we can say plainly: we never sell your data, we never use it for advertising, and you can delete your account and everything in it at any time. We are also intentionally US-only for now, while we build the legal and compliance foundation to expand responsibly. That is the honest version of what applies to a company like ours, and it is a narrower claim than "HIPAA compliant" on purpose.
Why does this confusion keep happening?
Part of it is marketing shorthand that predates the FTC's 2024 clarification, when the rules for non-covered health apps were less defined and companies filled the gap with whatever sounded authoritative. Part of it is that HIPAA is the only health privacy law most people have heard of, so it becomes the default word reached for even when it is the wrong one. The FTC's own guidance addresses this directly, stating that the rule was updated specifically because health apps and connected devices had been operating in a regulatory gray area that let exactly this kind of confusion persist (FTC, 2024 Final Rule announcement).
If a wearable app or health dashboard leads with "HIPAA compliant" as a headline claim and it is not a business associate of a covered entity, that claim is a red flag worth asking about directly, not a reason to trust it more.
Frequently Asked Questions
Is my Apple Health or Google Fit data covered by HIPAA?
No, in almost all cases. Apple and Google are not health care providers or insurers, and the data you generate yourself through a consumer app is not protected health information under HIPAA. It may still be covered by the FTC's Health Breach Notification Rule and by the platform's own privacy policy.
Can a health app legally say it is "HIPAA compliant" if it isn't a covered entity?
A company with no covered relationship claiming to be "HIPAA compliant" is making a claim that regulators and legal commentators have specifically called out as misleading, since HIPAA compliance is not something a company can simply opt into (HHS, Covered Entities and Business Associates). "Built to HIPAA-level standards" is a different and more defensible statement, but only if the company can actually back it up.
What happens if a wearable app has a data breach and it isn't HIPAA covered?
The FTC's Health Breach Notification Rule requires the company to notify affected users, and in larger breaches, the FTC and sometimes the media, without HIPAA needing to apply at all (FTC, Health Breach Notification Rule). It is a real legal backstop, just a narrower one than HIPAA's full compliance regime.
For the specific questions worth asking before connecting any wearable to a third-party dashboard, see Is It Safe to Connect Your Wearables to One Health App? For how MotionSync's AI processing actually works today, see Why Your Wearable Data Means Nothing Without Context


