EDIT: This is advice my HealthTech startup received from a very well respected lawfirm. It's not as black and white as this. However, it is a good rule of thumb.
EDIT: This is advice my HealthTech startup received from a very well respected lawfirm. It's not as black and white as this. However, it is a good rule of thumb.
Note that a random app that gets "medical data" is not covered unless it counts as a health care provider AND transmits data in certain HHS electronic formats.
They only need to be HIPAA compliant if they're a covered entity and dealing with an HHS related transaction.
https://www.hhs.gov/hipaa/for-professionals/covered-entities...
> A Health Care Provider .... ...but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard.
Not looking for legal advice. Just curious. In my company our lawyers tell us what to do anyway.
Neither based on my knowledge. They can do whatever they want with the data and give to whomever they want with no restrictions from HIPAA.
edit: Note that their privacy policy may provide protections and the government may get angry with certain sharing but only if it's politically useful (ie: tinder, hiv status and china).