PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Potential HIPAA Pitfalls for Developers of Healthcare Apps

Posted on May 20, 2017June 25, 2025 by Dissent

From PerkinsCoie:

As federal and state governments struggle to address future healthcare regulation, demand for healthcare that is cheaper, better and faster continues to surge. Every day, new healthcare apps are being developed to respond creatively to this demand. But pitfalls may await unsuspecting app developers where the lightning-fast technology sector meets the highly-regulated healthcare industry. Failure to comply with the Health Insurance Portability and Accountability Act (HIPAA) is one such pitfall.

In this update, we highlight several HIPAA issues that all developers in the healthcare app field should consider, as well as healthcare plans, insurers and others parties contracting with developers.

Their update covers a number of issues, but I thought I’d pull out just one for you that highlights some of the complexities in working in this space:

  • From whom will the developer be gathering data?  A customer or consumer?

Consumer-facing products that are not made available on behalf of a covered entity or business associate generally will not be subject to HIPAA, but may be subject to stringent privacy and security requirements under the Federal Trade Commission Act and state law. Products created for a covered entity or business associate customer that gather data from or provide data to consumers, however, may cause the developer to be subject to HIPAA.

Read their full alert on PerkinsCoie.

Related posts:

  • BULLETIN: HIPAA Privacy and Novel Coronavirus — from HHS OCR
Category: BusinessFeatured NewsHealthcare

Post navigation

← Computer Searches: A ‘General’ Warrant Can No Longer Satisfy Requirements
Health Care Task Force Pre-Releases Report on Cybersecurity Days Before Ransomware Attack →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance
  • Wiretap Suits Pit Old Privacy Laws Against New AI Technology
  • Action against tiny Scottish charity sparks huge ICO row
  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders

RSS Recent Posts on DataBreaches.net

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy