Research · 10 min read

What a Telehealth Company Does With Your Health Data

Two different federal rulebooks can govern the same medical facts about you, and which one applies depends on what kind of business is holding them rather than on how private the information feels. The gap between them is where most surprises live.

Key takeaways

  • Which federal privacy rulebook applies depends on what kind of organization holds the information, not on how medical the information is.
  • A covered entity is a health plan, a clearinghouse, or a provider who transmits health information electronically in connection with a covered transaction — the third category has a condition attached.
  • The Federal Trade Commission's health breach rule states that it does not apply to covered entities or to business associates acting as such, so the two regimes are drawn as alternatives.
  • That rule counts an unauthorized disclosure as a breach, not only an intrusion, and its amended definitions reach ordinary apps and connected devices that track health information.
  • Under the first rulebook you have an access right with hard mechanics: action within thirty days, one thirty-day extension with written reasons, your requested format where readily producible, and a fee limited to cost.

Answer first: the rule follows the entity, not the information

People assume that medical information is protected because it is medical. Federal law does not work that way. The privacy rule most readers have heard of attaches to particular kinds of organizations, and information held by an organization outside those categories is governed by something else.

So the same sentence about your weight, your medication and your symptoms can sit under one rulebook in a clinic and a different one inside an app, unchanged in every other respect.

This is not a loophole anyone is hiding. It is how the definitions are written, and the definitions are public. What follows is what they actually say.

The first rulebook, and who it binds

Federal regulation defines a covered entity as one of three things: a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a transaction covered by those rules.

The definition of a health care provider in the same section is broad. It reaches providers of services and of medical or health services as defined in the Social Security Act, and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.

Notice the condition attached to the third category. A provider becomes a covered entity by transmitting health information electronically in connection with a covered transaction — the standard electronic exchanges of health administration. The status is not automatic simply because a business is health-related.

The rules also reach a second tier. A business associate is, broadly, a person who creates, receives, maintains or transmits protected health information on behalf of a covered entity for a regulated function — the regulation lists claims processing, data analysis, utilization review, quality assurance, billing, benefit management, practice management and repricing among them — or who provides listed services to a covered entity where doing so involves disclosure of that information. Subcontractors of a business associate are included.

The second rulebook, and the boundary between them

The Federal Trade Commission's Health Breach Notification Rule occupies the territory the first rulebook does not. Its own scope provision says it applies to foreign and domestic vendors of personal health records, related entities and third party service providers that maintain information of United States citizens or residents — and that it does not apply to covered entities, or to any other entity to the extent it engages in activities as a business associate of one.

That sentence is the boundary, stated by the rule itself. The two regimes are drawn to be mutually exclusive rather than overlapping, which means the first question about any company is which side of the line it sits on.

The rule's definitions were amended in a version dated May 2024, and the amended text is expansive about what counts. It defines health care services or supplies to include any online service — a website, a mobile application, an internet-connected device — that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information or diet, or that provides other health-related services or tools.

Read that list and it is obvious how much modern software falls inside it. A tracker, a symptom log and a refill reminder are all describable in those words.

What that second rule counts as a breach

This is the part most worth knowing, because it is not what the word suggests. The rule defines a breach of security as acquisition of unsecured identifiable health information without the authorization of the individual, and states that a breach includes an unauthorized acquisition that occurs as a result of a data breach or an unauthorized disclosure.

An unauthorized disclosure is not a hacker. It is information going somewhere it was not authorized to go, which can happen through entirely ordinary business plumbing.

The rule also builds in a presumption. Unauthorized acquisition will be presumed to include unauthorized access unless the entity has reliable evidence showing there has not been, and could not reasonably have been, unauthorized acquisition.

Where the rule applies and a breach occurs, it requires notice to each affected individual who is a United States citizen or resident, notice to the Commission, and — where the information of five hundred or more residents of a state or jurisdiction is or is reasonably believed to have been acquired — notice to prominent media outlets serving that place.

The right that exists on one side of the line

Under the first rulebook, an individual has a right of access to inspect and obtain a copy of protected health information about themselves in a designated record set, subject to specified exceptions.

The mechanics are concrete. The entity must act on a request no later than thirty days after receiving it, either granting it and providing the access or providing a written denial. It may extend once by no more than thirty additional days, and only if it gives you, within the original window, a written statement of the reasons for the delay and the date by which it will finish. One extension is the limit.

Format is part of the right. The entity must provide the information in the form and format you requested if it is readily producible that way, and where the information is maintained electronically and you ask for an electronic copy, it must provide an electronic form and format you requested if readily producible, or one you and it agree on.

A fee is allowed but bounded. It must be reasonable and cost-based, and may include only labor for copying, supplies for a paper copy or portable electronic media you asked for, postage where you asked for it to be mailed, and preparing a summary or explanation you agreed to in advance.

A denial must be timely, in writing, in plain language, and must state the basis. That is a document you can act on, which is the point of requiring it.

What to actually read before you enroll

Start with which document you are being shown. A notice of privacy practices is the document a covered entity provides; a general website privacy policy is not the same thing and does not become one by being long.

Then look for the sharing language rather than the security language. Security paragraphs describe how information is protected from outsiders. Sharing paragraphs describe where it goes on purpose, and that is the section that determines what happens to your information in the ordinary case rather than the bad one.

Look for the word sell, and for the language around advertising, analytics and affiliates. A policy that reserves the right to share information with partners for marketing is telling you something specific, and it costs nothing to notice before you enroll.

Then look for the deletion route and for what survives it. Medical records are frequently subject to retention obligations that outlast an account, and a policy that says so plainly is more useful than one that promises deletion without qualification.

And check whether the privacy document names an entity you recognize. Where a consumer brand and a professional practice are separate, they may publish separate policies, and only one of them may be describing your medical record.

What this does not decide

It does not tell you which rulebook governs any particular company. That is a legal conclusion about a specific business, it depends on facts not visible from a homepage, and nothing here should be read as reaching it.

It does not tell you that information outside the first rulebook is unprotected. General consumer protection law, state privacy statutes and state medical records law all operate, and several states regulate health data more tightly than federal law does.

It does not tell you what any company has actually done. Definitions describe categories, not conduct.

And it is not legal advice. It describes what three federal texts say and who they bind, which is a different thing from advice about your situation.

Sources

  1. 45 CFR 160.103, "Definitions"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Current text as displayed · Retrieved September 2026The definition of covered entity as a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a transaction covered by the subchapter. The definition of health care provider as a provider of services and of medical or health services under the Social Security Act, and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business. The definition of business associate, including the listed functions (claims processing or administration, data analysis, utilization review, quality assurance, billing, benefit management, practice management, repricing) and the inclusion of subcontractors. The definition of protected health information as individually identifiable health information transmitted or maintained in electronic media or any other form or medium, with the stated exclusions.
  2. 16 CFR Part 318, "Health Breach Notification Rule"Federal Trade Commission, via the Electronic Code of Federal Regulations · 74 FR 42980, August 2009, as amended at 89 FR 47054, May 2024 (source note printed on the part) · Retrieved September 2026The scope provision stating the part applies to foreign and domestic vendors of personal health records, PHR related entities and third party service providers maintaining information of U.S. citizens or residents, and does not apply to HIPAA-covered entities or to any entity to the extent it engages in activities as a business associate of one. The definition of breach of security as acquisition of unsecured PHR identifiable health information without the individual's authorization, the presumption that unauthorized acquisition includes unauthorized access absent reliable contrary evidence, and the statement that a breach includes an unauthorized acquisition resulting from a data breach or an unauthorized disclosure. The definition of health care services or supplies covering online services, mobile applications and internet-connected devices providing mechanisms to track the listed categories. The notification duties in § 318.3: notice to each affected individual, notice to the Commission, and notice to prominent media outlets where 500 or more residents of a state or jurisdiction are affected.
  3. 45 CFR 164.524, "Access of individuals to protected health information"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Current text as displayed · Retrieved September 2026The right of access to inspect and obtain a copy of protected health information in a designated record set. The requirement to act within 30 days of receipt by granting access or issuing a written denial; the single permitted extension of no more than 30 further days, conditioned on a written statement of reasons and a completion date given within the original window. The form-of-access requirements, including provision in the requested form and format where readily producible and an electronic copy in a requested electronic form and format where the information is maintained electronically. The limitation of fees to a reasonable, cost-based fee covering only copying labor, supplies for paper or requested portable media, postage where mailing was requested, and preparing an agreed summary or explanation. The requirement that a denial be timely, written, in plain language, and state its basis.

Frequently asked questions

Is my telehealth information automatically covered by federal health privacy rules?

Not automatically, no. The regulation defines a covered entity as a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a covered transaction. The provider definition is broad — any person or organization who furnishes, bills, or is paid for health care in the normal course of business — but the covered entity status still turns on that electronic transaction condition. So the question is about the organization holding the information, not about how medical the information is. Whether a specific company meets the definition is a legal question about that business, and no article can answer it for you.

What is the other rulebook, and when does it apply?

The Federal Trade Commission's Health Breach Notification Rule. Its scope provision states that it applies to vendors of personal health records, related entities and third party service providers maintaining information of United States citizens or residents, and that it does not apply to covered entities or to an entity to the extent it acts as a business associate of one. The two regimes are drawn as alternatives rather than overlapping ones. Its amended definitions are broad about what counts, reaching any online service, app or connected device offering mechanisms to track conditions, treatment, medications, symptoms, fitness, sleep, mental health or diet, among others.

Does a breach have to be a hack?

No, and this is the most commonly misunderstood part of that rule. It defines a breach of security as acquisition of unsecured identifiable health information without the individual's authorization, and states that this includes an unauthorized acquisition occurring as a result of a data breach or an unauthorized disclosure. A disclosure is information going somewhere it was not authorized to go, which can happen through ordinary business arrangements rather than an intrusion. The rule also presumes that unauthorized acquisition includes unauthorized access unless the entity has reliable evidence that acquisition did not and could not reasonably have occurred.

How do I get a copy of my own medical record?

Where the first rulebook applies, you have a right of access to inspect and obtain a copy of protected health information about you in a designated record set. The entity must act within thirty days of the request, either providing access or issuing a written denial that states its basis in plain language. It may take one extension of no more than thirty further days, and only if it tells you within the original window, in writing, why and by what date. It must honor your requested form and format where readily producible, including an electronic copy where the information is kept electronically. Any fee must be reasonable and cost-based and is limited to copying labor, supplies, postage and an agreed summary.

Should I read the privacy policy or the notice of privacy practices?

Both, and notice that they are different documents. A notice of privacy practices is what a covered entity provides; a general website privacy policy is not one and does not become one by being detailed. Where a consumer brand and a clinical practice are separate entities, they may publish separate documents, and only one may describe your medical record. Inside whichever document applies, read the sharing language rather than the security language. Security describes protection from outsiders; sharing describes where information goes deliberately, which is what governs the ordinary case rather than the exceptional one.

If I delete my account, is my health information gone?

Not necessarily, and a policy that says so plainly is being straight with you. Medical records are commonly subject to retention obligations that outlive an account, and those obligations sit in state law and professional requirements rather than in a company's settings page. The useful questions are which entity holds the record, what its retention period is, what deletion actually removes, and what a deletion request does to information already shared with third parties. Ask them before enrolling rather than at the end, because the answers are much easier to obtain while an account is open.