The Data You Hold Isn't All Governed the Same Way

Ask a healthcare organization what regulatory regime applies to its data, and the answer is usually "HIPAA." That's often true, but it's rarely the whole answer. Most healthcare and health tech organizations hold several categories of sensitive data at once, and each one can trigger a different regulatory framework. Treating HIPAA as the only governing regime can mean the wrong rules get applied or the right rules are missed.

Consider a fictional company: Health Information Technologies, Inc. (HIT). HIT licenses software to hospital systems, runs a direct-to-consumer wellness app with symptom tracking and biometric login, creates de-identified and anonymized data from those data sets, employs staff in several states, and processes credit card payments. On paper, HIT might describe itself as governed by HIPAA. In practice, it's operating under multiple different regulatory regimes at once depending on which piece of data is in question.

Protected Health Information (PHI)

This is the category most organizations think of first, and it is defined in HIPAA as individually identifiable health information created, received, or maintained by a HIPAA covered entity or business associate in connection with treatment, payment, or health care operations. For HIT, this is the clinical data flowing through its hospital-facing software. Because HIT is acting as a business associate to its hospital clients in that relationship, this data is PHI, governed mostly by HIPAA alone. State privacy laws typically carve out HIPAA-regulated data specifically to avoid dual regulation. The determining question is relationship and context, not just content; this is PHI since it originates from a provider to whom HIT renders health care operations services.

Non-HIPAA Health Data

Meanwhile, HIT's consumer wellness app collects detailed symptom and health data directly from users, but HIT isn't acting as a HIPAA covered entity or business associate with respect to that data. This gap is exactly what a newer wave of regulation targets. The FTC's Health Breach Notification Rule requires notification when this kind of health data is breached or disclosed without authorization, even though HIPAA never applied to it in the first place; it explicitly covers vendors of personal health records and the health apps, wearables, and connected devices built around them. A growing number of states have gone further, with consumer health data laws like Washington's My Health My Data Act imposing consent and disclosure requirements on health-related data regardless of who's holding it. So, the same app data that HIPAA has nothing to say about is still very much regulated. It's just regulated by a different set of rules.

Personally Identifiable Information (PII), Including Employee Data

HIT also employs people in multiple states and holds the PII that comes with that - social security numbers, payroll records, HR files, etc. This has nothing to do with either of HIT's product lines, and it sits outside HIPAA entirely. Instead, it falls under a patchwork of state consumer privacy and breach notification laws. In a growing number of states, comprehensive consumer privacy laws reach employee data specifically. For example, in California employee PII is now regulated much like consumer PII under the statute. For its California employees HIT has to abide by the CCPA's rules regarding appropriate notices, opt-outs, and other consumer rights to their data.

Payment Card Data

HIT's business also collects payments by card from its consumers and clients. These fall under PCI-DSS, a contractual security standard enforced through the card networks and payment processors rather than a government regulator. It operates alongside HIPAA and everything else discussed here, not in place of any of it, and HIT being HIPAA-compliant on the clinical side of its business says nothing about whether it's PCI-compliant on the payment side. The determining question is simply whether card data is being processed, stored, or transmitted, regardless of what other regime also applies to the same transaction.

Biometric Data

HIT's consumer app also offers biometric login, and that introduces yet another layer. A small number of states now regulate biometric data directly, including Illinois's BIPA, Texas's CUBI, and Washington's biometric privacy law. Each of these laws has its own unique requirements and exposure and should be analyzed separately. For example. Illinois includes a private right of action regarding mishandling of biometric data. Meanwhile, Washington's My Health My Data Act treats biometric data as a form of consumer health data, triggering the law's applicability.

De-Identified, Non-Identifiable, and Anonymized Data

HIT also aggregates de-identified data for its own internal research and for client-facing products. If de-identifying under HIPAA, the de-identified data must abide by either the Safe Harbor or Expert Determination standard. Meanwhile, it may also anonymize or create non-identifiable data from the data ingests from the wellness app, which must abide by state law standards on creating such data. If HIT's de-identified, anonymized, or non-identifiable analytics dataset doesn't actually meet a recognized standard, it may still be PHI or consumer health data underneath that label.

One Company, Five Regimes

Put together, HIT is governed by HIPAA alone for its hospital-facing clinical data, the FTC's Health Breach Notification Rule and state data laws for its consumer app data, a patchwork of state privacy and breach notification laws for its employee data, PCI-DSS for anything touching a card transaction, and one or more state biometric statutes for its login feature, with real potential for overlap depending on where its users and employees are located. None of these regimes substitute for one another, and none of them talk to each other in any significant manner. A privacy program built around "we're HIPAA compliant" would cover exactly one of HIT's five categories and miss the other four entirely.

CohesiveIQ helps healthcare and health organizations understand the data they hold and navigate the regulations that govern it, across HIPAA, state laws, and beyond. Contact us today to discuss your data's regulatory regimes.

blogs and articles

Latest insights and trends

The Governance Gap: Why AI Needs a Program, Not Just a Policy

A committee isn't a governance program.

The Attacker Just Got a Co-Pilot: Cybersecurity in the Age of AI

AI didn't break security. It sped up the clock.

M&A Due Diligence Doesn't Wait for You to Be Ready

Compliance gaps show up in the price, not just the audit.

Why Healthcare Companies Can't Treat State Privacy Law as a One-Time Checkbox

HIPAA compliance isn't privacy compliance anymore.

What Your RCM Coding and Billing Audits Might Not be Catching

Coding compliance alone isn't enough anymore.

Why an Independent Assessment of Your Compliance Program Isn't Optional Anymore

DOJ and OIG now expect proof, not paperwork.

Stop retrofitting compliance after the fact.

The earlier you build it in, the cheaper and faster it gets.