July 2026 · Industry Guide

HIPAA Privacy Policy for Healthcare Apps: Free Generator & Compliance Guide

Healthcare applications handle the most sensitive personal data regulated by law. Whether you are building a telehealth platform, a patient portal, a medical device app, or a health & wellness service, your privacy policy must satisfy HIPAA Privacy Rule requirements while also addressing state laws, FDA regulations, and patient rights. Here is what every healthcare app needs — and a free generator that builds a HIPAA-aware privacy policy.

HIPAA Privacy Rule: Core Requirements

1. What Is PHI Under HIPAA?

Protected Health Information (PHI) is any individually identifiable health information held or transmitted by a covered entity or business associate. PHI includes 18 identifiers under the HIPAA Safe Harbor method: names, geographic subdivisions smaller than a state, dates (birth, admission, discharge, death), phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers and serial numbers, device identifiers and serial numbers, web URLs, IP addresses, biometric identifiers (fingerprints, voice prints), full-face photographs and comparable images, and any other unique identifying characteristic. Your privacy policy must define PHI broadly and list the categories of health information your application collects.

2. Business Associate Agreements (BAA)

Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity must sign a Business Associate Agreement. If your healthcare app uses cloud infrastructure (AWS, GCP, Azure), most major cloud providers offer BAAs for HIPAA-eligible services. Email providers (Google Workspace for Healthcare, Microsoft 365 for Healthcare) offer BAAs on specific plans. Analytics services (Google Analytics 4 with restricted data processing), communication APIs (Twilio for telehealth), and AI/ML services (AWS Comprehend Medical, Azure Health Bot) all require BAAs if they touch PHI. Your privacy policy should reference your BAA obligations and state that PHI is only shared with subprocessors who have signed BAAs. Maintain a current list of all business associates with BAAs in effect.

3. Permitted Uses and Disclosures of PHI

HIPAA permits PHI use and disclosure without patient authorization for: treatment (sharing PHI with other providers for patient care), payment (billing, claims management, collections), healthcare operations (quality improvement, credentialing, training), public health activities (disease reporting to CDC/state agencies), law enforcement and judicial proceedings (with proper legal process), as required by law (mandatory reporting of abuse, neglect, or violence), and research (with IRB approval or privacy board waiver). Your policy must describe these permitted uses. Any use beyond these requires written patient authorization, and the authorization must describe the specific PHI to be used, the purpose of the use, and the patient's right to revoke authorization.

4. Patient Rights Under HIPAA

Patients have specific rights under the HIPAA Privacy Rule that your policy must explain: right to access PHI (patients can inspect and obtain copies of their PHI in the format requested, typically within 30 days), right to request amendment (patients can ask to correct incorrect or incomplete PHI, with a formal process for acceptance or denial), right to request restrictions (patients can ask for limits on how PHI is used for treatment, payment, or operations, though covered entities are not required to agree except for disclosures to health plans when the patient pays out-of-pocket in full), right to confidential communications (patients can request that communications be sent by alternative means or to alternative locations), right to an accounting of disclosures (patients can request a list of disclosures made for six years prior, excluding disclosures for treatment, payment, operations, and certain other categories), and right to receive a copy of the privacy policy (the Notice of Privacy Practices).

5. Notice of Privacy Practices (NPP)

HIPAA requires covered entities to provide a Notice of Privacy Practices that describes: how PHI is used and disclosed, patient rights regarding PHI, the covered entity's duties to protect PHI, the right to file a complaint with HHS, and the effective date of the notice. The NPP must be posted prominently on your website and provided to patients at the first service encounter. Patients must sign an acknowledgment of receipt. For digital health apps, provide the NPP at account creation, at the point of data collection, and make it permanently accessible from the app or website footer.

Breach Notification: HIPAA vs. GDPR

Healthcare apps operating internationally must navigate different breach notification regimes. Under HIPAA, a breach is the acquisition, access, use, or disclosure of PHI not permitted by the Privacy Rule that compromises the security or privacy of the PHI. There is a risk assessment standard: if there is a low probability that PHI was compromised based on a four-factor assessment (nature and extent of PHI, the unauthorized person who accessed it, whether PHI was actually acquired or viewed, and the extent of risk mitigation), the breach may not require notification. Notifications must be made to affected individuals without unreasonable delay and within 60 days of discovery, to HHS (within 60 days for breaches affecting 500+ individuals, annually for smaller breaches), and to the media (for breaches affecting 500+ residents of a state or jurisdiction). Under GDPR, breach notification to the supervisory authority is required within 72 hours of awareness, with a higher threshold for communication to data subjects (high risk to rights and freedoms). The GDPR standard is stricter with a shorter timeline. Your policy should address both regimes if you serve both markets.

Telehealth Considerations

Telehealth introduces specific privacy obligations beyond standard HIPAA compliance. Video consultation platforms (Zoom for Healthcare, Doxy.me, Updox, VSee, Amazon Chime SDK) must all have BAAs in place. Recorded consultations create PHI that falls under the same retention and access rules as any other medical record. State licensure requirements may affect where patient data is stored and processed. Telehealth prescribing of controlled substances (Ryan Haight Act considerations) has specific video requirements. The HIPAA enforcement discretion for telehealth during the COVID-19 public health emergency has ended; regular HIPAA enforcement applies. Your policy should disclose: the platform used for video visits, whether consultations are recorded (with patient consent), data encryption in transit and at rest, and any third-party telehealth infrastructure providers.

Medical Device Data & FDA Digital Health Regulations

If your app qualifies as a medical device under FDA regulations (including Software as a Medical Device, SaMD), additional privacy and security obligations apply. The FDA's Digital Health Center of Excellence oversees software functions that meet the device definition. Your privacy policy should address: whether the app qualifies as a medical device, data collected from connected medical devices (glucose monitors, blood pressure cuffs, pulse oximeters, wearable ECG monitors), data quality and integrity measures for device data used in clinical decisions, and any clinical decision support (CDS) features. The FDA has issued final guidance on clinical decision support software, direct-to-consumer tests, and AI/ML-enabled medical devices. If your app processes device data for diagnostic purposes, your privacy and security framework must align with FDA premarket requirements and post-market surveillance obligations.

Additional State Privacy Laws

Healthcare apps must also navigate state-level privacy laws. California's Confidentiality of Medical Information Act (CMIA) imposes stricter fines than HIPAA for medical data breaches. Washington's My Health My Data Act extends to health data collected by non-HIPAA-covered entities. Nevada's SB 370, Connecticut's HB 6607, and other state health data laws create a patchwork of additional obligations. Your privacy policy should acknowledge applicable state laws and provide contact information for state-specific requests.

Generate Your Healthcare Privacy Policy — Free

Create a HIPAA-aware privacy policy for your healthcare app, telehealth service, or digital health platform. Select your business associates, PHI categories, and service types for complete coverage.

Generate Healthcare Privacy Policy →