Your Health Data in Telehealth
8 min readReviewed 2026-08-23
Telehealth generates a detailed record of some of the most sensitive information about you, and the legal framework protecting it is narrower than most people assume. Knowing where the boundaries fall makes it much easier to ask the right questions.
What HIPAA actually covers
HIPAA applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions — and to the business associates who handle protected health information on their behalf. Within that scope it is substantial. It restricts how protected health information may be used and disclosed, requires safeguards, mandates breach notification, and gives you rights: to access your records, to request corrections, to receive an accounting of certain disclosures, and to request restrictions. The important limit is that HIPAA protects information in the hands of covered entities, not categories of information in general. The same fact about your health is protected when your clinic holds it and unprotected when a fitness app does. A telehealth provider delivering care is a covered entity. A wellness product that never establishes a clinical relationship may not be.
Where telehealth companies got into trouble
The issue that produced regulatory action was not hacking. It was ordinary web tracking. Advertising and analytics technologies embedded in websites transmit information about what visitors do. On a general site that is unremarkable. On a page where someone is completing an intake for a specific condition, the transmitted data can reveal health information about an identifiable person — and sending it to an advertising platform without authorisation is a disclosure. The Federal Trade Commission brought enforcement actions against telehealth companies over exactly this, using the Health Breach Notification Rule against entities outside HIPAA's scope, and the Office for Civil Rights issued guidance on tracking technologies for those inside it. Several resulted in substantial penalties and bans on using health information for advertising. The practical question for you: does the intake flow you are completing load third-party advertising pixels, and does the privacy policy address it? A policy that discusses tracking technologies specifically, rather than in boilerplate, is a sign someone has looked at the problem.
What state law adds
Comprehensive consumer privacy statutes in California, Colorado, Connecticut, Utah and Virginia give residents rights that stack on top of HIPAA — access, deletion, correction, portability, and the ability to opt out of sale and of targeted advertising. Most treat health data as sensitive, requiring consent or a specific opt-out. Washington's My Health My Data Act goes further and is worth knowing about regardless of where you live, because it applies to consumer health data outside HIPAA and includes a private right of action — which is why some companies changed their national practices in response to it. Data covered by HIPAA is typically exempt from these state statutes, which is precisely why the question of whether a service is a covered entity matters.
Questions worth asking
Is this a HIPAA-covered entity? Look for a notice of privacy practices. Its presence is a strong indicator; its absence in a service that appears clinical is a question. What is shared with advertising platforms? The privacy policy should say. If it describes sharing "with partners" for "marketing purposes" without further detail, that is not an answer. Is my information sold? Under state statutes, sale has a broad definition that can include disclosure for consideration other than money. How long is it kept, and can I have it deleted? Medical records are subject to state retention requirements, so complete deletion often is not possible — but you should be told that rather than given a deletion promise that cannot be honoured. How do I get my records? Under HIPAA you have a right of access, generally within thirty days, in the form you request where readily producible. What happens if the company is acquired or shuts down? Records transfer in an acquisition. The privacy policy should address it.
Practical steps
Read the notice of privacy practices rather than only the privacy policy — they are different documents with different scopes. Prefer secure portal messaging over email for clinical matters. Request and keep copies of your own laboratory results, which are yours and which make you portable between providers. Where a state statute gives you rights, the mechanism to exercise them should be described in the policy; if it is not, that in itself is informative. None of this requires paranoia. It requires treating the handling of your health data as part of what you are choosing when you choose a provider, rather than as fine print you agree to afterwards.