Skip to content

Privacy & Security

Why privacy matters

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects your health information. HIPAA applies to DHCS and your healthcare providers. Most third-party apps are not covered by HIPAA. Once your data leaves DHCS and is stored in an app, HIPAA no longer protects it.

Risk of using apps not covered by HIPAA

  • Apps may use your health data for purposes other than your care, such as advertising or research.
  • Apps may collect non-health data from your device, such as your location.
  • Once data leaves DHCS, it is no longer protected by HIPAA or DHCS security measures.
  • DHCS-approved apps cannot share your personal data without your permission.

Steps to protect your data

  • Use strong, unique passwords for each app. Turn on security features like fingerprint or face recognition if available.
  • Share only the data you need.
  • Read the app’s privacy policy and terms of use before you give consent.

How to make an informed choice

Before you choose an app, review its privacy policy and ask:

  • What health data will this app collect? Will it collect non-health data like location?
  • Will my data be stored in a way that identifies me?
  • How will this app use my data? Will it disclose or sell my data?
  • Will this app share my data with other parties? If so, with whom and for what purpose?
  • What security measures does this app use to protect my data?
  • How can I limit this app’s use and disclosure of my data?
  • If I stop using the app, how do I end its access and request deletion of my data?
  • How does the app inform users of changes to its privacy practices?

Why this information is provided

Federal regulations require states to give members clear, plain-language guidance on privacy risks and how to choose apps safely. This helps you make informed decisions about using apps to view your health data.