Sequence Group

NEWSQUALITY & STANDARDS

HIPAA Compliance for Medical Devices & Digital Health: When Device Data Becomes PHI

Nick SoroJune 9, 2026Quality & Standards

One of the most common compliance questions we hear from connected-device and digital-health companies is whether they are subject to HIPAA. The answer is frequently misunderstood. HIPAA - the Health Insurance Portability and Accountability Act - does not regulate medical devices, and it does not automatically apply just because a product touches health data. Whether HIPAA applies depends entirely on who is handling the data and on whose behalf, not on the technology itself. Getting this determination right early avoids both unnecessary compliance overhead and serious legal exposure.

HIPAA Regulates Entities, Not Devices

HIPAA's privacy and security rules apply to two categories of organizations: covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates (vendors that create, receive, maintain, or transmit Protected Health Information on a covered entity's behalf). A medical device manufacturer is generally not a covered entity. The critical question is therefore whether your company acts as a business associate.

  • You likely ARE a business associate if you operate a cloud platform, remote-monitoring service, or data pipeline that stores or transmits identifiable patient data on behalf of a hospital, clinic, or physician using your device.
  • You likely are NOT subject to HIPAA if you sell a device directly to consumers who buy and use it themselves, with no covered entity involved - even though the data may be sensitive.

When Does Device Data Become PHI?

Protected Health Information is individually identifiable health information held or transmitted by a covered entity or business associate. Three conditions generally must be met for device data to be PHI: the data relates to health, it is individually identifiable (or can be linked to an individual), and it is handled within the covered-entity/business-associate relationship. Data that has been properly de-identified under the HIPAA Safe Harbor or Expert Determination methods is no longer PHI and falls outside HIPAA's scope. Conversely, the same physiological data that is unregulated in a direct-to-consumer wellness product can become PHI the moment it flows through a hospital's care workflow.

HIPAA Is Not the Same as FDA Cybersecurity

Manufacturers frequently conflate HIPAA with the FDA's cybersecurity requirements, but they address different risks. The FDA, through Section 524B of the FD&C Act, regulates the safety and effectiveness of a device, including whether it is secure against threats that could cause patient harm. HIPAA regulates the privacy and security of PHI to protect patient confidentiality. A device can fully satisfy FDA premarket cybersecurity expectations and still be non-compliant with HIPAA's Security Rule, and vice versa. A mature program treats them as complementary but distinct obligations.

The Security Rule and Business Associate Agreements

If your company is a business associate, you must comply with the HIPAA Security Rule, which requires administrative, physical, and technical safeguards - access controls, audit logging, encryption of PHI in transit and at rest, workforce training, and a documented risk analysis. You must also sign a Business Associate Agreement (BAA) with each covered-entity customer, and flow equivalent obligations down to your own subcontractors. The U.S. Department of Health and Human Services has also moved to strengthen the Security Rule, with proposed updates that would make several previously "addressable" safeguards mandatory and require more rigorous, regularly updated risk assessments.

Don't Forget the FTC and State Privacy Laws

Companies that fall outside HIPAA are not unregulated. Direct-to-consumer health apps and connected devices that are not covered by HIPAA may be subject to the FTC's Health Breach Notification Rule, the FTC Act's prohibition on unfair or deceptive practices, and a growing patchwork of state consumer-health-privacy laws. Building a privacy program around only HIPAA, or assuming no law applies, are both common and costly mistakes.

How Sequence Group Can Help

Sequence Group helps device and digital-health companies determine where they sit in the HIPAA framework, structure compliant data flows and BAAs, align HIPAA Security Rule safeguards with FDA cybersecurity documentation and ISO 14971 risk management, and avoid duplicative or missing controls. Contact us for a consultation on building a privacy and security program that satisfies regulators without slowing your product down.

Frequently Asked Questions

Does HIPAA apply to my medical device or health app?

Only if your company acts as a covered entity or a business associate. If you operate a cloud platform or data service that stores or transmits identifiable patient data on behalf of a hospital, clinic, or physician, you are likely a business associate and HIPAA applies. If you sell directly to consumers with no covered entity involved, HIPAA generally does not apply, though other privacy laws may.

When does device data become Protected Health Information (PHI)?

Device data becomes PHI when three conditions are met: it relates to health, it is individually identifiable or can be linked to an individual, and it is handled within a covered-entity or business-associate relationship. Properly de-identified data is not PHI.

Is HIPAA compliance the same as FDA cybersecurity compliance?

No. FDA cybersecurity under Section 524B addresses the safety and effectiveness of the device against threats that could cause patient harm. HIPAA addresses the privacy and security of PHI. A device can meet FDA premarket cybersecurity expectations and still be non-compliant with the HIPAA Security Rule, and vice versa.

Back to News|Get a Free Consultation →