Hacker News new | ask | show | jobs
by sjg007 3129 days ago
I think it is unclear. For example Apple has HealthKit which collects health related data.. That data is probably HIPAA protected. If it's not (and if Facebook is not) then I would imagine we will see legislation and/or lawsuits to clarify things.
1 comments

Apple is not a covered entity under HIPAA[0], and thus has no liability for the data it collects.

"If an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA Rules."

[0] - https://www.hhs.gov/hipaa/for-professionals/covered-entities...

Apple is most likely a business associate by definition.