Lexology September 11, 2025
Regulators and courts are expanding enforcement against digital health apps and online platforms that share sensitive health data without true consent, though these companies fall outside the scope of the Health Insurance Portability and Accountability Act (“HIPAA”). In order to reach non-covered entities, agencies and private claimants are now drawing on a patchwork of authorities to rein in misleading or undisclosed data practices:
- Section 5 of the Federal Trade Commission Act: The Federal Trade Commission (“FTC”) is invoking Section 5 of the FTC Act to target unfair or deceptive practices, especially where parties publicly promise to abide by certain privacy practices but fail to deliver. This is particularly common where a party makes representations in a privacy policy posted...







