ARTICLE
7 February 2024

Wellness Apps And Privacy

SS
Seyfarth Shaw LLP

Contributor

With more than 900 lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities-no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations-and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce.
Employers looking to enhance their suite of employee benefit programs, and focused on lessons learned during the pandemic on wellbeing, are interested in providing greater access to wellness tools.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

This article was originally posted to Seyfarth's Global Privacy Watch blog.

Employers looking to enhance their suite of employee benefit programs, and focused on lessons learned during the pandemic on wellbeing, are interested in providing greater access to wellness tools. And, the vendors who support those tools are more than happy to provide them. Global spend in the health and wellness market would be around $24.8 billion in 2023 according to a study by Kilo Health. Wellness apps and wearables abound in all sorts of areas — from counting steps to nutrition to mental health to physical fitness to financial fitness. These tools are relatively inexpensive to provide and easily accessible to the workforce – many times with just a simple download to a smartphone. And, best of all they're completely private with no middle man, and only the employee seeing their own data and progress. Right? Well — not so fast.

Federal Law

HIPAA is the federal statute that protects the privacy and security of individually identifiable health information, called Protected Health Information or PHI. Many people (plan sponsors and covered participants alike) assume that the wellness apps and the data they contain are protected by HIPAA. However, HIPAA does not address all types of health information. For HIPAA to apply, the information must be created or maintained by a "covered entity". Covered entities are generally health care providers (e.g., doctors, hospitals, pharmacies) and health plans.

Where the developer or license holder of a health application is a covered entity, and that entity maintains the application and the data that it collects, the underlying data will receive the protections of HIPAA. For example, a pharmacy may be the entity who is supplying patients with the access to the online application to manage their medications. In that case, the provider will have to design its security systems and protocols to meet HIPAA's high standards.

However, many times the developer of a wellness application is not a health care provider and the application is not utilized by a provider for detecting, curing, mitigating, treating or preventing diseases. Common examples of these types of applications are those that track individuals' walking steps or offer a tracker for weight or blood pressure. In this case, reviewing the privacy policy of the application and making an informed decision before loading personal information is critical.

On the other hand, where an employer is considering enhancing its benefits offering to include access to a wellness application or device, that benefit may be offered under and as part of its health plan. A clear example of this could be a heart monitor used for an individual complaining of an irregular or racing heartbeat. But, also a fitness tracker provided as part of the health plan's wellness benefit could fall into this category. In that case, the wellness vendor will likely be functioning as a business associate to the health plan, and the individually identifiable health data collected on the app or device will be HIPAA PHI. This means that the vendor and the health plan will need to enter into a HIPAA compliant business associate agreement that lays out the possible uses of the PHI and how it is to be secured.

State Law

Where an ERISA health plan is not involved, and HIPAA therefore would not apply, employers should still consider the implications of state law. A number of states are getting into the privacy game by passing their own privacy laws. As part of these initiatives, the states are attempting to plug the holes around health data privacy which are present in the scope of HIPAA. For example, California, Texas, and Florida all endeavor to regulate the use of health data when used for purposes of "profiling". Washington State passed a privacy statute directly pointed at health information.

However, almost all states' privacy laws, with the exception of California's, have an exclusion for information collected in the scope of an employment relationship. While providing benefits (and collecting information) related to workforce well-being is definitely an interest to the employer, the scope of the exclusion in these state privacy laws has not been litigated. As such, it is not clear if work place-adjacent activity, like the provision of wellness apps, would be covered by the employee exception in any given state.

Effectively, what this means is that even if HIPAA doesn't apply to the employer's provision of wellness apps or wearables, it is possible that a state law will apply. Therefore, it is possible that the employer will need to have its own privacy compliance program related to the collection and use of the wellness data.

Ultimately, employers who are deploying wellness apps need to consider the privacy implications at both the federal and state level before roll-out. If not, it is possible that the employer may generate privacy law liability without fully understanding its risk.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
7 February 2024

Wellness Apps And Privacy

United States Privacy

Contributor

With more than 900 lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities-no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations-and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More