SMU Science and Technology Law Review
Abstract
Consumer digital health platforms have become an increasingly prominent feature of modern health care, collecting and storing sensitive health information directly from users. Yet most of these applications operate outside the scope of the Health Insurance Portability and Accountability Act (HIPAA), creating a significant regulatory gap in the protection of personal health data. This case note examines how the Federal Trade Commission (FTC) has stepped into that gap by leveraging Section 5 of the FTC Act and the Health Breach Notification Rule (HBNR) to police privacy and data security practices among non-HIPAA-covered digital health platforms. Focusing on three landmark enforcement actions against Flo Health, GoodRx, and BetterHelp, the paper analyzes how the FTC has applied longstanding consumer protection principles to emerging health technologies and expanded its role in governing digital health privacy. It further explores the broader implications of these actions for digital health companies, consumers, and advertisers, highlighting the FTC’s increasingly expansive interpretation of sensitive health information and its emphasis on transparency, accountability, and third-party oversight.
Recommended Citation
Sandhya Srinivasa,
Beyond HIPAA: The FTC’s Expanding Role in Digital Health Privacy Enforcement,
29
SMU Sci. & Tech. L. Rev.
245
(2026)
Included in
Computer Law Commons, Intellectual Property Law Commons, Internet Law Commons, Science and Technology Law Commons
