Does HIPAA Protect My Connected Examination Image?
Privacy and consent questions come up fast when a connected examination image — a photo from an at-home otoscope, dermatoscope, or similar device — gets captured, stored, or shared. Whether federal privacy protections apply depends on who provided the app, not on how medical the image looks. This guide explains the difference and what to ask.
By Everyday Imaging Evidence Editorial Team | Last updated September 8, 2026
If your doctor’s office gave you the app or told you to use a specific one as part of your care, federal privacy rules likely apply. If you found and downloaded the app yourself, with no connection to a provider, those same rules generally do not apply once your image reaches that app.
Why Does It Matter Who Provided the App?
The Health Insurance Portability and Accountability Act (HIPAA) only covers “covered entities” — health care providers, health plans, and health care clearinghouses — and their “business associates,” meaning vendors that create, receive, maintain, or transmit health information on a covered entity’s behalf. A consumer app you chose on your own, with no tie to a provider, generally sits outside that framework entirely.
This matters for connected examination images because many of these tools sit in a gray area. Some are offered directly by a clinic as part of a telehealth visit. Others are general consumer products a person buys and uses independently, with no clinician involved.
What Does Federal Guidance Actually Establish?
- Established: If an app was developed for, or provided by or on behalf of, a covered health care provider, the provider can be held responsible under HIPAA for how that app handles the information it receives.
- Established: If a patient chooses their own third-party app that was not provided by the provider, the provider is not responsible under HIPAA for what that app does with the information once it’s received — even if the app later has a data breach.
- Established: A patient can generally direct their provider to send electronic health information to an app of their choosing, even one that doesn’t encrypt data, and the provider cannot refuse simply because of concerns about how that app might use the information.
- Depends on the product: Whether a specific connected examination device or its companion app was built by, for, or on behalf of a specific clinic or health system. Only the device maker or provider can confirm this.
- Depends on the product: What a given app’s own privacy policy says about storage location, retention period, third-party sharing, and data deletion. Federal guidance doesn’t set these details — the app’s own terms do.
When Does a Device Maker Need a Business Associate Agreement?
A business associate relationship exists when a company creates, receives, maintains, or transmits health information on behalf of a covered provider to carry out the provider’s functions. Simply helping a patient access their own information at the patient’s request does not, by itself, create that relationship.
A business associate agreement is required only if the app or device was developed to handle information on behalf of the provider, or was provided by or on behalf of the provider — including through an electronic health record system acting as the provider’s business associate. If a device maker sells the same app independently, outside any provider relationship, no such agreement applies to that use.
What Is the Mobile Health Apps Interactive Tool?
The Federal Trade Commission, working with the HHS Office for Civil Rights, the Office of the National Coordinator for Health IT, and the FDA, maintains a guidance tool for health app developers. It asks questions about an app’s function and the data it collects, then points toward the federal laws that may apply — potentially including the FTC Act, the FTC’s Health Breach Notification Rule, HIPAA, the Food, Drug and Cosmetic Act, the Children’s Online Privacy Protection Rule, and information-blocking rules under the 21st Century Cures Act. It’s built for developers, but it’s also a useful way for a reader to see how many different laws can touch a single connected health app.
What’s Known vs. What You Still Need to Check?
- Known: A provider-supplied app used as part of your care is generally subject to HIPAA privacy and security obligations.
- Known: An app you selected on your own, unconnected to a provider, is generally not subject to HIPAA once your data reaches it.
- Known: Providers cannot deny you access to your own health information just because you’re directing it to a third-party app.
- Unknown until you check: Whether your specific device’s manufacturer has any business associate relationship with a clinic or health system.
- Unknown until you check: Where a specific app stores your image and for how long.
- Unknown until you check: Whether a specific app shares de-identified or aggregated image data with research partners or advertisers — something HIPAA does not automatically prevent for non-covered apps.
What Should I Ask Before Using a Connected Examination Device?
Use this decision path: if a provider gave you the app, ask them directly whether it falls under their HIPAA privacy practices. If you found the app yourself, treat it as uncovered by HIPAA and read its privacy policy before you use it.
- Did a health care provider give you this app or device, or recommend a specific one, as part of your care?
- Did you choose and download the app entirely on your own, with no provider involved?
- Does the app’s privacy policy explain where images are stored, how long they’re kept, and whether they’re shared with third parties?
- Does the app give you a clear way to delete your images and account data if you stop using it?
- If you’re unsure whether an app counts as a “business associate” of your provider, ask your provider’s office directly — this is a fair question to raise at any visit involving connected imaging.
- If you believe a covered provider or its business associate mishandled your information, you can file a complaint with the HHS Office for Civil Rights. For a general consumer app with no provider connection, the FTC’s Health Breach Notification Rule may be the more relevant avenue.
What This Article Does Not Cover
This guide explains general federal privacy concepts related to health apps and connected devices. It does not evaluate any specific app, device, or company, and it is not a substitute for reading a product’s actual privacy policy or terms of use. State privacy laws may add further protections beyond HIPAA and are not covered here.
Frequently Asked Questions
Does HIPAA cover a photo I take myself with a home examination device?
Generally, no — not once it’s on an app you chose yourself, unless that app was developed for or provided by a covered health care provider. Check with the app’s own privacy policy for how it handles your data.
Can my doctor refuse to send my exam images to an app I chose?
Generally, no. Under the HIPAA right of access, a provider generally cannot refuse to send your electronic health information to a third-party app you’ve designated, even if that app is unsecure or shares data for research.
Who do I contact if I think my health app mishandled my images?
If a covered provider or its business associate was involved, you can file a complaint with the HHS Office for Civil Rights. If it’s a general consumer app unconnected to a provider, the FTC’s Health Breach Notification Rule may apply instead.
Sources
- U.S. Department of Health and Human Services, Office for Civil Rights — Resources for Mobile Health Apps Developers
- U.S. Department of Health and Human Services, Office for Civil Rights — The Access Right, Health Apps, and APIs
Related Reading on This Site
- Start Here — an overview of how this publication approaches consumer health imaging and device literacy.
- How We Research — our sourcing and review standards for every foundation guide on this site.
Medical and Legal Information Disclaimer
This article is for general educational purposes only. It is not legal advice, medical advice, or a substitute for consulting an attorney, your health care provider, or the HHS Office for Civil Rights about your specific situation — see our full medical information disclaimer. Everyday Imaging Evidence is an independent editorial publication and is not affiliated with, and does not continue the products, research, or team of, the former CellScope company — see our independence and domain-history notice.
Leave a Reply