Data as of Aug 25, 2026 · Based on 307 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
A user can compare data protection standards by checking whether a platform signs a **Business Associate Agreement (BAA)** , reviewing independent safety audits, and analyzing the platform's third-party data sharing practices.[](https://pmc.ncbi.nlm.nih.gov/articles/PMC9643945/)…
A user can compare data protection standards by checking whether a platform signs a Business Associate Agreement (BAA) , reviewing independent safety audits, and analyzing the platform's third-party data sharing practices.
Many standalone mental health apps (like mood trackers or journaling tools) operate as general wellness products and are not legally bound by HIPAA unless they connect directly to a healthcare provider or covered entity.
Steps to Evaluate and Compare Platforms
“Millions of people use mental health apps to track moods, journal emotions, manage anxiety, and support overall behavioral health. But a recent cybersecurity investigation suggests some popular mental health apps may not be adequately protecting user data.”
If you'd like, let me know:
I can help you locate their specific privacy guidelines or evaluate their safety features.
A good comparison starts with one important distinction: **“HIPAA compliant” does not mean “maximally private.”** HIPAA regulates protected health information in particular covered-entity/business-associate relationships; a standalone consumer mental-health app may handle sensitive health data without that data being…
A good comparison starts with one important distinction: “HIPAA compliant” does not mean “maximally private.” HIPAA regulates protected health information in particular covered-entity/business-associate relationships; a standalone consumer mental-health app may handle sensitive health data without that data being protected by HIPAA. HHS specifically notes that HIPAA generally does not cover health information a person voluntarily enters into an app that isn't offered by or on behalf of a HIPAA-regulated entity. Other laws, including the FTC Act and Health Breach Notification Rule, can still apply.
| What to compare | Questions to ask |
|---|---|
| HIPAA status | Is the service a covered entity, a business associate, or neither? Does HIPAA apply to your particular service/use, rather than just the company generally? |
| Business Associate Agreement | If an employer, insurer, clinician, or health system is involved, will the platform sign a BAA where appropriate? |
| What data is collected | Therapy notes, diagnoses, messages, audio/video, IP address, device identifiers, location, contacts, payment data, app activity, questionnaires? |
| Who receives it | Therapists, contractors, insurers, employers, analytics providers, advertisers, cloud providers, affiliates, research partners? |
| Advertising/tracking | Are advertising pixels, cookies, SDKs, or other trackers used around health-related activity? HHS warns that disclosures of PHI to tracking vendors can implicate HIPAA. HHS.gov |
| Secondary uses | Is data used for product development, AI/model training, research, analytics, personalization, or marketing? |
| Selling/sharing | Does the policy prohibit sale of health information? Be careful with broad definitions of “sale” versus “sharing.” |
| Retention/deletion | How long are therapy records and messages retained? Can you delete the account/data, and are there legal exceptions? |
| Security | Encryption in transit/at rest, access controls, authentication, audit logs, penetration testing, SOC 2/HITRUST/ISO certifications or attestations? |
| Your rights | Can you access, correct, obtain a copy of, restrict, or request deletion of your information? |
| Breach response | What happens after a breach, and which legal notification regime applies? |
| Corporate/employer plans | If you use the app through work or an insurer, can the employer/plan learn that you use it or obtain information about your care? |
Read three documents for each service:
This can reveal meaningful differences. For example, Talkspace says that U.S. subscriber data is PHI protected by HIPAA and explains that it can act either as a business associate or covered entity depending on the provider relationship.
Headspace similarly distinguishes its general platform privacy practices from its medical-services relationship: its current policy says U.S. care providers are HIPAA-covered entities and Headspace acts as their business associate. Its medical notice separately describes permitted PHI uses and says Headspace Medical will not sell PHI or use it for marketing without the required authorization.
Calm is a useful example of why the specific product and relationship matter: its consumer-health-data policy says Calm Health may be subject to a healthcare provider or insurer's HIPAA notice when the service is provided through that HIPAA-covered entity.
For teletherapy, ask explicitly:
Are therapy messages, video/audio recordings, transcripts, and clinical notes retained? For how long? Who can access them? Are they used for AI training, quality assurance, research, or product improvement? These can be substantially more sensitive than ordinary account information. For example, Talkspace says its therapy transcripts are treated like medical records and its current retention policy says they are retained for 10 years.
A service that isn't HIPAA-covered isn't necessarily a service with no privacy protection. The FTC's Health Breach Notification Rule can apply to certain health apps that aren't subject to HIPAA, and the FTC's 2024 amendments explicitly addressed health apps and similar technologies.
Conversely, HIPAA compliance isn't a privacy score. HIPAA permits numerous uses and disclosures of PHI—for example, treatment, payment, healthcare operations, and certain disclosures required or permitted by law. A platform can therefore comply with HIPAA while having data practices that are less restrictive than what a privacy-conscious consumer might prefer.
For each app, give 0–2 points in each category:
Score separately for:
HIPAA applicability · data minimization · third-party sharing · advertising/tracking · secondary/AI uses · retention/deletion · encryption/security · user rights · breach practices · employer/insurer confidentiality
Then keep HIPAA status as a separate column, rather than treating it as the overall privacy score.
That produces a much more meaningful comparison than a simple “HIPAA: yes/no.”
If privacy is the priority, favor platforms whose policies make it easy to answer “what data do you collect, why, who gets it, how long do you keep it, and can I delete it?” A company that provides detailed, product-specific answers is generally easier to evaluate than one relying mainly on a generic “HIPAA-compliant and secure” claim. The FTC itself cautions companies against vague or misleading claims such as “HIPAA certified” or “HIPAA secure.”
If you want, I can also turn this framework into a side-by-side comparison of 5–10 popular platforms (e.g., BetterHelp, Talkspace, Headspace, Calm, Brightside, and Teladoc) using their current privacy policies and HIPAA disclosures.
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms `requires looking past marketing claims` . Many direct-to-consumer wellness apps are **not** legally bound by HIPAA because they operate as lifestyle or self-help tools rather than traditional healthcare providers…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims . Many direct-to-consumer wellness apps are not legally bound by HIPAA because they operate as lifestyle or self-help tools rather than traditional healthcare providers or covered entities.
Evaluating and comparing these platforms effectively involves a structured, step-by-step approach:
Navigating the Fine Print
When looking at user advocacy reports and investigations into popular platforms, consumer consensus often highlights how tricky these policies can be to parse.
“Many of these apps do not have clear policies on how long they retain your data, and there is no rule requiring them to. HIPAA does not create any records retention requirements — they are regulated by state laws and unlikely to include health apps as...”
“Despite these apps dealing with incredibly sensitive issues — like depression, anxiety, suicidal thoughts, domestic violence, eating disorders, and PTSD — the worst of them routinely share data, target vulnerable users with personalized ads, allow weak...”
If you have a specific app or platform in mind, let me know its name and I can help look up its recent privacy evaluations or specific compliance disclosures.
The key is to **separate “HIPAA compliant” from “privacy-friendly.”** They overlap, but they are not the same thing. HIPAA generally applies to covered health-care providers and their business associates—not automatically to every consumer mental-health app. HHS specifically notes that information entered into an app…
The key is to separate “HIPAA compliant” from “privacy-friendly.” They overlap, but they are not the same thing. HIPAA generally applies to covered health-care providers and their business associates—not automatically to every consumer mental-health app. HHS specifically notes that information entered into an app that isn't offered by or on behalf of a HIPAA-covered entity may fall outside HIPAA, while other laws such as the FTC Act or Health Breach Notification Rule may still apply.
For each mental-health app or teletherapy platform, check these categories:
| What to compare | Questions to ask |
|---|---|
| HIPAA status | Does the company actually say it is subject to HIPAA? Is the therapy service/provider relationship HIPAA-covered, rather than merely the app claiming to be “HIPAA compliant”? |
| Business Associate Agreement (BAA) | If the platform handles PHI on behalf of a covered provider, is there a BAA? HHS identifies app developers that handle PHI for covered providers as potential business associates. HHS.gov |
| Data collected | Does it collect therapy notes, diagnoses, medications, mood journals, IP address, location, device identifiers, contacts, or other information beyond what's necessary? |
| Sharing | Does it share information with advertisers, analytics companies, data brokers, affiliates, researchers, or AI providers? |
| Advertising | Is mental-health information used for targeted advertising or advertising profiles? |
| Tracking technologies | Does the app/site use Meta Pixel, Google Analytics, advertising IDs, cookies, or similar tracking around sensitive health information? HHS warns that tracking technologies can create PHI disclosures for HIPAA-regulated entities. HHS.gov |
| Encryption/security | Is data encrypted in transit and at rest? Is multifactor authentication available? How are accounts, clinician access, and backups protected? |
| Retention/deletion | How long are records retained? Can the user delete an account and associated data? Are clinical records retained even after account deletion? |
| Data ownership/use | Does the company use conversations or therapy content to train AI models, improve products, or conduct research? Under what terms? |
| Third parties | Which vendors receive data? Look for a subprocessors/vendor list. |
| Breach history | Has the company experienced privacy/security incidents, regulatory investigations, or FTC enforcement? |
| User rights | What rights does the user have to access, correct, download, or delete information? |
| Legal jurisdiction | Does the service have additional protections under state privacy or health-data laws? |
A strong comparison should ask why HIPAA applies and to which data.
For example, HHS says a third-party app selected by a consumer to receive health information directly from a covered entity isn't necessarily a business associate; merely facilitating the individual's requested access does not create a BAA relationship.
So a better question than “Is this app HIPAA compliant?” is:
“Who is the HIPAA-covered entity, what data is covered by HIPAA, what role does this platform play, and what protections apply to everything outside HIPAA?” That distinction can substantially change the comparison.
For each service, collect:
Then record the findings in a spreadsheet rather than relying on each company's privacy-language summaries.
You could score each platform from 0–2 in each category:
For example:
Privacy score
Security score
Regulatory score
I would not collapse everything into a single “HIPAA score.” A platform could have a legitimate HIPAA-covered service while still having comparatively aggressive practices around analytics, advertising, or non-PHI consumer data.
This is particularly important with mental-health apps. HHS explicitly says HIPAA generally doesn't protect health information stored in consumer apps that aren't provided by a covered entity or business associate.
That doesn't mean the information is unprotected. The FTC says its Act can apply to companies outside HIPAA, and its Health Breach Notification Rule applies to many health apps and was amended in 2024 to emphasize its application to most health apps.
Consequently, a good comparison should have columns for:
HIPAA protections | FTC protections | state-law protections | company's voluntary privacy practices
rather than treating HIPAA as the entire privacy picture.
Also investigate the therapist/provider, not just the platform. Ask:
This helps distinguish a telehealth provider with a HIPAA-regulated clinical relationship from a consumer wellness app that happens to offer access to therapists.
For a user choosing among popular services, I'd rank them on privacy practices first and HIPAA status second:
Who gets my mental-health data, what exactly do they get, why do they get it, how long do they keep it, can they use it for advertising/AI/research, and what happens if there is a breach? HIPAA is an important baseline, but “HIPAA compliant” alone is not a sufficient privacy recommendation. HHS itself emphasizes that HIPAA's applicability depends on whether an entity is a covered entity or business associate.
For primary-source checking, the hhs.gov and ftc.gov are particularly useful starting points.
For a user choosing among popular services, I'd rank them on privacy practices first and HIPAA status second:
Who gets my mental-health data, what exactly do they get, why do they get it, how long do they keep it, can they use it for advertising/AI/research, and what happens if there is a breach? HIPAA is an important baseline, but “HIPAA compliant” alone is not a sufficient privacy recommendation. HHS itself emphasizes that HIPAA's applicability depends on whether an entity is a covered entity or business associate.
This is particularly important with mental-health apps. HHS explicitly says HIPAA generally doesn't protect health information stored in consumer apps that aren't provided by a covered entity or business associate.
That doesn't mean the information is unprotected. The FTC says its Act can apply to companies outside HIPAA, and its Health Breach Notification Rule applies to many health apps and was amended in 2024 to emphasize its application to most health apps.
A good comparison should separate **HIPAA coverage** from **overall privacy**. “HIPAA compliant” is not a synonym for “private,” and an app can have strong privacy practices even when HIPAA does not apply to all of its consumer-facing data. ## 1. First determine what HIPAA actually covers HIPAA applies to **covered…
A good comparison should separate HIPAA coverage from overall privacy. “HIPAA compliant” is not a synonym for “private,” and an app can have strong privacy practices even when HIPAA does not apply to all of its consumer-facing data.
HIPAA applies to covered entities and their business associates, not automatically to every mental-health app.
For each service, ask:
This last question is particularly important: HHS says HIPAA generally doesn't protect health information that a person voluntarily enters into an app that isn't provided by or on behalf of a HIPAA-regulated entity. Other laws, including FTC rules, can nevertheless apply.
For each platform, look for specific answers about:
| Question | What to look for |
|---|---|
| Data collected | Therapy messages, diagnoses, journal entries, voice/video, recordings, IP address, device identifiers, location, payment data |
| Purpose | Treatment, operations, analytics, personalization, advertising, research |
| Third-party sharing | Vendors, advertisers, analytics providers, employers, insurers, affiliates |
| Advertising | Whether mental-health information can be used for targeted advertising |
| AI | Whether conversations are used to train models, and whether you can opt out |
| Retention | How long clinical records, messages, recordings and account data remain |
| Deletion | Whether you can delete consumer data and what must legally be retained |
| Encryption | Encryption in transit and at rest; particularly important for video, messaging and stored records |
| Access controls | MFA, authentication, employee access, audit logging |
| Breach response | What constitutes a breach and how/when users are notified |
| Your rights | Access, correction, deletion, portability and applicable state-law rights |
For example, Talkspace currently says U.S. subscriber data is treated as PHI under HIPAA and describes encryption of server data and communications. Talkspace Help Center Talkspace Headspace's current materials distinguish its general consumer privacy policy from its HIPAA-covered medical services and publish a separate HIPAA Notice of Privacy Practices.
This is an often-overlooked differentiator.
HHS says tracking technologies on authenticated telehealth pages can have access to PHI, and regulated entities have to ensure that disclosures to tracking vendors comply with HIPAA. HHS also notes that information such as IP addresses, device identifiers and geolocation can become relevant health information in particular circumstances.
So don't just ask, “Is the video session encrypted?” Ask:
“What information about my use of the service is sent to analytics, advertising, social-media, or other third-party tracking companies?”
This is crucial when comparing a meditation/self-help app with a teletherapy service.
A teletherapy provider may maintain a formal medical record subject to HIPAA, while the same company's general wellness features, website activity, advertising identifiers, or other consumer data may have different legal treatment.
Similarly, a standalone mental-health app doesn't necessarily become HIPAA-covered merely because it handles very sensitive mental-health information. The FTC specifically notes that many health apps not covered by HIPAA may instead be subject to its Health Breach Notification Rule.
Give more weight to:
Be cautious with vague statements such as “bank-level security,” “100% confidential,” or “HIPAA compliant” without details. HIPAA itself imposes specific obligations concerning privacy, security, disclosures and business associates.
You could score each platform from 0–2 in these categories:
Then weight the categories according to your priorities. For someone choosing therapy, for example, third-party sharing, clinical-record handling, tracking, retention and AI use may matter more than the number of security certifications.
Finally, check the policies at the time you sign up. Privacy practices change, and even within one company different products or services can have different HIPAA status. HHS's current guidance specifically emphasizes examining the nature of the app, the information it collects, and the relationships among the app, providers and vendors.
For a rigorous comparison of specific platforms such as BetterHelp, Talkspace, Headspace, Calm, Teladoc, and traditional teletherapy platforms, I would compare their current 2026 privacy policies, HIPAA notices, tracking practices, data-retention rules, and AI policies side by side, rather than relying on their marketing claims.
So don't just ask, “Is the video session encrypted?” Ask:
“What information about my use of the service is sent to analytics, advertising, social-media, or other third-party tracking companies?”
This is crucial when comparing a meditation/self-help app with a teletherapy service.
A teletherapy provider may maintain a formal medical record subject to HIPAA, while the same company's general wellness features, website activity, advertising identifiers, or other consumer data may have different legal treatment.
Similarly, a standalone mental-health app doesn't necessarily become HIPAA-covered merely because it handles very sensitive mental-health information. The FTC specifically notes that many health apps not covered by HIPAA may instead be subject to its Health Breach Notification Rule.
Give more weight to:
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires `looking past marketing claims and examining technical architecture, legal agreements, and independent third-party evaluations` . Many consumer-facing wellness apps operate outside of HIPAA entirely,…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims and examining technical architecture, legal agreements, and independent third-party evaluations . Many consumer-facing wellness apps operate outside of HIPAA entirely, making a direct comparison tricky.
Key Frameworks for Comparison
If you'd like to narrow this down, tell me:
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms `requires looking past marketing claims` . Most standalone wellness apps (mood trackers, meditation tools, or AI chat companions) are **not** legally covered by HIPAA because they are tech companies rather than…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims . Most standalone wellness apps (mood trackers, meditation tools, or AI chat companions) are not legally covered by HIPAA because they are tech companies rather than traditional healthcare providers or insurers.
A step-by-step framework helps users evaluate and compare these platforms effectively:
Expert and Consumer Perspectives
Independent evaluations often reveal stark gaps between user expectations and actual app behavior.
“Most ignored our requests for transparency completely.”
“If another app picks up intimate information from the mental health or well-being app, details entered by the student aren't covered and can be sent elsewhere.”
If you have a specific app or teletherapy platform in mind, let me know its name so I can help you look into its specific privacy disclosures and compliance history.
A good comparison starts with one important distinction: **“HIPAA compliant” is not the same thing as “private.”** HIPAA applies to covered health-care entities and their business associates, not automatically to every mental-health app. Consumer-facing apps outside HIPAA can still be subject to the FTC Act and, in…
A good comparison starts with one important distinction: “HIPAA compliant” is not the same thing as “private.” HIPAA applies to covered health-care entities and their business associates, not automatically to every mental-health app. Consumer-facing apps outside HIPAA can still be subject to the FTC Act and, in some cases, the FTC Health Breach Notification Rule.
| Category | Questions to ask |
|---|---|
| HIPAA status | Does the platform explicitly say it is a HIPAA-covered entity or business associate? Is the therapy service covered, or merely certain enterprise/employer arrangements? |
| BAA | If you're receiving care through a provider/organization, will the platform sign or operate under a Business Associate Agreement (BAA) where required? HIPAA business associates generally need written assurances/contracts concerning PHI safeguards. www.hhs.gov |
| Data collected | Does it collect therapy-session content, diagnoses, medications, mood entries, IP addresses, device IDs, location, contacts, or browsing/activity data? |
| Secondary uses | Is data used for advertising, analytics, personalization, AI/model training, research, or product development? |
| Third-party sharing | Which vendors receive information—cloud providers, analytics companies, advertisers, payment processors, social-media/advertising platforms? |
| Advertising | Can mental-health information be used to target ads? This deserves particular scrutiny: the FTC has taken action concerning disclosure of sensitive health information for advertising. www.ftc.gov |
| Therapy-session privacy | Are video/audio sessions recorded? Are transcripts generated? If so, where are they stored, for how long, and can they be used for AI or quality assurance? |
| Encryption/security | Is data encrypted in transit and at rest? Does the company describe access controls, authentication, security testing, audit logging, and incident response? HIPAA's Security Rule addresses administrative, physical, and technical safeguards for electronic PHI. www.hhs.govwww.ftc.gov |
| Retention/deletion | Can users delete their account and data? What data must be retained for legal/clinical reasons, and for how long? |
| User rights | Can users access, correct, download, or request deletion of their information? What happens when they stop using the service? |
| Breaches | What notification obligations does the company describe? HIPAA-covered entities/business associates have HIPAA breach-notification obligations; qualifying non-HIPAA health apps can instead fall under the FTC's Health Breach Notification Rule. www.hhs.govwww.ftc.gov |
| Legal jurisdiction | Which state laws apply, and does the company discuss state consumer-health or medical-privacy requirements in addition to HIPAA? |
For each platform—whether it's a teletherapy service such as BetterHelp or Talkspace, a provider-connected platform, or a mental-wellness app—make a spreadsheet with these columns:
Platform → HIPAA role/status → BAA → data collected → advertising → third-party sharing → recording/transcription → AI use → encryption/security → retention → deletion → breach history/notifications → privacy-policy date.
Then give each category a 0–2 score:
I'd weight secondary data use, advertising, third-party sharing, therapy recordings/transcripts, and deletion/retention more heavily than marketing claims such as “secure” or “HIPAA-ready.”
A platform saying “HIPAA compliant” doesn't necessarily answer the question a consumer actually cares about: “What happens to my information when I use this service?” The FTC specifically cautions companies against misleading claims such as “HIPAA Certified” or “HIPAA Secure.”
Conversely, lack of HIPAA coverage isn't automatically proof that an app is unsafe. The FTC's Health Breach Notification Rule now expressly covers many health apps that aren't HIPAA-covered, and the FTC Act independently applies to misleading or unfair health-data practices.
When researching an app, prioritize:
Also check the date of the privacy policy; data practices can change substantially after an app is acquired, introduces AI features, or changes its advertising model.
For an especially sensitive use case, the strongest option is generally a provider/platform arrangement where you can establish exactly who is the HIPAA-covered entity, who is the business associate, what data is PHI, and what secondary uses are permitted, rather than assuming that the consumer app itself is comprehensively protected by HIPAA.
HHS HIPAA guidance for health apps · FTC Mobile Health App Interactive Tool ·
The key is to **separate “HIPAA compliance” from overall privacy**. An app can have strong security and privacy practices without being covered by HIPAA—and a HIPAA-covered provider can still have privacy practices you may dislike. ### 1. First, determine whether HIPAA actually applies HIPAA generally applies to…
The key is to separate “HIPAA compliance” from overall privacy. An app can have strong security and privacy practices without being covered by HIPAA—and a HIPAA-covered provider can still have privacy practices you may dislike.
HIPAA generally applies to covered entities (such as healthcare providers, health plans, and clearinghouses) and their business associates. A consumer-facing mental-health app isn't automatically covered merely because it handles mental-health information. HHS specifically notes that information voluntarily entered into an app that isn't offered by or on behalf of a HIPAA-regulated entity may fall outside HIPAA.
So don't treat a badge saying “HIPAA compliant” as the end of the investigation. Ask:
For each platform, look specifically for:
| Question | What to look for |
|---|---|
| Data collected | Therapy notes, intake answers, diagnoses, messages, IP/device IDs, location, contacts, payment information |
| Purpose | Treatment vs. analytics, personalization, marketing, advertising |
| Third parties | Cloud providers, analytics companies, advertisers, social-media platforms, contractors |
| Advertising | Whether health-related information can be used for targeted advertising |
| Tracking | Pixels, cookies, SDKs, session replay, ad trackers |
| Retention | How long records remain after cancellation/deletion |
| Deletion | Whether you can delete your account/data and what exceptions apply |
| Data sales/sharing | “Sale,” “sharing,” “disclosure,” and similarly broad terminology |
| AI use | Whether conversations or journal entries are used to train models or improve products |
| Security | Encryption, access controls, breach response, authentication |
| Legal requests | What happens when law enforcement or courts request information |
Pay particular attention to vague phrases such as “business purposes,” “service providers,” “affiliates,” “partners,” and “de-identified information.”
A company's enforcement history can tell you more than a polished privacy page.
For example, the FTC alleged that BetterHelp shared sensitive information—including email addresses, IP addresses, and answers to health questions—with companies such as Facebook and Snapchat for advertising, despite privacy representations it had made to consumers. BetterHelp ultimately agreed to a $7.8 million FTC settlement and restrictions on sharing sensitive health data for advertising.
That doesn't necessarily tell you what BetterHelp's practices are today, but it is highly relevant historical evidence when comparing platforms.
This is an especially important distinction. HHS says information collected by a mobile app operated by a HIPAA-regulated entity can constitute PHI, including information subsequently disclosed to tracking-technology vendors. But information voluntarily entered into a non-HIPAA-regulated consumer app isn't automatically protected by HIPAA.
For a privacy-conscious user, therefore, ask:
“Does this app send information about what I'm doing or what I'm seeking help for to analytics or advertising companies?”
rather than simply:
“Is this app HIPAA compliant?”
Depending on where the user lives, other laws can matter. State consumer-health-data and medical-information laws may apply even when HIPAA doesn't. This is particularly relevant in states with comprehensive or specialized health-data privacy regimes.
A practical comparison could use a 0–2 scale:
Score each service on:
Then compare the total score and the individual red flags, rather than relying on a single “HIPAA compliant” yes/no label.
For a person choosing among popular therapy platforms, I'd prioritize them roughly in this order:
1. What data does it collect? → 2. Who receives it? → 3. Is it used for advertising/AI? → 4. Can I delete it? → 5. What security protections exist? → 6. Does HIPAA actually apply?
That's more informative than treating HIPAA as a universal privacy certification. HHS itself makes clear that HIPAA's applicability depends on the entity and relationship involved.
If you're comparing specific platforms such as BetterHelp, Talkspace, Headspace, Calm, Wysa, and Teladoc, I can also make a current side-by-side comparison of their HIPAA status, data collection, advertising/tracking, deletion policies, AI practices, and regulatory history.
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires looking past marketing claims . Many direct-to-consumer apps operate in a regulatory gray area where federal health privacy laws do not apply, meaning standard app store ratings or download counts tell…
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires looking past marketing claims . Many direct-to-consumer apps operate in a regulatory gray area where federal health privacy laws do not apply, meaning standard app store ratings or download counts tell you very little about safety.
A step-by-step approach can help users and clinicians systematically evaluate and compare these platforms:
Would you like help evaluating a specific app or teletherapy platform , or do you need recommendations on how to check mobile device permission settings for privacy?