Data as of Sep 18, 2026 · Based on 325 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
The key is to **separate “HIPAA compliance” from overall privacy**. An app can be HIPAA-covered in one part of its service while collecting other data that HIPAA doesn't protect, and some consumer mental-health apps aren't covered by HIPAA at all. HHS specifically notes that HIPAA generally does not protect health…
The key is to separate “HIPAA compliance” from overall privacy. An app can be HIPAA-covered in one part of its service while collecting other data that HIPAA doesn't protect, and some consumer mental-health apps aren't covered by HIPAA at all. HHS specifically notes that HIPAA generally does not protect health information a person voluntarily enters into an app that isn't provided by or on behalf of a HIPAA-covered entity or business associate.
| What to compare | Questions to ask |
|---|---|
| HIPAA status | Is the company itself a covered entity, a business associate, or neither? Which specific services are covered? |
| BAA | If the platform handles PHI for a therapist/health provider, is there a Business Associate Agreement? HHS says an app developer acting as a business associate generally needs a BAA. HHS.gov HHS.gov |
| Data collected | Does it collect therapy messages, diagnoses, medications, session recordings/transcripts, location, contacts, device identifiers, IP address, or advertising IDs? |
| Secondary use | Can data be used for advertising, analytics, product development, AI training, research, or sold/shared with third parties? |
| Tracking technologies | Does the app/site use advertising pixels, SDKs, cookies, or other tracking technologies around health information? HHS warns that tracking technologies can create HIPAA disclosure issues when PHI is involved. HHS.gov |
| Encryption/security | Is data encrypted in transit and at rest? Is MFA available? What security certifications or independent audits are disclosed? |
| Therapy content | Are messages, recordings, transcripts, and psychotherapy notes stored? For how long? Who can access them? |
| Retention/deletion | Can you delete your account and data? What must legally be retained, and for how long? |
| Third parties | Who receives data—therapists, cloud providers, payment processors, analytics companies, insurers, employers, or other vendors? |
| User rights | Can you access, correct, download, or request restrictions on your information? |
| Government/legal requests | What does the privacy policy say about subpoenas, court orders, law-enforcement requests, and emergency disclosures? |
| State privacy laws | Does the company provide protections beyond HIPAA under applicable state privacy laws? HHS notes that state laws can apply to entities outside HIPAA's scope. telehealth.hhs.gov |
Look for the actual HIPAA relationship. For example, Talkspace's current Notice of Privacy Practices says that, depending on the arrangement, it can act as a HIPAA Business Associate for independently contracted providers or as a Covered Entity when services are provided directly by Talkspace.
That's much more informative than simply seeing a “HIPAA compliant” badge.
Also check whether the company's privacy policy covers all of its products. Talkspace's privacy policy, for example, distinguishes medical information/PHI from other personal data and describes information collected during registration and service use.
A useful spreadsheet might have columns for:
This prevents a common mistake: treating HIPAA = maximum privacy. HIPAA establishes particular legal protections for PHI in particular relationships; it isn't a comprehensive privacy law covering every piece of data an app collects. The FTC also points out that consumer health apps can fall under the FTC Act and Health Breach Notification Rule even when HIPAA doesn't apply.
For mental-health services, this can be more consequential than ordinary account information. Ask whether text messages, audio/video recordings, transcripts, and psychotherapy notes are retained, who can access them, and whether they're used for anything beyond providing care.
As one concrete example, Talkspace says its therapy transcripts are treated as medical records and retained for 10 years under its retention policy.
Look for concrete controls rather than marketing language:
HHS specifically recommends considering encryption, authentication, and the risks surrounding stored recordings/transcripts when evaluating telehealth technologies.
Rather than producing a single “most private” ranking, make a side-by-side evidence table and link each conclusion to the platform's current privacy policy, HIPAA Notice of Privacy Practices, security documentation, and terms.
For example:
| Platform | HIPAA relationship | Advertising/tracking | Therapy data retention | AI/data-use policy | Deletion rights | Security disclosures |
|---|---|---|---|---|---|---|
| Platform A | Verify | Verify | Verify | Verify | Verify | Verify |
| Platform B | Verify | Verify | Verify | Verify | Verify | Verify |
| Platform C | Verify | Verify | Verify | Verify | Verify | Verify |
That approach is especially important because privacy policies change, and the answer can differ between therapy provided through an employer/insurer, direct-to-consumer therapy, and a standalone wellness app.
If you're choosing among particular services such as BetterHelp, Talkspace, Headspace, Calm, Brightside, and Teladoc, I can also build this side-by-side comparison using their current 2026 privacy policies and HIPAA disclosures, with citations for each row.
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires `looking past marketing claims and examining technical, legal, and operational realities` . Many standalone wellness apps operate completely outside of HIPAA bounds, meaning they answer to lax consumer…
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires looking past marketing claims and examining technical, legal, and operational realities . Many standalone wellness apps operate completely outside of HIPAA bounds, meaning they answer to lax consumer protection standards rather than strict healthcare laws.
Here is a practical framework a user can follow to evaluate and compare these platforms:
If you'd like, let me know:
I can help you look into their specific privacy standing and data policies.
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims. Many consumer-facing apps operate in a regulatory gray area, meaning they may not legally be bound by HIPAA unless they are acting directly as a "covered entity" (like a…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims. Many consumer-facing apps operate in a regulatory gray area, meaning they may not legally be bound by HIPAA unless they are acting directly as a "covered entity" (like a healthcare provider) or a "business associate."
A structured, step-by-step approach can help evaluate and compare these platforms effectively:
If you have a specific app or platform in mind, tell me its name and I can help look up its recent privacy evaluations or compliance history.
The key is to **separate “HIPAA compliance” from overall privacy**. A mental-health app can have strong privacy protections without being HIPAA-covered, and a statement that an app is “HIPAA compliant” does not by itself tell you how much data it collects or shares. HIPAA generally applies to covered health-care…
The key is to separate “HIPAA compliance” from overall privacy. A mental-health app can have strong privacy protections without being HIPAA-covered, and a statement that an app is “HIPAA compliant” does not by itself tell you how much data it collects or shares. HIPAA generally applies to covered health-care entities and their business associates—not every consumer health app.
For each app or teletherapy platform, compare these categories:
| What to check | Questions to ask |
|---|---|
| HIPAA status | Is the service actually a HIPAA covered entity or business associate? If it is acting as a business associate, will it sign a Business Associate Agreement (BAA) where applicable? |
| What data is collected | Therapy notes, diagnoses, messages, assessments, audio/video, IP address, device identifiers, location, contacts, payment information? |
| Who receives the data | Therapists, clinicians, employers, insurers, analytics providers, advertisers, AI vendors, cloud providers or other third parties? |
| Advertising/tracking | Are advertising pixels, cookies, SDKs or other tracking technologies used on health-related pages or inside the app? |
| Secondary uses | Can data be used for advertising, research, product development, AI training, analytics or other purposes? |
| Data retention | How long are records and messages retained? Can you delete your account and associated data? |
| User controls | Can you opt out of optional data collection, marketing, personalization or sharing? |
| Security | Encryption in transit/at rest, access controls, authentication, audit logging and breach-response procedures? |
| Legal disclosures | Does the company clearly explain subpoenas, law-enforcement requests, emergencies and other circumstances in which information can be disclosed? |
| State privacy laws | Does the company comply with applicable state consumer-health/privacy laws in addition to HIPAA? |
| Clinical relationship | Is this simply a wellness/self-help app, or are you actually receiving care from a licensed provider? |
The American Psychiatric Association specifically recommends asking about the app's privacy policy, data collected, HIPAA claims and BAA, de-identification, opt-outs, deletion, cookies, third-party sharing and cloud storage.
This is probably the most important distinction.
If you're using a therapist's telehealth service and the technology provider is acting as the therapist's business associate, HIPAA protections may apply to the relevant protected health information. By contrast, information that a consumer voluntarily enters into an app that isn't a covered entity or business associate generally isn't protected by HIPAA merely because it concerns mental health.
Non-HIPAA apps aren't necessarily unregulated, though. The FTC's Health Breach Notification Rule can apply to certain health apps and personal health-record companies and requires notification following qualifying breaches of unsecured identifiable health information.
Also be skeptical of marketing language. The FTC warns companies against making misleading claims such as “HIPAA Certified” or “HIPAA Secure.”
For popular services, don't rely on a third-party “HIPAA apps” list. Open each company's current:
For example, Headspace currently states that it is subject to HIPAA in its role as a business associate to its care providers, while its medical services have a separate HIPAA Notice of Privacy Practices. Headspace Headspace That illustrates why it's important to determine which service/product and which relationship with the provider you're evaluating rather than assigning one HIPAA label to an entire company.
You can make a spreadsheet and score each platform from 0–2 in each category:
I'd give extra weight to:
This is broadly consistent with established mental-health-app evaluation criteria, which include whether sensitive data are collected, whether security practices are explained, whether users can opt out/delete data, where data are stored, and which third parties receive them.
For actual therapy, prioritize the privacy protections surrounding the clinical relationship—not merely the consumer app's privacy label. For a self-help app, scrutinize what happens to your data even more carefully because HIPAA may not apply.
And don't assume that “anonymous,” “de-identified,” or “encrypted” means “private.” Ask what can be linked back to you, who has access, and for what purposes the information can subsequently be used. The APA likewise recommends looking beyond an app-store description and examining the company's privacy practices and evidence for its claims.
If you want, I can also make a side-by-side comparison of specific popular platforms (e.g., BetterHelp, Talkspace, Headspace, Calm, Teladoc, and a few others), including their current HIPAA status, data-sharing practices, tracking, deletion options, and privacy-policy red flags.
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms `requires looking past marketing claims` . Many direct-to-consumer wellness apps are **not** legally bound by HIPAA because they operate outside traditional healthcare provider…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims . Many direct-to-consumer wellness apps are not legally bound by HIPAA because they operate outside traditional healthcare provider networks.
A structured approach helps evaluate and compare these platforms effectively:
If you'd like, let me know:
I can help you look into their specific data-sharing practices and compliance standing.
The key is to **separate “HIPAA-covered” from “private”**. They overlap, but they are not the same thing. HIPAA generally applies to covered health-care providers, health plans, clearinghouses, and their business associates—not automatically to every consumer mental-health app. HHS specifically warns that information…
The key is to separate “HIPAA-covered” from “private”. They overlap, but they are not the same thing. HIPAA generally applies to covered health-care providers, health plans, clearinghouses, and their business associates—not automatically to every consumer mental-health app. HHS specifically warns that information voluntarily entered into a consumer app that isn't offered by a HIPAA-regulated entity generally isn't protected by HIPAA.
When comparing popular apps and teletherapy platforms, look at these dimensions:
| What to compare | Questions to ask |
|---|---|
| HIPAA status | Does the service actually operate as a HIPAA covered entity or business associate for my service? Is there a Business Associate Agreement (BAA) where applicable? |
| What data is collected | Therapy notes, diagnoses, medications, messages, audio/video, IP address, device identifiers, location, contacts, payment data, and usage/analytics? |
| Who receives it | Therapists, affiliated companies, employers, insurers, advertisers, analytics providers, cloud vendors, or other third parties? |
| Advertising | Is mental-health information used for targeted advertising or shared with advertising/marketing companies? |
| Data retention | How long are messages, session records, assessments, and account information retained? Can you delete the account/data? |
| Encryption/security | Is data encrypted in transit and at rest? Does the company describe access controls, authentication, security testing, and breach procedures? |
| Your rights | Can you access, correct, download, restrict, or request deletion of your information? |
| AI features | Are conversations or journal entries used to train AI models? Is data shared with an AI provider? Can you opt out? |
| Legal disclosures | What happens when the company receives a subpoena, court order, or law-enforcement request? |
| Employer/insurance arrangements | If you access the platform through an employer or insurer, what information can that organization receive? |
For example, Talkspace currently states that its technology is HIPAA compliant and describes encryption and annual assessments. Its current Notice of Privacy Practices also explains that Talkspace can act as a HIPAA business associate for independently contracted providers or as a covered entity when services are provided directly by Talkspace employees.
Headspace similarly distinguishes between its general platform privacy practices and its health-care services: its privacy policy says Headspace is subject to HIPAA as a business associate of its care providers, while Headspace Medical has its own HIPAA Notice of Privacy Practices.
That's much more informative than simply seeing the words “HIPAA compliant.” The FTC specifically cautions companies against misleading claims such as “HIPAA certified” or “HIPAA secure,” and stresses that consumers should understand what health data is collected, how it is used, where it goes, and how long it is retained.
For each service, I'd make a one-page scorecard:
Then give each category a simple 0–2 score rather than trying to determine which company is universally “most private.”
A non-HIPAA app isn't necessarily unregulated. The FTC's Health Breach Notification Rule can cover certain health apps that aren't subject to HIPAA, and the FTC says its 2024 amendments clarified the rule's application to many health apps and similar technologies.
So a good comparison asks:
“What legal protections and contractual promises govern my data in this particular service?” rather than simply:
“Is this app HIPAA compliant?” Finally, remember that device-level privacy matters too. HHS notes that HIPAA generally doesn't protect health information simply because it is stored on your personal phone or tablet, and other app/device companies may collect information outside HIPAA's scope.
If you're comparing specific services such as BetterHelp, Talkspace, Headspace, Calm, Cerebral, and traditional telehealth providers, I can also build a current side-by-side privacy/HIPAA comparison using their actual policies.
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims.[](https://www.hipaavault.com/resources/how-to-tell-if-software-is-hipaa-compliant-a-guide-for-healthcare-vendors-and-it-teams/)…
Comparing HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms requires looking past marketing claims.
Because the U.S. Department of Health and Human Services (HHS) does not officially "certify" consumer software or issue a universal compliance badge, users and evaluators must systematically audit platforms across legal, technical, and operational dimensions.
Step 1: Consult Independent Trust & Privacy Guides
Before diving into legalese, check expert security audits that specifically rate consumer mental health technology:
Step 2: Key Criteria for Comparison
When contrasting two or more platforms, structure your evaluation around these core pillars:
Step 3: Build a Side-by-Side Comparison Matrix
To make a clear evaluation, create a simple checklist matrix mapping out your shortlisted platforms:
| Evaluation Criteria | Platform A (e.g., Clinical Teletherapy) | Platform B (e.g., Wellness/Mood App) |
|---|---|---|
| Target Regulation | Governed by HIPAA / BAA available | Governed by general consumer privacy laws |
| Account Creation | Requires MFA / Strong passwords | Allows weak passwords or social logins |
| Third-Party Pixels | None on authenticated health portals | Contains tracking SDKs / ad trackers |
| Data Deletion | Clear user-initiated purge protocols | Retention length opaque / uncertain |
| Audit Logs | Role-based access controls present | Not specified |
If you have specific apps or platforms in mind (e.g., Talkspace, BetterHelp, Wysa, or Calm), let me know their names and I can help you look up their specific documented privacy findings and compliance postures.
A user can compare HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms by looking beyond a simple “HIPAA compliant” label. HIPAA status is only one part of the picture: some apps handle protected health information (PHI) as healthcare providers or business associates, while…
A user can compare HIPAA compliance and data privacy practices among mental health apps and teletherapy platforms by looking beyond a simple “HIPAA compliant” label. HIPAA status is only one part of the picture: some apps handle protected health information (PHI) as healthcare providers or business associates, while others may collect sensitive mental health data without being covered by HIPAA in the same way.
Create a distinction between:
Questions to ask:
Make a table for each platform:
| Category | Questions to compare |
|---|---|
| Data collected | Does it collect therapy notes, diagnoses, mood data, location, contacts, device IDs, or usage analytics? |
| Data sharing | Are data shared with advertisers, analytics companies, research partners, or other third parties? |
| Advertising | Does the company use mental health-related data for targeted advertising? |
| Data retention | How long are records kept after account deletion? |
| Deletion rights | Can users request deletion of personal information? |
| International transfers | Is data stored outside the user’s country? |
Health apps can collect information outside traditional medical records, and privacy protections may differ depending on the app’s relationship to healthcare providers.
Look for:
A platform should clearly explain how it protects sensitive information rather than relying only on marketing language.
For teletherapy platforms, compare:
Look for disclosures about:
Tracking technologies can create privacy concerns when sensitive health information is shared with third parties, especially for HIPAA-regulated entities.
Higher-privacy platforms typically offer:
Useful questions:
Useful sources include:
A user could score each platform from 1–5:
| Factor | Score |
|---|---|
| Clear HIPAA/business associate explanation | |
| Minimal data collection | |
| No advertising use of mental health data | |
| Strong encryption/security practices | |
| Easy deletion and account controls | |
| Transparent privacy policy | |
| Therapist credential verification |
A platform with a strong HIPAA posture may still collect more data than a privacy-focused competitor, and a non-HIPAA consumer app may still have good security practices. The key is matching the platform’s privacy model to how sensitive the information is and how much control the user wants over their data.
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires looking past marketing language and examining technical safeguards, legal frameworks, and third-party data sharing. Because many consumer-facing wellness apps fall *outside* of HIPAA jurisdiction, a…
Comparing HIPAA compliance and data privacy practices across mental health apps and teletherapy platforms requires looking past marketing language and examining technical safeguards, legal frameworks, and third-party data sharing. Because many consumer-facing wellness apps fall outside of HIPAA jurisdiction, a structured evaluation framework is essential.
Community Perspectives
Users and digital rights advocates frequently note that consumer mental health tools often fail basic user trust expectations regarding data handling:
“Mozilla's mental health apps investigation returned dismal results, with researchers saying that mental health apps were ‘worse than any other product category’ when it comes to privacy and security.”
“Many other apps were packed with trackers, with the app Cerebral setting a new record for number of trackers: 799 within the first minute of download.”
If you have a specific app or platform in mind , let me know its name. I can help you look into its privacy policy, tracking disclosures, and compliance standing.
The key is **not to treat “HIPAA-compliant” as synonymous with “private.”** HIPAA applies only in particular contexts—typically when a provider is a covered entity or a platform is acting as its business associate. A consumer wellness app may hold highly sensitive mental-health information without being subject to…
The key is not to treat “HIPAA-compliant” as synonymous with “private.” HIPAA applies only in particular contexts—typically when a provider is a covered entity or a platform is acting as its business associate. A consumer wellness app may hold highly sensitive mental-health information without being subject to HIPAA in the same way. HHS explicitly notes that HIPAA generally does not protect information a person voluntarily enters into a non-HIPAA-regulated app, although other laws, including the FTC's Health Breach Notification Rule, may apply.
For each app or teletherapy platform, check these categories:
| What to compare | Questions to ask |
|---|---|
| HIPAA status | Is the company itself a covered entity, a business associate, or neither? Which services are actually covered? |
| BAA | If the platform handles PHI for a therapist/healthcare provider, will it sign a Business Associate Agreement? |
| Data collected | Does it collect therapy notes, diagnoses, messages, recordings, IP addresses, device IDs, location, contacts, or behavioral/usage data? |
| Secondary use | Can data be used for advertising, analytics, product development, AI training, research, or personalization? |
| Third parties | Who receives data—cloud providers, analytics companies, advertisers, insurers, employers, AI vendors, or other affiliates? |
| Tracking technologies | Does the app/site use pixels, SDKs, cookies, or other tracking technologies around health-related activity? |
| Therapy records | Are sessions recorded or transcribed? How long are messages, transcripts, and notes retained? Can they be deleted? |
| Encryption/security | Is data encrypted in transit and at rest? Does the company undergo independent security assessments or maintain certifications such as SOC 2 or ISO 27001? |
| User rights | Can you access, correct, download, or request deletion of your information? What happens after you close your account? |
| Employer/insurer sharing | If you obtain the service through an employer or health plan, what individual-level information can that organization see? |
| Government/legal requests | Under what circumstances can information be disclosed in response to subpoenas, warrants, or other legal processes? |
| Breach history | Has the company experienced breaches, regulatory investigations, or privacy settlements? |
This is especially important with companies that offer both meditation/wellness products and clinical care.
For example, Headspace currently says its U.S. care providers are HIPAA-covered entities and Headspace acts as their business associate. Its separate consumer-health-data policy also addresses information covered by state consumer-health privacy laws.
So instead of asking “Is Headspace HIPAA compliant?”, ask:
“Which Headspace service am I using, who is the healthcare provider, and which of my data is covered by HIPAA?” That's a much more useful question.
Don't stop at a company's HIPAA statement.
The HIPAA notice tells you what happens to PHI within the HIPAA framework. The broader privacy policy may describe other personal information—such as account information, device information, website activity, advertising/analytics data, or inferences—that can be governed by different rules.
Talkspace, for example, distinguishes between its HIPAA Notice of Privacy Practices and its broader Privacy Policy. Its current notice says that, depending on the service arrangement, Talkspace can act as a HIPAA business associate or covered entity.
This is one of the easiest things to overlook.
HHS says that identifiable health information collected through a regulated entity's website or app can constitute PHI, including information transmitted to tracking-technology vendors.
For a consumer app outside HIPAA, however, different rules may apply. The FTC's Health Breach Notification Rule can cover certain health apps that aren't HIPAA-regulated.
Look specifically for language concerning:
A company can have excellent encryption and still retain your information for a very long time.
Ask:
“If I stop using the service today, what happens to my messages, assessments, recordings, transcripts, and account information?”
This can produce substantial differences between providers. For example, Talkspace says its therapy transcripts are treated similarly to medical records and retained for 10 years.
Also determine whether “deletion” means actual deletion or merely removal from the active account while legally required records remain archived.
An employer-sponsored mental-health benefit deserves special scrutiny.
Ask:
“Can my employer or health plan see that I used the service?” and separately:
“Can they see what I discussed with my therapist?” These aren't necessarily the same thing.
Headspace, for example, says its Headspace Care service does not share an individual's activity, signup information, or private data with the health plan, instead providing aggregated/anonymized reports.
Useful security indicators include:
These don't automatically make a service better, but they provide additional evidence about its security program. Headspace, for example, says its security program aligns with HIPAA, HITRUST, SOC 2 Type II, and ISO 27001/27002.
For a personal comparison, you could score each platform 0–2 in six areas:
I'd also give extra weight to secondary data use and third-party sharing. A platform can be technically HIPAA-compliant while its overall privacy practices still aren't what a privacy-conscious user expects.
Finally, read the current policies immediately before signing up. Privacy policies, vendors, AI practices, and legal requirements change. For the regulatory side, HHS's current mobile-health guidance and the FTC's Mobile Health Apps Interactive Tool are particularly useful starting points.
If you want, I can also make a side-by-side 2026 comparison of BetterHelp, Talkspace, Headspace, Calm, and major teletherapy alternatives, focusing specifically on HIPAA status, data sharing, AI use, advertising/tracking, retention, and deletion.
“Can my employer or health plan see that I used the service?” and separately:
“Can they see what I discussed with my therapist?” These aren't necessarily the same thing.
Headspace, for example, says its Headspace Care service does not share an individual's activity, signup information, or private data with the health plan, instead providing aggregated/anonymized reports.
Useful security indicators include:
HHS says that identifiable health information collected through a regulated entity's website or app can constitute PHI, including information transmitted to tracking-technology vendors.