Updated 2 min read

Is your period-tracking app covered by health privacy law?

In the United States, almost certainly not. HIPAA’s Privacy Rule protects health information handled by “covered entities”: healthcare providers, health plans, and clearinghouses. A consumer app you downloaded yourself is none of these. The FemTech apps used by tens of millions of women to track their cycles, hormones, and symptoms operate outside HIPAA’s scope entirely.

That surprises most people, because the data involved is some of the most intimate that exists. The three largest menstrual apps alone have been downloaded more than 250 million times.

What the research actually found

A peer-reviewed scoping review of the 23 most popular women’s mHealth apps found that 20 of them shared data with third parties, and that current practices do not comply with the GDPR. Several major cycle-tracking apps have shared user data with advertisers, and at least one was investigated by regulators for disclosing sensitive reproductive information.

The pattern is structural: the apps that collect the most intimate data about women’s bodies are, as a category, among the least accountable. In Europe the GDPR does apply to these apps, and classifies cycle data among its “special categories”, but the review above shows how far practice lags behind the law.

What to look for in any cycle-tracking app

A different structure is possible

Health Data Safe exists to give cycle data the same governance as medical records: held by the person, on open-source infrastructure, with explicit and revocable consent, under a Swiss non-profit foundation whose statutes treat health data as a common good that is neither bought nor sold. The platform already supports cycle-data file imports for FEMM, Cyclefeminin.net, and Read Your Body.

If you build or run a FemTech product and want consent, audit and compliance machinery you can inherit instead of building alone, see Join as a partner.