Contact Us
Categories
- Data Privacy
- Kentucky Consumer Data Protection Act
- Department of Health and Human Services' Office of Civil Rights
- Medical Residents
- DEI
- Medical Cannabis
- SB 47
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- Medical Spas
- medical billing
- No Surprises Act
- Mandatory vaccination policies
- Workplace health
- Coronavirus Aid, Relief and Economic Security Act
- Code Enforcement
- Department of Labor ("DOL")
- Employment Law
- FFCRA
- CARES Act
- Nursing Home Reform Act
- Acute Care Beds
- Clinical Support
- Coronavirus
- COVID-19
- Emergency Medical Services
- Emergency Preparedness
- Families First Coronavirus Response Act
- Family and Medical Leave Act (“FMLA”)
- KBML
- medication assisted therapy
- SB 150
- Department of Health and Human Services
- Legislative Developments
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Opioid Epidemic
- Sexual Harassment
- Health Resource and Services Administration
- House Bill 333
- Litigation
- Medical Malpractice
- Senate Bill 79
- Locum Tenens
- Physician Prescribing Authority
- Senate Bill 4
- Chronic Pain Management
- HIPAA
- Prescription Drugs
- "Two Midnights Rule"
- 340B Program
- Drug Screening
- EHR Systems
- Electronic Health Records (“EHR")
- Hospice
- ICD-10
- Kentucky minimum wage
- Minimum wage
- Primary Care Physicians ("PCPs")
- Skilled Nursing Facilities (“SNFs”)
- Uncategorized
- Urinalysis
- Accountable Care Organizations (“ACO”)
- Affordable Insurance Exchanges
- Anti-Kickback Statute
- Centers for Medicare & Medicaid Services (“CMS”)
- Certificate of Need ("CON")
- Compliance
- Data Breach
- Department of Health and Human Services (HHS)
- Electronic Protected Health Information (ePHI)
- False Claims Act
- Federally Qualified Health Centers (“FQHCs”)
- Fee for Service
- Fraud
- Health Care Fraud
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- HIPAA Risk Assessment
- HPSA
- KASPER
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Part D
- Pharmacists
- Physician Assistants
- Qui Tam
- Rural Health Centers (“RHCs”)
- Stark Laws
- Telehealth
- Affordable Care Act
- Alternative Payment Models
- American Telemedicine Association (“ATA”)
- Charitable Hospitals
- Criminal Division of the Department of Justice (“DOJ”)
- Health Care Fraud Prevention and Enforcement Action Team (“HEAT”)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HRSA
- Hydrocodone
- Kentucky Board of Nursing
- Kentucky Pharmacists Association
- Limited Services Clinics
- Medicaid
- Medical Staff By-Laws
- Medically Underserved Area ("MUA")
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Qualified Health Care Centers (“FQHC”)
- Rural Health Clinic
- Telemedicine
- Agreed Order
- APRNs
- Chain and Organization System (“PECOS”)
- Douglas v. Independent Living Center of Southern California
- Drug Enforcement Agency ("DEA")
- Hinchy v. Walgreen Co.
- Jimmo v. Sebelius
- Maintenance Standard
- Overpayments
- United States ex. Rel. Kane v. Continuum Health Partners
- Vitas Innovative Hospice Care
- Webinar
- 2014 Medicare Physician Fee Schedule (“PFS”)
- 501(c)(3)
- All-Payer Claims Database ("APCD")
- Appeal
- Centers for Disease Control and Prevention
- Chiropractic services
- Chronic Care Management
- Clinical Laboratory Improvement Amendments of 1988 (“CLIA”)
- Compliance Officer
- Compounding
- CPR
- Dispenser
- Drug Quality and Security Act (“DQSA”)
- Emergency Rooms
- Enrollment
- Essential Health Benefits
- Food and Drug Administratio
- HealthCare.gov
- House Bill 3204
- ICD-9
- Kentucky Senate Bill 7
- Kindred v. Cherolis
- Kynect
- Long-term care communities
- Medicare Part D
- Minors
- Mobile medical applications ("apps")
- National Drug Code ("NDC")
- National Institutes of Health
- New England Compounding Center ("NECC")
- Ophthalmological services
- Outsourcing facility
- Physician Compare website
- Ping v. Beverly Enterprises
- Power of Attorney ("POA")
- Prescriber
- Re-validation
- State Health Plan
- Sustainable Growth Rate (“SGR”)
- Texting
- "Plan of Correction"
- Advanced Practice Registered Nurses
- Affinity Health Plan
- Arbitration
- Audit
- Business Associate Agreements
- Business Associates
- Cadillac tax
- Call Coverage
- Community health needs assessment (“CHNA”)
- Condition of Participation ("CoP")
- Daycare centers
- Decertification
- Denied Claims
- Department of Medicaid Services’ (“DMS”)
- Division of Regulated Child Care
- Doe v. Guthrie Clinic
- EHR vendor
- Employer Group Health Plans
- Employer Mandate
- ERISA
- Fair Labor Standards Act (FLSA)
- False Billings
- Federation of State Medical Boards (“FSMB”)
- Form 4720
- Grace Period
- Group Purchasing Organizations ("GPO")
- Health Professional Shortage Areas (“HPSA”)
- Health Reform
- Home Health Prospective Payment System
- Home Medical Equipment Providers
- Hospitalists
- House Bill 104
- Individual mandate
- Inpatient Care
- Intermediate Sanctions Agreement
- Kentucky Health Benefit Exchange
- Kentucky House Bill 217
- Kentucky Medical Practice Act
- Licensed practical nurses (LPN)
- Licensure Requirements
- List of Excluded Individuals and Entities
- LLC v. Sutter
- Long-Term Care Providers ("LTC")
- Low-utilization payment adjustment ("LUPA")
- Meaningful use incentives
- Medicare Administrative Coordinators
- Medicare Benefit Policy Manual
- Medicare Shared Saving Program (MSSP)
- Model Policy for the Appropriate Use of Social Media and Social Networking in Medical Practice (“Model Policy”)
- Network provider agreement
- Nonprofit hospitals
- Nonroutine medical supplies conversion factor (“NRS”)
- Nurse practitioners (NP)
- Office of the National Coordinator for Health Information Technology (“ONC”)
- Part A
- Part B
- Patient Autonomy
- Patient Privacy
- Payors
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Physician Recruitment
- Physician shortages
- Provider Self Disclosure Protocol
- Qualified Health Plan ("QHP")
- Quality reporting
- Registered nurses (RN)
- Residency Programs
- Self-Disclosure Protocol
- Social Media
- Spousal coverage
- Statement of Deficiency ("SOD")
- Trade Association Group Coverage
- Upcoding
- UPS
- “Superuser”
- Abuse and Waste
- Autism/ASD
- Center for Disease Control
- Compliance Programs
- Consumer Operated and Oriented Plan programs (“CO-OPS”)
- Critical Access Hospitals (“CAHs”)
- Essential Health Benefits (“EHBs”)
- Genetic Information Nondiscrimination Act ("GINA")
- Healthcare Information and Management Systems Society (HIMSS)
- Kentucky Cabinet for Health and Family Services
- Kentucky Health Care Co-Op
- Kentucky Health Cooperative (“KYHC”)
- Kentucky House Bill 159
- Kentucky Primary Care Centers (“PCCs”)
- Managed Care Organizations (“MCOs”)
- Medicare Audit Improvement Act of 2012
- Occupational Safety and Health Administration (“OSHA”)
- Recovery Audit Contractors (“RAC”)
- Senate Bill 39
- Senate Finance Committee Report
- Small Business Health Options Program (“SHOP”)
- State Medicaid Expansion
- Sunshine Act
- Employee Agreement
- Free Conference Committee Report
- Health Care Fraud and Abuse Control Program
- House Bill 1
- House Bill 4
- Kentucky “Pill Mill Bill”
- Pain Management Facilities
- Health Care Law
- Health Insurance
- Healthcare Regulation
McBrayer Blogs
Beyond HIPAA: Legal Risks of Consumer Health Apps and Wearables for Kentucky Healthcare Providers
Patients are increasingly generating their own health data through wearables and apps, transforming how providers engage with them. However, much of this data falls outside HIPAA’s protections, creating legal gaps. With Kentucky’s Consumer Data Protection Act (KCDPA) taking effect in January 2026, these gaps will become even more complex for providers to navigate.
The HIPAA Gap: When “Health Data” Isn’t Protected Health Information
HIPAA only applies to covered entities and their business associates, regulating how they handle protected health information (PHI). But data from consumer health apps and wearables, unless tied to a covered entity, is not considered PHI and falls outside HIPAA’s protections.
That means a patient’s health data could be:
- Collected by a wearable device vendor;
- Stored on a cloud platform owned by a non-covered company; and
- Shared with advertisers, analytics firms, or other partners, all without HIPAA’s restrictions.
If a patient shares that data with a healthcare provider and it enters the patient’s electronic health record (EHR) or is used to inform diagnosis or treatment, it transforms into PHI and becomes subject to HIPAA. But by then, the information may already have traveled through non-compliant hands.
Beyond HIPAA: Other Legal Frameworks at Play
Even where HIPAA stops, other laws begin. Providers and their vendors must be aware of a patchwork of state privacy and consumer-protection statutes that regulate health-related data collected outside the healthcare setting.
The Federal Trade Commission (FTC), for example, has used its authority under Section 5 of the FTC Act to pursue app developers for deceptive or unfair data practices involving health information. The FTC has also begun enforcing the Health Breach Notification Rule, which applies to non-HIPAA entities that handle personal health records.
Additionally, many states, including Kentucky, are enacting their own privacy laws that regulate “personal data” or “sensitive data,” terms that often encompass health and biometric information.
Kentucky’s Upcoming Data-Privacy Law
From a healthcare perspective, the KCDPA is particularly significant because it extends privacy obligations beyond HIPAA-covered entities. Under the Act, businesses that process personal data of Kentucky residents—meeting certain revenue or volume thresholds—must:
- Provide clear privacy notices describing categories of data collected and purposes of processing;
- Offer consumers rights to access, correct, delete, and obtain copies of their personal data;
- Implement reasonable data-security measures; and
- Obtain consent before processing “sensitive data,” which may include health-related information.
While HIPAA-regulated PHI is exempt, hybrid scenarios can arise where consumer-app data isn’t PHI but still constitutes “personal data” under the KCDPA. Providers integrating such technologies must evaluate whether their vendors qualify as “controllers” or “processors” under the Act—and ensure contracts address these roles.
Proactive alignment with the KCDPA now will position providers to avoid last-minute compliance crises when the law takes effect in 2026. To navigate overlapping privacy laws, Kentucky providers should:
- Map data flows to identify where HIPAA or KCDPA applies.
- Review vendor contracts for compliance with both federal and state requirements.
- Update policies and notices to reflect integration of wearable/app data.
- Educate staff and patients on how this data is used and protected.
- Conduct risk assessments that include new technologies.
- Prepare for KCDPA by aligning practices and contracts ahead of 2026.
Compliance Risks
Failing to stay ahead of evolving privacy laws like the KCDPA exposes Kentucky healthcare providers to significant legal and financial risks. These include regulatory investigations by state and federal agencies, fines for noncompliance, breach notification obligations, and potential lawsuits from patients whose data is mishandled. Even if HIPAA doesn’t apply, providers may still be liable under state consumer protection laws or FTC enforcement actions. Furthermore, reputational damage from a data incident involving consumer health apps can erode patient trust and impact clinical relationships. Overlooking these risks is not just a compliance issue, it’s a business and legal liability.
Conclusion
The boundaries of healthcare data privacy are rapidly expanding. HIPAA remains a foundational safeguard, but it was never designed for a world where consumers generate and share vast quantities of health data through commercial technologies. As healthcare continues to merge with consumer technology, compliance vigilance is no longer optional, but is a strategic requirement. Contact a McBrayer Healthcare attorney today to ensure your organization stays ahead of evolving regulations and protects patient trust in this new era of data-driven care.
Valerie Michael is an Associate in McBrayer's Lexington office. Ms. Michael focuses her area of practice on healthcare law, handling a wide variety of matters, such as healthcare professional licensure defense and compliance and regulatory issues. She also handles civil and criminal Medicare and Medicaid fraud cases, facility licensing, and certification. Ms. Michael can be reached at vmichael@mcbrayerfirm.com.
Services may be performed by others. This article does not constitute legal advice.

