Patients are increasingly generating their own health data through wearables and apps, transforming how providers engage with them. However, much of this data falls outside HIPAA’s protections, creating legal gaps. With Kentucky’s Consumer Data Protection Act (KCDPA) taking effect in January 2026, these gaps will become even more complex for providers to navigate.
HIPAA only applies to covered entities and their business associates, regulating how they handle protected health information (PHI). But data from consumer health apps and wearables, unless tied to a covered entity, is not considered PHI and falls outside HIPAA’s protections.
That means a patient’s health data could be:
If a patient shares that data with a healthcare provider and it enters the patient’s electronic health record (EHR) or is used to inform diagnosis or treatment, it transforms into PHI and becomes subject to HIPAA. But by then, the information may already have traveled through non-compliant hands.
Even where HIPAA stops, other laws begin. Providers and their vendors must be aware of a patchwork of state privacy and consumer-protection statutes that regulate health-related data collected outside the healthcare setting.
Additionally, many states, including Kentucky, are enacting their own privacy laws that regulate “personal data” or “sensitive data,” terms that often encompass health and biometric information.
From a healthcare perspective, the KCDPA is particularly significant because it extends privacy obligations beyond HIPAA-covered entities. Under the Act, businesses that process personal data of Kentucky residents—meeting certain revenue or volume thresholds—must:
While HIPAA-regulated PHI is exempt, hybrid scenarios can arise where consumer-app data isn’t PHI but still constitutes “personal data” under the KCDPA. Providers integrating such technologies must evaluate whether their vendors qualify as “controllers” or “processors” under the Act—and ensure contracts address these roles.
Proactive alignment with the KCDPA now will position providers to avoid last-minute compliance crises when the law takes effect in 2026. To navigate overlapping privacy laws, Kentucky providers should:
Failing to stay ahead of evolving privacy laws like the KCDPA exposes Kentucky healthcare providers to significant legal and financial risks. These include regulatory investigations by state and federal agencies, fines for noncompliance, breach notification obligations, and potential lawsuits from patients whose data is mishandled. Even if HIPAA doesn’t apply, providers may still be liable under state consumer protection laws or FTC enforcement actions. Furthermore, reputational damage from a data incident involving consumer health apps can erode patient trust and impact clinical relationships. Overlooking these risks is not just a compliance issue, it’s a business and legal liability.
The boundaries of healthcare data privacy are rapidly expanding. HIPAA remains a foundational safeguard, but it was never designed for a world where consumers generate and share vast quantities of health data through commercial technologies. As healthcare continues to merge with consumer technology, compliance vigilance is no longer optional, but is a strategic requirement. Contact a McBrayer Healthcare attorney today to ensure your organization stays ahead of evolving regulations and protects patient trust in this new era of data-driven care.
Services may be performed by others. This article does not constitute legal advice.