guides

Published by Floriva · Updated 2026-04-29 · How Floriva checks its guides

State Health Privacy Laws in 2025: What Protects Your Period Data After HIPAA

The Biden-era HIPAA amendment protecting reproductive health data was vacated in 2025. What remains: a patchwork of state laws. Washington, California, Nevada, and a few others have real protections. Most states don't.

The Biden administration's HIPAA amendment requiring healthcare providers to protect reproductive health data from law enforcement was vacated by a federal court in 2025. What remains: state-level protections, which are uneven. Washington's My Health MY Data Act and California's CPRA provide the strongest protections for reproductive health data collected by non-HIPAA apps. In states without these laws, period app data has no specific legal shield. The federal protection gap is real.

The protection gap for reproductive health data in consumer apps is real, documented, and not fixed by any single federal law. Understanding what protections actually exist, and where they apply, is the starting point for making informed decisions about which apps can safely hold your data.

What HIPAA Actually Covers (And What It Doesn't)

HIPAA is the most commonly cited health privacy law in the US, and it's commonly misunderstood. HIPAA applies only to covered entities: healthcare providers, health plans, and their business associates. It does not apply to:

  • Period tracking apps

  • Fitness apps

  • Wellness platforms

  • Employer wellness programs (unless operating as a health plan)

  • Life insurance companies

  • Most consumer health technology

This gap was intentional: in 1996, when HIPAA was passed, consumer health apps didn't exist. The gap has never been closed at the federal level.

The FTC Act gives the Federal Trade Commission authority over "unfair or deceptive acts or practices," which it has used to take action against health apps that violated their own stated privacy policies (the Flo case). But FTC enforcement is reactive, complaint-driven, and doesn't establish affirmative rights. It punishes deceptive practices rather than prohibiting data collection.

The Biden HIPAA Rule: What It Was, What Happened to It

In response to Dobbs v. Jackson Women's Health Organization (2022), the Biden administration issued a new HIPAA rule in April 2024: the "Support for Reproductive Health Care Privacy" rule. It required HIPAA-covered entities (doctors, hospitals, pharmacies) to:

  1. Decline to disclose reproductive health records to law enforcement for investigations into lawfully obtained care

  2. Update Notice of Privacy Practices

  3. Obtain attestation from requestors that requests aren't for prohibited purposes

This rule would have restricted, for example, a Texas law enforcement request to an OB/GYN in California asking for records about a Texas resident who traveled to California for an abortion.

What happened: In June 2025, the US District Court for the Northern District of Texas vacated the rule, holding that HHS exceeded its statutory authority under HIPAA in restricting law enforcement disclosures. The rule is no longer in effect.

The practical implication: HIPAA-covered entities are no longer specifically prohibited from disclosing reproductive health records to law enforcement by this rule. Other HIPAA provisions still apply (minimum necessary use, limited disclosure for treatment purposes) but the specific reproductive health shield is gone.

What this rule never covered: Period tracking apps. Even if the rule had survived, it applied only to covered entities, not to Flo, Clue, Natural Cycles, or any other consumer app.

State Laws That Actually Apply to Period Apps

Washington: My Health MY Data Act (MHMD)

The strongest protection for period app data in any US state. Enacted in 2023, effective for small businesses in 2024.

Key provisions:

  • Applies to any business (not just healthcare) that collects Washington residents' consumer health data

  • "Consumer health data" is broadly defined to include menstrual health, reproductive health, and data that could identify a person seeking reproductive healthcare

  • Requires affirmative consent before collecting or sharing health data

  • Prohibits selling health data without consent

  • Requires a mechanism for consumers to withdraw consent and delete data

  • Prohibits geofencing within 2,000 feet of healthcare facilities (including reproductive healthcare)

  • Private right of action: Washington residents can sue companies directly, not just through the state AG

If you're a Washington resident, you have the strongest existing legal protections for your period app data.

California: CPRA (California Privacy Rights Act)

California's comprehensive privacy law covers health data under its "sensitive personal information" category. Relevant provisions:

  • Right to limit use and disclosure of sensitive personal information, including health data

  • Opt-out right for sharing for advertising or marketing purposes

  • Right to deletion

  • California AG can bring enforcement actions; private suits are limited to security breaches

California's protections are broad but less specifically targeted to reproductive health data than Washington's MHMD.

Nevada: SB 370 (Consumer Health Data Privacy)

Enacted in 2023. Covers consumer health data including reproductive health. Similar requirements to MHMD: consent for collection, prohibition on selling without consent, deletion rights. Does not include a private right of action (enforcement through state AG only).

Other States With Some Relevant Protections

As of 2025-2026, Connecticut, Colorado, and several others have enacted comprehensive privacy laws that include health data protections, though few are as specifically focused on reproductive health as MHMD.

States Without Meaningful Protections

In states without comprehensive health privacy laws, which includes most US states as of 2025, period app data collected by non-HIPAA entities has no specific legal protection. Law enforcement in those states can issue valid legal requests to app companies; the company has no legal basis to refuse.

What the Gap Means Practically

If a period tracking app is incorporated in Delaware (common for US companies) with servers in Virginia, and you're a user in Texas, the relevant laws are: federal (no HIPAA protection for apps), Delaware (no specific consumer health data law), and possibly Texas. Texas has no comprehensive consumer privacy law with health data protections as of 2025.

A Texas law enforcement request to that company for your cycle records, served on the company's legal team, has a legal basis the company may not be able to refuse.

The only architecture that eliminates this risk: data that doesn't exist on the company's servers is less exposed to company-side legal requests.

What This Means for Floriva Users

The federal protection gap is a design requirement, not just a feature consideration. Period tracking data held in cloud apps has limited legal protection in most US states. Floriva's local-first architecture means there are no servers holding your cycle data, so there is nothing to subpoena. This is a logical consequence of the architecture, not a marketing claim.

Definitions

HIPAA covered entity
An entity subject to HIPAA's Privacy Rule: healthcare providers that transmit health information electronically (hospitals, doctors, pharmacies), health plans (insurance companies, HMOs), and healthcare clearinghouses. Period tracking apps, fitness apps, wellness platforms, and employer health programs are generally not HIPAA covered entities, meaning they are not prohibited by HIPAA from sharing, selling, or disclosing health data they collect. HIPAA's scope has not been updated to include the vast category of consumer health apps.
Private right of action
A legal mechanism allowing individuals to sue companies for violations of a law, without waiting for a government agency to bring enforcement action. Washington's My Health MY Data Act includes a private right of action for health data violations, meaning individuals (not just the state Attorney General) can file civil lawsuits against companies that violate the law. This distinguishes MHMD from laws like California's CPRA, which allows private suits only for security breaches, not for unauthorized data sharing.

Quick answers to the obvious questions.

Does HIPAA protect period app data?

No. HIPAA (Health Insurance Portability and Accountability Act) applies only to covered entities: healthcare providers, health plans, and their business associates. Period tracking apps are not covered entities, so HIPAA does not restrict what they can do with your data. A period app can sell your reproductive health data, share it with law enforcement, or provide it to employers without violating HIPAA.

What happened to the Biden HIPAA reproductive health rule?

In April 2024, the Biden administration issued a HIPAA rule amendment requiring healthcare providers to decline to disclose reproductive health records to law enforcement in states where the care was sought lawfully. In 2025, a federal district court vacated this rule, finding it exceeded HHS's statutory authority. The rule is no longer in effect. HIPAA-covered providers are no longer specifically prohibited from disclosing reproductive health records to law enforcement by this rule.

Which states protect reproductive health data from apps?

Washington's My Health MY Data Act (effective 2023 to 2024) is the strongest state law specifically addressing non-HIPAA health data including reproductive health data. It applies to any business that collects Washington residents' health data, requires consent for collection, prohibits selling without consent, provides a private right of action, and specifically covers geofencing near healthcare facilities. California (CPRA), Nevada (SB 370), Connecticut, Colorado, and several others have relevant but less targeted protections.

What is the My Health MY Data Act?

Washington State's My Health MY Data Act (MHMD) is the most comprehensive state law protecting health data collected by non-HIPAA entities, including period apps. It applies to any business that processes Washington residents' health data, broadly defined. Requirements include: consumer consent for health data collection; prohibition on selling health data without consent; right to access, correct, and delete health data; prohibition on geofencing reproductive healthcare facilities; and a private right of action (individuals can sue, not just the state AG).