Skip to main content

HIPAA-Aligned Safeguards

Why HIPAA mostly does not apply here, and which law actually gives you rights

4 min readUpdated Sep 3, 2026

The honest version of a question people ask often.

ClapDiet is not covered by HIPAA

HIPAA binds covered entities — health plans, clearing houses, and

providers who bill electronically — and the business associates who handle

health information on their behalf. ClapDiet is a consumer app you sign up for

yourself. It is neither.

That matters more than it might sound, because several things people expect

from HIPAA do not follow from it here:

  • We are not subject to HIPAA's breach-notification rule, which is where
  • the widely quoted 60-day deadline comes from.

  • We have no Business Associate Agreements to show you, because there is no
  • covered entity we are acting for.

  • Your rights over the data you keep here do not come from HIPAA.
  • An earlier version of this article claimed both the BAAs and the 60-day

    deadline. Neither was true, and inherited authority is the worst kind to claim

    on a page about health data.

    Where your rights actually come from

    GDPR, and the equivalent laws that follow its shape. They apply to

    ClapDiet, and the ones that matter most are implemented rather than promised:

    RightWhere it is Access and portabilityDownload your data from Settings > Privacy & Security, whole or per topic. See Exporting Your Data. RectificationEdit anything you recorded, in the app, at any time. ErasureDelete your account and the health record goes with it, in one operation. See Account Deletion. Restriction of processingRemove the conditions, medications or allergies you would rather we did not use — the guidance recomputes without them.

    Which HIPAA-style safeguards are genuinely in place

    HIPAA's Security Rule is a sensible checklist regardless of who it binds. Of

    its technical safeguards, here is the true state:

    SafeguardState Access controlYes — every record is scoped to its owner, and the admin surface is role-gated Audit controlsYes — application audit rows plus database triggers, kept 90 days Transmission securityYes — HTTPS with a one-year strict-transport policy AuthenticationYes — bcrypt password hashing, optional TOTP two-factor, progressive lockout Encryption at restNo. In transit only. Automatic logoffPartial — sessions expire and expired ones are purged nightly, but there is no idle timeout Data Security describes each of these

    in more detail, including the things we deliberately do not claim.

    If a clinician gives you data

    Take it. Bring it. Type it in, or upload the panel. What we cannot do is

    receive it from your provider under an agreement, because that agreement would

    make us a business associate, and we are not set up to be one.

    The traffic runs the other way instead: the Clinician Report prints your

    conditions, medications, allergies, current interactions and recent labs onto

    one page you can hand across a desk. You generate it; nothing is sent anywhere

    on your behalf.

    Questions

    Email privacy@clapdiet.com.


    Note: This article describes how ClapDiet is structured. It is not legal

    advice, and if HIPAA obligations apply to you in your own work, your compliance

    officer is the right reader of that question.

    Related Articles:
  • Data Security
  • Exporting Your Data
  • Tagshipaacompliancehealthcareregulationsmedical
    ClapDiet
    PrivacyTermsContact

    © 2026 ClapDiet. All rights reserved.