The honest version of a question people ask often.
ClapDiet is not covered by HIPAA
HIPAA binds covered entities — health plans, clearing houses, and
providers who bill electronically — and the business associates who handle
health information on their behalf. ClapDiet is a consumer app you sign up for
yourself. It is neither.
That matters more than it might sound, because several things people expect
from HIPAA do not follow from it here:
the widely quoted 60-day deadline comes from.
covered entity we are acting for.
An earlier version of this article claimed both the BAAs and the 60-day
deadline. Neither was true, and inherited authority is the worst kind to claim
on a page about health data.
Where your rights actually come from
GDPR, and the equivalent laws that follow its shape. They apply toClapDiet, and the ones that matter most are implemented rather than promised:
RightWhere it is Access and portabilityDownload your data from Settings > Privacy & Security, whole or per topic. See Exporting Your Data. RectificationEdit anything you recorded, in the app, at any time. ErasureDelete your account and the health record goes with it, in one operation. See Account Deletion. Restriction of processingRemove the conditions, medications or allergies you would rather we did not use — the guidance recomputes without them.Which HIPAA-style safeguards are genuinely in place
HIPAA's Security Rule is a sensible checklist regardless of who it binds. Of
its technical safeguards, here is the true state:
SafeguardState Access controlYes — every record is scoped to its owner, and the admin surface is role-gated Audit controlsYes — application audit rows plus database triggers, kept 90 days Transmission securityYes — HTTPS with a one-year strict-transport policy AuthenticationYes — bcrypt password hashing, optional TOTP two-factor, progressive lockout Encryption at restNo. In transit only. Automatic logoffPartial — sessions expire and expired ones are purged nightly, but there is no idle timeout Data Security describes each of thesein more detail, including the things we deliberately do not claim.
If a clinician gives you data
Take it. Bring it. Type it in, or upload the panel. What we cannot do is
receive it from your provider under an agreement, because that agreement would
make us a business associate, and we are not set up to be one.
The traffic runs the other way instead: the Clinician Report prints your
conditions, medications, allergies, current interactions and recent labs onto
one page you can hand across a desk. You generate it; nothing is sent anywhere
on your behalf.
Questions
Email privacy@clapdiet.com.
Note: This article describes how ClapDiet is structured. It is not legal
advice, and if HIPAA obligations apply to you in your own work, your compliance
officer is the right reader of that question.
Related Articles: