Health groups push for stricter rules on third-party apps - third-party app rules

A coalition of hospitals, health plans, pharmaceutical companies, and other healthcare stakeholders has urged federal agencies to tighten oversight of third-party apps handling patient health data. In a letter sent to Commerce Secretary Gina Raimondo and HHS Secretary Xavier Becerra on March 24, the Confidentiality Coalition and the Workgroup for Electronic Data Interchange (WEDI) argued that current HIPAA protections fail to cover apps outside traditional healthcare entities.

This letter points to a critical flaw in patient privacy laws. HIPAA only applies to covered entities like hospitals and their business associates, not third-party apps that may access or transmit health data. The groups said they are also concerned that patients will not have adequate information to be educated regarding third-party apps and the risk that their information may not be protected by HIPAA. The Confidentiality Coalition, which includes EHR vendors and medical device manufacturers, also noted that healthcare providers are not legally required to verify app security—though they recognize this “safe harbor” does not address vulnerabilities when data is sent to unregulated platforms.

The industry’s push follows growing reliance on third-party apps for data exchange, often without standardized safeguards. While HIPAA establishes baseline protections, apps developed by tech companies or startups frequently operate beyond its reach. The groups offered several recommendations for the federal government to increase security and protect privacy.

Related: State medical debt gaps raise hospital compliance risks

Regulators have faced similar pressure before. In December 2020, the Centers for Medicare & Medicaid Services (CMS) proposed rules under the 21st Century Cures Act to improve electronic health data exchange. The final rule, released later, required HL7 FHIR-based APIs for data sharing and set a national standard for healthcare operations. However, its focus remained limited to interoperability between providers and payers, excluding third-party apps.

At the 2022 HIMSS conference, CMS Administrator Chaquita Brooks-LaSure admitted the rule’s limitations. She acknowledged that while the framework enhanced data exchange, it did not fully address payer accountability for implementing these standards. Brooks-LaSure also stated that CMS would soon propose further rules to strengthen data-sharing requirements.