Woman stretching outside, wearing fitbit.

For Healthtech

Understand all your legal privacy requirements, beyond HIPAA

We keep your privacy practices up-to-date with each new regulatory update, so you can take on the future of healthtech.

Privacy Matters

Your approach to user privacy can make or break your business

Healthtech companies are constantly walking a tightrope between groundbreaking innovations and stringent regulations.

Yet, privacy isn't just about avoiding fines. It's the bedrock of customer trust and a catalyst for adoption, and whoever makes it a priority has an opportunity to differentiate.

Is it time to update your privacy policy?

Take our Privacy Quiz
Online tracking technologies: FTC and HHS warn hospitals and providers

The U.S. government is warning telehealth firms about their use of trackers on their websites that may be illegally disclosing customers’ personal health data to third parties. In a letter sent to about 130 hospitals and telehealth providers last year, regulators stated that technologies such as Meta/Facebook pixel and Google Analytics can gather identifiable information about users without their knowledge or ability to opt out. Such trackers could collect data about health conditions, treatments and where a patient is seeking care. The letter also noted that companies not covered by HIPPA still have an obligation to protect health data users disclose on their websites.

Premom App Will be Barred from Sharing Health Data for Advertising

The maker of the free Premom ovulation tracking app now has strict limits on sharing user data, following an FTC complaint that it had deceived users by sharing their personal health information with marketers without notification. The FTC alleged Easy Healthcare’s privacy policy made several false promises regarding how it would share personal data and if users could be identified through that data. Regulators claim the company failed to protect sensitive and private information, such as an individual user’s sexual and reproductive health, and their parental and pregnancy status. Easy Healthcare is now barred from sharing data for advertising, and the firm must collect consent before sharing users’ health information for any other reasons. It is also required to disclose to users how their data will be used.

Cerebral to Pay $7 Million Fine and Limit Health Data Use for Ads Under Federal Order

The FTC has fined Cerebral $7 million and set strict limits for how the healthtech firm may use health data in marketing. Regulators allege the company improperly shared its customers’ personal health information to external parties for advertising. According to the FTC, Cerebral sent medical histories, insurance information and prescription data, among other personal information, to third parties that used the information for ads and analytics. In 2023, Cerebral had self-reported a health data breach that affected more than 3 million users. In what the FTC said is a “first-of-its-kind prohibition,” Cerebral is now banned from using any health information for most advertising purposes, and it must get consent for any instances when it does disclose health information. It was also required to post a notice about this penalty on its website and the steps it is taking to remediate the issue.

The Washington My Health My Data act: not just Washington (or health)

The My Health My Data Act includes extensive new obligations for many companies that may not realize the sweeping scope of the Act applies to them. While the law was originally intended to protect health data not otherwise covered by HIPPA, the new requirements – including multiple consent requests and complex authorizations – go far beyond HIPPA. Depending on how judges interpret the new law, it could cover a broad range of retailers and other companies that handle personal data about health and related topics.

Consumer health information: Handle with (extreme) care

The FTC has recently ordered several disciplinary actions for healthtech firms that do not follow through with the promises they make in their privacy policies. In one case, regulators sued Monument, which provides alcohol treatment services, for sharing customers’ health data with third-party advertisers without user consent. While Monument repeatedly pledged to not share its users’ personal information, the company in fact shared that data with third-party advertisers through secret trackers. Monument was fined $2.5 million, but that penalty was suspended due to the firm’s inability to pay.

Eleven new state privacy laws coming in the next 12 months. Is your policy compliant?

There are 11 new state privacy laws scheduled to go into effect over the next two years, and dozens more currently under consideration by local legislatures. In July, new requirements in Florida, Oregon, and Texas could result in substantial fines for companies that are behind on data collection and consent requirements in those states. While there are similar elements among the new laws, each has unique provisions; for example, Florida’s law will primarily affect large companies, while the laws in Texas and Oregon may also apply to nonprofit groups and small businesses, respectively. Regulatory changes are coming quickly throughout the U.S., and without a thorough understanding of the new laws, your business is vulnerable to legal challenges. Common Sense Privacy closely monitors new legislation and can alert you when your policies fail to meet new requirements.

How we help

Avoid fines & disruption

We help you identify and address new privacy laws designed to protect sensitive health information in the healthtech sector.

Accelerate adoption

Our scorecard helps you answer the toughest privacy questions your customers might have.

Demonstrate trust

The Privacy Seal helps you reassure customers that their sensitive data is in good hands.

Common Sense Privacy DashboardCommon Sense Privacy Dashboard - Identify gaps to relevant laws
Common Sense Privacy DashboardCommon Sense Privacy Dashboard - Follow the best privacy practices for your business
A woman wearing glasses and a white shirt. Common Sense Privacy Seal
FTC warns it will go after edtech companies misusing children’s data

In a policy statement meant to clarify COPPA, the Federal Trade Commission warned ed tech firms not to use students’ data for marketing and other commercial purposes, to eventually delete collected data, and to have adequate security procedures for protecting students’ information. The commission was especially concerned with data collected from low-income students using free apps. This new guidance is meant to include broad consent agreements from schools and districts.

IXL Learning faces class action lawsuit over collecting and uses kids' data

IXL Learning says its subscription-based platform follows federal privacy laws, but a new class-action suit from a group of parents alleges the company collects and uses students’ data without their knowledge or proper consent. The three Kansas families bringing the legal action are co-represented by the EdTech Law Center, a firm focused on the use of personal data in edtech. IXL claims the suit is “based on speculative concerns about educational technology in general” and does not reflect their policies.

FTC levies $6M penalty against Edmodo over child privacy violations

The FTC has proposed a settlement for alleged child privacy and consent violations by Edmodo, which operated a platform for virtual classes. Regulators claim the edtech firm failed in its consent requirements in part by relying inappropriately on the school to get parental consent on using children’s information for commercial purposes. They said schools and teachers “could never be solely responsible for complying” with COPPA.

Eleven new state privacy laws coming in the next 12 months. Is your policy compliant?

There are 11 new state privacy laws scheduled to go into effect over the next two years, and dozens more currently under consideration by local legislatures. In July, new requirements in Florida, Oregon, and Texas could result in substantial fines for companies that are behind on data collection and consent requirements in those states. While there are similar elements among the new laws, each has unique provisions; for example, Florida’s law will primarily affect large companies, while the laws in Texas and Oregon may also apply to nonprofit groups and small businesses, respectively. Regulatory changes are coming quickly throughout the U.S., and without a thorough understanding of the new laws, your business is vulnerable to legal challenges. Common Sense Privacy closely monitors new legislation and can alert you when your policies fail to meet new requirements.

Privacy Matters

The stakes are getting  higher when it comes to   student privacy 

With increasing scrutiny from regulators and rising expectations from parents and teachers, educational apps face significant challenges around compliance.

Privacy protection is a legal requirement, but it can also be a strategic advantage for the best players, fostering trust, recognition, and removing barriers to adoption.

Is it time to update your privacy policy?

Take our Privacy Quiz

The impact we're making

Adeel Khan
Common Sense helped us stand out in an emerging market for educators with a trusted brand, a thorough privacy review and best practice guidance.
Adeel Khan
Founder and CEO of MagicSchool.ai
Joel Hames
We are the leader in engaging and impactful online courses, and Common Sense is the leader in understanding privacy in education. Choosing their software to stay current with fast-changing privacy regulation made sense.
Joel Hames
Chief Product Officer at Subject
Yves Lermusiaux
I wanted to partner with a privacy expert, so I could focus on building my business. Common Sense's software was easy to use, helped us launch faster, and gave us confidence we were doing it right.
Yves Lermusiaux
CEO of WoPa
Lynzi Ziegenhagen
The Common Sense Privacy platform was simple to use for my early-stage startup. It is also robust enough for us to keep the same provider and continue evolving our privacy policy as the product and company grow, with the ease of a fixed annual subscription.
Lynzi Ziegenhagen
Founder of Bandio
Oliver Page
As a cyber security form focused on K12, we need to demonstrate our commitment to the highest privacy standards. Common Sense provided attorney level expertise but with the savings, convenience and access that comes from this type of software.
Oliver Page
Founder of CyberNut
Robert Miller
I am actually an attorney by training. I know HIPAA and COPPA inside and out, but I don't have time to keep up with the latest laws. The FTC is really scrutinizing privacy in health tech and I need expert help from a company I trust.
Robert Miller
Founder of Appa Health

Your trusted privacy partner

Man running outside with his smartwatch on, tracking his run.Move fast and save money with Common Sense PrivacyA woman sitting at a desk with a laptop.Manage your privacy policy effortlessly using Common Sense Privacy.
It’s like having a fractional Chief Privacy Officer
Schedule Your Free Demo

Stay ahead of new
healthtech privacy laws

As healthtech evolves, our dashboard  keeps you ahead of new privacy requirements.

Get immediate expertise, whenever you want it

Get instant, tailored best-in-market guidance, without costly lawyer bills.

Move fast, and
save money

Create a customized policy early, avoid fines, and focus on perfecting your product.

Build trust with
a recognized brand

Your customers know a Common Sense Seal means they can trust you with their data.

FAQs

Can’t find the answer to your question in this list?

How do I update my privacy policy?

Simply sign up online, go through a guided interview with the Wizard, generate your draft.

Do I need any legal background

No, our wizard will walk you through the assessment, you just need to know your business.

Are Common Sense Media and Common Sense Privacy the same?

No, Common Sense Media ia a not for profit that helps families, teachers and schools make content and technology decisions. Common Sense Privacy is a public benefit spinout from Common Sense Media that helps companies stay on top of privacy regulation and build trust with their customers through best privacy practices.

Can you help me with App Store Labels?

Yes, our Wizard generates privacy policies and Google Play store labels

Is Common Sense Privacy a law firm?

No, Common Sense Privacy does not offer legal advice. We offer evaluations based on our general understanding and review of industry standards and practices.

Do I have to pay every time I generate a new privacy policy?

No, we offer an annual subscription price so you can get the advice you need when you need it, without paying again and again.

What's behind your software?

Our models are trained on Common Sense Media's 150 point rubric (developed in partnership with academics, legislators, industry experts and key stakeholders) and Common Sense's proprietary database of 5000+ company and product evaluations.

How do I earn the Common Sense Privacy Seal?

Here are the priciples that guide us when awarding the Common Sense Privacy Seal:

  • being respectful of user data
  • protecting user data
  • disclosing how targeted advertising is used
  • respecting for user anonymity across the web & apps
  • communicating user profiles creation process

If your company follows these principles, then reach out to us to apply for the Privacy Seal.

Easy, affordable, accessible
privacy solutions by Common Sense