Filled with anticipation, a woman in her early 30s downloads a fertility-tracking app. She and her husband are finally ready to start their young family and have a baby. Every morning she logs her cycle, her basal temperature, her symptoms. She grants the app access to her Apple Health data because the onboarding screen says it will improve predictions—of course she takes the opportunity to better plan by having accurate insights on her body and health. The app’s privacy policy, which she does not read because nobody reads those, promises her that personal health information will not be shared with third parties without her consent.
What she does not know—what is effectively hidden from her—is that the app has embedded software tools from advertising companies in its code. Every time she logs her ovulation window or records a missed period, that event is tagged with a descriptive label and transmitted to Google, an analytics firm, and to two companies based overseas. She is not a patient in this transaction—she is a data point. Her hope of becoming a mother is, to someone else’s algorithm, a signal to sell.
This isn’t science fiction. It is, in substance, what the Federal Trade Commission discovered when it investigated the fertility app Premom in 2023. And Premom was not alone. The FTC determined that GoodRx, the prescription-discount platform used by millions of Americans, had been sharing users’ medications and personal health conditions with Facebook and Google for years. It found that BetterHelp, the online therapy service, disclosed the fact that people were receiving mental health counseling to advertising platforms. It found that Cerebral, a telehealth company treating patients for anxiety, depression, and substance use disorders, sent patient names, medical histories, and prescription information to Facebook, Google, and TikTok through invisible tracking tools embedded in its website. More than 3 million people were affected by that breach alone.
And worse, the FTC also barred the data broker X-Mode from selling geolocation data precise enough to identify which Americans were visiting cancer treatment centers and addiction clinics.
In every one of these cases, the people involved believed their information was protected. They were wrong, but not because they were naive. They were wrong because the law told them they were protected—and then failed to make it true.
That failure has a name, though most people have never heard of it: the HIPAA handoff. HIPAA, the federal health-privacy law most Americans vaguely know exists, protects your data inside the clinical system. Your doctor’s office, your insurance company, your hospital. But HIPAA was written in 1996, before smartphones, before apps and before the commercial health-data economy came to be. It covers a specific, narrow list of institutions. It does not cover the fertility app. It does not cover the prescription discount platform. It does not cover the online therapy service. The instant your health data crosses the threshold of a covered institution and enters the commercial world, federal protection vanishes.
In other words, protection attaches to the institution that holds the data, not to the data itself. When the institution’s role ends, whether by a privacy policy’s fine print, a tracking tool’s invisible transfer, or a bankruptcy court’s order, the safeguard does not follow.
Texas, remarkably, already has the instruments to fix this; it instituted them a generation apart. But the state has yet to connect them in a way that would make their safeguards real.
In 2001, the Legislature passed the Texas Medical Records Privacy Act (TMRPA). Tucked inside it was a definition of “covered entity” that, two decades later, appears almost prophetic: any actor that assembles, collects, uses, stores, or transmits protected health information for commercial gain. Not just doctors and insurers. The app developers. The data brokers. The analytics firms. Everyone who profits from a patient’s information. That definition has been Texas law for more than 20 years.
Then in 2023, the Legislature passed the Texas Data Privacy and Security Act (TPDSA), giving Texans enforceable rights to access, correct, delete, and move their personal data. It required affirmative consent before a company could process sensitive information. It voided any contract that tried to waive those rights. In its domain, it is one of the strongest privacy frameworks in the country.
But it assumed that HIPAA adequately covers health data online. It does not.
One statute defines who should be held accountable. The other defines what rights people hold over their data. The statute with the rights lacks the reach. The statute with the reach lacks the rights. Between them sits a gap—the HIPAA handoff—and into that gap has poured every case described above.
The consequences of this gap on ordinary people—on each and every one of us—are manifold. It means the woman tracking her fertility has fewer enforceable privacy rights over her ovulation data than over her online shopping history. It means the man who sought therapy through a telehealth app during the worst year of his life has no guarantee that the fact of his treatment will not appear in an advertising profile. It means the college student who bought a DNA kit out of curiosity about her ancestry now has her genetic blueprint in the hands of a company she never chose, sold to a buyer she will never know, for purposes no one disclosed to her.
It means a parent has no uniform right to view their teenager’s health records through a hospital portal, because the software vendor, not the state, decides who gets access. It means that same teenager, at age 14, has less data protection under Texas law than a 12-year-old, because the TDPSA’s child protections stop at 13 and treat everyone older as an adult consumer.
Texas does not need to build something new to protect these people from these harms. The fix only requires connecting the instruments it already has. Lawmakers should extend the TDPSA’s principles of consent and portability into the health-data context. They should anchor those protections to Texas’ existing broader definition of who bears the obligation. They should make records genuinely portable, so that a patient trying to move their medical history to a new doctor is not told to wait thirty days and pay per page. They should require that consent travels with data past the institutional boundary. They should give patients the ability to see who has accessed their records. And they should give parents a uniform standard for portal access rooted in Texas family law, not a software vendor’s default settings.
The cases brought to light by the FTC were the sounding of the alarm. But the real crisis is quieter: it is the daily, ordinary movement of health information from places where it is protected to places where it is not, from doctors’ offices to patient portals to wellness apps to data brokers, with the person whose body produced that information left holding neither the data nor any say over what becomes of it.
Texas legislators wrote the tools. It is time to use them.