Compliance · Updated July 16, 2026

HIPAA-compliant eating disorder apps: what to look for in 2026

The moment an app connects a patient to your practice - meal photos, check-ins, messages - it is handling protected health information. Most consumer food and mood apps were never built for that. Here is what HIPAA compliance actually means for an eating disorder app, and the questions to ask any vendor before a single patient enrolls.

Why consumer trackers don't qualify

A patient using a consumer calorie tracker on their own is outside HIPAA - the law binds covered entities and their business associates, not individuals. The moment your clinic receives that data or directs its collection, you need a tool that operates as a proper business associate: encrypted storage, access controls, audit trails, and a signed BAA. Consumer trackers offer none of that - and for eating disorder care specifically, they add a clinical hazard on top of the compliance one: visible calorie counts, which most ED clinicians consider contraindicated.

The six questions to ask any vendor

Where does patient data live?

Behind clinician login in a secure dashboard, or in a consumer cloud? Ask specifically how meal photos, chat logs, and biometrics are stored and encrypted.

Is there a consent gate before visibility?

A patient’s data should become visible to a clinician only after documented consent. Look for signed waivers that are captured and logged, not a buried checkbox.

How is patient–clinician messaging authorized?

Direct messaging is PHI in motion. Stronger tools require an agreement signed by both parties before messaging unlocks at all.

Can patients revoke and delete?

Revocable consent and account deletion that permanently removes your data are both a privacy baseline and increasingly a patient expectation.

If there’s an AI, is it transparent?

Any AI chat should be disclosed as AI, never impersonate a clinician, surface crisis resources (like 988), and - critically - be reviewable by the care team. A chatbot your patient confides in that you cannot audit is a clinical risk, not a feature.

What is NOT claimed?

Be wary of vague "bank-level security" language. Ask directly about SOC 2, EHR integration, and FDA status - an honest "not yet" is a better sign than evasion.

Special considerations for minors

Eating disorders skew young, so an app serving your program will likely touch minors. Look for a neutral age gate before any personal data is collected, parental consent flows for children under 13 (COPPA territory), and guardian agreement to terms for teens. School and university deployments add another layer: guardian consent handling should be built in, not improvised.

How Pippa approaches this

Since we publish this guide, here is our own answer sheet. Pippa's clinician dashboard is HIPAA-compliant, with patient data behind clinician login. No patient data is visible to a clinician until the patient signs a consent waiver, captured with a signature and photo and logged in the dashboard. Direct messaging unlocks only after a HIPAA agreement is signed by both parties. PippaChat is always disclosed as AI, surfaces the 988 Suicide and Crisis Lifeline on crisis language, and every transcript is reviewable by the connected care team. Patient journals stay on-device, data is encrypted and never sold, consent is revocable, and deletion permanently removes your data. And the honest not-yets: no SOC 2 certification, no EHR integration, no FDA status - the dashboard is a standalone secure web app today.

Choosing between tools? Start with our 2026 guide to the best eating disorder recovery apps for clinicians or see the Pippa vs. Recovery Record comparison.