What HIPAA does not tell you about data trust
Photo by Markus Winkler on Unsplash
insight

What HIPAA does not tell you about data trust

By Jason Alan Snyder·April 24, 2026

HIPAA protects against unauthorized disclosure of health information, but it says nothing about whether that data is accurate, current, or trustworthy. The gap between HIPAA compliance and actual data trust is where health AI fails, clinical decisions go wrong, and patients lose confidence in the system.

HIPAA is a privacy law. It is not a data trust law. That distinction matters more now than it ever has, because organizations across healthcare are building AI models, deploying clinical decision tools, and sharing records across networks on the assumption that HIPAA-compliant data is trustworthy data. It is not.

HIPAA tells you who can see health information and under what conditions. It does not tell you whether that information is accurate, current, complete, or collected with meaningful consent. Those are the dimensions of data trust, and HIPAA was never designed to address them.

What HIPAA actually covers

HIPAA is built on five main rules. The Privacy Rule governs who can access protected health information (PHI). The Security Rule requires administrative, physical, and technical safeguards for electronic PHI. The Breach Notification Rule mandates disclosure when PHI is compromised. The Enforcement Rule establishes penalties. The Omnibus Rule, finalized in 2013, expanded compliance requirements to include business associates and their subcontractors.

These rules set a floor for data protection. They do not set a standard for data quality.

What cannot be disclosed under HIPAA

HIPAA restricts the disclosure of 18 categories of identifiers, including names, dates, Social Security numbers, medical record numbers, device identifiers, biometric data, and full-face photographs. Even if a patient has publicly shared health details, a covered entity generally cannot confirm or disclose them without authorization.

Three recognized exceptions allow disclosure without patient consent: when required by law (such as mandatory disease reporting), for public health activities, and when necessary to prevent a serious and imminent threat to health or safety. These exceptions are narrow. They do not extend to data sharing for model training, analytics, or commercial purposes.

What are the four types of privacy

Privacy scholars identify four types: informational privacy (control over personal data), physical privacy (freedom from intrusion), decisional privacy (autonomy in personal choices), and dispositional privacy (control over how others perceive you). HIPAA addresses only informational privacy, and only within the context of covered entities and business associates. It does not address how health data is scored, weighted, or used to make inferences about patients.

The trust gap HIPAA leaves open

Consider what HIPAA does not require. It does not require that a health record be current. A provider directory entry can be HIPAA-compliant and three years out of date. It does not require that data be validated against a primary source. A lab result can be HIPAA-compliant and transcribed incorrectly. It does not require that consent be granular. A patient can sign a single authorization that covers uses they never anticipated, including AI model training.

The 23andMe bankruptcy, covered extensively by MedPage Today in April 2025, illustrates this gap precisely. Millions of genetic data records were collected under HIPAA-adjacent privacy frameworks. When the company entered bankruptcy proceedings, questions about who would control that data had no satisfying answers. The privacy policies were technically compliant. The trust was not there.

BetterHelp paid a $7.8 million FTC settlement in 2023 for sharing user health data with advertising platforms. The company operated in a gray zone where HIPAA's reach was limited. Privacy was violated not because HIPAA was broken, but because HIPAA was insufficient.

Key statistics

Data Trust Index: 8 dimensions HIPAA does not measure
Data Trust Index: 8 dimensions HIPAA does not measure

These numbers define the distance between compliance and trust:

  • HIPAA covers 18 categories of identifiers but zero dimensions of data quality, recency, or provenance.
  • The SuperTruth Data Trust Index scores records across 8 dimensions, weighted from Provenance (25%) to Stability (5%), none of which HIPAA addresses.
  • In the imaware case study, SuperTruth standardized 105,000 diagnostic records, reducing processing time by 95%, from 3 weeks to 2 hours.
  • BetterHelp's privacy violation resulted in a $7.8 million FTC settlement, exposing gaps HIPAA could not close.
  • The 2013 Omnibus Rule expanded HIPAA to business associates, but an estimated 70% of health data now flows through entities that fall outside traditional covered entity definitions, including app developers, AI vendors, and wearable manufacturers.
  • What data trust actually requires

    imaware diagnostic record processing: before vs. after DTI
    %22%2C%22titleFontSize%22%3A12%2C%22bodyFontSize%22%3A11%2C%22xPadding%22%3A10%2C%22yPadding%22%3A10%7D%7D%7D) imaware diagnostic record processing: before vs. after DTI

    Data trust is not a policy. It is a measurable condition. At SuperTruth, we built the Data Trust Index to score every health data record from 0 to 100 across eight dimensions: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%).

    Think of it as a FICO score for health data. A record can be HIPAA-compliant and score a 30 on the DTI because it lacks provenance documentation, has stale timestamps, or was collected under a consent framework that did not anticipate its current use.

    This is not hypothetical. When we worked with imaware on 105,000 diagnostic records, we found records that met every HIPAA requirement but failed on recency, concordance, and validation. The lab industry had no trust standard. The DTI created one. As imaware CEO Brodie Flanders put it: "The lab industry has never had a trust standard. DTI created one."

    Why this matters now

    The FDA is moving toward auditing AI training data. CMS is tightening requirements on provider directories and member communications, including cracking down on Medicare Advantage ads appearing in patient portals. NCQA credentialing standards for 2025-2026 demand data accuracy beyond what HIPAA alone can verify.

    Every one of these regulatory vectors points in the same direction: compliance is necessary but not sufficient. The question regulators, payers, and patients are asking is not "Is this data protected?" but "Is this data true?"

    HIPAA cannot answer that question. The Data Trust Index can.

    What you should do next

    If your organization treats HIPAA compliance as the ceiling for data governance rather than the floor, your AI models, clinical tools, and reporting infrastructure are built on data you cannot fully trust. Contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140 to learn how the DTI Engine scores your data before any model touches it.

    Further reading:

  • DTI Engine
  • Health systems solution
  • The HIPAA problem health AI companies are ignoring: patient consent does not cover model training
  • Why consent governance fails in healthcare data and what fixes it
  • The eight dimensions of health data trust: a practical guide
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    DTI scores the record, not the patient.

    8 dimensions. 0–100. Travels with every record permanently.

    See the DTI Engine
    Share