Privacy Policy Generator for healthcare
Written for health data: Article 9 conditions, HIPAA where it applies, and the wellness gap where it does not.
A health privacy policy has to name the Article 9 condition it relies on, not just the lawful basis - and it has to be honest about whether advertising and analytics technology touches any part of the clinical journey, because that is where enforcement has concentrated.
Health data is special category data under GDPR and UK GDPR, which means an Article 6 basis is not enough on its own - you also need an Article 9 condition, and the ones available to a private business are narrower than most people expect. Explicit consent, health or social care provision, and public health are the usual candidates, and each carries its own conditions.
In the US the position is more confusing, because most consumer health products are not covered by HIPAA at all. HIPAA reaches covered entities and their business associates; a fitness app, a symptom tracker or a wellness marketplace usually falls outside it - and straight into Washington’s My Health My Data Act, which has a private right of action, and into FTC health breach notification rules.
The recurring failure across both regimes is advertising technology. Pixels on appointment booking pages, symptom checkers and patient portals transmit health-adjacent data to ad platforms, and this has produced some of the largest health privacy enforcement actions and class settlements of recent years.
What a privacy policy for a healthcare or health-tech business has to cover
The Article 9 condition and, in the UK, the Schedule 1 condition with its appropriate policy document
Which processing is care, which is administration, and which is marketing - with separate bases
Whether any tracking technology operates on booking, intake or portal pages
Recipients: labs, insurers, device manufacturers, messaging providers, and the agreements with each
Statutory retention schedules for clinical records, stated by record type
How a healthcare or health-tech business actually moves personal data
Intake forms and symptom questionnaires
Health data collected before any clinical relationship exists, often through a web form with the same tracking as the marketing site.
Appointment booking
The fact of booking with a particular specialist is itself health data, which is why booking pages are the highest-risk place to run advertising pixels.
Clinical records and notes
Retained under statutory schedules, accessible only to those with a clinical need, and subject to access requests with clinical exemptions.
Wearables and connected devices
Continuous measurement data, frequently transmitted through a device manufacturer’s cloud before it reaches you.
Insurance and billing
Claims data links diagnosis to identity and moves between multiple organisations, each with its own role.
Research and secondary use
Using clinical data for research or product improvement is a new purpose needing its own basis and usually its own governance.
Third parties the draft will ask you about
practice management systems · Stripe · Twilio for reminders · AWS or Azure with a BAA where required · lab and imaging partners · insurance clearing houses
The rules that apply
GDPR Article 9
Health data needs a condition in addition to a lawful basis, plus in the UK a Schedule 1 condition and often an appropriate policy document.
HIPAA where it applies
Covered entities and business associates: privacy rule, security rule, breach notification, and business associate agreements down the chain.
The consumer health gap
Washington My Health My Data, Nevada’s equivalent, and FTC health breach notification reach products HIPAA does not.
Clinical records retention
Statutory retention schedules for health records are long and specific, and they override ordinary minimisation instincts.
Professional confidentiality
A duty of confidence separate from data protection, enforced through regulators and the courts.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Health data compliance essentials
Identify your Article 9 condition and record it
Plus the UK Schedule 1 condition and appropriate policy document where required.
Remove advertising tags from clinical journeys
Booking, intake, symptom and portal pages. Verify with a scan rather than a policy statement.
Determine your HIPAA status honestly
And if you fall outside it, work out which consumer health statutes apply instead.
Put BAAs or DPAs in place down the chain
Including hosting, messaging and analytics vendors that touch health data.
Apply statutory retention schedules
Clinical records have their own periods that override general minimisation.
Separate care processing from marketing
Different systems where possible, different bases always.
Where this usually goes wrong
Advertising pixels on booking or symptom pages
The specific pattern behind the largest health privacy enforcement and class actions of recent years.
Assuming HIPAA covers you, or that not being covered means no rules
Both are wrong for most consumer health products. The state consumer health laws are the ones that bite.
Relying on consent alone under GDPR
Consent in a care context is often not freely given. Health or social care provision is usually the better condition.
No appropriate policy document in the UK
Several Schedule 1 conditions require one, and its absence invalidates reliance on the condition.
Marketing to patients from clinical records
A different purpose from care, requiring its own basis and usually explicit consent.
Sharing data with a device manufacturer without disclosure
Wearable data usually passes through the manufacturer’s infrastructure before it reaches you.
Frequently asked questions
Is health data different from other personal data?
Yes. Under GDPR and UK GDPR it is special category data requiring an Article 9 condition in addition to a lawful basis, and in the UK often a Schedule 1 condition with an appropriate policy document.
Does HIPAA apply to my health app?
Usually not. HIPAA applies to covered entities and their business associates. Most direct-to-consumer health and wellness products fall outside it - and inside state consumer health laws and FTC breach notification rules instead.
Can I run analytics on a patient booking page?
Not without extreme care. The fact of booking with a particular provider is health data, and transmitting it to an ad platform is the pattern behind the largest enforcement actions in this area.
How long must clinical records be kept?
Statutory schedules apply and vary by record type and jurisdiction, often running to decades. They override the instinct to minimise.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for healthcare
Answer a short questionnaire and get a draft written for a healthcare or health-tech business. Free to start, no card required.
Generate your privacy policyOther documents a healthcare or health-tech business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.