What the law may want from POP
POP is a direct-to-consumer app that collects health conditions, medications, home addresses, children's details and the movements of a family through their week. That combination attracts more regulation than any single part of it would.
This page maps obligations to the screens that trigger them, so a design decision can be weighed against its consequences while it is still a design decision.
This is a structure, not a finished analysis
The research pass behind this page was deliberately cut short. What is here is the shape of the problem — which regimes apply, why they apply, and which screen sets each one off — written from general knowledge rather than from a source-by-source review of current law.
Treat every specific figure, deadline and threshold as unverified. Items marked check are ones where I am least confident, or where the law was actively moving. A full pass should cite primary sources and confirm what is in force today. Not legal advice.
What each screen collects
9 screensExposure rises sharply at screen 06 and does not come down. Everything before it is ordinary personal data; from there on it is health data about identifiable people, including children.
Screen 08 is the one most likely to be underestimated. A week of a named child's locations, with departure times and who accompanies them, is a pattern of life for a minor.
It is more sensitive than any single medical fact on screen 07, and it is the part of the product that looks least like health data.
HIPAA
probably does not apply, and that is the trapHIPAA reaches covered entities — providers, health plans, clearing houses — and the business associates who handle protected health information on their behalf. A consumer app that a family fills in themselves is generally neither, so HIPAA very likely does not apply to POP as it stands.
The trap is reading that as "so health privacy law does not apply". The opposite is closer to true: the regimes that do reach direct-to-consumer health apps have grown specifically to fill this gap, and several are stricter about consent than HIPAA is.
Would change if: POP contracts with a provider, clinic or health plan to handle data on their behalf; or integrates with a provider's records; or handles data flowing out of a covered entity. Any of those can make POP a business associate, at which point a written agreement, the Security Rule and breach rules all land at once.
FTC and health data
the likeliest enforcerHealth Breach Notification Rule check
The FTC has read this rule broadly, and amended it to make clear it covers consumer health apps. Two things matter for a designer. First, "breach" has been interpreted to include unauthorised disclosure, not only a hack — sending health data to an advertising or analytics SDK without proper consent has been treated as a reportable event. Second, notification duties run to individuals, the FTC, and in some cases the media.
Triggered by: screens 06 and 07 — the moment conditions and medications exist in the product. Any third-party SDK in the app is in scope for this analysis.
Section 5, unfair or deceptive practices
The enforcement pattern in this area has been consistent: companies said one thing in a privacy policy or an interface and did another with the data. Cases involving health and prescription data have produced significant penalties and multi-year compliance obligations.
For design specifically, a promise made in the interface counts. If a screen says data is only used to coordinate care, that is a representation, and using it for anything else is the violation.
Triggered by: any reassuring copy. POP's onboarding contains several such lines already, including "Nobody is contacted now" on the carers step.
Children's data
highest exposureCOPPA check
COPPA governs personal information collected from children under 13. POP collects children's names, photographs, birth dates and health conditions — but from a parent, not from the child, and the app is not directed at children.
That distinction genuinely matters and is the most common place this analysis goes wrong in both directions. It is a real argument that classic COPPA verifiable-parental-consent duties are not triggered by a parent entering data about their own child in an adult-facing product. It is not a safe assumption, because the analysis turns on who the service is directed to and how the data is later used, and because the Rule has been amended recently.
Triggered by: screen 07. A child's photo and health conditions are the two most sensitive fields in the product.
Watch: if children are ever given their own login, or if the product markets to families with children as users rather than subjects, the analysis changes completely.
Age-appropriate design codes check
Several states have passed age-appropriate design code laws imposing duties on services likely to be accessed by minors — data protection assessments, high-privacy defaults, limits on profiling. These have been the subject of active constitutional litigation, so their status has been genuinely unsettled and varies by state.
Verify before relying on anything here. This is the fastest-moving area on the page.
State consumer health laws
the ones written for apps like thisWashington My Health My Data check
The most consequential of these for a product like POP, for one reason: it carries a private right of action. Most privacy laws are enforced by an attorney general with limited resources; this one can be enforced by any consumer, which changes the practical risk enormously.
It defines consumer health data broadly enough to capture inferences, not just stated diagnoses — and POP infers a great deal. A routine that puts a named person at a clinic every second Tuesday is health data about that person, even though nobody typed a diagnosis.
- Separate, specific consent to collect, distinct from consent to share
- A dedicated consumer health data privacy policy
- Rights to access and to delete, with the deletion duty running to downstream recipients
- A near-prohibition on selling such data without a signed authorisation
Triggered by: screens 06, 07 and — through inference — 08. Applies to Washington consumers regardless of where the company is.
Nevada, Connecticut and others check
Nevada passed a similar consumer health data law without the private right of action. Connecticut amended its comprehensive law to add consumer health provisions. Other states have followed and more were moving.
The practical consequence for design is that the strictest state sets the bar, because building a different consent flow per state is not realistic in an app this size.
Comprehensive state privacy laws
~20 states, and countingRoughly twenty states had comprehensive privacy laws in force or coming into force, led by California, and the number was still rising. check
They differ in detail but agree on the parts that touch design. Health data is sensitive data in essentially all of them, and sensitive data generally requires opt-in consent rather than a buried notice. Several treat precise geolocation as sensitive too, which POP collects at screens 05 and 08.
- A privacy notice that actually describes what happens
- Opt-in consent for sensitive categories, obtained separately
- Rights to access, correct, delete and port, with a route to exercise them
- Recognition of universal opt-out signals in several states
- Data protection assessments for high-risk processing, which this is
Design consequence: consent has to be a real moment in the flow, not a line under a Continue button. POP's onboarding currently has no consent step at all — worth noting, not because it should be added now, but because there is nowhere obvious to put it later without disrupting the flow.
Photos and biometrics
storage is fine; recognition is notIllinois BIPA is the one with teeth, again because of a private right of action and statutory damages per violation. Texas and Washington have comparable laws enforced by the state.
The distinction that matters: storing a photograph is generally not covered. Deriving a faceprint from it — face detection, matching, clustering, auto-tagging — generally is. POP stores photos and does nothing else with them, which is very likely outside BIPA today.
Would change if: photos are ever used to group people, suggest tags, verify identity, or anything that involves measuring a face. A feature as innocent as "is this the same person?" crosses the line, and it would cross it for children's faces.
Breach notification
all 50 statesEvery state has a breach notification law, and they are not uniform in what counts as covered data, how fast you must notify, or who else has to be told. Many now name health or medical information explicitly, which POP holds for both adults and children.
Layered on top: the FTC rule above, and any contractual duties. A single incident can trigger several regimes with different clocks.
Design consequence: almost none directly — this is an operational obligation. The design decision it argues for is collecting less, since data never collected cannot be breached.
Scheduling paid carers
the next section's problemThe planned shifts feature moves POP from recording a family's week to scheduling other people's labour, and that is a different legal category. Worth knowing before it is designed, not after.
- Employment classification. A platform that schedules, directs and tracks a worker can attract joint-employer arguments. Domestic workers have specific protections in several states, and some have domestic worker bills of rights with written-agreement and rest-break requirements.
- Wage and hour. If POP records hours, those records may become evidence. Live-in and overnight care has notoriously complicated rules about which hours count.
- Care referral licensing. Several states license nurse registries, home care agencies and care referral services. What tips a product from "a tool a family uses" into "a referral service" is a real line, and it varies by state.
- Background checks. If POP ever screens or displays screening results for carers, the FCRA applies, with notice, authorisation and adverse-action duties.
Triggered by: nothing in the current prototype. All of it by the shifts section described on screen 09.
Separated parents
screen 04 asks the questionPOP asks about co-parenting on screen 04 and will act on it. That makes a set of questions unavoidable that most family apps discover late and painfully.
- Which parent may see a child's health information, and does the app's answer match the custody order it has never seen?
- Can one parent see the other's location or schedule, and what happens when a relationship becomes hostile?
- Who can delete a child's record, and what if the parents disagree?
- Do older minors have any say — several states give adolescents rights over specific categories of their own health information, including from their parents.
Design consequence: significant, and it lands on the household screen's cascading effects, which are deliberately not designed yet. The safety dimension here is at least as important as the legal one.
Medical device lines
currently well clearSoftware becomes a regulated medical device when it does things like diagnose, treat, or drive clinical decisions. Recording that someone takes ramipril is record-keeping and is well clear of that line.
Would move toward it if: POP interprets rather than records — flagging interactions between two medications, warning about a missed dose in clinical terms, recommending a change, or scoring anyone's condition. Reminders are generally fine; advice is the boundary.
Also worth noting: 42 CFR Part 2 gives substance use disorder treatment records unusually strong protection. POP does not ask about it, but a free-text conditions field will eventually contain it.
Accessibility
a design obligation, unlike most of this pageWhether the ADA reaches a private mobile app has been litigated inconsistently, but the practical standard the market has settled on is WCAG, and health-adjacent products attract more attention than most. check
This is the one area on this page where the prototype already has a known, measured gap: the brand orange fails contrast for white text at 2.97:1 against a 3.0 requirement, and the orange text token is 4.20:1 against 4.5. The audit reports both on every run.
Already tracked as an open brand decision. Listed here so the reason it matters is written down next to everything else that does.
What is not covered
for the full passKnown omissions, so the next pass starts from a list rather than a blank page:
- No primary sources or citations anywhere on this page
- No state-by-state breakdown; the comprehensive-privacy section treats twenty-odd laws as one
- No penalty figures, notification deadlines or effective dates
- Nothing on international users, which the address search would happily accept
- Nothing on insurance, records retention, or law enforcement requests
- Nothing on the in-app chat and task features planned alongside shifts, which carry their own issues
- No verification that any law described here is still in the form described