Tuly is in development and not yet accepting members or payments. This page explains the framework we are building toward. It is general information, not legal advice — have it reviewed by qualified healthcare-privacy counsel before launch.
HIPAA & Your Health Data
Last updated: September 21, 2026
Women's health is deeply personal, so people reasonably ask whether Tuly is “HIPAA compliant.” The honest answer is more nuanced than a yes or no, and we would rather be clear than reassuring. This page explains where the federal Health Insurance Portability and Accountability Act (HIPAA) actually applies to a service like Tuly, where a different law — the FTC Health Breach Notification Rule — applies instead, and the protections we commit to regardless of which rule governs.
1. What HIPAA is
HIPAA is a U.S. federal law that protects certain health information — called Protected Health Information, or PHI — but it only governs specific organizations. Under HIPAA these are called “covered entities” and “business associates”:
- Covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with billing and claims.
- Business associates — vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity under a written contract.
HIPAA does not regulate every company that touches health data. A consumer app that you choose to use directly — a period or cycle tracker, for example — is generally outside HIPAA unless it is operating for one of the entities above.
2. When HIPAA applies to Tuly
Tuly plans to offer clinician visits and at-home lab testing alongside the app and community. In those specific flows, HIPAA is likely to apply to the data handled by our licensed providers and testing partners — and to Tuly where we act as their business associate. Concretely, we expect HIPAA to govern:
- Information created during a telehealth or clinician visit arranged through Tuly.
- Lab orders, results, and diagnoses handled by a partner laboratory or provider.
- Any prescription or treatment records generated through a covered provider.
Where we handle this information on a provider's or lab's behalf, we will do so under a Business Associate Agreement and apply HIPAA's Privacy and Security Rule safeguards to that data.
3. When it doesn't — and what does
The everyday app and community experience — the cycle data, symptoms, and notes you log for yourself — is information you share directly with Tuly as a consumer service, not with a healthcare provider. For most of that data, HIPAA does not apply.
That does not mean the data is unprotected. Consumer health apps are covered by the FTC Health Breach Notification Rule (16 CFR Part 318), which — following amendments effective July 2024 — explicitly applies to health apps and connected devices that are not regulated by HIPAA. It requires us to notify you, the Federal Trade Commission, and in some cases the media if there is a breach of unsecured, individually identifiable health information, including certain unauthorized disclosures such as those caused by third-party tracking tools. State privacy laws — several of which treat reproductive and sexual-health data as especially sensitive — may also apply. Our Privacy Policy describes how we handle all of this data in practice.
4. Which rule applies when
Broadly, here is how the two frameworks map onto different parts of Tuly:
| Type of data | Primary framework | What it means for you |
|---|---|---|
| Cycle, symptom & wellness data you log in the app | FTC Health Breach Notification Rule + state privacy law | Protected as consumer health data; you must be notified of a qualifying breach. |
| Account, waitlist & community activity | General privacy law & our Privacy Policy | Handled under our published privacy commitments. |
| Clinician visits arranged through Tuly | HIPAA (via the provider) | Treated as PHI with full HIPAA safeguards. |
| Lab orders & test results | HIPAA (via the lab/provider) | Treated as PHI; shared only as permitted or directed by you. |
5. Business Associate Agreements
Where Tuly handles PHI for a covered provider or laboratory, we will enter into a Business Associate Agreement (BAA) with that partner before any PHI is exchanged. A BAA legally requires us to:
- Use and disclose PHI only as the agreement and HIPAA permit.
- Apply administrative, physical, and technical safeguards to protect it.
- Report security incidents and breaches to the partner without unreasonable delay.
- Ensure our own subcontractors agree to equivalent protections.
6. Our safeguards
We apply strong protections to sensitive health data whether or not HIPAA technically requires it. The safeguards we are building toward include:
- Encryption of data in transit (TLS) and at rest.
- Access controls and least-privilege permissions, so staff see only what their role requires.
- Audit logging of access to sensitive records.
- Vendor due diligence and data-processing agreements with our infrastructure providers.
- A policy of not selling your personal health data.
- Data-minimization — collecting only what a feature genuinely needs.
7. Your rights
Depending on which framework applies and where you live, you may have the right to access, correct, export, or delete your information, and to withdraw consent. Where HIPAA applies to records held by a provider, you also have rights of access and amendment under the Privacy Rule. You can exercise the rights we control at any time — see Privacy Policy for how to make a request.
8. Breach notification
If a breach of your unsecured health information occurs, we will notify affected users and the appropriate regulators as required by the framework that applies — the HIPAA Breach Notification Rule for PHI, or the FTC Health Breach Notification Rule for consumer health data — and we will explain what happened and the steps we are taking.
9. Contact us
Questions about how HIPAA or health-data protection applies to Tuly? Reach our privacy team at Info@tulyhealth.com, or write to Tuly Health, 265 Denison Drive, Mount Pleasant, MI 48858.