Therapy data is the most aggressively policed corner of digital-health privacy. Mental-health records fetch up to each on the dark web, and the FTC built its modern health-privacy program almost entirely on mental-health cases. If you built a teletherapy portal, intake form, or AI chatbot with Lovable, Bolt, or Replit, none of them sign a HIPAA Business Associate Agreement.
Free Mental Health App Scan → Talk to UsFrom teletherapy portals to AI "supportive chat" features, here is where AI-built mental-health apps create the sharpest legal and ethical exposure in digital health.
Mental-health records fetch up to roughly each on dark-web markets, versus – for standard medical records. Confidant Health's 2024 exposure leaked 5.3 TB including psychotherapy intake notes, trauma histories, and audio/video of actual sessions. A breach here doesn't just leak data — it leaks a client's inner life, and it is unrecoverable.
The FTC's three signature mental-health cases — BetterHelp (.8M), Cerebral (M), and Monument (.5M) — all involved routine marketing tech: Meta, TikTok, and LinkedIn pixels sending intake answers and event names like "Paid: Weekly Therapy" to ad platforms. Any AI-built site with default analytics or retargeting scripts is one crawl away from the same charge.
Illinois now bans AI from delivering therapy outright ( per violation). Utah requires chatbot disclosure and bans ad-targeting on chatbot inputs ( per violation). The FTC opened a 6(b) inquiry into AI companion chatbots in September 2025, and Character.AI and Google settled wrongful-death lawsuits in January 2026. A vibe-coded "supportive chat" feature with no crisis-escalation logic carries both regulatory and liability exposure at once.
Non-HIPAA mood trackers, journaling apps, and coaching tools still sit under the FTC's Health Breach Notification Rule, where any unauthorized disclosure — including an ad pixel — counts as a reportable "breach" at up to per violation. Washington's My Health My Data Act adds a private right of action already used against a health-adjacent app in 2025.
88% of psychologists now practice remote or hybrid. AI-generated codebases have been found storing call recordings in unencrypted, public cloud storage with no audit logging — a direct HIPAA Security Rule failure that OCR is actively fining under its Risk Analysis Initiative.
Apps supporting substance-use-disorder treatment trigger 42 CFR Part 2 on top of HIPAA, with enforcement live since February 2026. This was the exact regime Monument's .5 million FTC penalty sat alongside, after it disclosed user data to Meta and Google.
| What you built | Hidden risk |
|---|---|
| Teletherapy portal / video sessions | Recordings/transcripts in unencrypted or public storage; no host signs a BAA |
| Intake / screening form (PHQ-9, GAD-7, "get matched") | Answers routed to ad pixels — the exact pattern behind BetterHelp's .8M fine |
| Mood tracker / journaling app | Assumed "not HIPAA so fine" — still covered by the FTC Health Breach Notification Rule |
| Appointment booking | The fact of booking with a therapist is regulated "consumer health data" in Washington |
| Client portal / progress notes | Missing row-level security on the backend database exposes every client's notes |
| AI chatbot / "AI therapist" feature | State bans, chatbot disclosure statutes, and wrongful-death liability |
| Regulation | Triggers when… | Penalty |
|---|---|---|
| HIPAA | Practice transmits health info electronically; psychotherapy notes need separate authorization | up to /yr per category |
| FTC Act §5 | Any wellness/teletherapy app breaks its own privacy promises, even without HIPAA | BetterHelp .8M; Cerebral M |
| FTC Health Breach Notification Rule | Non-HIPAA personal-health-record apps; unauthorized disclosure (an ad pixel) counts as a breach | Up to /violation/day |
| Washington My Health My Data Act | Collecting WA residents' "consumer health data," explicitly including mental-health status | Up to /violation + private right of action |
| 42 CFR Part 2 | Federally assisted substance-use-disorder programs | Civil –/violation; criminal to + 10 yrs |
| Illinois WOPR Act | AI making therapeutic decisions or delivering therapy to Illinois users | Up to /violation |
| Utah Mental Health Chatbot Act | Any "mental health chatbot" reachable by Utah users | Up to /violation |
No major AI app builder signs a HIPAA Business Associate Agreement. If your app stores session notes, recordings, or client PHI, you need a BAA-backed host and a security review before real clients use it — regardless of which tool wrote the code.
Yes, if you run a mood tracker, journaling app, or wellness tool that isn't HIPAA-covered. The rule treats any unauthorized disclosure, including data sent to an ad pixel, as a reportable breach, with penalties up to per violation per day.
Only with real guardrails. Illinois bans AI from delivering therapy outright. Utah requires disclosure and bans ad-targeting on chatbot inputs. Any chatbot needs reviewed crisis-escalation logic and, in most states, a licensed professional in the loop for anything resembling treatment.
Both were fined by the FTC for sending intake answers and user data to Facebook, Snapchat, TikTok, and LinkedIn through standard marketing pixels — BetterHelp paid .8M, Cerebral paid M. Any AI-built site with default analytics scripts can recreate this exact violation.
If you collect data from Washington residents, likely yes. The law explicitly covers "past, present, or future mental health status," including the mere fact someone booked an appointment, and it carries a private right of action already used in a 2025 lawsuit.
We check whether your host will sign a BAA, whether analytics or ad pixels touch intake or booking pages, database access controls on client records, encryption on session recordings, and chatbot safety guardrails. You get a plain-English report with fixes ranked by risk.
Get a free, no-obligation scan of your mental-health app — HIPAA exposure, ad-tech leaks, and chatbot risk, in plain English.
Start With a Free Scan →