This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision establishes the regulatory framework governing sensitive health information collected through Headspace's mental health services. By designating Care Providers as HIPAA covered entities and Headspace as their business associate, the clause creates specific compliance obligations regarding the collection, use, and disclosure of protected health information under federal health privacy law.
Users of Headspace's mental health services are provided the protections and requirements established under HIPAA, including requirements around the use and disclosure of their health information by Care Providers and Headspace as a business associate. The terms authorize collection of personal information through the products and services that is subject to HIPAA's regulatory framework for covered entities and their business associates.
How other platforms handle this
"By clicking 'Next', you are indicating that you have read and agree to the TERMS OF USE AND PRIVACY POLICY"
We automatically collect certain information from your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Service, we collect information about the individual web pages or products th...
Location data. Data about your device's location, which can be either precise or imprecise. For example, we collect location data using Global Navigation Satellite System (GNSS) (e.g., GPS) and data about nearby cell towers and Wi-Fi hotspots. Location can also be inferred from a device's IP address...
Monitoring
Headspace has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Headspace may deliver coaching services, psychotherapy services (i.e. therapy), and psychiatry services (collectively the 'Services') using the Products or via other delivery methods, as applicable. This Privacy Policy covers the 'personal information,' meaning information about an identified or identifiable individual that is collected through our Product or Services. Our Services are delivered by our Care Providers. For Care Providers in the US, they are classified as covered entities under the Health Insurance Portability and Accountability Act ('HIPAA'). Headspace is subject to HIPAA as our Care Providers' business associate.— Excerpt from Headspace's Headspace Privacy Policy
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The provision establishes the regulatory framework governing sensitive health information collected through Headspace's mental health services. By designating Care Providers as HIPAA covered entities and Headspace as their business associate, the clause creates specific compliance obligations regarding the collection, use, and disclosure of protected health information under federal health privacy law.
Users of Headspace's mental health services are provided the protections and requirements established under HIPAA, including requirements around the use and disclosure of their health information by Care Providers and Headspace as a business associate. The terms authorize collection of personal information through the products and services that is subject to HIPAA's regulatory framework for covered entities and their business …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.