Headspace · Headspace Privacy Policy · View original document ↗

HIPAA Business Associate Status and Clinical Health Data Governance

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Headspace recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Headspace Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When you use Headspace's therapy or psychiatry services, your clinical health information is protected by HIPAA, and Headspace itself is bound by HIPAA rules as a business associate of the treating providers.

This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

HIPAA provides meaningful federal protections for clinical health data, including restrictions on how it can be used and shared, and gives patients specific rights including access, amendment, and accounting of disclosures that go beyond general privacy law.

Clause Stability Stable

0
Changes
3
Months Monitored
May 10, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 3350 other provisions on other platforms.

Change history

modified Jun 24, 2026

Severity downgraded from high to medium and provision expanded with detailed HIPAA coverage explanation and reference to additional Care Provider privacy notices.

View full change record →

Consumer impact (what this means for users)

Users who receive therapy, psychiatry, or clinical coaching through Headspace have their clinical health records protected under HIPAA, which restricts sharing with third parties including advertisers and provides rights to access and correct those records; however, this protection applies specifically to clinical service data and not to general wellness or behavioral data collected through other Headspace features.

How other platforms handle this

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

Calm Medium

With your permission, we may also receive data from your mobile device's health app (like Apple HealthKit or Google Health Connect), including hours of sleep and sleep goals. However, we do not infer any health-related characteristics from this information and only process it consistent with the pur...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

Headspace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Our Services are delivered by our Care Providers. For Care Providers in the US, they are classified as covered entities under the Health Insurance Portability and Accountability Act ("HIPAA"). Headspace is subject to HIPAA as our Care Providers' business associate. Our Care Providers may provide you an additional privacy notice during enrollment which we encourage you to review.

— Excerpt from Headspace's Headspace Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly implicates HIPAA, enforced by the HHS Office for Civil Rights. Headspace's classification as a business associate requires execution of a Business Associate Agreement with each covered Care Provider, compliance with the HIPAA Privacy Rule and Security Rule, and breach notification obligations under the HIPAA Breach Notification Rule. The provision does not detail the scope of the BAA or the specific permitted and required uses of protected health information, which are material compliance details. GOVERNANCE EXPOSURE: High. The business associate relationship creates significant compliance obligations including technical and administrative safeguards, minimum necessary use standards, and breach notification timelines. The policy's acknowledgment of this structure is positive from a transparency standpoint, but compliance teams should verify that BAAs are in place with all relevant Care Providers and that data flows are mapped to distinguish PHI from non-PHI wellness data. JURISDICTION FLAGS: HIPAA applies federally in the United States to covered entities and their business associates. Users outside the US accessing clinical services may be governed by different frameworks (GDPR for EU users). California users may have additional protections under the CMIA (Confidentiality of Medical Information Act). The dual applicability of HIPAA and state medical privacy laws in California creates heightened exposure. CONTRACT AND VENDOR IMPLICATIONS: Any vendor or partner receiving PHI from Headspace must have a valid BAA in place. Procurement teams should verify that downstream technology vendors used in clinical service delivery (telehealth platforms, EHR systems, analytics tools) are covered by appropriate BAAs and that their data practices are consistent with HIPAA minimum necessary standards. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the completeness of BAA coverage across all Care Provider relationships, confirm that PHI data flows are segregated from general consumer data flows, and verify that breach notification procedures meet HIPAA's 60-day notification requirement. The policy's reference to a separate HIPAA Notice of Privacy Practices should be reviewed for consistency with the main policy.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA and has jurisdiction over complaints related to the handling of protected health information by covered entities and their business associates including Headspace
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Headspace Privacy Policy
Entity
Headspace
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009695
Document ID
CA-D-00216
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c1c69938a2255531d9160216a80441cc6e236ee7a78005f747b818b71812b907
Analysis generated
May 8, 2026 10:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Headspace
Document: Headspace Privacy Policy
Record ID: CA-P-009695
Captured: 2026-05-08 10:00:58 UTC
SHA-256: c1c69938a2255531…
URL: https://conductatlas.com/platform/headspace/headspace-privacy-policy/hipaa-business-associate-status-and-clinical-health-data-governance/
Accessed: June 28, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Headspace's HIPAA Business Associate Status and Clinical Health Data Governance clause do?

HIPAA provides meaningful federal protections for clinical health data, including restrictions on how it can be used and shared, and gives patients specific rights including access, amendment, and accounting of disclosures that go beyond general privacy law.

How does this clause affect you?

Users who receive therapy, psychiatry, or clinical coaching through Headspace have their clinical health records protected under HIPAA, which restricts sharing with third parties including advertisers and provides rights to access and correct those records; however, this protection applies specifically to clinical service data and not to general wellness or behavioral data collected through other Headspace features.

Is ConductAtlas affiliated with Headspace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.