UnitedHealthcare · UnitedHealthcare Privacy Policy · View original document ↗

Mobile Device Health, Location, and File Access

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time UnitedHealthcare changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for UnitedHealthcare Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The Policy states that the mobile application may collect health and medical information, financial information, GPS and network-based location data, and user files including calendars, photos, and videos from users' devices, subject to device-level permission grants.

This analysis describes what UnitedHealthcare's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data minimization principles and HIPAA minimum necessary standards where health data is involved.

Consumer impact (what this means for users)

Under this clause, the UnitedHealthcare mobile application may access and collect GPS location, calendars, photos, and videos from users' devices when device-level permissions are granted. Users can withdraw consent to location data collection by disabling location-based features in device settings, though the Policy states this will disable associated navigation and distance functionality.

Cross-platform context

See how other platforms handle Mobile Device Health, Location, and File Access and similar clauses.

Compare across platforms →

Monitoring

UnitedHealthcare has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
In addition to the Information identified above, we may collect the following Information: Information that Identifies You Health, medical, therapy, or financial information; Information created by the Company; Location data such as GPS, Wi-Fi, or carrier network location (see below for more details); and User files stored on your device like calendars, photos, and videos, if you grant permission through your device settings.

Excerpt from UnitedHealthcare's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages HIPAA minimum necessary standards where health and medical information is collected through mobile applications. FTC Act Section 5 authority applies to mobile health application data practices, and the FTC has issued guidance on mobile health app data collection. State biometric privacy laws including Illinois BIPA may be implicated depending on whether photo or video data collected through the application is processed for biometric identification. State location privacy statutes in California and Washington may apply to GPS and network location collection. 2. GOVERNANCE EXPOSURE: Medium. The collection of device files including photos, calendars, and videos through a health insurance mobile application involves sensitive personal data categories beyond core health plan functionality. The conditional permission-based access described in the Policy represents a standard mobile platform disclosure, though the breadth of file types accessible may warrant a data minimization review. 3. JURISDICTION FLAGS: Illinois BIPA creates elevated exposure if facial recognition or biometric processing is applied to photos or videos collected through the application. California location privacy protections and CCPA sensitive data category requirements apply to GPS and precise geolocation data. Washington's My Health MY Data Act may apply to health-related data collected through the mobile application. 4. CONTRACT AND VENDOR IMPLICATIONS: Third-party SDKs or analytics components integrated into the mobile application that access device permissions should be identified and assessed against data minimization and vendor agreement requirements. If location or file data is shared with third-party vendors, BAA and data processing agreement coverage should be confirmed. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a mobile application permissions audit to verify that each device permission requested corresponds to a disclosed and operationally necessary data collection purpose, and assess whether health and location data collection satisfies HIPAA minimum necessary standards and applicable state law requirements.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has issued guidance and taken enforcement action regarding mobile health application data collection practices and data minimization
    File a complaint →
  • Hhs Ocr
    HIPAA minimum necessary standards apply to health and medical information collected through mobile applications operated by HIPAA-covered entities
    File a complaint →

Provision details

Document information
Document
UnitedHealthcare Privacy Policy
Entity
UnitedHealthcare
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074535
Document ID
CA-D-00603
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8fd5e1abe15c4edc31df089ee6f248319a8528f2ca9479e303144fdb83757295
Analysis generated
July 12, 2026 17:38 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: UnitedHealthcare
Document: UnitedHealthcare Privacy Policy
Record ID: CA-P-074535
Captured: 2026-07-12 17:38:39 UTC
SHA-256: 8fd5e1abe15c4edc…
URL: https://conductatlas.com/platform/unitedhealthcare/unitedhealthcare-privacy-policy/provision/CA-P-074535/mobile-device-health-location-and-file-access/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does UnitedHealthcare's Mobile Device Health, Location, and File Access clause do?

This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data …

How does this clause affect you?

Under this clause, the UnitedHealthcare mobile application may access and collect GPS location, calendars, photos, and videos from users' devices when device-level permissions are granted. Users can withdraw consent to location data collection by disabling location-based features in device settings, though the Policy states this will disable associated navigation and distance functionality.

Is ConductAtlas affiliated with UnitedHealthcare?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by UnitedHealthcare.