Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Policy states that the mobile application may collect health and medical information, financial information, GPS and network-based location data, and user files including calendars, photos, and videos from users' devices, subject to device-level permission grants.
This analysis describes what UnitedHealthcare's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data minimization principles and HIPAA minimum necessary standards where health data is involved.
Under this clause, the UnitedHealthcare mobile application may access and collect GPS location, calendars, photos, and videos from users' devices when device-level permissions are granted. Users can withdraw consent to location data collection by disabling location-based features in device settings, though the Policy states this will disable associated navigation and distance functionality.
Cross-platform context
See how other platforms handle Mobile Device Health, Location, and File Access and similar clauses.
Compare across platforms →Monitoring
UnitedHealthcare has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In addition to the Information identified above, we may collect the following Information: Information that Identifies You Health, medical, therapy, or financial information; Information created by the Company; Location data such as GPS, Wi-Fi, or carrier network location (see below for more details); and User files stored on your device like calendars, photos, and videos, if you grant permission through your device settings.Excerpt from UnitedHealthcare's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages HIPAA minimum necessary standards where health and medical information is collected through mobile applications. FTC Act Section 5 authority applies to mobile health application data practices, and the FTC has issued guidance on mobile health app data collection. State biometric privacy laws including Illinois BIPA may be implicated depending on whether photo or video data collected through the application is processed for biometric identification. State location privacy statutes in California and Washington may apply to GPS and network location collection. 2. GOVERNANCE EXPOSURE: Medium. The collection of device files including photos, calendars, and videos through a health insurance mobile application involves sensitive personal data categories beyond core health plan functionality. The conditional permission-based access described in the Policy represents a standard mobile platform disclosure, though the breadth of file types accessible may warrant a data minimization review. 3. JURISDICTION FLAGS: Illinois BIPA creates elevated exposure if facial recognition or biometric processing is applied to photos or videos collected through the application. California location privacy protections and CCPA sensitive data category requirements apply to GPS and precise geolocation data. Washington's My Health MY Data Act may apply to health-related data collected through the mobile application. 4. CONTRACT AND VENDOR IMPLICATIONS: Third-party SDKs or analytics components integrated into the mobile application that access device permissions should be identified and assessed against data minimization and vendor agreement requirements. If location or file data is shared with third-party vendors, BAA and data processing agreement coverage should be confirmed. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a mobile application permissions audit to verify that each device permission requested corresponds to a disclosed and operationally necessary data collection purpose, and assess whether health and location data collection satisfies HIPAA minimum necessary standards and applicable state law requirements.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data …
Under this clause, the UnitedHealthcare mobile application may access and collect GPS location, calendars, photos, and videos from users' devices when device-level permissions are granted. Users can withdraw consent to location data collection by disabling location-based features in device settings, though the Policy states this will disable associated navigation and distance functionality.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by UnitedHealthcare.