Loading...

IoT and HIPAA: What New Jersey's Data Privacy Act Actually Means for Connected Health Devices

Healthcare IoT

Published by IOT New Jersey Research & Editorial Team

IoT and HIPAA: What New Jersey's Data Privacy Act Actually Means for Connected Health Devices

Anyone building or deploying connected health devices in New Jersey has probably heard some version of "HIPAA covers that" as a reflexive compliance answer. It's often wrong, or at least incomplete, and the gap between that assumption and the actual legal landscape has gotten more specific and more important to understand correctly since New Jersey's own comprehensive privacy law took effect. This isn't a general HIPAA explainer. It's specifically about where HIPAA's protections end, where New Jersey's Data Privacy Act picks up, and why that boundary matters enormously for the kind of connected devices increasingly deployed across New Jersey's healthcare and consumer wellness landscape.

The Core Distinction: HIPAA Covers Entities, Not Devices

The most important thing to understand about HIPAA in the context of IoT devices is that it doesn't regulate technology categories it regulates covered entities and their business associates, and the protected health information those entities create, receive, maintain, or transmit. A connected blood pressure cuff used by a hospital as part of a clinical remote monitoring program generates data that's almost certainly protected health information, subject to HIPAA's Privacy and Security Rules. The exact same physical device, sold directly to a consumer and used independently of any healthcare provider relationship, generates data that typically falls entirely outside HIPAA's scope, because there's no covered entity or business associate in the picture at all.

This distinction is the single most consequential thing to understand about connected health device compliance, and it's also the one most frequently misunderstood, including by device manufacturers who assume "health data" and "HIPAA-protected data" are the same category. They're not, and the gap between them is exactly where New Jersey's own privacy law becomes relevant.

Where New Jersey's Data Privacy Act Fits In

The New Jersey Data Privacy Act, which took effect January 15, 2025, is a comprehensive consumer privacy law establishing rights around data access, correction, deletion, and portability, along with opt-out rights for targeted advertising and data sales. Critically for this conversation, the law explicitly exempts protected health information collected by a covered entity or business associate under HIPAA. A January 2026 amendment expanded that exemption further, also covering certain non-PHI data when a covered entity or business associate handles it in accordance with HIPAA's privacy and security requirements though the amendment specifically notes this expanded exemption doesn't extend to data like website analytics or app data that isn't integrated into actual clinical care workflows.

What this means in practice is that data generated by connected devices operating genuinely outside the HIPAA-covered ecosystem consumer wellness wearables, direct-to-consumer health apps, fitness trackers not integrated into a clinical relationship falls squarely under the NJDPA's requirements rather than HIPAA's, and the two laws impose meaningfully different obligations.

Why This Distinction Matters for Connected Device Builders

  • Different consent and access models: HIPAA's minimum necessary standard and authorization requirements differ substantially from the NJDPA's consumer rights framework around access, correction, deletion, and opt-out, meaning a device generating non-PHI data needs a genuinely different compliance approach than one generating clinical PHI.
  • Different breach notification pathways: PHI breaches follow HIPAA's established 60-day notification timeline to individuals, HHS, and in some cases media. Breaches involving non-PHI personal information instead fall under New Jersey's state breach notification framework, which includes a requirement to notify state authorities before individual consumer notice a materially different process that device makers need to plan for separately.
  • No private right of action under the NJDPA: Unlike some other state privacy frameworks, enforcement of the New Jersey Data Privacy Act rests exclusively with the state Attorney General's office through the Division of Consumer Affairs, meaning individual consumers cannot bring their own lawsuits under this specific law, which shapes the practical enforcement risk profile differently than HIPAA violations that intersect with other liability frameworks.
  • Universal opt-out mechanism compliance: As of July 15, 2025, businesses engaged in targeted advertising or data sales under the NJDPA must honor user-selected universal opt-out signals, a requirement with no direct HIPAA equivalent that connected device companies operating consumer-facing wellness products need to build into their platforms.

A Realistic Example: The Fitness Wearable That Isn't Covered by HIPAA

Consider a consumer wearable device sold directly to New Jersey residents, tracking heart rate, sleep patterns, and activity levels, with no integration into any healthcare provider's clinical workflow. Even though this device generates data that looks and feels like health information to any reasonable observer, it isn't protected health information under HIPAA, because there's no covered entity or business associate involved in its collection or use. This data falls under the New Jersey Data Privacy Act instead, meaning the manufacturer needs to honor New Jersey consumers' rights to access, correct, delete, and port their data, respond to verified requests within the law's specified timelines, and, if the company engages in targeted advertising using this data, honor universal opt-out signals.

Now consider the same physical device deployed by a New Jersey hospital as part of a formal remote patient monitoring program integrated into a patient's clinical care. In that context, the data generated is very likely protected health information, subject to HIPAA's Privacy and Security Rules and specifically exempted from the NJDPA. Same device, fundamentally different legal treatment, based entirely on the relationship and workflow context in which the data is collected and used a distinction that device manufacturers building products intended for both consumer and clinical markets need to architect for deliberately, not treat as an afterthought.

Implementation Challenges for Healthcare Organizations and Device Makers

Dual-Use Devices Crossing the PHI Boundary

Devices marketed to both consumers and healthcare providers need clear technical and contractual mechanisms to determine which regulatory framework applies to a given data stream, since the same device model may generate PHI in one deployment context and NJDPA-covered non-PHI in another, requiring genuinely different handling, storage, and disclosure practices depending on context.

New Jersey's Additional Sensitive Category Protections

Beyond the general HIPAA and NJDPA framework, New Jersey maintains specific statutes offering protections beyond HIPAA's baseline for particularly sensitive categories, including the New Jersey Genetic Privacy Act governing genetic testing information and the state's AIDS Assistance Act governing HIV-related information, both of which impose consent and disclosure requirements that can exceed HIPAA's standard protections. Connected devices touching these specific data categories need to account for these additional state-specific requirements regardless of whether the broader NJDPA exemption applies.

Vendor and Business Associate Agreement Clarity

Healthcare organizations working with IoT device vendors need contractual clarity about which data streams are treated as PHI under a business associate agreement versus which fall outside that relationship, since ambiguity here creates genuine compliance risk under both frameworks data mistakenly treated as HIPAA-exempt when it should have been handled as PHI, or vice versa.

Keeping Pace With an Evolving Framework

The January 2026 amendment expanding the NJDPA's HIPAA-based exemptions illustrates that this regulatory landscape is still actively evolving, meaning organizations need ongoing legal review rather than treating their initial compliance analysis as a permanent, static determination.

Practical Compliance Considerations

ScenarioLikely Governing FrameworkKey Consideration
Hospital-deployed remote monitoring device, integrated into clinical workflowHIPAAStandard PHI handling, Privacy and Security Rule compliance, business associate agreements with device vendors
Consumer wellness wearable, no provider integrationNew Jersey Data Privacy ActConsumer rights framework, opt-out mechanisms, state breach notification requirements
Device generating genetic or HIV-related dataHIPAA plus NJ-specific statutesAdditional consent requirements under New Jersey's Genetic Privacy Act or AIDS Assistance Act may exceed HIPAA baseline
App-based health data not integrated into clinical care, even if offered by a covered entityLikely New Jersey Data Privacy ActThe 2026 NJDPA amendment specifically notes this kind of non-clinical data may not qualify for the expanded HIPAA-based exemption

Where This Is Headed

Several trends are likely to shape this regulatory landscape going forward. Continued growth in consumer-facing health and wellness technology that sits outside traditional clinical relationships is likely to keep expanding the practical footprint of the New Jersey Data Privacy Act relative to HIPAA within the broader connected health device space. Ongoing legislative and regulatory refinement, as demonstrated by the January 2026 amendment, suggests the specific boundary between these frameworks will likely continue to be clarified and adjusted rather than remaining static. And as other states continue enacting their own comprehensive privacy laws with varying HIPAA-related exemption structures, device manufacturers and healthcare organizations operating across state lines will likely face growing complexity in maintaining a compliance framework that correctly accounts for New Jersey's specific approach alongside potentially different frameworks in other states where they operate.

For organizations building or deploying connected health devices in New Jersey, the practical priority is straightforward: don't assume "health data" automatically means "HIPAA-protected data." Map each specific device and data flow against the actual relationship and workflow context in which it operates, and build compliance processes that account for the real possibility that the same device may fall under entirely different legal frameworks depending on how and by whom it's deployed.

Frequently asked questions

No, HIPAA applies specifically to protected health information handled by covered entities and their business associates, not to health-related data generally. A consumer device collecting the same type of data, but operating outside any covered entity relationship, typically falls outside HIPAA's scope entirely.

The NJDPA is a comprehensive state consumer privacy law effective since January 15, 2025, that applies to personal data generally, but specifically exempts protected health information handled by HIPAA-covered entities and business associates, along with certain related non-PHI data as expanded by a 2026 amendment.

Related articles

Top