Quick answer: Function Health data privacy is governed by HIPAA, meaning your lab results are protected health information under federal law and cannot be sold to third parties without your explicit consent. Your data is stored on encrypted servers, shared only with the ordering physician network that operates under Function’s umbrella, and optionally with any third-party integrations you choose to connect. Function’s privacy policy does permit de-identified, aggregated data use for research, which is standard across nearly every health platform, but individually identifiable results are not sold to advertisers or data brokers.

Is Function Health a HIPAA-Covered Entity?

Data flow diagram showing bloodwork data moving from lab to encrypted database to physician to patient app
Bloodwork data typically flows through several encrypted checkpoints between the lab and the patient’s app. Illustration: Vital Signs Today.

Yes, Function Health operates under HIPAA as a covered entity through its physician network model. When you order labs through Function, the tests are technically ordered by a licensed physician (contracted through Function’s clinical infrastructure), which places the entire transaction inside the HIPAA framework. That matters practically: it means Function is legally prohibited from disclosing your protected health information (PHI) without your authorization, subject to civil and criminal penalties under the Health Information Technology for Economic and Clinical Health (HITECH) Act.

100+ biomarkersEarly signs of 1,000+ conditionsPhysician-reviewed

Wondering who actually sees your bloodwork? See how a HIPAA-protected, physician-reviewed 100+ biomarker panel handles your data. One at-home Superpower draw checks 100+ biomarkers, physician-reviewed.

See my 100+ panel →

$199/year in most states  ·  results in about a week  ·  no doctor referral needed

One nuance worth knowing: direct-to-consumer lab companies that do NOT use a physician-ordered model, such as some wellness apps that rely on device-based measurements alone, can sometimes argue they fall outside HIPAA because no covered entity is involved in the transaction. Function sidesteps that gray zone because every panel flows through an ordering physician, making the HIPAA tie unambiguous.

If you want to understand what biomarkers are actually being ordered and why, the function health 100 biomarkers explained piece walks through the full panel in plain language.

Function Health Data Privacy: Who Sees Your Bloodwork - at-home health test kit
At-home health test kit.

Who Actually Sees Your Function Health Results?

The access chain is narrower than most people assume. Here is who can see your results and under what conditions:

  • You. Results appear in your personal dashboard and app. You control downloads and sharing.
  • The ordering physician. A licensed clinician within Function’s network reviews flagged or critical values. This is not a random contractor, it is a credentialed physician required by lab-ordering law in most states.
  • The CLIA-certified reference lab. Quest Diagnostics processes Function’s draws. Quest, as a covered entity itself, handles your sample under its own HIPAA obligations. The lab sees your sample ID, age, and the tests ordered, not your full profile.
  • Third-party integrations you authorize. Function allows data export to Apple Health, some wearable platforms, and personal health record apps. You initiate and can revoke each connection.
  • Your designated clinicians. You can generate a shareable PDF or grant access to your own doctor. This is voluntary and you control it.

What does NOT see your results: advertisers, your employer, your insurer (unless you specifically submit the results for a claim, which most Function members never do since it is a cash-pay membership), and data brokers.

Does Function Health Sell Your Data?

Function Health does not sell individually identifiable health data to third parties. Their privacy policy, as of 2025 to 2026, explicitly states that PHI is not sold or rented for marketing purposes. This is both a contractual commitment and a HIPAA requirement, so there are two independent layers of protection.

What they do reserve the right to do, like virtually every health platform from Epic to Apple Health, is use de-identified, aggregated data for research, product improvement, and population health analytics. De-identified means your name, date of birth, address, and any other direct identifiers have been stripped using HIPAA’s Safe Harbor or Expert Determination method, leaving only anonymous statistical patterns. A researcher might see “32-year-old male, elevated ferritin, low vitamin D” with no tie to your identity.

Some users conflate this with selling data, but they are legally and practically different. De-identified aggregate analysis is how every lab network, hospital system, and research institution generates medical knowledge. The commercial risk to you is effectively zero because there is no way to re-identify you from those records if the de-identification is done correctly, and HIPAA holds companies liable if they do it wrong.

How Does Function Health Secure Your Data Technically?

Function Health data security relies on a stack common to enterprise healthcare software: encryption at rest (AES-256 is the current standard), encryption in transit (TLS 1.2 or higher for all API calls and web sessions), role-based access controls so that only the staff members who need your data for clinical or support reasons can view it, and audit logging so every access event is tracked.

The platform is hosted on cloud infrastructure with SOC 2 Type II compliance, meaning an independent auditor has verified that the security controls are operating as documented. This is the same certification level used by most electronic health record systems and health-data startups of Function’s size.

A few things Function Health data security does NOT guarantee:

  • Zero breach risk. No system is immune. The question is response protocol and notification speed. HIPAA requires breach notification to affected individuals within 60 days of discovery.
  • Permanent data deletion on cancellation. Check the current privacy policy for retention timelines. Most health platforms retain records for a minimum of several years to comply with state medical records laws, even after you cancel.
  • Immunity from valid legal orders. If a court subpoenas your records, Function is legally required to comply, just as any hospital or lab would be.

You can get a fuller picture of what the membership actually delivers day-to-day in this function health review.

Function Health Data Privacy: Who Sees Your Bloodwork - person using laptop health app
Person using laptop health app.

Function Health Privacy Policy: The Clauses That Matter

Most people skim privacy policies, but a few specific clauses in Function’s policy carry real-world weight:

Clause What It Means for You
Business Associates Vendors who handle your PHI (Quest, cloud host, billing processors) must sign Business Associate Agreements (BAAs) committing them to HIPAA standards. Function is required to have these in place by law.
Marketing Use Function may send you health-related communications, but is prohibited from selling your PHI to third-party marketers. You can opt out of non-clinical emails.
De-identified Data Aggregated, stripped data may be used for research and product development. Not individually traceable to you.
Third-Party Integrations Connecting Apple Health or other apps is your choice and creates a separate data relationship governed by that app’s own privacy policy. Function cannot control how Apple Health handles data once you export it.
Right of Access Under HIPAA, you have the right to request a copy of all PHI Function holds about you, plus a record of disclosures made in the past six years.
Data Retention Records are retained according to applicable state medical records law, typically six to ten years depending on state. Canceling your membership does not immediately delete your records.

If Function’s pricing structure is part of your evaluation, the function health cost breakdown explains exactly what you pay and what is included.

Function Health vs. Superpower: Which Has the Stronger Privacy Posture?

Both Function Health and Superpower operate as HIPAA-covered physician-ordered lab services, so the baseline privacy protection is structurally similar. The differences come down to clinical model and data use philosophy.

name=”Longitudinal Tracking”>

Factor Function Health Superpower
HIPAA Coverage Yes, physician-ordered Yes, physician-reviewed
PHI Sale to Third Parties No No
De-identified Research Use Yes (standard clause) Yes (standard clause)
Doctor Reviews Every Result Physician oversight for flagged values Doctor reviews every result with personalized commentary
Longitudinal Tracking Annual trend data Year-over-year baseline tracking built in
Data Export PDF, Apple Health, selective integrations PDF, selective integrations
Reference Lab Quest Diagnostics Quest Diagnostics

The material practical difference is that Superpower includes a physician who reviews every single result and writes personalized commentary, which means a second clinician’s eyes on your PHI, but also a more robust safety net for results that fall into gray zones. If you value having a doctor’s interpretation attached to your data rather than just a flag when something is out of range, that changes the calculus.

Full comparison details are in this superpower blood test review.

The simplest way to actually get this done

Superpower is a full-body lab membership that runs 100+ biomarkers, has each result reviewed by a doctor, and tracks your numbers year over year (about $199/year). It is what we point readers to when they would rather get one clean, complete draw than chase single tests one at a time. Here is superpower reviewed in full.

What Happens to Your Data If You Cancel Function Health?

Canceling your Function Health membership does not trigger immediate deletion of your health records. This is not a loophole; it is a legal requirement. Most states mandate that medical records be retained for a minimum of six years from the date of service, and some states (California, for instance) require seven years. For patients who were minors at the time of service, records often must be kept until they turn 25 or for a set period after age 18, whichever is longer.

Practically speaking, this means your lab results remain accessible to you through whatever account access the platform provides post-cancellation, and the underlying records are held by the ordering physician’s practice and the reference lab (Quest) on their own retention schedules.

What you should do before canceling: download a complete PDF of all your results. This protects you if the platform shuts down or changes its post-cancellation access policy. It also gives your personal physician a clean historical record without requiring them to submit a medical records request.

If you are comparing the cost side of the equation, the function health cost page and the how much does superpower cost page are the two most useful data points side by side.

Function Health Data Privacy: Who Sees Your Bloodwork - home blood test collection
Home blood test collection.
★ Our top at-home blood test pickOne draw · physician-reviewed
100+
biomarkers
early signs of
1,000+
conditions

Get a Privacy-First 100+ Biomarker Panel

  • One draw at 3,000+ labs including Quest, or at home, results in about a week
  • 100+ biomarkers across heart, hormones, metabolic, liver, kidney and more
  • A physician reviews your report and builds a personalized action plan
Get a physician review →

$199/year · in most states
$199/year in most states  ·  results in about a week  ·  no doctor referral needed

Can Your Employer or Insurance Company See Your Function Health Results?

Access-level chart comparing what the patient, lab, physician, and third-party vendors can see
A schematic view of how access levels typically differ between the patient, the lab, the reviewing physician, and outside vendors. Illustration: Vital Signs Today.

No, not through any direct channel. Because Function Health is a cash-pay membership, your results are never submitted to your health insurer as a claim, which eliminates the most common route through which lab data ends up in an insurance file. Your employer has no legal access to PHI held by a covered entity like Function.

The risk most privacy-conscious users are actually worried about is the Medical Information Bureau (MIB), a database that life and disability insurers use. MIB records are populated from insurance claims, not from direct lab company disclosures. Since Function is cash-pay and never files insurance claims, your results do not feed into MIB through this pathway.

The one scenario where results could theoretically affect insurability: if you voluntarily disclose your Function results on a life insurance application, or if you later submit a claim related to a condition that appeared in your results. That is a decision you make, not something Function initiates.

Talk to a clinician about any results that concern you before making disclosure decisions that could affect coverage.

Red Flags to Watch for in Any Health Data Privacy Policy

Whether you are evaluating Function or any competitor, these four clauses deserve scrutiny before you hand over a blood sample:

  1. “We may share data with our partners.” The word “partners” is deliberately vague. Look for a list of named categories (payment processors, reference labs, BAA-signed vendors) versus an open-ended carve-out that could include advertisers.
  2. “Aggregate or de-identified data.” This is normal and nearly universal. The question is whether the policy defines de-identification using HIPAA’s Safe Harbor method (which removes 18 specific identifiers) or just says “we remove identifying information” without a standard. Vague language here is a yellow flag.
  3. “You consent to receive health-related communications.” Fine if it means clinical follow-ups and appointment reminders. A problem if it means marketing your data to supplement, fitness, or pharma companies.
  4. “This policy may be updated at any time.” True of every platform, but look for whether they commit to notifying you of material changes versus simply posting them to a webpage without notice.

The function health andrew huberman coverage offers context on how Function has marketed its scientific credibility, which is relevant when evaluating whether the company’s stated commitments are likely to be honored over time.

What GINA Adds That HIPAA Does Not Cover

HIPAA gets most of the attention, but for blood testing that touches genetic markers, a second federal law does heavy lifting: the Genetic Information Nondiscrimination Act of 2008 (GINA). This matters for Function Health members because some panels include or border on genetic and genomic data, and people worry specifically about whether an abnormal result could be used against them.

GINA has two independent pieces of muscle. Title I bars health insurers from using your genetic information to decide eligibility, cost, coverage, or benefits, and it prohibits plans from requesting or requiring you to undergo a genetic test for underwriting purposes (National Human Genome Research Institute). Title II, enforced by the Equal Employment Opportunity Commission, prevents employers from requesting, requiring, buying, or acting on your genetic information in hiring, firing, pay, or promotion decisions.

Two limits are worth knowing so you do not over-trust the protection:

  • GINA does not cover life, disability, or long-term care insurance. Those underwriters can, in most states, consider health and genetic information you disclose. This is the same gap discussed above with the life insurance application scenario.
  • GINA’s employment protection does not apply to employers with fewer than 15 employees, and the U.S. military is exempt from parts of it.

The practical takeaway: for the two channels most people fear, your regular health plan and your job, GINA plus HIPAA give you real, enforceable protection. The exposure that remains is voluntary disclosure, which is a decision you control.

Function Health Data Privacy: Who Sees Your Bloodwork - modern medical lab
Instruments inside a modern diagnostic lab.

How to Exercise Your Right of Access Correctly

Your strongest privacy tool is not a setting inside the app; it is a federal right you can invoke in writing. Under HIPAA’s Right of Access, a covered entity must act on your request for a copy of your protected health information no later than 30 calendar days after receiving it, with one possible 30-day extension if they notify you in writing of the reason and the new completion date (U.S. Department of Health and Human Services).

How to use this effectively with a platform like Function:

  1. Submit the request in writing, by email or the platform’s designated channel, and use the phrase “Right of Access request under HIPAA.” Specific language triggers specific obligations.
  2. Ask for the format you want. HIPAA gives you the right to receive records in the electronic form you request if the entity can readily produce it, which for a lab platform usually means a machine-readable file or PDF rather than paper.
  3. Request the accounting of disclosures too. You are entitled to a log of certain disclosures the entity made of your PHI in the prior six years. This tells you where your data actually went.
  4. Watch the fees. A covered entity can charge only a reasonable, cost-based fee for copies. Excessive charges are one of the most common HIPAA Right of Access violations that the HHS Office for Civil Rights has penalized.

Getting a full export on your own timeline, rather than at cancellation under pressure, is the cleanest way to keep control of your longitudinal record.

The Real Threat Model: Where Health Data Actually Leaks

Most privacy anxiety fixates on the wrong villain. The scenario people imagine, a lab company quietly selling your named cholesterol number to an advertiser, is both illegal under HIPAA and commercially pointless. The leaks that actually happen tend to come from mundane, predictable places. Knowing the real threat model helps you spend your caution where it counts.

  • Third-party integrations you turn on. The moment you export results to a wearable app, a fitness platform, or a personal health record, that copy of your data lives under a different privacy policy, and many consumer wellness apps are not HIPAA-covered entities. This is the single most common way lab data escapes a protected environment, and it is entirely under your control.
  • Screenshots and shared PDFs. Once you download a result and text it to a spouse or email it to a coach, HIPAA no longer governs that copy. Human sharing, not corporate malice, is the usual path.
  • Account credentials. A reused password exposed in an unrelated breach can hand someone your dashboard. Unique passwords and two-factor authentication do more for your practical privacy than any clause in a policy.
  • Legal process. As covered above, no health platform is immune to a valid subpoena. This is rare for routine bloodwork but is the one channel that overrides everything else.

Notice the pattern: the highest-probability leaks are downstream of choices you make, not of the platform’s core handling. That is genuinely good news, because it means your privacy is largely in your own hands.

A Practical Privacy Checklist Before You Order Any At-Home Panel

Whether you go with Function, Superpower, or a competitor, run this quick audit before your first draw. It takes ten minutes and closes most of the gaps described above.

  • Confirm the physician-ordered model. If a licensed clinician orders the labs, HIPAA almost certainly applies. If the service is a pure consumer app with no ordering physician, ask directly whether it is a HIPAA-covered entity, because it may not be.
  • Read the de-identification clause. Look for a reference to HIPAA’s Safe Harbor method or Expert Determination. Vague language like “we remove identifying details” without a standard is a yellow flag.
  • Set a strong, unique password and enable two-factor authentication before you upload anything.
  • Decide your integration policy up front. Only connect apps you actually use, and understand that each connection creates a separate data relationship you will need to revoke later if you change your mind.
  • Plan your exit. Know how to download a complete PDF export, and do it periodically rather than only at cancellation.
  • Keep insurance disclosure deliberate. Remember that GINA covers health insurance and employment but not life or disability underwriting, so treat any voluntary disclosure on those applications as a considered decision.

Run these steps once at signup and your data footprint stays small and controllable for the life of the membership.

100+ biomarkersEarly signs of 1,000+ conditionsPhysician-reviewed

Don’t just read about your health, track it.

A single result is a snapshot. Superpower re-tests 100+ markers over time so you can watch them move as you change sleep, food, and training.

Compare with Superpower →

$199/year in most states  ·  results in about a week  ·  no doctor referral needed

FAQ

Is Function Health HIPAA compliant?

Yes. Function Health processes labs through a physician-ordered model, which makes it a covered entity subject to full HIPAA obligations. Your test results are protected health information (PHI) and cannot be sold or shared without your authorization except in limited circumstances defined by the law (treatment, payment, and healthcare operations).

Does Function Health sell my data?

Function Health does not sell individually identifiable health data to third parties. Their privacy policy prohibits selling or renting PHI for marketing purposes, which is also required by HIPAA. They do retain the right to use de-identified, aggregated data for research and product improvement, which is standard across health platforms.

Who sees my Function Health bloodwork results?

You, the ordering physician who reviews flagged values, and the reference lab (Quest Diagnostics) processing the sample. Third-party integrations like Apple Health see only what you authorize, and you can revoke that access at any time. No advertisers, employers, or insurers receive your results through Function’s systems.

How does Function Health store my health data?

Function Health uses encrypted storage (AES-256 at rest, TLS in transit), role-based access controls, and audit logging, hosted on cloud infrastructure with SOC 2 Type II certification. This is comparable to the security stack used by most mid-size electronic health record systems.

Can I delete my Function Health data?

You can request deletion of non-clinical account data (profile information, payment records). Medical records themselves are subject to state retention laws, which typically require keeping them for six to ten years. You have the right under HIPAA to request a copy of all PHI Function holds about you and a log of past disclosures.

Does Function Health share data with Quest Diagnostics?

Yes, Quest processes Function’s blood draws and therefore sees your sample along with the tests ordered. Quest is itself a HIPAA-covered entity and is bound by a Business Associate Agreement with Function, obligating it to handle your PHI under HIPAA standards. Quest does not receive your full profile or membership data, only the clinical information needed to run the ordered tests.

Will my Function Health results affect my health insurance?

Not directly. Function is cash-pay and never submits claims to your insurer, so results do not appear in insurance databases through Function’s systems. If you voluntarily disclose Function results on a life or disability insurance application, that is a separate decision with its own implications, but that is true of any health information you choose to share.

How does Function Health’s privacy policy compare to a regular doctor’s office?

The privacy protections are structurally the same because HIPAA applies to both. The practical difference is that a traditional doctor’s office operates within a network that may share records across providers via health information exchanges (HIEs) for continuity of care, whereas Function’s data stays within a more controlled ecosystem unless you specifically export or share it. For people who prefer compartmentalized health data, that narrower sharing footprint is an actual advantage.

Can law enforcement access my Function Health records?

Like any HIPAA-covered entity, Function must comply with valid court orders, subpoenas, or law enforcement requests that meet the specific legal standards defined in HIPAA’s law enforcement disclosure rules. This applies to every hospital, lab, and health platform. There is no category of health data storage that is immune to lawful legal process.

Is Superpower safer for privacy than Function Health?

Both operate under the same HIPAA framework and neither sells individually identifiable data. The substantive difference is that Superpower’s model involves a physician reviewing every result with personalized notes, which means an additional clinician accesses your data but also provides a medically-reviewed interpretation. Neither platform offers meaningfully stronger privacy protection than the other at the infrastructure level.

Vital Signs Today may earn a commission if you buy through links on this page. It does not affect our editorial assessments.