The Veteran Clicked Allow. Who Owns the Next Move?
“Just because I handed you the keys doesn’t mean I gave you the damn truck.”
The Veteran clicked Allow. That authorizes a defined trip—not ownership of the truck, everything inside it, and every place somebody might decide to drive it.
I am not saying Veterans should lock their information in the garage and never let anybody use it. I am saying we ought to know who is driving, where they are going, what they are allowed to carry, and whether they plan to bring the damn truck back.
Permission Is Not a Blank Check
When a Veteran authorizes VA to send health information to an outside application, that permission applies to a specific data flow. It is not permission to sell the information, feed every algorithm in the building, hand it to seventeen “partners,” or bury the explanation on page 46 of a privacy policy written by somebody billing by the syllable.
Once the information arrives outside VA, the protections, responsibilities, and people holding the bag may change. If we are serious about moving Veteran health information responsibly, we need to stop using consent, HIPAA, Business Associate Agreement (BAA), sharing, and integration as though they all mean the same thing.
They do not.
The Better Questions
“Who owns the data?” sounds like one question with one clean answer. Usually, it is not. The useful questions are:
• Who holds the authoritative source record?
• Who currently possesses a copy?
• What exactly did the Veteran authorize?
• Who controls future access?
• Who else can receive the information?
• How long can it be retained?
• Can the Veteran revoke future access?
• What happens to existing copies and derived information?
• Who is accountable if the information is exposed, sold, distorted, or used for something the Veteran never reasonably expected?
Those questions determine whether Veteran control is real or simply a blue button somebody clicked before the fine print swallowed the room.
What Happens When Data Leaves VA
The U.S. Department of Health and Human Services explains that when an individual directs a covered entity to send health information to an application that is neither a HIPAA-covered entity nor a business associate, the information received by that independent application is no longer protected by the HIPAA Rules.
HHS guidance: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access-right-health-apps-apis/index.html
Notice the precision. The copy received by that particular app may no longer be protected by HIPAA. VA’s original record does not suddenly lose its protection, and the outside company has not entered a digital Wild West where anything goes.
Depending on the company, product, data flow, promises made, and location of the Veteran, other obligations may still apply. The Federal Trade Commission’s Health Breach Notification Rule reaches many personal health-record vendors, health applications, connected devices, and related entities that are not covered by HIPAA. The FTC has also clarified that an unauthorized disclosure—not merely a hacker breaking into a database—may qualify as a breach.
FTC rule: https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule
“No longer covered by HIPAA” does not mean “no longer protected by anything.” Companies building a business model around that confusion may learn that the early bird does not always get the worm. Sometimes it gets the subpoena.
A BAA Is Not Holy Water
A Business Associate Agreement matters when a company creates, receives, maintains, or transmits protected health information on behalf of a covered entity. But the letters BAA are not a magic privacy force field.
If a Veteran independently selects an application to receive a copy of their information, that act alone does not automatically make the application a business associate. The same company may even serve in different roles under different arrangements.
Map the function. Do not merely admire the paperwork. A BAA cannot bless a bad data flow.
VA API Access Begins the Accountability Period
VA Lighthouse gives approved applications a pathway to access Veteran-authorized information through VA application programming interfaces (APIs). VA’s production-access requirements prohibit monetizing or selling Veteran data and require companies to explain their business model, requested information, security practices, breach procedures, third-party vendors, and what happens if the company is sold or closed.
VA production-access requirements: https://developer.va.gov/production-access/request-prod-access
That is a meaningful starting point. It is not the end of governance. Someone still has to confirm whether the company does what it promised after the information arrives—who receives it, whether new inferences are created, how long everything is retained, and what revocation actually accomplishes.
Revoking access should stop future collection. It may not automatically erase every copy already received, every permitted backup, or every conclusion derived from the information. Veterans deserve that distinction before they click the button, not after something goes sideways.
What Meaningful Consent Should Explain
A company handling Veteran health information responsibly should be able to answer, in plain English:
1. What specific information are you requesting?
2. Why do you need each category?
3. What will you do with it?
4. Who else will receive it?
5. Will it support advertising, research, model training, product development, or new inferences?
6. How long will you keep it?
7. Can the Veteran download or delete it?
8. What happens when authorization is revoked?
9. What happens if the company is sold or shuts down?
10. Who is accountable if the information is misused?
If the explanation requires a law degree, a flashlight, and a three-day weekend, we have not created meaningful consent. We have created legal camouflage.
The Wrist Is Not the Workflow
A company may receive data legally and protect it appropriately yet still fail to make it clinically useful. Another dashboard, score, alert, or 90-day graph is not clinical integration unless the pathway identifies:
• What produced the information
• Whether it is a measurement, estimate, trend, inference, or proprietary score
• What changed from the Veteran’s normal baseline
• Whether the signal was confirmed appropriately
• Who receives and reviews it
• What threshold prompts action
• What enters the official health record
• Who closes the loop with the Veteran
If nobody owns those steps, we do not have clinical integration. We have data taking a field trip.
Who Owns the Next Move?
The Veteran clicked Allow. Now everybody touching that information needs to explain what they have been allowed to do—and who owns the next move.
For VA, industry, and connected-care teams, the challenge is not simply moving information. It is building a responsible path from the Veteran’s wrist, app, or device to the right person, with the right context, at the right time.
JhetVet helps companies map that path across Veteran need, clinical workflow, data governance, VA market strategy, and execution. If your technology collects or moves Veteran-generated health information, let’s make sure the route ends somewhere useful.
Discuss your VA opportunity: https://www.jhetvetgovcon.com/contact-us
Originally published through Wrist To Clinician™ on LinkedIn: https://www.linkedin.com/pulse/veteran-clicked-allow-who-owns-next-move-wrist-to-clinician--nbrrc/
This article provides general educational information and is not legal advice. Companies should consult qualified counsel regarding their specific products, roles, contracts, and data flows.
Chet J. McLendon, CEO
JhetVet GovCon | Wrist To Clinician™

