This document has some bullshit example: Identifying users by zipcode and gender? huh?
"Imagine that a covered entity is considering sharing the information in the table to the left in Figure 3. This table is devoid of explicit identifiers, such as personal names and Social Security Numbers. The information in this table is distinguishing, such that each row is unique on the combination of demographics (i.e., Age, ZIP Code, and Gender). Beyond this data, there exists a voter registration data source, which contains personal names, as well as demographics (i.e., Birthdate, ZIP Code, and Gender), which are also distinguishing. Linkage between the records in the tables is possible through the demographics. Notice, however, that the first record in the covered entity’s table is not linked because the patient is not yet old enough to vote."
hmmm, It made me realize that I may be on the verge of breaching the HIPAA laws. I'm developing an app on Google App Engine (which afaict won't sign a BAA), this app will help users with storing and interpreting their data (some of which may be considered health data: like all the biometric data). Anyone knows if I have to comply to HIPAA in spite of not being an health provider myself?