HIPAA—passed 22 years ago to improve information security, control costs and reduce administrative burdens—faces daily challenges with increasing cybersecurity attacks and data breaches. But what about personal information that is not covered by this law? A physician can’t tell an advertiser about someone’s diabetes, for example—but what about social media posts, credit card purchases and publicly available information?