The Hidden HIPAA Risk in Life360 and Cozi (and What It Could Cost Your Program)

The Hidden HIPAA Risk in Life360 and Cozi (and What It Could Cost Your Program)

Sober living and treatment operators lean on Life360 and Cozi because they are free and familiar. Here is why putting resident data in them can put your license and your budget on the line.

If you run a sober living home or a treatment program, there’s a good chance your house already runs on apps that were never built for it. Life360 tells you where residents are. Cozi handles the shared calendar and the chore chart. Both are free, both are easy, and both are quietly turning your operation into a compliance problem.

The apps aren’t the ones on the hook. You are.

The part most operators miss

HIPAA doesn’t care that Life360 is “just for safety.” or Cozi is “just a calendar”. It cares about what you put in them.

The moment resident information ties back to their care, it can become protected health information (PHI):

  • A recurring calendar entry for a resident’s IOP sessions or medication times
  • A chore rotation that doubles as a treatment or accountability record
  • A note that someone relapsed, left AMA, or is on a specific medication
  • A resident’s real-time location tracked as a condition of their program

For substance use records, the bar is even higher. Federal rule 42 CFR Part 2 protects SUD treatment records with consent requirements that are stricter than HIPAA on its own. Location and attendance data that reveals someone is in addiction treatment sits squarely inside that protection.

Here’s the rule that trips people up: any vendor that creates, receives, stores, or transmits PHI on your behalf has to sign a Business Associate Agreement (BAA). No BAA, no compliant use. Consumer apps do not sign BAAs. That’s the whole ballgame.

Why Cozi fails

Cozi is a consumer family organizer. It’s genuinely good at that. It is not built to be part of a healthcare operation, and it shows:

  1. No BAA. Cozi will not sign one. Full stop. That alone makes it non-compliant the second real PHI lands in it.
  2. Consumer data collection. Cozi collects and processes personal information under a standard consumer privacy policy, not a healthcare one. You have no control over how that data is used or retained.
  3. No role-based access. Everyone on the account sees everything. There’s no clinician-only view, no separation between staff and residents, no way to limit who sees what.
  4. No audit trail. If a regulator or an attorney asks who viewed a resident’s information and when, you have no answer. HIPAA expects you to have one.

Why Life360 is worse

Cozi is the wrong tool. Life360 is the wrong tool that also sells the data.

Life360 is a family location app, and its whole business model has leaned on the movement data of its users. A 2021 investigation by The Markup reported that Life360 was selling precise location data on tens of millions of users to roughly a dozen data brokers. After the reporting, the company said it would scale back, but it still shares location and movement data with partners, and that sharing is switched on by default with an opt-out buried in settings.

Now apply that to your house. When a resident’s location is tracked as part of a treatment program, that location is health information. Feeding it into an app with a documented history of monetizing exactly that kind of data is close to a worst case:

  • No BAA, same as Cozi.
  • Location as PHI. Where a person in treatment is, and where they aren’t, can reveal their care status. That’s protected.
  • Third-party sharing by default. You cannot promise a resident their data is private when the app’s default behavior is to share it.
  • 42 CFR Part 2 exposure. Selling or sharing data that identifies someone as being in SUD treatment is exactly what Part 2 exists to prevent.

What this actually costs you

This is the part that’s easy to ignore until it isn’t.

  • Penalties are tiered and steep. HIPAA fines scale with how negligent the violation was, and they can climb past a million dollars per violation category in a single year. A single breach involving multiple residents can stack fast.
  • Breach notification is public. Larger breaches get reported to HHS and, in many cases, to the media. For a program that runs on trust and referrals, that’s a reputation you don’t get back cheaply.
  • Your license and your contracts are at risk. Licensing bodies, county partners, and payers increasingly expect documented compliance. One incident can cost you a referral relationship or a funding stream you spent years building.
  • Residents lose trust. People come to you at their most vulnerable. Handing their recovery data to apps that broker it undercuts the entire point of what you do.

The apps are free. The exposure is not.

What to do instead

You don’t fix this by being more careful inside Cozi and Life360. There’s no careful way to use a tool that won’t sign a BAA and shares data by default. You fix it by moving resident information into a system built for it.

That means a platform that:

  1. Signs a BAA with you, so the vendor is legally on the hook for protecting PHI alongside you.
  2. Separates access by role, so clinicians, house managers, and residents each see only what they should.
  3. Logs everything, so you can answer the “who saw what, and when” question instantly.
  4. Handles scheduling, chores, and resident tracking in one compliant place, so you’re not stitching together consumer apps and hoping.

That’s exactly why we built Roomi: scheduling, chores, resident management, and records for sober living, treatment, and behavioral health, with HIPAA baked in and a BAA on the table from day one.

If your program is running on Life360 and Cozi today, the safest assumption is that you already have PHI sitting in places it shouldn’t be. The good news is that this is fixable, and it’s a lot cheaper to fix now than to explain later.

Talk to us about moving your house onto Roomi.