Healthcare & Medical

Your Health App Knows More Than You Think: Who Gets Your Health Data?

You entered your symptoms into an app. You tracked your period. You logged your weight. You bought a test. But who else can see that information?

"Not Covered by HIPAA" Doesn't Mean "Unregulated"

Most consumer health apps — period trackers, symptom checkers, weight-loss and telehealth platforms, prescription discount apps — are not HIPAA-covered entities. That doesn't mean they operate in a legal vacuum. The FTC has been explicit that these companies remain subject to the FTC Act's prohibition on unfair and deceptive practices, and to the Health Breach Notification Rule specifically when they draw personal health data from multiple sources and experience an unauthorized disclosure.

A Pattern of Real Enforcement, Not a Hypothetical Risk

Over the past several years, the FTC has taken action against a consistent pattern of health apps sharing user data with advertising platforms, contrary to their own privacy promises:

In every case, the mechanism was largely the same: tracking pixels and software development kits embedded in the app or website that quietly passed user activity — sometimes including specific health conditions or search terms — to advertising and analytics platforms.

What "Private" Actually Needs to Mean in a Privacy Policy

A privacy policy stating your data is "private" or "secure" is a specific, enforceable claim under the FTC Act — not a vague marketing statement. If the company's actual practices contradict that stated promise, that gap is exactly what the FTC has repeatedly pursued as a deceptive practice. The presence of a privacy policy is not, by itself, evidence that your data is being handled the way the policy describes.

What This Means Practically

Sources