The evidence is showing that health apps have turned our most intimate data into a commodity, traded without consent. The majority of top-ranked health apps share user data with third parties, and it’s often buried as a footnote in the fine print.
Understanding what health apps do behind the scenes may help you take the right steps to protect your digital data.
What the Research Found
Researchers at the University of Bremen recently uncovered notable gaps between what health apps claim about data protection and what they actually do. Their study of twenty popular mHealth apps found that several transmitted personal data before users had even given consent. All twenty apps sent data to third countries, particularly the United States.
How Health Apps Collect Data
Health apps employ multiple collection methods. They request explicit permissions for device features to get started.
- Permissions as trojan horses. Apps request access to GPS, contacts, cameras, and microphone, often bundling these permissions with core functionality. Granting location for route tracking also unlocks continuous background monitoring. It feeds precise movement patterns to data brokers.
- Active input capture. Every metric you log is stored and linked to your unique advertising ID. Top examples include weight, mood, blood pressure, and sleep quality. This self-reported data is valuable because it reveals intimate health concerns.
- Passive telemetry. Even when idle, apps transmit device information, screen time, battery level, and Wi-Fi networks. This behavioural fingerprint builds a detailed profile of your daily habits, social interactions, and even stress levels.
- Dark patterns in consent. Pre-ticked boxes, convoluted privacy policies, and “accept all” buttons disguised as the only option are standard tricks. Researchers found most apps manipulate users into agreeing to data-sharing clauses within seconds. You’ll find they often hide third-party recipients under vague terms like “partners” or “service providers”.
- Cross-app tracking and SDKs. Embedded third-party software development kits (SDKs) from advertising giants like Meta and Google silently funnel data across multiple apps. Hence, a shadow profile is created that connects your health records to your browsing history, shopping habits, and social media activity.
Protect Your Online Data
Awareness is the first step toward change. Audit the apps on your phone, question their permissions, and demand clearer privacy policies.
Regulators are catching up, but we shouldn’t wait for fines to protect ourselves. Consider using an online VPN service to encrypt your internet traffic and mask your IP address, adding a layer of protection against third-party interception. Combined with careful app selection and regular privacy check-ups, it can reduce your digital exposure.
Regulatory Actions
Regulators are finally catching up with the health app industry.
The Period-Tracker Settlement That Shook the Industry
Google and Flo Health agreed to a multi-million dollar settlement over claims that the menstrual tracking app shared user intimate health information with advertising giants. The case alleged that embedded tracking technologies funnelled pregnancy status and menstrual data to third parties, violating California privacy laws.
Flo and Google settled, while Meta faced a jury verdict, exposing how deeply personal data had been weaponised for ad targeting. The settlement sent a clear message that reproductive health data demands the highest protection, and regulators will enforce it.
California’s First Major Test Case
California’s Attorney General secured a landmark settlement with Healthline Media for sharing article titles about serious medical conditions with advertisers.
The investigation revealed that the health publisher’s opt-out mechanisms were misconfigured — they continue to share data even after users attempt to withdraw consent. Its cookie banner misled users about whether tracking would actually stop.
The case demonstrated that even reading health content online carries privacy risks, and regulators are scrutinising how health information flows through digital advertising pipelines.
Europe’s Intensified Scrutiny
French regulators imposed a substantial sanction on a health software publisher for failing to secure health data properly, signalling intensified oversight of the sector. Health data breaches accounted for a significant share of all notifications in France during 2025.
Furthermore, across Europe, data protection authorities have ramped up penalties against health apps and platforms, reflecting growing concern that sensitive medical information requires safeguarding. The trend shows that European regulators are treating health privacy as a fundamental right, not an optional compliance exercise.
