💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Millions of people daily monitor their blood pressure, glucose levels and weight through smartphone applications that feel secure and private. This perception masks a complex reality: depending on the app and user settings, sensitive health information may be transmitted to cloud servers, distributed to service providers, or sold to advertising and analytics companies with minimal oversight.
The Federal Trade Commission has documented cases in which major health platforms disclosed personal medical information to third-party advertisers and analytics firms operating silently in the background. Additionally, specialized data brokers compile and market health-related consumer profiles that scammers can purchase to craft more convincing fraudulent schemes targeting vulnerable populations.
Many consumers assume HIPAA, the Health Insurance Portability and Accountability Act, protects all health information. However, HIPAA’s protections apply only to covered healthcare providers, health plans and their business associates. Standalone health apps downloaded independently typically fall outside HIPAA’s regulatory framework, though they may still be subject to FTC rules and state consumer protection laws.
Senator Bill Cassidy introduced the Health Information Privacy Reform Act, which would extend HIPAA-like standards to health information held outside traditional systems and require plain-language warnings about unprotected wellness data. As of now, the proposal remains in introductory status and has not been enacted into law.
A Duke University researcher contacted 37 data brokers posing as a buyer and found that 26 responded to inquiries. Eleven of those brokers indicated willingness to sell mental health data, including information tied to depression, anxiety and specific conditions, with some offering names and postal addresses. Pricing ranged from $275 for aggregated data to annual licensing fees exceeding $75,000.
California’s privacy regulator fined Datamasters $45,000 in December 2025 for failing to register as a data broker while buying and reselling contact lists connected to sensitive health conditions. The company’s inventory included 435,245 postal addresses associated with Alzheimer’s disease, more than 2.3 million linked to blindness or visual impairment, 133,142 tied to addiction, and 857,449 connected to bladder-control issues.
Scammers exploit health-related commercial profiles to personalize fraudulent pitches. A caller impersonating a Medicare representative or diabetes organization might reference a target’s specific condition while offering free glucose meters or test strips, then request Medicare numbers or financial information. Federal health officials have warned repeatedly about such schemes involving fraudulent Medicare, Social Security and diabetes organization impersonations.
Users retain greater control over their data than many realize, though exercising these controls requires navigating app settings deliberately. iPhone users can disable app tracking requests and personalized advertising through the Privacy & Security menu, while Android users can manage ad topics and measurement through Google settings. These actions limit advertising-related collection but do not prevent apps from processing information users enter directly.
Within individual health apps, users should disable settings related to marketing, ad personalization and third-party data sharing, then disconnect unused linked applications. Many platforms provide controls labeled “Do Not Sell or Share My Personal Information” or similar phrases, allowing users to opt out of certain data practices under California’s Consumer Privacy Act and comparable state laws.
Companies including Apple, Google Fitbit, OMRON, Dexcom, Withings and Medisafe handle health data differently based on their business models and regulatory obligations. Apple’s Health app encrypts information and prevents HealthKit data from supporting advertising, while Google committed through regulatory conditions not to use Fitbit health data for advertising purposes. Users should review current privacy policies for each service they use.
Disabling tracking prevents future data collection but cannot eliminate information companies have already gathered, shared or sold across dozens of data broker and people-search sites. Professional data removal services can submit opt-out requests to brokers and monitor for information reappearing, though no service can eliminate every digital trace. Individuals can submit removal requests independently, though the process requires repeated effort as information frequently reappears.
More Stories
Nearly 100 Dead as Thousands of Migrants Remain Stranded in Spanish Enclave of Ceuta
Paxton Dismisses Polling Deficit in Texas Senate Race, Says Voters Will Reject ‘Real’ Talarico
GOP Senators Push Amendment to Preserve State Women’s Sports Protections in College Athletics Bill