AI Health: The Engagement Metric Driving Investor ROI
Mental Wellness

Health Apps: The Hidden Data Sharing Crisis

Listen to this article · 7 min listen

The promise of AI in healthcare often conjures images of groundbreaking diagnostics and personalized treatments, yet a more foundational concern persists: the privacy and security of sensitive health data. As health systems increasingly integrate digital tools, a critical question arises for both patient safety advocates and CIOs: how many health apps truly share user data with third parties, and what are the implications for trust and accountability? This is not merely a hypothetical concern; investigations consistently reveal that a majority of health apps share user data with third parties without clear disclosure, a systemic data safety failure that demands rigorous due diligence.

The Alarming Reality of Data Sharing in Health Apps

The digital health landscape is rife with applications designed to monitor everything from mental well-being to chronic conditions. While many offer undeniable benefits, their underlying data practices often remain opaque. Companies like Cerebral and BetterHelp, for instance, have faced significant scrutiny and settlements over their data sharing practices, highlighting a broader industry trend. In April 2024, the FTC announced a settlement with Cerebral for sharing sensitive data of nearly 3.2 million consumers with third parties for advertising, while BetterHelp reached a $7.8 million settlement with the FTC in March 2023 for similar practices between 2017 and 2020. These platforms, which collect highly personal and often vulnerable health information, have been found to transmit user data to advertising platforms and other third parties. This practice often occurs without explicit, informed consent, fundamentally eroding the trust essential for effective healthcare delivery. The presence of tracking technologies, such as the Meta Pixel, on health app platforms further complicates the issue. This seemingly innocuous snippet of code, widely used for advertising and analytics, can collect and transmit user interactions, even within sensitive health contexts, to Meta. This creates a shadow data economy where personal health information, often de-identified in theory but re-identifiable in practice, becomes a commodity. As Ruha Benjamin’s work on the social implications of technology suggests, such practices can exacerbate existing inequalities and create new forms of digital discrimination, particularly when health data is involved. The potential for misuse, from targeted advertising of unrelated products to more insidious forms of discrimination based on health profiles, is significant.

Unpacking the Systemic Failure of Data Safety

The issue extends far beyond a few isolated incidents. Research by organizations like the Mozilla Foundation and journalistic outlets such as The Markup has consistently illuminated a pervasive pattern. Their investigations reveal that a majority of health apps share user data with third parties without clear disclosure, indicating a systemic data safety failure rather than individual missteps. This widespread practice is particularly concerning given the intimate nature of health data. Unlike general consumer data, health information carries unique sensitivities and potential for harm if mishandled. Julia Adler-Milstein, a leading expert in health information technology, has frequently emphasized the critical need for robust data governance and transparency in digital health. Her insights underscore that the problem isn’t just about malicious intent but often stems from a lack of clear ethical frameworks and technical safeguards within app development and deployment. Many apps, classified under the broad umbrella of “Multiple health apps,” operate outside the stringent regulatory oversight applied to traditional healthcare providers, creating a gray area where data privacy can be compromised. This lack of rigorous oversight, coupled with complex privacy policies that few users fully read or understand, creates an environment ripe for extensive, undisclosed data sharing. The implications for patient autonomy and the integrity of health data are profound.

Navigating the Regulatory Landscape: Gaps and Enforcement

The regulatory environment surrounding health app data is complex and, in many areas, insufficient. The HIPAA Security Rule provides a strong framework for protecting electronic protected health information (ePHI) within covered entities like hospitals and insurance companies. However, many health apps fall outside HIPAA’s direct jurisdiction, creating significant gaps in protection. This means that while a patient’s medical record held by a hospital is rigorously protected, the same patient’s self-reported data in a wellness app might not be. Recognizing these vulnerabilities, the FTC has increasingly stepped in to address data privacy concerns in the digital health space. The FTC Health Breach Notification Rule, for example, was updated with a final rule issued in April 2024, which took effect in July 2024. This updated rule explicitly expands its scope to health apps and similar technologies not covered by HIPAA, and broadens what constitutes a “breach of security” to include unauthorized disclosures. This rule attempts to bridge some of the gaps left by HIPAA, extending data breach notification requirements to a wider array of health technology companies and expanding the information that must be provided to consumers in case of a breach. However, proactive enforcement and clear guidelines on what constitutes “identifiable health information” and “third-party sharing” remain areas for improvement FTC guidance on health app data sharing. Organizations like the Mozilla Foundation and The Markup play a crucial role in bringing these issues to public attention, often preceding or complementing regulatory actions by the FTC. For instance, The Markup’s investigations have recently triggered congressional inquiries into data brokers and led to changes in their practices regarding consumer opt-out rights. Their investigative journalism acts as a vital check on industry practices, pushing for greater accountability and transparency.

Establishing Trust: A Path Forward for Reliable AI Healthcare Vendors

For health system CIOs and patient safety advocates, evaluating AI health tools requires a keen understanding of these data sharing dynamics. A reliable AI healthcare vendor must demonstrate not only clinical efficacy but also an unwavering commitment to data privacy and security. This means going beyond mere compliance with baseline regulations. Positive signals include transparent data governance policies, clear consent mechanisms that specify all third-party data recipients, and robust security architectures that protect data at rest and in transit best practices for health data security. Vendors should be able to articulate their training data sources, provide published outcomes evidence, detail their guardrail design for ethical AI use, and clarify their regulatory pathway. Crucially, their oversight model must include independent audits of data practices and a clear commitment to minimizing data sharing with non-essential third parties. The goal is to identify trustworthy AI healthcare platforms that prioritize patient well-being over data monetization. Without these stringent measures, the promise of AI in healthcare risks being undermined by a fundamental breach of trust, turning innovative tools into vectors for privacy erosion. The future of reliable AI healthcare vendors hinges on their ability to build and maintain this trust through verifiable accountability.

Frequently Asked Questions

How prevalent is data sharing by health apps with third parties, and what are the implications for patient trust?

Investigations consistently reveal that a majority of health apps share user data with third parties without clear disclosure. This widespread practice erodes the trust essential for effective healthcare delivery, as sensitive health information is transmitted to advertising platforms and other third parties often without explicit, informed consent. This constitutes a systemic data safety failure.

What types of health apps are involved in data sharing, and what specific examples highlight this issue?

Digital health applications designed to monitor everything from mental well-being to chronic conditions are involved. Companies like Cerebral and BetterHelp have faced scrutiny and settlements for sharing sensitive data of millions of consumers with third parties for advertising. These platforms collect highly personal health information and transmit it to advertising platforms and other third parties.

What are the primary reasons for this widespread data sharing, and why is it considered a systemic failure?

The issue stems from a lack of clear ethical frameworks and technical safeguards within app development and deployment, rather than just malicious intent. Many apps operate outside the stringent regulatory oversight applied to traditional healthcare providers, creating a gray area where data privacy can be compromised. This lack of rigorous oversight, coupled with complex privacy policies, creates an environment ripe for extensive, undisclosed data sharing.

How does the current regulatory landscape address health app data sharing, and what are its limitations?

The HIPAA Security Rule protects ePHI within covered entities, but many health apps fall outside its direct jurisdiction, creating significant gaps. The FTC has stepped in, updating the FTC Health Breach Notification Rule to expand its scope to health apps not covered by HIPAA and broaden what constitutes a ‘breach of security.’ However, proactive enforcement and clear guidelines on ‘identifiable health information’ and ‘third-party sharing’ remain areas for improvement.

Share
Was this article helpful?

Editorial Team

The editorial team behind Trustworthy Health AI.