Health Data Privacy: Fitness Trackers, Period Apps and Patient Portals


Health data is the most sensitive category of personal information there is, and most of it now lives outside the medical system entirely. Your step count, sleep patterns, heart rate, menstrual cycle, mental health app entries, and the symptoms you typed into a search bar at 2am are held by consumer technology companies, not doctors — and consumer technology companies are governed by their privacy policy, not by medical confidentiality law.

This is one of the widest gaps between what people assume and what is actually true. This guide explains where the gap is and how to close it.

The Misconception That Causes the Problem

Most people believe health privacy laws cover their health data. In the US, HIPAA is the law people name — and HIPAA applies to covered entities: healthcare providers, health plans, and clearinghouses, plus their business associates.

It does not generally cover:

  • Your fitness tracker or smartwatch app
  • Your period-tracking or fertility app
  • Your meditation or mental health app
  • A symptom checker website
  • A DNA testing company
  • Your search history about a condition
  • A wellness app your employer gives you

All of that is consumer data. In the EU and UK, GDPR treats health data as a special category with stronger protections regardless of who holds it, which is a meaningfully better position — but the protection still depends on the company honouring it and on you managing your consent.

What Each Source Actually Knows

Fitness trackers and smartwatches

Continuous heart rate, sleep stages, activity, and location. Together these infer far more than fitness: irregular sleep and elevated resting heart rate can indicate illness, pregnancy, or stress. Location plus time reveals where you go and how long you stay — including clinics.

Period and fertility apps

Cycle dates, symptoms, sexual activity, contraception, pregnancy attempts and outcomes. This is among the most sensitive data any app collects, and the category has a documented history of sharing data with advertisers and analytics firms. Regulators in several countries have taken enforcement action over it.

Mental health and therapy apps

Mood logs, journal entries, crisis usage, and sometimes session content. Several such services have been penalised for sharing user data with advertising platforms despite promising confidentiality.

DNA testing companies

The most permanent data you can hand over — you cannot change your genome after a breach, and it implicates blood relatives who never consented. Also consider what happens to the database if the company is sold or goes bankrupt.

Patient portals and health systems

These are covered by health privacy law, and the risk is different: account takeover. A portal contains your full medical record, prescriptions, and often billing details — a rich source for insurance fraud and targeted phishing.

Search engines and browsers

Searching a diagnosis, then visiting a hospital site, then reading treatment pages builds an advertising profile that infers a condition without you ever entering it into a health app.

Why It Matters

  • Targeted advertising you did not consent to. Health inferences are commercially valuable and can surface uncomfortably on shared devices.
  • Insurance and employment concerns. Rules vary by country, but the direction of travel — wellness programmes, usage-based premiums — makes people reasonably cautious.
  • Data brokers. Health-adjacent inferences get packaged and sold alongside other consumer data.
  • Breaches. Health records sell for far more than card numbers because they cannot be cancelled and enable long-term medical identity fraud.
  • Legal exposure. In some jurisdictions reproductive health data has become legally sensitive in ways it was not a few years ago.
  • Personal safety. In an abusive relationship, shared health app access reveals pregnancy, medication, and clinic visits.

Warning Signs Your Health Data Is Leaking

  • You get adverts for a condition you never searched for publicly — only logged in an app.
  • Pregnancy or fertility adverts appear shortly after you started tracking.
  • Marketing arrives from companies you have no relationship with, referencing a treatment area.
  • A health app asks for permissions unrelated to its function — contacts, precise location, full photo library.
  • Your patient portal shows appointments, prescriptions, or test results that are not yours.
  • You receive an explanation of benefits for care you never had — a classic sign of medical identity theft.

How to Protect Your Health Data

1. Read the sharing settings, not the privacy policy

Nobody reads policies. Instead open the app's settings and look for anything labelled data sharing, personalisation, analytics, partners, or research. Turn off what you did not intend to enable. This takes two minutes per app and is the highest-value step.

2. Choose apps that store data on the device

Some period and health apps offer local-only storage or end-to-end encryption. If cloud sync is optional, consider whether you need it. Data that never leaves your phone cannot be breached or sold.

3. Delete the data, not just the app

Removing an app from your phone leaves the account and its history on the company's servers. Log in, request account and data deletion, and get confirmation. In the EU/UK use your GDPR erasure right; in California and similar jurisdictions use the equivalent.

4. Audit permissions ruthlessly

A step counter needs motion data. It does not need your contacts, microphone, or precise background location. Revoke everything unnecessary — Settings → Privacy on iPhone, Settings → Apps → Permissions on Android.

5. Lock down the patient portal like a bank account

Unique strong password, two-factor authentication if offered, and a review of the "proxy access" list — old entries often let a former partner or adult child still see your record.

6. Be careful with employer wellness programmes

Ask specifically what is shared with your employer and in what form. Aggregate reporting is normal; individual-level sharing should be questioned. Participation is often optional even when it does not feel that way.

7. Think twice before DNA testing

If you do it, opt out of research and law-enforcement matching, use a dedicated email alias, and decide in advance what you want to happen to the sample. Remember it exposes relatives too.

8. Separate your health identity

Use an email alias for health apps rather than your main address. It limits cross-linking with your other accounts and makes it obvious who leaked your data.

9. Reduce search-based leakage

Use a private search engine or a browser with tracking protection for medical queries, and clear the history from shared devices.

10. Review shared access on your devices

Apple Health and Google Fit both support sharing with other people. Check who is on the list. Also check Family Sharing, since it can expose more than you expect.

If Your Health Data Has Been Exposed

  1. Read the breach notice carefully to see exactly what was taken — records, insurance details, and identity documents each require a different response.
  2. Change the password and enable two-factor on the affected portal or app, and anywhere you reused that password.
  3. Request your medical records and read them. Medical identity theft shows up as treatments, diagnoses, or prescriptions that are not yours, and errors in your record can affect your future care.
  4. Review every explanation of benefits from your insurer for services you did not receive.
  5. Notify your insurer and providers if you find fraudulent entries, and ask for a formal correction of the record.
  6. Place a fraud alert or credit freeze if identity documents or financial details were involved.
  7. Take the credit monitoring if the breached company offers it — it costs you nothing.
  8. File a complaint with your health regulator or data protection authority. In the US, the HHS Office for Civil Rights; in the UK, the ICO; in the EU, your national DPA.
  9. Expect targeted phishing. Breached health data makes very convincing fake calls from "your clinic" or "your insurer." Verify by calling the number on your card.

The Bottom Line

Your doctor is bound by medical confidentiality. Your period app is bound by a privacy policy it can change with an email notification. That distinction is the entire issue, and almost nobody is told about it.

You do not have to give up the tools. Do three things: open the sharing settings in every health app you use and turn off what you did not intend, revoke permissions that have nothing to do with the app's purpose, and treat your patient portal like a bank account with a unique password and two-factor.

And when you stop using a health app, delete the account and the data — not just the icon on your phone.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed