Healthcare Data Surveillance — Research Reference
Flo Health FTC settlement: Shared data from millions of users with Facebook, Google despite privacy promises. Didn't stop until 2019 WSJ exposé. FTC finalized order June 2021. In 2025, Google paid $48M, Flo $8M, and Flurry $3.5M (total $59.5M).
Contents
Period Tracking Apps Post-Dobbs
Flo Health FTC settlement: Shared data from millions of users with Facebook, Google despite privacy promises. Didn’t stop until 2019 WSJ exposé. FTC finalized order June 2021. In 2025, Google paid $48M, Flo paid $8M, and Flurry $3.5M (total $59.5M) in the class action.
84% of period-tracking apps shared data with third parties; an ORCHA review found most would share data for marketing, and such data can be compelled by law enforcement on subpoena.
Nebraska case: Celeste Burgess (17) and mother Jessica charged after police obtained Facebook DMs via warrant detailing how Jessica obtained abortion pills. Meta complied. 24GB extracted from seized devices.
Mozilla review: 18 of 25 period/pregnancy apps earned “Privacy Not Included” warning. Only Euki (stores all data locally) earned “Best Of.”
- Source: FTC Finalizes Order with Flo Health
- Source: HIPAA Journal: Flo Health, Google, Flurry to Pay $59.5M to Settle Privacy Lawsuit
- Source: Vice: This Is the Data Facebook Gave Police to Prosecute a Teenager for Abortion
- Source: Mozilla: 18 of 25 Apps Labeled Privacy Not Included
- Source: Public Health Post: Period Apps After Dobbs
Mental Health Apps Selling Data
BetterHelp FTC settlement ($7.8M): Shared email addresses, IP addresses, health questionnaire info with Facebook, Snapchat, Criteo, Pinterest. Used consumer data to instruct Facebook to find “lookalike” audiences.
Cerebral: Shared private health information of nearly 3.2 million patients with third-party advertising and analytics platforms (including LinkedIn, Snapchat, and TikTok) via tracking pixels since founding (October 2019). Data included clinical visit data and mental-health self-assessment responses. FTC order: ~$7M actual ($5.1M refund judgment plus a $10M civil penalty suspended after $2M paid, due to inability to pay).
Crisis Text Line / Loris.ai: Shared data from crisis conversations with for-profit spinoff Loris.ai, founded by CTL’s own co-founder Nancy Lublin. CTL held 53% interest. Removed prohibition on commercial use from website October 2017; Loris incorporated one month later. Ended data-sharing after January 2022 Politico exposé.
Mozilla review: 29 of 32 mental health apps earned “Privacy Not Included” warning (2022) — worst category Mozilla ever reviewed.
- Source: FTC: Ban BetterHelp from Revealing Consumers’ Data
- Source: TechCrunch: Cerebral Shared Millions of Patients’ Data
- Source: FTC: Proposed Order Will Prohibit Cerebral from Disclosing Sensitive Data for Advertising
- Source: Popular Science: Crisis Text Line Stops Sharing Data with Loris.ai
- Source: Mozilla: Top Mental Health and Prayer Apps Fail Spectacularly
23andMe Bankruptcy (March 2025)
15+ million users’ genetic data at stake. Filed Chapter 11 less than two years after a breach that exposed 6.9 million profiles via DNA Relatives (~14,000 accounts were directly accessed through credential stuffing). Privacy policy explicitly stated company may sell personal information in bankruptcy.
California AG Rob Bonta issued urgent consumer alert advising users to delete genetic data before any sale.
Sold to TTAM Research Institute (nonprofit created by 23andMe’s founder/CEO). Legal scholars noted existing laws provide limited protection regardless of buyer.
- Source: NPR: 23andMe Filing for Bankruptcy
- Source: CA AG: Urgent Consumer Alert
- Source: NEJM: Bankruptcy, Genetic Information, and Privacy
- Source: Lawfare: Privacy, Consent, and National Security After 23andMe Bankruptcy
HIPAA Gaps
HIPAA covers only covered entities (providers, insurers, clearinghouses) and business associates. Period trackers, fitness wearables, health apps, genetic testing companies are NOT covered. If you buy a Fitbit yourself, not HIPAA-protected; if a hospital gives you one, covered.
Data brokers legally sell health data. Duke University study (February 2023): 11 of 26 data brokers willing to sell mental health data — depression, ADHD, anxiety, bipolar — combined with ethnicity, age, zip code, net worth. One charged $275 for 5,000 records; others $75K-$100K/year for subscription access.
- Source: ProPublica: Federal Patient Privacy Law Does Not Cover Most Period-Tracking Apps
- Source: Duke Tech Policy: Data Brokers and the Sale of Americans’ Mental Health Data
- Source: NBC News: A Researcher Tried to Buy Mental Health Data. Surprisingly Easy.
Genetic Data and Law Enforcement
Golden State Killer (April 2018): Joseph James DeAngelo identified via GEDmatch. Crime-scene DNA uploaded to public genealogy database, identified 10-20 distant relatives, genealogist built family trees.
Scale: As of December 2023, forensic genetic genealogy has solved 651 criminal cases, identified 318 perpetrators. Science estimated the technique could identify ~60% of white Americans via familial matches.
Only Maryland and Montana have explicit statutory limits. Montana requires a search warrant. Maryland mandates written consent, precludes covert collection, requires sample destruction. Twelve states explicitly allow the technique.
- Source: NPR: In Hunt for Golden State Killer
- Source: Forensic Magazine: How Many Cases Solved with Forensic Genetic Genealogy?
- Source: EFF: Maryland and Montana Pass First Genetic Genealogy Laws
Location Data Revealing Healthcare Visits
SafeGraph sold abortion clinic visit data for $160. Vice/Motherboard: a week’s data on visitors to 600+ Planned Parenthood locations. Some locations had only 4-5 device visits, making deanonymization trivial. SafeGraph removed data after story broke.
FTC enforcement actions: Kochava sued August 2022 for selling data tracing individuals to reproductive clinics, shelters, places of worship. Gravy Analytics, Mobilewalla, X-Mode, InMarket all hit by FTC in 2024 for similar practices.
- Source: Vice: Data Broker Selling Location Data of Abortion Clinic Visitors
- Source: FTC v. Kochava Case Page
- Source: FTC: Action Against Gravy Analytics (December 2024)
Healthcare Data Breaches
2024 was the worst year on record: 276,775,457 records breached — 81.38% of the US population.
Change Healthcare (2024): 192.7 million individuals — largest healthcare breach ever. Ransomware via missing MFA on a legacy server. Cost: $2.87 billion in 2024 alone.
Medical records sell for up to $1,000 on dark web (vs. $1-2 for credit cards). Uses: medical identity theft ($13,500 average to resolve), fake insurance claims, prescription fraud, blackmail.
- Source: HIPAA Journal: Healthcare Data Breach Statistics
- Source: HHS OCR Breach Portal
- Source: Krebs on Security: Change Healthcare Breach Hits 100M Americans
Pharmacies Sharing Prescription Data
IMS Health v. Sorrell (Supreme Court, 2011): 6-3 ruled Vermont law restricting sale of prescription records violated First Amendment. Pharmaceutical marketing = protected speech. Three quarters of US retail pharmacies send electronic records to IMS Health (now IQVIA). $9 billion health care commercial intelligence industry. Drug reps walk into doctors’ offices with custom profiles showing prescribing patterns.
- Source: Justia: Sorrell v. IMS Health, 564 U.S. 552
- Source: ProPublica: Big Data + Big Pharma = Big Money
Wearable Health Data
Fitbit/Google ($2.1B, 2021): Google committed Fitbit health data wouldn’t be used for ads. But users face February 2, 2026 deadline to merge accounts or lose all stored health data.
Apple Health in criminal cases: UK pharmacist convicted after iPhone Health app showed frantic activity (racing around house) while victim’s app remained still. Karen Read trial: Apple Watch data showed victim took steps after being dropped off, supporting defense — Read acquitted.
John Hancock stopped underwriting traditional life insurance entirely — only “interactive policies” requiring wearable data sharing.
Grindr location data: Monsignor Jeffrey Burrill resigned as general secretary of the US Conference of Catholic Bishops after The Pillar used commercially available Grindr data to track his movements to gay bars and bathhouses. A conservative Catholic nonprofit spent millions buying data to identify priests using hookup apps. Norway fined Grindr ~€6.5M for sharing GPS, profiles, sexual orientation with five advertising companies.
- Source: EFF: Google-Fitbit Merger Would Cement Google’s Data Empire
- Source: 9to5Mac: iPhone Murder Conviction — Health Data Provides Crucial Evidence
- Source: NBC News: Priest Outed Via Grindr App Highlights Rampant Data Tracking
- Source: Norwegian DPA: Record Fine Against Grindr Confirmed
The Reproductive Surveillance State
Post-Dobbs aggregate: period apps + location data + search history + pharmacy records + EHR data + social media messages = prosecution without traditional warrants. Facebook’s tracking pixel found on one-third of top hospitals’ websites.
In the first year after Dobbs, at least 210 pregnant people faced criminal charges. Since 1973, nearly 2,000 women in the US prosecuted for reproductive conduct. Nineteen states enacted shield laws — easily circumvented when prosecutors purchase data commercially instead of issuing subpoenas.
- Source: Pregnancy Justice: Pregnancy as a Crime — A Preliminary Report on the First Year After Dobbs
- Source: ABA: Digital Privacy and Access to Abortion Post-Dobbs
- Source: EPIC: Two Years Post-Dobbs — Commercial Surveillance Landscape
- Source: CDT: Two Years After Dobbs — State Laws Analysis
Related research
- Healthcare espionage — the breach / nation-state layer
- Health-governance ratchet — the pharma/WHO/funding layer
- 23andMe / the genetic database · Digital ID