Healthcare Data Surveillance — Research Reference

Flo Health FTC settlement: Shared data from millions of users with Facebook, Google despite privacy promises. Didn't stop until 2019 WSJ exposé. FTC finalized order June 2021. In 2025, Google paid $48M, Flo $8M, and Flurry $3.5M (total $59.5M).

2026-06-16 7 min read Research file
Contents

Period Tracking Apps Post-Dobbs

Flo Health FTC settlement: Shared data from millions of users with Facebook, Google despite privacy promises. Didn’t stop until 2019 WSJ exposé. FTC finalized order June 2021. In 2025, Google paid $48M, Flo paid $8M, and Flurry $3.5M (total $59.5M) in the class action.

84% of period-tracking apps shared data with third parties; an ORCHA review found most would share data for marketing, and such data can be compelled by law enforcement on subpoena.

Nebraska case: Celeste Burgess (17) and mother Jessica charged after police obtained Facebook DMs via warrant detailing how Jessica obtained abortion pills. Meta complied. 24GB extracted from seized devices.

Mozilla review: 18 of 25 period/pregnancy apps earned “Privacy Not Included” warning. Only Euki (stores all data locally) earned “Best Of.”


Mental Health Apps Selling Data

BetterHelp FTC settlement ($7.8M): Shared email addresses, IP addresses, health questionnaire info with Facebook, Snapchat, Criteo, Pinterest. Used consumer data to instruct Facebook to find “lookalike” audiences.

Cerebral: Shared private health information of nearly 3.2 million patients with third-party advertising and analytics platforms (including LinkedIn, Snapchat, and TikTok) via tracking pixels since founding (October 2019). Data included clinical visit data and mental-health self-assessment responses. FTC order: ~$7M actual ($5.1M refund judgment plus a $10M civil penalty suspended after $2M paid, due to inability to pay).

Crisis Text Line / Loris.ai: Shared data from crisis conversations with for-profit spinoff Loris.ai, founded by CTL’s own co-founder Nancy Lublin. CTL held 53% interest. Removed prohibition on commercial use from website October 2017; Loris incorporated one month later. Ended data-sharing after January 2022 Politico exposé.

Mozilla review: 29 of 32 mental health apps earned “Privacy Not Included” warning (2022) — worst category Mozilla ever reviewed.


23andMe Bankruptcy (March 2025)

15+ million users’ genetic data at stake. Filed Chapter 11 less than two years after a breach that exposed 6.9 million profiles via DNA Relatives (~14,000 accounts were directly accessed through credential stuffing). Privacy policy explicitly stated company may sell personal information in bankruptcy.

California AG Rob Bonta issued urgent consumer alert advising users to delete genetic data before any sale.

Sold to TTAM Research Institute (nonprofit created by 23andMe’s founder/CEO). Legal scholars noted existing laws provide limited protection regardless of buyer.


HIPAA Gaps

HIPAA covers only covered entities (providers, insurers, clearinghouses) and business associates. Period trackers, fitness wearables, health apps, genetic testing companies are NOT covered. If you buy a Fitbit yourself, not HIPAA-protected; if a hospital gives you one, covered.

Data brokers legally sell health data. Duke University study (February 2023): 11 of 26 data brokers willing to sell mental health data — depression, ADHD, anxiety, bipolar — combined with ethnicity, age, zip code, net worth. One charged $275 for 5,000 records; others $75K-$100K/year for subscription access.


Genetic Data and Law Enforcement

Golden State Killer (April 2018): Joseph James DeAngelo identified via GEDmatch. Crime-scene DNA uploaded to public genealogy database, identified 10-20 distant relatives, genealogist built family trees.

Scale: As of December 2023, forensic genetic genealogy has solved 651 criminal cases, identified 318 perpetrators. Science estimated the technique could identify ~60% of white Americans via familial matches.

Only Maryland and Montana have explicit statutory limits. Montana requires a search warrant. Maryland mandates written consent, precludes covert collection, requires sample destruction. Twelve states explicitly allow the technique.


Location Data Revealing Healthcare Visits

SafeGraph sold abortion clinic visit data for $160. Vice/Motherboard: a week’s data on visitors to 600+ Planned Parenthood locations. Some locations had only 4-5 device visits, making deanonymization trivial. SafeGraph removed data after story broke.

FTC enforcement actions: Kochava sued August 2022 for selling data tracing individuals to reproductive clinics, shelters, places of worship. Gravy Analytics, Mobilewalla, X-Mode, InMarket all hit by FTC in 2024 for similar practices.


Healthcare Data Breaches

2024 was the worst year on record: 276,775,457 records breached — 81.38% of the US population.

Change Healthcare (2024): 192.7 million individuals — largest healthcare breach ever. Ransomware via missing MFA on a legacy server. Cost: $2.87 billion in 2024 alone.

Medical records sell for up to $1,000 on dark web (vs. $1-2 for credit cards). Uses: medical identity theft ($13,500 average to resolve), fake insurance claims, prescription fraud, blackmail.


Pharmacies Sharing Prescription Data

IMS Health v. Sorrell (Supreme Court, 2011): 6-3 ruled Vermont law restricting sale of prescription records violated First Amendment. Pharmaceutical marketing = protected speech. Three quarters of US retail pharmacies send electronic records to IMS Health (now IQVIA). $9 billion health care commercial intelligence industry. Drug reps walk into doctors’ offices with custom profiles showing prescribing patterns.


Wearable Health Data

Fitbit/Google ($2.1B, 2021): Google committed Fitbit health data wouldn’t be used for ads. But users face February 2, 2026 deadline to merge accounts or lose all stored health data.

Apple Health in criminal cases: UK pharmacist convicted after iPhone Health app showed frantic activity (racing around house) while victim’s app remained still. Karen Read trial: Apple Watch data showed victim took steps after being dropped off, supporting defense — Read acquitted.

John Hancock stopped underwriting traditional life insurance entirely — only “interactive policies” requiring wearable data sharing.

Grindr location data: Monsignor Jeffrey Burrill resigned as general secretary of the US Conference of Catholic Bishops after The Pillar used commercially available Grindr data to track his movements to gay bars and bathhouses. A conservative Catholic nonprofit spent millions buying data to identify priests using hookup apps. Norway fined Grindr ~€6.5M for sharing GPS, profiles, sexual orientation with five advertising companies.


The Reproductive Surveillance State

Post-Dobbs aggregate: period apps + location data + search history + pharmacy records + EHR data + social media messages = prosecution without traditional warrants. Facebook’s tracking pixel found on one-third of top hospitals’ websites.

In the first year after Dobbs, at least 210 pregnant people faced criminal charges. Since 1973, nearly 2,000 women in the US prosecuted for reproductive conduct. Nineteen states enacted shield laws — easily circumvented when prosecutors purchase data commercially instead of issuing subpoenas.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.