The common assumption is that health information is legally protected wherever it lives. It is not. Medical privacy frameworks generally regulate specific entities — healthcare providers, insurers, and the businesses that serve them. A fitness tracker, a symptom checker, a meditation app, or a nutrition logger is usually none of those, and the same heart rate data is treated completely differently depending on who holds it.
Knowing where the line falls tells you which controls you actually have.
What changed in 2026
- Regional consumer health data laws expanded. Several jurisdictions enacted rules covering health information held by non-medical entities, which is precisely the gap the traditional framework leaves.
- Enforcement against health apps increased. Regulators pursued cases involving apps sharing sensitive health information with advertising networks, establishing that general consumer protection law reaches this conduct.
- Inferred health data drew scrutiny. Attention shifted toward data that implies a health condition without being labelled as health data — purchase history, search behavior, location patterns.
- On-device processing spread in wearables. More analysis happening locally reduced how much raw health data left devices by default.
Who holds your health data
| Holder |
Typically covered by medical privacy law |
Notes |
| Doctor, hospital, clinic |
Yes |
The core of the framework |
| Health insurer |
Yes |
Included |
| Pharmacy dispensing records |
Yes |
Included |
| Fitness tracker or wearable app |
Generally no |
Governed by its privacy policy |
| Symptom checker or wellness app |
Generally no |
Same |
| Period or fertility tracker |
Generally no |
Higher sensitivity, same gap |
| Direct-to-consumer genetic testing |
Generally no |
Data can outlive the company |
| Retailer or search engine |
No |
Inferred health data lives here |
| General AI assistant |
No |
Consumer terms are not health terms |
The genetic testing row deserves particular thought because the data is permanent, identifies relatives who never consented, and can survive a company's bankruptcy as a transferable asset. Read the terms about what happens to your sample and data if the company is sold.
What you can actually control
Check the sharing settings in each health app you use. Most have them, most default to some sharing, and most people have never opened that screen. Turning off research participation, advertising identifiers, and third-party analytics takes a minute per app and is the highest-value action available.
Review the platform-level health permissions on your phone. Both major mobile platforms centralize which apps can read from and write to the health store, and the list typically includes apps you granted access to years ago for a single feature.
Delete accounts you no longer use rather than abandoning them. Dormant health accounts continue holding data, and the company's obligations to it do not improve with time.
Be careful about the inferred category, which you cannot control through health app settings at all — it is assembled from ordinary behavior. A data broker removal pass is the relevant lever, and it is covered in data broker opt out.
And treat consumer AI assistants as public for this purpose. Describing symptoms to a general assistant on a free consumer account puts that information under ordinary consumer terms, not medical ones. The settings review in personal AI privacy checklist applies directly.
Common mistakes
- Assuming health data is always protected. The framework covers entities, not categories of information.
- Never checking app sharing settings. They exist and default to sharing.
- Ignoring inferred data. Purchases and searches can imply more than you disclosed.
- Abandoning rather than deleting accounts. Dormant is not deleted.
- Using consumer AI for sensitive health questions. No health-specific protections apply.
FAQ
Does medical privacy law apply if my doctor recommends an app?
Usually not to the app itself unless it is operating on the provider's behalf under a formal arrangement. A recommendation does not extend coverage.
Can my health app data affect insurance?
Rules on using such data in underwriting vary considerably by jurisdiction and insurance type. The practical answer is to limit sharing rather than rely on prohibitions.
What happens to genetic data if a company is acquired?
It is generally a transferable asset subject to the privacy policy in force. Some companies commit to specific handling; read the terms before submitting a sample.
Is on-device processing meaningfully safer?
Yes, when analysis genuinely stays local. Whether the underlying data also syncs to a cloud account is a separate setting worth checking.
Where to go next
For the broader settings pass, read personal AI privacy checklist. For reducing your data footprint, data broker opt out, and for AI mental health tools specifically, AI therapy apps.