Medtechchronicles
  • Home
  • Industry Insights
  • Future Of Healthtech
  • Digital Health
  • Women In Medtech
  • Medical Devices
  • Home
  • Industry Insights
  • Future Of Healthtech
  • Digital Health
  • Women In Medtech
  • Medical Devices
Medtechchronicles
  • Home
  • Industry Insights
  • Future Of Healthtech
  • Digital Health
  • Women In Medtech
  • Medical Devices
  • Home
  • Industry Insights
  • Future Of Healthtech
  • Digital Health
  • Women In Medtech
  • Medical Devices
Digital Health

Is Your Health App Selling Your Data? The Hidden Privacy Risks of Menstrual and Fitness Trackers

Michael Robin
Last updated: August 11, 2026 9:12 am
By
Michael Robin
Share
12 Min Read
The Hidden Privacy Risks of Menstrual and Fitness Trackers
Medtech Chronicles
SHARE

Your period tracker knows things about you that your mother doesn’t. Your fitness app knows your resting heart rate, your sleep patterns, and possibly your exact location every morning at 6 a.m. when you go for a run. And here’s the part that catches most people off guard: almost none of that is protected by HIPAA.

Contents
Does HIPAA Actually Cover Your Period Tracker? (Spoiler: No.)The Real Difference Between “Medical-Grade” and “App Store” Health SoftwareHow Your Data Actually Gets Out the DoorThe Flo Health Case That Changed EverythingIs Anyone Closing the Gap?How to Protect Yourself Without Deleting Every AppThe Bottom Line on Health App Privacy

You’ve probably assumed otherwise. HIPAA, the Health Insurance Portability and Accountability Act, sounds like it should cover anything medical. It doesn’t. It was written in 1996, back when “health data” meant a folder in your doctor’s filing cabinet, not a river of biometric information flowing out of your phone 24/7. That gap between what people assume is protected and what’s actually protected is exactly where a lot of health apps are quietly operating.

Does HIPAA Actually Cover Your Period Tracker? (Spoiler: No.)

Most period-tracking, fitness, and wellness apps aren’t protected by HIPAA at all, because HIPAA only applies to “covered entities”: hospitals, doctors, insurers, clearinghouses, and their business associates. An app you downloaded yourself, with no connection to a healthcare provider, is neither.

That’s not a technicality. Because healthcare providers don’t own most third-party cycle-tracking apps, those apps simply don’t have to follow HIPAA rules, which means the data inside them can be used with none of the medical-privacy protections you’d expect. Flo, one of the biggest period trackers on the market, is the clearest example of how far that gap can stretch; more on that shortly.

The same logic applies to your smartwatch. Apple, Google, and Fitbit’s parent company Alphabet aren’t healthcare providers; they’re tech companies, and unless there’s a specific business associate agreement with a covered entity, the health data these devices collect sits entirely outside HIPAA’s reach. Your smart ring doesn’t need a warrant to be searched. It just needs a subpoena, a data broker willing to sell, or a privacy policy vague enough to allow it.

The Real Difference Between “Medical-Grade” and “App Store” Health Software

Here’s the direct answer: a medical-grade app is built for or contracted by a licensed healthcare provider and is either FDA-regulated as a device or bound to HIPAA as a business associate; a consumer wellness app is neither, even if it tracks identical data.

The distinction isn’t about how sophisticated the app looks. It’s about who commissioned it and what it claims to do. A health application sold directly to consumers may operate entirely outside HIPAA, but that same application can become subject to HIPAA the moment a hospital contracts with the developer to process protected health information. Nothing about the code changes. Just the ownership.

The FDA draws its own, separate line based on intent rather than data sensitivity. A fitness tracker that counts your steps and estimates calories burned is treated as a wellness tool, while an app that analyzes your heart rhythm and flags a potential arrhythmia is treated as a medical device, even though both live on the same phone and collect similarly personal information. One gets FDA oversight. The other gets a terms-of-service page nobody reads.

Even when an app is technically a business associate on paper, that status is narrower than people assume. A smartwatch app that a patient downloads on their own, without being commissioned by a hospital and without ever touching an electronic health record, isn’t a business associate at all; HIPAA simply doesn’t apply, regardless of how sensitive the data inside it is.

How Your Data Actually Gets Out the Door

It’s rarely a hack. That’s the uncomfortable part. Most of this is just business as usual.

Independent research keeps landing on the same conclusion, even if the exact numbers vary by category. A JAMA-published study of 578 mental health apps found that 44% shared data they collected with third parties. Mozilla’s own review of reproductive-health apps found that 18 of 25 popular period and fertility trackers failed to meet even its minimum privacy bar. Whichever study you pick, the pattern holds: a meaningful share of the apps people trust with their bodies are quietly routing that data somewhere else.

Devices like Whoop alone collect heart rate, heart rate variability, skin temperature, blood oxygen, respiratory rate, sleep stages, strain scores, and recovery metrics, an extraordinarily detailed physiological profile, all generated passively, all potentially shareable under a privacy policy most users never read past the “Accept” button.

And this data doesn’t stay theoretical once it exists. Fitness-tracker data has been used in court since 2014, when a Calgary personal injury lawyer became the first known attorney to introduce a client’s Fitbit data as evidence, using her activity levels to demonstrate that an injury had measurably reduced her physical capacity. It didn’t stay a plaintiff’s tool for long; insurance companies can request the same data through a court order, and if it shows more activity than the claimed injury should allow, it can be used to reduce or deny a payout entirely. No breach required. Just a subpoena.

The Flo Health Case That Changed Everything

If you want the clearest cautionary tale in this space, it’s Flo Health. The FTC alleged that Flo Health shared users’ health information with outside data analytics providers, including Facebook and Google, after promising that information would stay private. The company settled with the FTC in 2021; that settlement required Flo to obtain users’ affirmative consent before sharing health data going forward, to notify affected users about the earlier disclosures, and to instruct any third party that had received the data to destroy it.

That wasn’t the end of it. A related class action, covering everyone who used the app and entered menstruation or pregnancy data between November 2016 and February 2019, went considerably further. Flo Health settled mid-trial on July 31, 2025, and the very next day, a jury found Meta liable for its role in the unauthorized collection and commercial use of that health data. Google and Flurry, an analytics firm, had already settled separately. Flo, Google, and Flurry’s combined settlement totals $59.5 million, still pending final court approval as of this writing. Meta, meanwhile, didn’t settle; the jury found it liable under California’s wiretapping-era privacy law, and plaintiffs are seeking $5,000 in statutory damages per class member across a subclass of roughly 1.6 million people, with total exposure still undetermined.

The kicker: Flo wasn’t doing anything HIPAA prohibited. HIPAA never applied to Flo to begin with.

Is Anyone Closing the Gap?

Slowly, yes, but unevenly, and mostly at the state level. Washington moved first. State lawmakers explicitly noted that residents expect their health data to be protected the way HIPAA protects it, but HIPAA only covers data collected by specific healthcare entities, leaving apps and websites that collect the same kind of information with no equivalent safeguard. The resulting My Health My Data Act makes it unlawful to sell or even offer to sell consumer health data without first obtaining valid, specific authorization from the consumer, and gives consumers a sweeping right to demand deletion of their health data, one that, unlike most privacy laws, doesn’t even carve out an exception for data companies are otherwise required to retain.

Federally, the FTC has leaned on a different tool: the Health Breach Notification Rule, originally written in 2009 for personal health record vendors HIPAA never touched. 2024 amendments to that rule clarified that it expressly covers health apps, fitness trackers, and other wearables, precisely the category of products that HIPAA and, increasingly, the FDA’s general wellness guidance leave unregulated. It’s not HIPAA-level protection, but it does mean unauthorized disclosures, even by the company itself, can now trigger mandatory breach notifications.

Still, if you don’t live in a state with its own law, you’re mostly relying on a company’s privacy policy and its own definition of “consent.”

How to Protect Yourself Without Deleting Every App

You don’t need to throw your smartwatch in a drawer. A few habits go a long way:

  • Read the data-sharing section, not the whole policy. Look specifically for “third parties,” “analytics partners,” or “advertising.” That’s where the sharing lives.
  • Check for end-to-end encryption on sensitive trackers, especially period and fertility apps; some now advertise this specifically, meaning even the company can’t hand your data over on request.
  • Turn off ad personalization and analytics permissions inside the app’s own settings, not just your phone’s.
  • Favor apps built for or by healthcare providers when the data is genuinely sensitive: reproductive health, mental health, chronic conditions. That’s your best shot at actual HIPAA coverage.
  • Know your state’s law. If you’re in Washington, Connecticut, Nevada, or a handful of others, you have deletion and consent rights that HIPAA never gave you.

The Bottom Line on Health App Privacy

The uncomfortable truth is that most health apps were never built inside HIPAA’s walls; they were built entirely outside them, on purpose, because operating outside those walls is cheaper and more profitable. That’s not a bug in the system. It’s a gap the system never closed. Until federal law catches up, and there’s no clear sign it will anytime soon, the burden of protecting sensitive health data sits with you: reading the fine print, checking your state’s protections, and picking your apps with the assumption that HIPAA isn’t watching, because it probably isn’t.

Michael Robin
+ postsBio ⮌
  • Michael Robin
    Why Doctors Are Telling Healthy Patients to Stop Wearing Continuous Glucose Monitors
  • Michael Robin
    Why Hospital Waiting Times Are Shrinking Thanks to Bed-Tracking Algorithms
  • Michael Robin
    Smart Rings vs. Smartwatches: Which Sleep and Recovery Tracker Is Actually Accurate?
  • Michael Robin
    Leading the AI Revolution in Brain Care: A Conversation with Dr. David Bates, CEO of Linus Health
TAGGED:Digital HealthcareHealthtech
Share This Article
Facebook Copy Link Print
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Fast Four Quiz: Precision Medicine in Cancer

How much do you know about precision medicine in cancer? Test your knowledge with this quick quiz.
Get Started
David Veino: Leading Neuros Medical’s Bioelectric Revolution in Amputee Care

Imagine surviving the severe physical and emotional trauma of losing a limb,…

Inside Phantom Neuro: How Dr. Connor Glass is Revolutionizing the Muscle-Machine Interface

A Radical Shift in Bionic Evolution For decades, the concept of a…

Inside CergenX: How Jason Mowles Is Scaling AI-Powered Neonatal EEG Technology

Every year, approximately 140 million infants are born across the globe. For…

Your one-stop resource for medical news and education.

Your one-stop resource for medical news and education.
Sign Up for Free

You Might Also Like

Alfons Carnicero, Co-founder and CEO of ABLE Human Motion
Featured

Inside Alfons Carnicero’s Vision for ABLE Human Motion. The Future of Neurorehabilitation

By
Michael Robin
Seth Merritt, CEO of Welby Health
Digital Health

Seth Merritt, CEO of Welby Health: Scaling AI-Driven Virtual Care for Chronic Conditions

By
Michael Robin
Zach Newman, CEO of Enzo Health
Digital Health

Zach Newman’s Answer to Legacy EHR Systems: Enzo Health

By
Michael Robin
Kara Egan, CEO of Teal Health
Future Of Healthtech

The Future of At-Home Diagnostics: Kara Egan & Teal Health

By
Michael Robin
Twitter Linkedin
Company
  • Newsletter
  • News & Perspective
More Info
  • Home
  • Industry Insights
  • Future Of Healthtech
  • Digital Health
  • Women In Medtech
  • Medical Devices

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

Made by Adaptica Solutions For THE HEALTH CHRONICLES

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?