Skip to content

How to Protect the Privacy of Your Health and Fitness Data

⚡ Health Sovereignty — Protect your wellbeing like it belongs only to you (it does): fewer watchers, clearer choices, real strength back.

Cover card: How to Protect the Privacy of Your Health and Fitness Data

The short version

  • Health, fitness, sleep and cycle data in consumer apps is often not covered by HIPAA, the US medical-privacy law. In the US the FTC enforces consumer-protection law and its Health Breach Notification Rule against some of it; in the UK it is “special category data” under UK GDPR.
  • In about 20 minutes (our estimate) you can tighten permissions, cut off advertising IDs, and read a privacy policy for four things: what is collected, who gets it, how long it is kept, and how to delete it.
  • Removing an app from your phone is not the same as deleting your account. Export first, then use the in-app delete option or, in the UK, a written erasure request, and keep a record.

Information as of 6 October 2026.

Who this is for

Anyone in the UK or US who uses a period, sleep, fitness, mental-health or prescription app, or a smartwatch or band. It explains rights and settings; it does not recommend products. The access and erasure steps are UK GDPR rights. If you are in the US, rights vary by state and we could not verify them, so we do not cover them here.

Free download: The Sovereign Toolkit Blueprint 2026

The 12-point setup for a private, secure, high-output digital life — in one afternoon. No spam, unsubscribe anytime.

What you need

  • About 20 minutes for the audit, plus a few minutes per app for any request. All time estimates here are our estimates, except the ICO’s figure for its own SAR service.
  • Logins for each health app and wearable account, including ones you no longer use.

Why health data in apps is treated differently

United States

The FTC says many companies that collect health information, such as fitness trackers or diet apps, are not covered by HIPAA. It enforces Section 5 of the FTC Act and its Health Breach Notification Rule, which it says applies to “health apps and similar technologies not covered by HIPAA”. It covers vendors of personal health records, “PHR related entities” and their service providers. A personal health record is an electronic record of identifiable health information that can draw information from multiple sources and is managed, shared and controlled by or primarily for the individual. Its example: a health app that can sync with a fitness tracker is “probably a vendor of personal health records”.

The FTC says a breach “is not limited to cybersecurity intrusions”; a company’s disclosure of covered information without a person’s authorization can trigger notification duties. Affected people must be told within 60 calendar days of discovery. Since the 2024 amendments, in most cases notices must name third parties that acquired the information, and for breaches affecting 500 or more people the FTC must be told at the same time as individuals. The FTC page states a civil penalty of up to $53,088 per violation (page edited January 2025; the figure is adjusted for inflation).

Cases the FTC has published, described as it describes them. Three of the four were proposed orders or settlements on the FTC pages; these are allegations, not findings:

  • GoodRx (February 2023, proposed order): the FTC said this was its first action under the Health Breach Notification Rule, alleging unauthorized disclosures of personal health information to Facebook, Google and other companies. The proposed order, which the FTC said needed federal court approval, would require a $1.5 million civil penalty and permanently prohibit disclosing user health information to applicable third parties for advertising.
  • BetterHelp (July 2023): the FTC alleged disclosure of email addresses, IP addresses and health questionnaire information to Facebook, Snapchat, Criteo and Pinterest for advertising despite promises of limited use. The final order bars sharing health data for advertising and requires $7.8 million for partial refunds.
  • Premom (May 2023, proposed order): the FTC charged that the fertility app’s developer deceived users by sharing sensitive information with third parties and failed to notify consumers. The proposal included a $100,000 civil penalty.
  • Flo Health (January 2021, proposed settlement): the FTC alleged the company promised to keep health data private but disclosed data from millions of users to marketing and analytics providers. The proposed settlement would require an independent privacy review and user consent before sharing health information.

United Kingdom

UK GDPR defines “data concerning health” as personal data related to physical or mental health which reveals information about health status. The ICO lists “data from fitness trackers” as an example. Health data is a “special category”; the ICO says the UK GDPR recitals explain that these types of data merit specific protection. A company needs both an ordinary lawful basis and a separate Article 9 condition, and explicit consent is one such condition. The ICO also says profiling that infers health status is processing of special category data.

The 20-minute audit, step by step

  1. List your apps and devices (3 minutes)

    Note every health, fitness, sleep, cycle, mental-health and pharmacy app, each wearable and its companion app. Expected result: one list, with unused ones marked for deletion.

  2. Review system permissions (4 minutes)

    On Android, open Settings, Security & Privacy, Privacy, Permission manager (names vary by phone). For location, pick the narrowest option that works, such as “only while using the app”. On iPhone, review Settings, Privacy & Security. Expected result: no health app has background location or microphone access it does not need.

  3. Check what each app can read and write in your health store (3 minutes)

    On iPhone, open Health, tap your profile picture, then Privacy, Apps; you can switch read and write permission on or off per app. On Android, open Health Connect, Permissions and data, App permissions; removing an app’s connection revokes all its read and write permissions. Expected result: each app reaches only the data types it needs.

  4. Turn off tracking and the advertising ID (3 minutes)

    On iPhone, go to Settings, Privacy & Security, Tracking and turn it off for health apps. Apple says that if you choose “Ask App Not to Track” the developer cannot access the advertising identifier (IDFA). On Android the advertising ID is user-resettable and user-deletable, and apps requesting a deleted ID receive zeros; look for it in your privacy settings. Expected result: no health app is on the tracking list.

  5. Read the policy for four answers (5 minutes per app)

    Apple’s App Store privacy information shows what an app might collect, including health information, and how it may be used. Then open the full policy and find:

    1. What is collected? Cycle dates, symptoms, heart rate, sleep, location, device IDs, inferences.
    2. Who gets it? Watch for “advertising partners”, “analytics providers” and “affiliates”; sharing health data with advertising and analytics firms is what the FTC cases above concerned.
    3. How long is it kept? Our view: a fixed period is clearer than “as long as necessary”.
    4. How do I delete it?

    On iPhone, App Privacy Report (Settings, Privacy & Security) shows how often apps use permissions. Expected result: four notes per app and a keep, limit or leave decision.

  6. Download your data (5 minutes to request)

    Use the app’s export option. On iPhone you can export all Health data in XML format from your profile screen. Apple’s Data and Privacy page offers a copy of your Apple Account data. Google notes that downloading your Google data does not delete it. Expected result: a file showing what is actually held.

  7. No export? Make a subject access request (10 minutes)

    This step is UK GDPR only. Under UK GDPR you can ask an organisation whether it uses or stores your personal information and ask for copies. Anyone can make this “subject access request” (SAR) and no solicitor is needed; organisations usually have one month to respond. The ICO suggests a subject line saying “subject access request”, the date, your name, contact details and any account number, exactly what you want (for example “all cycle and sleep data and the third parties that received it”), and how you want it delivered. Find the contact in the privacy notice. The ICO’s SAR service builds the email and says it takes about 10 minutes. Expected result: a dated record and a one-month deadline.

  8. Delete data and account properly (10 minutes per app)

    Export first (step 6): deletion cannot be undone and the company may not return your records. If an app is tied to a current provider or prescription, check how you will keep access to your records before deleting. Store exports and request replies somewhere only you control, because they are new copies of sensitive data. Then use the app’s own account deletion, not just uninstalling; Apple and Google both require an account-deletion route in apps that let you create an account. Apple’s guideline says apps should offer to delete the entire account record with associated personal data, and that only deactivating is insufficient. Google Play requires an in-app deletion path and a web link for requests. For Apple’s own account, its Data and Privacy page lets you permanently delete it and the associated data.

    In the UK you can also send a written erasure request to any part of the organisation; the ICO says verbal requests are allowed but recommends following them up in writing. The right applies only in certain circumstances, for example when the data is no longer needed for its original purpose or you withdrew consent. The organisation has one calendar month, extendable by up to two more months in certain circumstances. It should tell others it shared the data with, and tell you who if you ask, but copies already shared with third parties may remain. Exceptions include special category data processed for health-care purposes by or under a professional bound by professional secrecy. If refused, it should explain and mention your right to complain to the ICO.

    On Android, deleting in Health Connect removes data from that database only; other apps or devices may keep copies, so delete in each app too. Expected result: a deletion confirmation or a written reply.

Cycle tracking and wearables

Cycle, fertility and pregnancy data can be health data under UK GDPR’s definition, and two FTC cases above involved fertility apps. These precautions follow from the steps; they are not legal advice.

  • Check the four questions before first use.
  • Deny location, contacts and microphone unless a feature needs them, and decline tracking.
  • Export before you delete, so you keep your own history.
  • For wearables, review the device, the companion app and the maker’s cloud account, and delete the cloud account when you retire the device.
  • Prefer services that collect less, share less, keep data for a shorter time and delete more easily. See data minimization, digital footprint and our health pillar.
  • Use two-factor authentication.

Mistakes to avoid

  • Removing the app and assuming the account is deleted.
  • Deactivating instead of deleting.
  • Treating a download as deletion, or forgetting connected third-party apps.
  • Assuming an app is covered by medical privacy law.

How to check it worked

  • Try the old login on the web: it should fail or show an empty account.
  • Confirm the app is gone from Health or Health Connect and the Tracking list.
  • Diary the one-month date for each request and chase in writing if it passes.
  • Run our self-audit; see also how we test.

What we could not verify

  • HHS statements on HIPAA. HHS pages returned access-denied errors to our fetch tools, so we rely only on the FTC’s wording that many health apps are “not covered by HIPAA” and make no further claims about HIPAA’s scope.
  • EU rules and US state laws. We did not fetch these, so they are not described here. We found no fetched source for US access or deletion rights, so we state none.
  • Effective date of the 2024 amendments. The FTC guidance page refers to “July 2024 amendments”; we did not fetch the Federal Register notice.
  • Status of the FTC cases. GoodRx, Premom and Flo are described as proposed orders or settlements on the FTC press releases; we did not check whether and when they were finalised.
  • Exact menu names and the Android advertising ID path. They vary and were not on the pages we fetched.
  • ICO guidance status. ICO pages say the guidance is under review following the Data (Use and Access) Act.

Sources

All fetched 2026-10-06. FTC pages reject default curl but were read in full with a browser User-Agent header, TLS verification on.

This guide is general information, not medical or legal advice.

Dr. AshR · Founder & Editor, The Unhacked

Dr. AshR is the founder and editor of The Unhacked, an independent publication on digital sovereignty — privacy, self-custody, health, and money. The Unhacked publishes disclosure-first, independently-tested guidance and never lets a commercial link change a verdict. More about our methodology →

The Signal - free dispatch

One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.

Free. No spam. Unsubscribe any time.

Affiliate disclosure. The Unhacked may earn a commission when you use some links on this page. Recommendations remain editorially independent.
📡

Join the Inner Circle

Weekly dispatches. No algorithms deciding what you see. Just sovereign intelligence, direct to your inbox.

Zero spam · Fully private · Sovereign by design.