Your blood pressure cuff may expose your health data

Health apps may expose sensitive data to advertisers and brokers. Learn how to limit tracking, remove personal information and avoid scams.













At a glance
  • Health apps often fall outside HIPAA protections, even when they collect highly sensitive medical information.
  • Regulators have caught major health platforms sharing user data with advertising and analytics companies.
  • Data brokers can sell medical profiles that help scammers create convincing Medicare, pharmacy and supplement pitches.
  • Turning off tracking and third-party sharing can limit future collection, but it cannot erase data already circulating online.

 

Every morning, you strap on the cuff, press the button and watch the number pop up on your phone. It feels private. It feels like it is just between you and your app. That sense of privacy can be misleading.

Depending on the app and your settings, that reading, along with your glucose numbers, weight and medication schedule, may be stored in the cloud or shared with service providers. FTC cases show that some health apps have also disclosed sensitive information to advertising and analytics companies. Separately, data brokers market health-related profiles that scammers could exploit.

Here’s what may be happening behind the screen of your health app and how to limit the exposure.

 

 

A home blood pressure monitor can send sensitive health readings to a connected app, where privacy protections may vary.

The app on your phone isn’t your doctor’s office

Here’s the assumption almost everyone makes: “My health data is protected. Isn’t that what HIPAA is for?” Often, no.

HIPAA generally protects health information held by covered health care providers, health plans and their business associates. A consumer app you choose independently often falls outside HIPAA. However, an app may come under HIPAA when it handles protected health information on behalf of a covered provider or health plan.

Apps outside HIPAA do not operate without any rules. Many may still fall under the FTC’s Health Breach Notification Rule, state consumer health laws and general protections against unfair or deceptive business practices.

Sen. Bill Cassidy introduced the Health Information Privacy Reform Act. The proposal would extend HIPAA-like privacy, security and breach-notification standards to some health information held outside the traditional HIPAA system. It would also require plain-language warnings before certain technologies begin generating wellness data that HIPAA does not protect.

As of today, the proposal remains introduced and has not become law. That means the same blood sugar reading can receive different legal protections depending on who holds it and why.

 

What these apps are actually doing with your data

You would think a company that builds a blood pressure app would only use your numbers to track your blood pressure. Federal regulators have repeatedly found otherwise.

  • GoodRx agreed to pay a $1.5 million civil penalty to settle FTC allegations that it failed to report unauthorized disclosures of health information to Facebook, Google and other companies. The FTC said GoodRx uploaded identifiers connected to people who had purchased certain heart disease and blood pressure medications so Facebook could target them with ads.
  • BetterHelp agreed to pay $7.8 million after the FTC alleged that it shared email addresses, IP addresses and answers to personal health questions with Facebook, Snapchat, Pinterest and Criteo for advertising. About 800,000 people later received notices that they were eligible for refunds.
  • Flo Health settled FTC allegations that it shared sensitive health data from millions of users with Facebook, Google and other analytics providers. In a separate class action, Flo agreed to contribute $8 million toward settlements totaling $59.5 million. Google agreed to pay $48 million, and Flurry agreed to pay $3.5 million.
  • Premom’s developer agreed to pay a total of $200,000 to resolve federal and state allegations involving its privacy practices. The FTC alleged that the fertility app disclosed sensitive health and location information to Google and two China-based analytics companies.

These were not obscure apps built by scammers. They were mainstream health services, and regulators alleged that the sharing happened through ordinary advertising and analytics tools running in the background.

That does not mean every blood pressure app behaves the same way. However, it gives you a strong reason to check what your own app collects, where it stores the information and which companies receive it.

Digital blood pressure systems make tracking easier, but they can also create another path for health data to leave your control.

The data broker connection: Your condition has a price tag

Here’s the part that should genuinely unsettle you. A Duke University researcher contacted 37 data brokers as a prospective buyer. Twenty-six responded, and 11 were willing and able to sell mental health data. Some advertised information tied to depression, anxiety and other conditions, along with demographic details. One broker advertised names and postal addresses connected to specific conditions. Prices ranged from $275 for aggregated counts to annual licensing fees of $75,000 or more.

This problem reaches beyond mental health, as data brokers can collect and sell many forms of health-related information. The FTC has documented data broker categories related to pregnancy, diabetes, high cholesterol and other potentially sensitive health interests.

In a final order issued in December 2025, California’s privacy regulator fined Datamasters $45,000 for failing to register as a data broker. The order said the company bought and resold contact lists tied to sensitive conditions.

Those lists included 435,245 postal addresses associated with Alzheimer’s disease, more than 2.3 million associated with blindness or visual impairment, 133,142 associated with addiction and 857,449 associated with bladder-control issues. California’s enforcement chief warned that reselling lists connected to Alzheimer’s disease could enable targeting that goes far beyond ordinary advertising.

If you want to look up your exposed information online, now is the time. Use Incogni’s free tool and see how vulnerable you might be.

 

How scammers use a “medically profiled” list

Put yourself in a scammer’s shoes for a second. Random cold-calling is a numbers game. Most people hang up. However, a list of people associated with diabetes or high blood pressure could help a scammer choose a much more convincing lie, including fake Medicare and health care offers.

 

The “free” diabetic supplies pitch

A caller claims to be from Medicare or a diabetes association and offers free glucose meters or test strips. All they need is your Medicare number “to process the shipment.” Federal health officials have warned about callers impersonating Medicare, Social Security or diabetes organizations while offering free glucose meters, test strips and other supplies. The supplies may never arrive, or someone may fraudulently bill Medicare using your information.

 

The Medicare Advantage pitch that already knows your conditions

A caller could reference your blood pressure or diabetes like a nurse checking in, then pivot to a plan that supposedly covers exactly what you need. Knowing a real detail about your health does not prove the caller represents Medicare, your doctor or an insurance company.

 

The supplement and pharmacy pitch

Ads, emails or calls may push treatments or supplements connected to a condition associated with your profile. Their timing may make the offer feel personal, but that does not make the medical claim or the seller legitimate. A scammer does not need to hack your phone to personalize a pitch. Health-related information can come from commercial profiles, public records, online activity, data breaches or other sources. A medically segmented list could help a caller make a fraudulent offer sound far more believable.

 

“But I’ve never given my information to a data broker”

You do not have to. That is what makes this so hard to see coming. Your blood pressure app, glucose monitor and smart scale can each add information to a larger profile, depending on the service, its partners and the settings you enable. Data brokers may also compile property records, voter files, online activity and information purchased from other companies. Once information enters this ecosystem, companies may buy, resell, combine and refresh it across data broker and people-search services you have never heard of.

Even routine blood pressure readings can become valuable data when apps share information with advertisers, analytics firms or other partners.

How exposed is your specific device?

Not every app behaves the same way. Some provide stronger privacy controls than others. Features, settings and company practices can change, so review the current privacy notices for every service you use.

 

Omron Connect, blood pressure

Connected OMRON monitors can transfer readings to the OMRON Connect app through Bluetooth, where you can upload, store and share your heart health history. Data handling may depend on your device, permissions and connected services, so review OMRON’s current privacy notices before syncing.

 

Dexcom, continuous glucose monitoring

Certain Dexcom products fall under HIPAA when Dexcom or a health care provider supplies them as insurance-reimbursable products in the United States. Other Dexcom websites, support programs and services may process information outside that HIPAA-covered context. Dexcom also provides opt-outs for certain data sales, sharing and targeted advertising under applicable state laws.

 

Withings, smart scales

Withings says it does not share health information with advertising partners. It may share some non-health personal information to deliver tailored advertising, and information can sync with outside apps or partners when you authorize a connection.

 

Fitbit

Google committed not to use health and wellness information collected from Fitbit devices for Google Ads and to keep that information in a separate data silo. That commitment came through regulatory conditions attached to Google’s Fitbit acquisition, so continue reviewing current Fitbit and Google privacy controls.

 

Medisafe, medication reminders

If you choose pharmacy or coupon features, Medisafe says your personal information may be disclosed to partner pharmacies or coupon companies. Those companies will then handle the information under their own privacy practices.

 

Apple Health

Your device encrypts Health information, and iCloud uses end-to-end encryption when you enable the required account protections. In addition, Apple prohibits apps from using HealthKit data for advertising. You decide which outside apps can read or write individual categories of Health information.

 

The takeaway is that you have more control than you might think, but you need to go into the settings and use it.

The cuff may look simple, but the information it collects can reveal personal details about your health and medical conditions.

Lock it down: Your 20-minute privacy tune-up

Here’s a simple step-by-step guide to increasing your privacy when using health apps.

 

Step 1: Shut off ad tracking at the phone level

iPhone: Go to Settings > Privacy & Security > Tracking, then turn off Allow Apps to Request to Track. Next, go to Settings > Privacy & Security > Apple Advertising and turn off Personalized Ads.

Android: Go to Settings > Google > All services > Ads > Ads privacy. From there, you can turn off ad topics, app-suggested ads and ad measurement. Some devices also provide an option to delete the advertising ID. Menu names can vary by phone.

These settings limit certain forms of advertising and cross-app tracking. They do not stop every app from collecting information you enter directly or using other identifiers allowed under its privacy policy.

 

Step 2: Turn off sharing inside every health app

Open the account or privacy settings in each health app you use. Switch off anything labeled marketing, ad personalization or third-party sharing. Disconnect any linked apps you do not actively use.

 

Step 3: Look for privacy opt-outs

Check for links labeled “Do Not Sell or Share My Personal Information,” “Your Privacy Choices” or something similar. Covered businesses must provide these controls under laws such as California’s CCPA when they sell or share personal information as the law defines those terms. Your available rights may depend on where you live. An opt-out can restrict certain data practices, but it does not guarantee that all of your information will remain with the company.

 

Step 4: Know the red flags before the phone rings

Medicare does not make unsolicited calls offering free medical supplies in exchange for your Medicare or financial information. If a caller references a specific health condition, the detail may have come from a commercial profile, public record, data breach or another source. Do not assume the caller is legitimate simply because they know something about you. Never confirm personal or Medicare information during an unexpected call.

 

But here’s the problem: You can’t fix what you can’t see

Turning off tracking in your apps helps protect you going forward. It does nothing about the information already sitting on hundreds of broker sites, including the same sites that build the “medically profiled” lists scammers buy. Manually opting out of every broker means filling out hundreds of individual removal requests on hundreds of different sites. You may also need to repeat the process every few months because your information can quietly reappear. That is a full-time job most people do not have time for. This is why I recommend Incogni.

Incogni automatically sends removal requests to more than 420 data broker and people-search websites on your behalf. It keeps monitoring and resubmitting those requests when your data reappears. Unfortunately, information often does reappear because of how these sites operate.

Exclusive Deal for CyberGuy Readers (60% off): Incogni offers a 30-day, money-back guarantee and applies a special CyberGuy discount to all annual plans, as low as $6.39/month for one person, billed annually, or $13.19/month for your family of up to five people. This fully automated data removal service provides ongoing protection from more than 420 data brokers, and the Unlimited plan allows you to request removals from specific sites where your personal information appears.

I recommend the family plan. It works out to only $2.64 per person per month, or $4.80 per person per month for the Family Unlimited plan, for powerful, year-round privacy protection. It is an excellent service and well worth trying to see exactly how much of your information is being exposed right now.

Related Links:

 

 

Kurt’s key takeaways

Your health app may not receive the same HIPAA protections as your doctor’s office. FTC cases show that some major health platforms disclosed sensitive information to advertising and analytics companies, while data brokers market profiles connected to health conditions. Scammers could use details like these to make Medicare, pharmacy and supplement pitches sound more believable. Turn off tracking and sharing where possible, and use available deletion or opt-out requests for information companies have already collected.

Would you stop using a health app if it shared your medical data, or would stronger privacy controls be enough to keep you? Let us know your thoughts in the comments below.

FOR MORE OF MY TECH TIPS & SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER HERE

 

We created this article in partnership with Incogni.

Copyright 2026 CyberGuy.com. All rights reserved. CyberGuy.com articles and content may contain affiliate links that earn a commission when purchases are made.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow