What happens to what you type into a health app

People type things into health apps they have not said to anyone. The research suggests the privacy policy will not reliably tell you where it goes.

People type things into health apps that they have not said to anyone. A symptom they are embarrassed about. A worry about a parent. A question about a diagnosis they have not told the family about yet.

It is worth knowing where that text goes, and the honest answer is that with most health apps you cannot tell from the outside, and the published research suggests the privacy policy will not reliably tell you either.

What the research found

The largest study of this was published in the BMJ in 2021. Tangari and colleagues examined more than 20,000 mobile health apps. They found that "88.0% of mHealth apps included code that could potentially collect user data", and identified 665 distinct third-party entities receiving data, with the top 50 accounting for most of it.

Their conclusion was not hedged. The analysis revealed "serious problems with privacy and inconsistent privacy practices in mHealth apps", and they recommended that clinicians be aware of this and raise it with patients when weighing up whether an app is worth using.

A 2019 study in JAMA Network Open looked closely at a smaller set: 36 top-ranked apps for depression and smoking cessation, categories where the content is unusually sensitive. It found that "twenty-nine of 36 apps (81%) transmitted data for advertising and marketing purposes or analytics to just 2 commercial entities, Google and Facebook".

The finding that matters most is the next one. Of the apps sending data to Google, only 43 percent disclosed it. Of those sending data to Facebook, only 50 percent did.

So for these apps, reading the privacy policy would have given you roughly a coin flip's worth of information about where your data was going. That is the part worth absorbing: the usual advice to check the privacy policy assumes the policy is complete, and in this category it often was not.

The gap most people do not know exists

There is a common and reasonable assumption that health information is protected by law in the United States, and that anything medical is therefore covered.

HIPAA protects health information held by covered entities, essentially health plans, health care clearing houses, and health care providers who transmit information electronically, along with the business associates working on their behalf. A consumer app that is not operating as or for one of those is generally outside that framework, whatever it is about.

In other words, the same sentence about your father's medication can be protected health information when it sits in a medical record and ordinary commercial data when you type it into an app that is not part of a provider. The words are identical. The legal status is not.

We are deliberately not summarising the finer detail of the regulations here, because we could not verify the government pages describing them at the time of writing. If that distinction matters to your situation, the source to read is the HHS guidance on health apps and the FTC's material on health privacy, directly.

What to ask about any health app

  • Is this app run by an actual health care provider, or by a company that is not one? That single question determines most of the legal position.
  • Does the free version pay for itself with advertising? If the business model is attention, the data has commercial value to somebody.
  • Does the policy name the third parties it shares with, or only refer to "partners" and "service providers"?
  • Can you delete your data, and does deleting the app do it?
  • Would you be comfortable if what you typed were linked to your name in a marketing profile? Not because that is certain, but because it is the question the research suggests you cannot fully rule out.

Where we stand, since we are one of these

Dr.life is built by Life Medical, a health care provider, so the record it works from is a medical record held by a provider rather than a consumer database. Life Medical is subject to HIPAA and to its Notice of Privacy Practices as a provider, and the app is a way into that practice rather than a separate data business alongside it.

On this website, which is not the app, we say plainly what we collect: the email you leave and the question you type into the chat bar, and page views counted without cookies. Our privacy page spells it out, and it asks you not to put medical details into that form precisely because a waitlist is not a care channel.

We would rather you interrogate that than take it on trust. The research above is the reason interrogating it is reasonable.

Sources

  1. Mobile health and privacy: cross sectional study. Tangari G, Ikram M, Ijaz K, Kaafar MA, Berkovsky S. BMJ, 2021. Used for the proportion of apps containing data collection code, the number of third parties, and the authors' conclusion.
  2. Assessment of the Data Sharing and Privacy Practices of Smartphone Apps for Depression and Smoking Cessation. Huckvale K, Torous J, Larsen ME. JAMA Network Open, 2019. Used for the proportion of apps transmitting data to Google and Facebook and the proportion that disclosed it.

Every source above was read before it was cited. Where the evidence is uncertain, this article says so rather than rounding it into advice.


More for families

Why seeing the same doctor matters

It feels like a preference, the way liking a particular barber is a preference. The research suggests otherwise, and the effect is larger than most people would guess.

When a parent refuses help

It looks like stubbornness. Understanding what is actually happening matters, because the usual family response makes it worse.

All articles


Dr.life is the app behind this

A healthcare AI with real doctors ready to join the conversation when needed, from Life Medical. Not live yet.