Blood Pressure Cuffs Could Potentially Expose Personal Health Data

Featured & Cover Dementia Risk May Be Indicated by Simple Blood Pressure Readings

Your blood pressure cuff may be unintentionally sharing your health data with advertisers and data brokers, raising concerns about privacy and security.

Recent Federal Trade Commission (FTC) cases have revealed that many health apps, including those for tracking blood pressure and glucose levels, may be disclosing sensitive health data to advertising and analytics companies without users’ knowledge.

For many, the daily ritual of strapping on a blood pressure cuff and checking readings on a smartphone app feels like a private affair. However, this sense of privacy can be misleading. Depending on the app and user settings, health data—including blood pressure readings, glucose levels, weight, and medication schedules—can be stored in the cloud or shared with third-party service providers.

In light of these findings, it is crucial for users to understand what happens behind the scenes of their health apps and how to limit potential exposure of their sensitive information.

One common assumption is that health data is protected under the Health Insurance Portability and Accountability Act (HIPAA). However, this is not always the case. HIPAA generally safeguards health information held by covered healthcare providers, health plans, and their business associates. Many consumer apps, especially those chosen independently by users, often fall outside HIPAA’s protections.

While some apps may be subject to HIPAA when they handle protected health information on behalf of a covered provider, many do not operate under these regulations. However, they may still be governed by the FTC’s Health Breach Notification Rule, state consumer health laws, and general protections against unfair or deceptive business practices.

In response to these concerns, Senator Bill Cassidy of Louisiana has introduced the Health Information Privacy Reform Act. This proposal aims to extend HIPAA-like privacy, security, and breach-notification standards to health information held outside traditional HIPAA systems. It also seeks to require plain-language warnings before certain technologies begin generating wellness data that HIPAA does not protect. As of now, this proposal remains in the legislative process and has not yet become law.

Federal regulators have found that some well-known health apps have shared sensitive information through common advertising and analytics tools running in the background. This raises questions about the practices of companies that develop health tracking applications. While not all blood pressure apps behave the same way, users are encouraged to investigate what data their apps collect, where it is stored, and which companies may have access to it.

Research from Duke University highlights the extent of the problem. A researcher contacted 37 data brokers as a potential buyer, and 26 responded, with 11 willing to sell mental health data. Some brokers offered information related to conditions such as depression and anxiety, along with demographic details. Prices for this data ranged from $275 for aggregated counts to annual licensing fees exceeding $75,000.

The FTC has documented various categories of health-related data that brokers can collect and sell, including information related to pregnancy, diabetes, and high cholesterol. In a notable case, California’s privacy regulator fined a data broker $45,000 for failing to register as a data broker and for reselling contact lists tied to sensitive health conditions.

Scammers can exploit this data. For instance, a list of individuals with diabetes or high blood pressure could enable a scammer to craft a more convincing narrative, such as offering free glucose meters or test strips in exchange for Medicare information. Federal health officials have warned about such scams, where callers impersonate Medicare or diabetes organizations, potentially leading to identity theft or fraudulent billing.

Health apps, glucose monitors, and smart scales can contribute to a larger profile of personal information, depending on the services used and the settings enabled. Data brokers may compile information from various sources, including property records, voter files, and online activity, creating a comprehensive profile that can be bought and sold.

Not all health apps are created equal when it comes to privacy controls. Some offer stronger protections than others, and users should review the current privacy notices for each service they utilize. For example, OMRON monitors can transfer readings to the OMRON Connect app, but data handling practices may vary based on device permissions and connected services.

Similarly, Dexcom products may fall under HIPAA when supplied as insurance-reimbursable products, but other services may process information outside this context. Companies like Withings claim not to share health information with advertising partners, while Google has committed to keeping health data from Fitbit devices separate from its advertising operations.

To enhance privacy when using health apps, users can adjust their settings. On iPhones, users can go to Settings > Privacy & Security > Tracking to disable app tracking requests. Android users can navigate to Settings > Google > All services > Ads to manage ad preferences.

Additionally, users should review the privacy settings of each health app they use, turning off any options related to marketing, ad personalization, or third-party sharing. Many businesses are required to provide controls under laws like California’s CCPA, allowing users to opt out of certain data practices.

It is important to remember that Medicare does not make unsolicited calls offering free medical supplies in exchange for personal information. If a caller references a specific health condition, it may indicate that they have obtained this information from a commercial profile or data breach. Users should exercise caution and never confirm personal or Medicare information during unexpected calls.

While turning off tracking can help reduce future data collection, it does not erase information that has already been gathered or shared. Users can submit removal requests to data brokers, but this process can be time-consuming. Reputable data removal services can assist in managing these requests and monitoring for reappearing information.

In conclusion, users of health apps should be aware that their data may not receive the same protections as information held by healthcare providers. With the potential for sensitive information to be disclosed to advertisers and data brokers, it is essential to take proactive steps to safeguard personal health data. Regularly reviewing privacy settings and opting out of data sharing can help mitigate risks associated with health app usage.

For further information on protecting your personal data, visit CyberGuy.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

More Related Stories

-+=