Study: 88% of health apps secretly track users across platforms without consent

Your health data is flowing to advertisers building profiles of your vulnerabilities
A study of 20,000+ health apps reveals how personal medical information becomes a commodity for third-party tracking.
Mark

Why does it matter that health apps are tracking users? Isn't that just how apps work now?

Mimi

It matters because health data is different. When an app knows you searched for symptoms of depression, or that you're tracking your menstrual cycle, or that you have a specific chronic condition, it's not learning about your shopping preferences—it's learning about your vulnerabilities. That information in the hands of advertisers becomes a tool for manipulation.

Mark

But the apps' terms of service probably disclose this, right?

Mimi

Technically, yes. But disclosure and consent are not the same thing. Most people don't read terms of service. And even if they do, the language is deliberately opaque. The real issue is that users think they're sharing data with a health service, not with an advertising network.

Mark

What's the practical harm? If an advertiser knows I'm tracking my fitness, they'll just show me gym ads.

Mimi

That's the optimistic version. But health data is more sensitive. Advertisers can infer things you haven't disclosed—mental health struggles, fertility issues, chronic illnesses. They can target you with predatory offers. Insurance companies could theoretically access this data. The harm isn't always immediate, but it's real.

Mark

So what should users do?

Mimi

Right now, the honest answer is: be very careful what health apps you download, and assume anything you share will eventually be monetized. But the real solution requires regulation—uniform privacy standards that treat health data as the sensitive information it is.

Mark

Will Google's review actually change anything?

Mimi

Probably not much, unless it's backed by enforcement. Google has reviewed privacy concerns before. Without consequences for violations, the incentive to change is minimal.

  • Researchers found that 88% of over 20,000 health apps on Google Play are quietly tracking users across devices and platforms, often without their knowledge.
  • The data being harvested is not trivial — heart rates, menstrual cycles, sleep patterns, and symptom searches are flowing directly to advertisers and third-party data brokers.
  • The absence of any uniform global privacy standard means app developers can exploit the weakest regulatory environment available, leaving users everywhere exposed.
  • Google has pledged to review the study's findings, but the structural incentives that make user data a revenue stream remain firmly in place.
  • Tapping 'accept' on a terms-of-service screen is being treated as informed consent — a legal fiction that regulators have yet to meaningfully challenge.

Across the world, millions of people have quietly handed over the most intimate details of their bodies — their sleep, their cycles, their symptoms — to health apps they trusted to keep those secrets. A study from Macquarie University, published in the British Medical Journal, reveals that nearly nine in ten of the 20,000-plus health apps on Google's Play Store are using tracking tools to follow users across platforms and devices, feeding that data to advertisers without meaningful consent. It is a reminder that in the digital age, the patient is rarely just a patient — they are also a product. The question of who owns our most personal data, and who profits from it, has never been more urgent.

Tim Cook has spent years positioning Apple as a champion of health and wellness. Mark Zuckerberg has made similar promises about virtual reality and fitness. The market has responded enthusiastically — fitness trackers are everywhere, and people now routinely share intimate details about their bodies with apps on their phones, trusting those companies to handle the information responsibly.

A new study from Macquarie University suggests that trust is largely misplaced. Researchers analyzed more than 20,000 health apps on Google's Play Store — symptom checkers, step counters, period trackers — and published their findings in the British Medical Journal. Nearly nine in ten of these apps use tracking tools to monitor user behavior not just within the app, but across multiple platforms and devices, typically without the user's knowledge or explicit permission.

The scale matters. Health apps serve real purposes — managing chronic conditions, counting calories, monitoring cycles — but the problem is not what the apps do for users. It is what they do with users' data. According to Macquarie's Muhammad Ikram, 87% of the apps studied collect data on behalf of advertisers and third-party tracking companies, building detailed profiles of users' habits, health concerns, and vulnerabilities through a process he calls data mining.

The business model makes this almost inevitable. When an app's survival depends on monetizing user information, privacy becomes secondary. There is no uniform global standard for health app privacy, which means companies can follow the loosest rules available to them regardless of where their users live.

Google says it is reviewing the findings and will act where warranted — but the structural problem remains. Terms-of-service agreements that almost no one reads technically disclose these practices, blurring the line between agreement and genuine informed consent. For anyone who has downloaded a health app in recent years, the data trail is already long. Whether regulators will finally treat that distinction seriously is the question that now hangs in the air.

Tim Cook has spent years positioning Apple as a champion of health and wellness, betting that wearables and fitness tracking will become central to how people manage their lives. Mark Zuckerberg has made similar claims about virtual reality—that devices like the Oculus Quest 2 could help users exercise and improve their overall fitness. The market has responded. Apple Watches are everywhere. Fitness trackers have become ordinary. People now routinely hand over intimate details about their bodies—heart rate, sleep patterns, menstrual cycles, calorie intake—to apps on their phones, trusting that these companies will handle that information responsibly.

A new study from Macquarie University in Australia suggests that trust may be misplaced. Researchers analyzed more than 20,000 health apps available on Google's Play Store, examining everything from symptom checkers to step counters to period trackers. What they found was sobering enough to warrant publication in The British Medical Journal: nearly nine out of ten of these apps are using tracking tools to monitor what users do—not just within the app itself, but across multiple platforms and devices—often without the user's knowledge or explicit permission.

The scale of the health app market makes this finding particularly urgent. As of 2021, nearly 2.87 million apps existed on the Google Play Store alone. Health apps represent a booming sector, targeting not just sick people seeking medical guidance but anyone interested in fitness or wellness. The apps themselves serve legitimate purposes: they help people manage chronic conditions, check symptoms, count steps, track calories, monitor their menstrual cycles. The problem is not the apps' stated function. The problem is what happens to the data they collect.

According to Muhammad Ikram, a lecturer at Macquarie University's Cyber Security Hub, 88 percent of the apps studied employ tracking identifiers and cookies to follow user behavior across devices and platforms. In 87 percent of cases, this data collection was done on behalf of advertisers and similar third parties. The data itself becomes a commodity. Tracking companies and advertisers use it to build profiles of users—their habits, their health concerns, their vulnerabilities—a process Ikram describes as data mining. This profiling happens both explicitly and implicitly, and crucially, it happens without users consenting to it.

The business model underlying many health apps makes this inevitable. Some apps generate revenue by selling subscriptions. Others rely on advertising. Still others sell access to user data itself. When a health app's survival depends on monetizing user information, privacy becomes a secondary concern. The researchers note that health apps face no uniform global standard for privacy protection. A company operating in multiple countries can follow the loosest rules available to it, leaving users in stricter jurisdictions still vulnerable to exploitation.

Google, which operates the Play Store where these apps are distributed, said it is reviewing the study's findings and will take action where warranted. But the company has made similar promises before. The real issue is structural: there is no enforcement mechanism that would prevent a health app from continuing to track users and sell their data to advertisers, provided the app's terms of service—which almost no one reads—technically disclose the practice. Users believe they are sharing health information with a doctor or a fitness coach. In reality, they are sharing it with an advertising network.

For anyone who has downloaded a health app in the past few years, the implications are direct. Your step count, your calorie intake, your sleep data, your symptom searches—all of it may be flowing to advertisers and data brokers who are building a detailed profile of your health and habits. You probably agreed to this when you tapped "accept" on a terms-of-service screen. But agreement and informed consent are not the same thing. The question now is whether regulators will treat them as such.

Some of this information is used for tracking and profiling by third parties like advertisers, done without user consent, both explicitly and implicitly
— Muhammad Ikram, Macquarie University Cyber Security Hub
Envie de l'histoire complète ? Lire l'original sur BGR ↗
Nous contacter FAQ