A dedicated health or symptom-tracking app is a different privacy situation from typing a question into a general AI chatbot — it usually asks for more structured, sensitive data over time (cycle dates, medication lists, recurring symptoms) and monetizes differently, often through advertising partnerships rather than model training. The regulatory story here is also more concrete: there are real, named enforcement actions to look at, not just policy language.
What's actually happened to health apps that got this wrong
The FTC's 2023 settlement with GoodRx — the agency's first enforcement action under its Health Breach Notification Rule — addressed advertising trackers on GoodRx's site and app that shared users' medication and health information with Facebook, Google, and other ad platforms without proper disclosure; GoodRx paid a $1.5 million penalty. The same year, Easy Healthcare settled FTC allegations that its Premom period and fertility tracker shared sensitive health data with Google, AppsFlyer, and two firms in China, despite telling users otherwise. These aren't hypothetical risks — they're the reason the FTC updated its Health Breach Notification Rule, effective July 29, 2024, to explicitly cover health apps and wellness platforms that sit outside HIPAA's jurisdiction.
What "local" or "on-device" processing actually means
Some platforms process health data differently — locally on your device rather than sending it to a company's servers. Apple states in its own health privacy documentation that it "minimizes data collection by processing as much of your health data on your device as we can," and that Health app data is end-to-end encrypted when you use a passcode with two-factor authentication, to the point where Apple describes it as unreadable by anyone but you, including Apple itself. This is a genuinely different privacy model than a cloud-processed app that must transmit your symptom entries to a server to function — but it only applies to the specific features that are built this way, not to every app that claims to be "private."
How to actually check before you use a symptom app
1. Read the app's specific data-sharing section, not just a general privacy tagline — look for whether it names third-party advertising or analytics partners.
2. Check whether the app is HIPAA-covered or not. Most consumer symptom-tracker and period-tracker apps are not, which is exactly why the FTC's Health Breach Notification Rule update matters — it's the backstop for apps HIPAA doesn't reach.
3. Look for an explicit on-device or local-processing claim, and treat it as more credible when the company also states data isn't accessible to it — a vague "your privacy matters to us" line is not the same claim.
4. Review your notification settings and any advertising-ID sharing toggles — a large share of these enforcement cases involved code that shared data via advertising SDKs, not a deliberate decision by the company to sell your health record wholesale.
# Before entering symptoms into a health/symptom-tracking app
[ ] Read the "Data Sharing" or "Third Parties" section of the
privacy policy, not just the summary tagline
[ ] Search "[app name] FTC settlement" or "[app name] privacy
lawsuit" -- GoodRx and Premom are proof this is checkable
[ ] Confirm whether the app claims HIPAA coverage or instead
falls under the FTC Health Breach Notification Rule
[ ] Look for a specific on-device/local-processing claim,
not just a generic "we value your privacy" statement
[ ] Check advertising-ID and analytics-sharing toggles in
the app's own settings, not just the OS-level ones
| App type | Primary regulator/mechanism | What to check |
|---|---|---|
| Consumer symptom/period/fertility tracker | FTC (Health Breach Notification Rule, updated July 2024) | Named enforcement history, third-party ad-sharing disclosures |
| Portal or tool provided directly by your clinic | HIPAA (covered entity/business associate) | Should have a Business Associate Agreement and formal breach obligations |
| OS-level health feature with on-device processing (e.g., Apple Health) | Platform's own architecture + privacy policy | Whether the specific feature you use is actually processed locally, not just the platform in general |
The honest answer is that "is it private" depends on which specific app and which specific feature — there's no blanket yes or no. But this is a checkable question, not a guessing game: real enforcement history exists for apps that got it wrong, a real regulatory backstop now exists for apps outside HIPAA, and platforms making on-device claims generally document the mechanism rather than asking you to take it on faith.
Practical Challenge
Pick a symptom-tracking or wellness app you actually use and find its "third-party sharing" disclosure. If you can't find one within a couple minutes of looking, treat that itself as useful information.
Concept Check
Sources & Further Reading
- FTC: Updated Health Breach Notification Rule — the FTC's own explanation of the July 2024 rule update extending coverage to non-HIPAA health apps.
- FTC & HHS: Warning on Online Tracking Technologies — joint FTC/HHS guidance on health data tracking risk, part of the same enforcement push that included the GoodRx and Premom cases.
- Apple: Consumer Health Personal Data Privacy Policy — Apple's own documentation of on-device processing and end-to-end encryption for Health app data.
AI