ARTICLE
10 February 2023

Privacy Concerns For Health Apps

DM
Duane Morris LLP

Contributor

Duane Morris LLP, a law firm with more than 800 attorneys in offices across the United States and internationally, is asked by a broad array of clients to provide innovative solutions to today's legal and business challenges.
Free health apps – often funded by advertising revenue – may result in disclosure of private health information to third parties without permission from consumers.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Free health apps - often funded by advertising revenue - may result in disclosure of private health information to third parties without permission from consumers.

A company that operates a health app or collects consumer health data should analyze how ad-tracking tools are used within their ecosystem. In 2021, the Federal Trade Commission ("FTC") issued a policy statement clarifying mobile health app makers' obligations to notify consumers if their data is exposed or shared without their permission, and the FTC stated that the policy was meant to fill a "gap" in regulations for health apps which generally are not covered by the Health Insurance Portability and Accountability Act ("HIPPA").

Failure to fulfil these obligations may result in a government action, such as an action by the FTC which: (1) has authority over businesses that collect health information under the FTC Act and (2) may bring enforcement actions regarding deceptive claims about the use or disclosure of health data. Recent federal and state enforcement actions include:

  • FTC action: Flo Health Inc. settled FTC allegations that the company shared health information of its users with outside data analytics providers after promising such information would be kept private. The FTC filed the Complaint against Flo Health asserting that Flo Health: (1) disclosed health data from millions of users of its Flo Period & Ovulation Tracker app to third parties that provided marketing and analytics services to the app, including Facebook's analytics division and Google's analytics division, (2) disclosed sensitive health information, such as the fact of a user's pregnancy, to third parties in the form of "app events," which is app data transferred to third parties for various reasons and, (3) did not limit how third parties could use this health data.
  • California AG action: Glow Inc. settled a probe by the California Attorney General regarding its fertility-tracking mobile app that stores personal and medical information. The Attorney General's Complaint alleged that the app: (1) failed to adequately safeguard health information, (2) allowed access to user's information without the user's consent, and (3) had additional security problems with the app's password change function that could have allowed third parties to reset user account passwords and access information in those accounts without user consent. Within the settlement, Glow was required to: (1) incorporate privacy and security design principles into its app and (2) obtain affirmative consent from users prior to sharing or disclosing personal, medical, or sensitive information and require the users to revoke previously granted consent.

In sum, a company that operates a health app or collects consumer health data should analyze how ad-tracking tools are used within their ecosystem.

Disclaimer: This Alert has been prepared and published for informational purposes only and is not offered, nor should be construed, as legal advice. For more information, please see the firm's full disclaimer.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More