Independent since 2023  ·  No affiliate links.  ·  We buy every subscription ourselves. New York, NYIssue No. 148
Home / News / Privacy
AnalysisPrivacy

The consent era arrives for health apps

An FTC intervention on tracking-technology consent, new HIPAA rules and a wave of state sensitive-health-data laws are converging on the same practice: the advertising pixel quietly sitting inside a health flow.

By Tomás Villaseca Published 14 August 2026 Verified 1 Sep 2026 6 min read
What happened

On 10 August 2026 the FTC weighed in on consent requirements for tracking technologies — two weeks after suing Hims & Hers over health data allegedly shared with Meta and Snap. Combined with new HIPAA regulations, state sensitive-health-data laws and broadened FTC breach-notification rules, the compliance floor for anyone handling health-adjacent data has moved sharply.

The facts, in brief

FTC guidance10 August 2026 — consent for tracking technologies
ContextFTC v. Hims & Hers filed 29 July 2026
Also in playNew HIPAA regulations; state sensitive-health-data statutes; broadened FTC breach-notification rules
Practice targetedAdvertising pixels and SDKs inside health flows

What's actually shifting

For a decade the working assumption in consumer health software was that data became protected only when a covered entity touched it. Everything else — a symptom search, a supplement order, a mood log — was ordinary consumer data, and ordinary consumer data gets a pixel.

Three forces are closing that gap at once: federal enforcement that treats deceptive privacy promises as an unfair practice, state statutes that define sensitive health data broadly and don't care whether you're a covered entity, and breach-notification rules with a wider reach. The FTC's August intervention on tracking-technology consent is the piece that speaks directly to implementation.

What we found when we looked

We run a network capture on first launch for every app we test. The category median has been three third-party SDKs on launch, and we've flagged apps requesting location permission with no plausible use for it — six of twenty-two sleep apps in our most recent permission audit. Two dropped the request within a week of our email. Four did not.

None of that is unlawful on its face. It is, however, exactly the surface area that this regulatory wave is aimed at, and companies that treated it as a growth-team decision are about to discover it was a legal one.

What you can do now

Open the privacy settings of every health app you use and look for an analytics or advertising toggle — most have one, few advertise it. Then check whether the app offers a real data export and a deletion request that gets acknowledged. In our testing, the presence of a working deletion path is the single best predictor of everything else being handled decently.

3

third-party SDKs on first launch — the category median in our teardowns. Most users have never been asked about any of them.Applandica privacy teardowns

Applandica's read

Tomás Villaseca · Data & Privacy Lead

I've been running these teardowns for three years and this is the first period where I've felt the wind change. What used to be a footnote in a review — "drops a Meta pixel on the symptom screen" — is now the substance of a federal complaint.

My prediction, for what it's worth: the next twelve months bring a lot of quiet SDK removals and very few announcements. Nobody publishes a blog post saying they've stopped sending your health data to an ad network. Which is precisely why we'll keep re-running the captures and publishing what changed.

Frequently asked questions

What did the FTC say about tracking technologies?

In August 2026 the FTC addressed consent requirements for tracking technologies, following its late-July action against Hims & Hers over health data allegedly shared with advertising platforms.

Does HIPAA cover health apps?

Often not. Many consumer health apps are not covered entities, which is why state sensitive-health-data statutes and FTC enforcement — which reach beyond HIPAA — are the relevant pressure here.

How do I know if an app is sharing my health data?

You usually can't see it directly. Practical proxies: look for an analytics or advertising opt-out in settings, check whether the app offers genuine data export, and see whether a deletion request is acknowledged and completed.

Sources

Tomás Villaseca

Data & Privacy Lead

Runs Applandica's teardowns: network captures, SDK inventories, permission audits and the deletion requests we file on every app. Maintains the pricing-history database behind our intelligence work.

Corrections. We publish corrections at the foot of the story, dated and signed, and leave them there. Spotted an error? corrections@applandica.com. This report summarises publicly reported events; allegations described as allegations remain unproven unless a court or regulator has ruled.