The consent era arrives for health apps
An FTC intervention on tracking-technology consent, new HIPAA rules and a wave of state sensitive-health-data laws are converging on the same practice: the advertising pixel quietly sitting inside a health flow.
On 10 August 2026 the FTC weighed in on consent requirements for tracking technologies — two weeks after suing Hims & Hers over health data allegedly shared with Meta and Snap. Combined with new HIPAA regulations, state sensitive-health-data laws and broadened FTC breach-notification rules, the compliance floor for anyone handling health-adjacent data has moved sharply.
The facts, in brief
| FTC guidance | 10 August 2026 — consent for tracking technologies |
| Context | FTC v. Hims & Hers filed 29 July 2026 |
| Also in play | New HIPAA regulations; state sensitive-health-data statutes; broadened FTC breach-notification rules |
| Practice targeted | Advertising pixels and SDKs inside health flows |
What's actually shifting
For a decade the working assumption in consumer health software was that data became protected only when a covered entity touched it. Everything else — a symptom search, a supplement order, a mood log — was ordinary consumer data, and ordinary consumer data gets a pixel.
Three forces are closing that gap at once: federal enforcement that treats deceptive privacy promises as an unfair practice, state statutes that define sensitive health data broadly and don't care whether you're a covered entity, and breach-notification rules with a wider reach. The FTC's August intervention on tracking-technology consent is the piece that speaks directly to implementation.
What we found when we looked
We run a network capture on first launch for every app we test. The category median has been three third-party SDKs on launch, and we've flagged apps requesting location permission with no plausible use for it — six of twenty-two sleep apps in our most recent permission audit. Two dropped the request within a week of our email. Four did not.
None of that is unlawful on its face. It is, however, exactly the surface area that this regulatory wave is aimed at, and companies that treated it as a growth-team decision are about to discover it was a legal one.
What you can do now
Open the privacy settings of every health app you use and look for an analytics or advertising toggle — most have one, few advertise it. Then check whether the app offers a real data export and a deletion request that gets acknowledged. In our testing, the presence of a working deletion path is the single best predictor of everything else being handled decently.
third-party SDKs on first launch — the category median in our teardowns. Most users have never been asked about any of them.Applandica privacy teardowns
Applandica's read
Tomás Villaseca · Data & Privacy LeadI've been running these teardowns for three years and this is the first period where I've felt the wind change. What used to be a footnote in a review — "drops a Meta pixel on the symptom screen" — is now the substance of a federal complaint.
My prediction, for what it's worth: the next twelve months bring a lot of quiet SDK removals and very few announcements. Nobody publishes a blog post saying they've stopped sending your health data to an ad network. Which is precisely why we'll keep re-running the captures and publishing what changed.
Frequently asked questions
What did the FTC say about tracking technologies?
In August 2026 the FTC addressed consent requirements for tracking technologies, following its late-July action against Hims & Hers over health data allegedly shared with advertising platforms.
Does HIPAA cover health apps?
Often not. Many consumer health apps are not covered entities, which is why state sensitive-health-data statutes and FTC enforcement — which reach beyond HIPAA — are the relevant pressure here.
How do I know if an app is sharing my health data?
You usually can't see it directly. Practical proxies: look for an analytics or advertising opt-out in settings, check whether the app offers genuine data export, and see whether a deletion request is acknowledged and completed.
Sources
- Nixon Peabody — FTC enters the conversation regarding consent for tracking technologies, 10 August 2026. Accessed 1 Sep 2026
- Coblentz Law — Updates to U.S. health-data privacy and wearable tech. Accessed 1 Sep 2026
- Troutman Pepper Locke — Wellness trackers, “medical” status and cybersecurity: how FDA, FTC and state laws interlock. Accessed 1 Sep 2026
FTC sues Hims & Hers over health data sent to Meta and Snap
The complaint pairs the two failures we log most often — advertising trackers on sensitive health data, and a…
AnalysisFDA steps back from wearables and AI health software
A January guidance shift means many wearables and AI health tools can reach the market without formal device review.…