Whether you text your pharmacy for a prescription refill, visit a reproductive health clinic, message your doctor on an online patient portal, or have a teletherapy appointment, your health care providers are generally prohibited from sharing your health information without your permission. That’s thanks to the Health Insurance Portability and Accountability Act (HIPAA).
HIPAA was passed 30 years ago, paving the way for the associated privacy and security rules that established boundaries on the use and disclosure of certain health information. HIPAA’s privacy requirements have been so ingrained that the acronym has come to serve as shorthand for confidential. “We can’t share that information – HIPAA!”
But in a modern digital health ecosystem, HIPAA’s protections fall short – notably not extending to most apps, wearables, cell phone location data, and more. And the resulting risks are magnified, especially as corporate profiteering and government exploitation go unchecked. To mark HIPAA’s 30th anniversary, we’ve compiled a list of 30 ways health privacy is being threatened.
30 Threats to Health Privacy in the Digital Age
HIPAA provides a critical foundation for health privacy, but does not sufficiently respond to modern technologies or safeguard all sensitive data.
1. There is widespread misunderstanding that HIPAA protects all health data, but health information is no longer confined to medical records.
We have a much expanded universe of smartphone and mobile apps, remote monitoring devices, wearables, and other consumer-facing apps that help to collect, share, manage, and use one’s health data. Much of the data currently being generated and used for health and care is not protected by HIPAA. Indeed, the same data might or might not have HIPAA protections depending upon who creates or stores it.
2. HIPAA does not go far enough to protect sensitive data from law enforcement access.
The 2000 HIPAA Privacy Rule allows individual health care providers to decide whether or not to disclose protected health information to law enforcement. This leaves patients without the protections they need to trust that their reproductive health information is not used against them amid the broader landscape of health care criminalization. Marginalized communities that are already over-surveilled and over-policed, including people of color, low-income people, and immigrants, are disproportionately at risk.
3. New technologies generating and collecting health information are not legally required to protect consumer data, creating immense privacy and discrimination risks.
There are few guardrails in place to prevent technology companies from disclosing or selling health data to third parties, including data brokers, advertisers, and law enforcement. This is particularly important as location data, browsing and purchase history, and other information not traditionally thought of as health data are increasingly used to draw inferences about health status and influence access and cost of care.
4. The lack of a comprehensive federal privacy law means that Americans face a fragmented landscape of privacy protections that leaves their personal data exposed.
This gap results in a patchwork of sector-specific laws, state consumer privacy regulations, and technology companies setting their own privacy terms and conditions, while many types of data are not protected at all.
The lack of guardrails around corporate greed and government misuse of data harms patient privacy and safety
5. The widespread commercial “notice and consent” standard fails to protect consumer data privacy.
Companies must inform users about data collection and use and get their permission before processing personal information, but most people do not review companies’ complex, often intentionally confusing privacy policies before agreeing, and fail to realize their data is being shared and sold.
6. Data brokers amass and sell troves of data gathered from wellness and fitness apps, location history, and other sources, often without user knowledge or consent.
Third-party advertisers and insurance companies often purchase this data to charge people more for insurance policies or target vulnerable individuals with manipulative ads and predatory medical scams.
7. Technology companies and data brokers unlawfully sell sensitive health and location data to federal, state, and local law enforcement.
These data practices facilitate warrantless government surveillance and put people at risk of legal action.
8. Data breaches expose the sensitive medical records of tens of millions of Americans each year.
The past few years have seen some of the biggest health-related data breaches, including Change Healthcare in 2024, which comprised the PHI of 192.7 million, and Conduent Business Services in 2025, which comprised more than 62 million Americans’ health information.
9. Health care providers are targeted for ransomware attacks.
One particular type of breach is a ransomware attack, which has risen dramatically in recent years (a 278% increase between 2018 and 2023). The health care industry is particularly susceptible to ransomware attacks due to the value of health data in illegal markets and providers’ urgency for information access to be restored.
10. People’s sensitive data is feeding generative artificial intelligence (AI) models in ways that exacerbate privacy concerns.
AI companies can legally purchase the same troves of sensitive data that insurers and law enforcement can, or just ask people to share their medical information. Elon Musk invited people to submit their X-rays, MRIs, or other medical images to Grok, its generative AI bot, for analysis.
11. Companies use “bossware” like workplace monitoring platforms and AI to surveil workers and share their personal data with third parties.
Some companies have disclosed employee data to Big Tech and major advertisers, and Meta allegedly used AI to target workers who took maternity or disability leave for layoffs.
The lack of comprehensive health privacy protections puts patients at risk of criminalization and undermines access to reproductive health care
12. Law enforcement uses medical records and electronic data to investigate and prosecute people for their reproductive health care and pregnancy outcomes.
Especially in the wake of the Dobbs v. Jackson Women’s Health Organization decision overturning the federal constitutional right to abortion, there are heightened risks of reproductive health data being weaponized to criminalize patients.
13. The Trump administration refused to defend the 2024 HIPAA Privacy Rule for Reproductive Health
The 2024 HIPAA Privacy Rule safeguarded reproductive health records and lessened the risk of patients being reported to law enforcement for their abortion care and pregnancy outcomes. The Department of Justice declined to appeal a district court ruling that took these protections against criminal inquiries away from patients nationwide.
14. The “data broker loophole” enables law enforcement to violate the Fourth Amendment’s protection against unlawful search.
Local police, sheriffs, and prosecutors are sidestepping the requirement to obtain a court’s approval for investigations (i.e., a warrant or subpoena) and are instead using location information, communications metadata, or web browsing data to investigate patients. Law enforcement can buy sensitive information from data brokers to build cases against people for seeking or facilitating reproductive health care.
15. Anti- abortion crisis pregnancy centers (CPCs) collect and store reproductive health data on pregnant people.
CPCs are not HIPAA-covered entities and often deceive abortion seekers about their privacy practices, leaving sensitive information vulnerable to misuse by anti-abortion networks, data breaches, and disclosure to law enforcement.
16. The Department of Health and Human Services launched Moms.gov to funnel users to a tool that collects unprotected data on pregnant people.
Heartbeat International – an anti-abortion organization with a history of data breaches exposing private health information down to the date of people’s last menstrual period – operates this data collection system and hundreds of CPCs across the country.
Authoritarian leaders are exploiting our sensitive information in new, destructive ways
17. Big Tech billionaires have unprecedented influence over and presence within the current administration.
From front-row seating at the inauguration to key leadership positions to behind-the-scenes personal and financial influence, a handful of big tech billionaires loom large on the Administration’s actions related to health data and privacy.
18. The Trump administration is building an inter-agency data arsenal for mass surveillance under the “Stopping Waste, Fraud, and Abuse by Eliminating Information Silos” executive order.
The Department of Government Efficiency’s (DOGE) consolidation of sensitive data empowers the government to target marginalized communities and political opponents by denying them public services and benefits, including medical care.
19. Palantir is building dossiers on Americans on behalf of the Trump administration.
The company’s big data analytics and AI products paved the way for the administration to use personal information, including health and insurance records, to advance their political agenda.
20. The proliferation of wearable health technologies without adequate privacy features expands mass surveillance,
undermines civil rights, endangers vulnerable communities, and exploits consumers. From Meta’s facial recognition glasses to Oura ring’s partnership with Palantir, the potential for data weaponization is alarming.
21. The Trump Administration handed over the data of 79 million Medicaid users to U.S. Immigration and Customs Enforcement (ICE),
in violation of HIPAA privacy protections and other federal laws. This disclosure is part of a broader effort to force federal agencies and programs (including the Temporary Assistance for Needy Families and the Internal Revenue Service) to hand over immigrants’ personal information to ICE, creating a dangerous precedent where information gathered from essential public services is weaponized against immigrants.
22. ICE is misusing a range of health data, including federal Medicaid data and insurance and medical billing data from third-party brokers, to track down people for deportation.
ICE’s tactics, including contracting with Palantir for data analytics to facilitate mass deportations, threaten undocumented immigrants and their families and erodes trust in public health.
23. ICE uses smartwatches to track pregnant women even during labor and delivery,
exacerbating fear and undermining care. ICE surveillance requirements leave immigrant patients too scared to remove the device, even when recommended by providers, given risks of deportation and family separation.
24. The Centers for Medicare & Medicaid Services promotes shady apps to Medicare beneficiaries.
The administration’s Medicare app library raised security concerns when launched given the risks of sharing sensitive patient information with companies that are not covered by HIPAA. Advocates’ fears were verified when later reporting found several of the apps to be using online tracking technologies to send user data to third-party companies.
25. The Department of Justice attempted to seize the private medical records of trans youth as part of a broader attack on gender-affirming care.
The Department of Justice sought identifying information and sensitive health data to harass and intimidate patients and providers.
26. The Office of Personnel Management can now collect the medical records of millions of federal workers, retirees, and their families.
The recent agency regulation leaves the door open for the Trump administration to identify and discipline or target federal workers who do not adhere to its political agenda.
27. Department of Health and Human Services Secretary Robert F. Kennedy Jr. Kennedy is seeking personal medical records to use for vaccine research.
This is another means of exploiting records held by state information exchanges to push a debunked agenda and fake science.
28. The Consumer Product Safety Commission pressured hospitals to share personally identifiable health data with a private contractor.
Officials are using threats of “information blocking” to pressure hospitals to share data of all patients coming through emergency departments as part of the National Electronic Injury Surveillance System.
29. The Trump administration is dismantling federal agencies responsible for protecting data privacy and taking legal action against companies for mishandling consumer data, including the misuse of health and fertility data.
From weakening the authority of the Federal Trade Commission to dismantling the Consumer Financial Protection Bureau, the administration is weakening agencies’ ability to curb harmful corporate data practices.
30. Sacrificing privacy and confidentiality to require information exchange puts patients at risk.
Appropriate and secure information sharing between health care team members should be the standard of care, but never at the expense of patient privacy. Any renewed efforts from the Trump administration to revisit HIPAA and require information sharing are terrifying at a time when people are being targeted and punished for their health care decisions.
Privacy Protections to Meet the Moment
HIPAA never went far enough to protect health privacy. What’s needed is no longer just a floor of privacy protections, but bold and visionary privacy laws that keep pace with the changing digital and political landscape. Medical information should no longer be currency for corporate greed, fuel political targeting, or be exploited to criminalize health care.
We cannot truly have health privacy without a comprehensive federal data privacy law. The lack of federal protections leaves people without sufficient guardrails to prevent their personal information from being exploited. Minimizing unnecessary data collection and sharing, closing the data broker loophole, and stopping health surveillance are key among sorely needed reforms.
Thirty years after HIPAA became law, it is far past time for federal lawmakers to take action to strengthen our privacy laws.
