The biggest tech companies have access to your health data

Facebook, Amazon and Google are among many others that receive your health app data as standard

health app on smartphone

Sensitive data collected by popular smartphone health apps isn't being kept confidential and instead gets shared with big tech companies, a study from the British Medical Journal has revealed.

Of the 24 apps used in the study, 19 of them were found to share sensitive data such as blood pressure, Android ID, birthdays, email addresses and precise locations, with the likes of Facebook, Google and Amazon. But permissions for such data sharing were found to be well obfuscated. 

28 types of user data were identified as being shared with other companies and their parent companies too and using these data, companies could easily' piece together the true identity of a person based on multiple pieces of confidential data, said the report.

The recipients of the data were far and wide. Data was received by 55 entities and 46 parent companies, included in these were Facebook, Amazon, Google and Oracle - some of the biggest names in tech.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The study warns the data could be passed on to other bodies such as credit agencies, pharmaceutical companies and others for use in targeted advertising.

"The semi-persistent Android ID will uniquely identify a user within the Google universe, which has considerable scope and ability to aggregate highly diverse information about the user," the research team wrote in the BMJ.

Many of the apps examined in the study were free to download and one caveat was that most included explicit mention of their data sharing practises. However, much like how Facebook recently buried incriminating details of plaint text-stored user passwords and Amazon's reluctance to share details of data breaches with those affected, the mention of said practices was buried deep in the fine print of the app's user agreement.

From a legal perspective, there's no evidence of wrongdoing and it's well-known that 'free' apps come at a hidden, give-me-all-your-data price, but it's clear to see that tech companies show little respect for user privacy when it comes to the handling of its users' data from the blatant obfuscation of important information.

"Although it is well known and documented that apps use customers' data as a currency, it is particularly troubling when that data includes sensitive information such as medical records and health metrics, said Lamar Bailey, director of security research and development at Tripwire. "It is paramount that these apps clearly state in their registration process if they plan to divulge their customers' information to third parties, so that subscribers are able to opt out."

The study also identified the possibility of data sharing between fourth parties, which represent companies that are not the app developers, nor the developer's parent company. 237 entities were identified in this fourth party network comprised of various industries including advertising, marketing and telecoms corporations and of these, only three of the entities were in any way affiliated with the health sector.

Advertisement - Article continues below

The BMJ provided us with a list of the apps used in the study and Ada, an app which appears at the number 5 spot on the Google Play medical store, is among the biggest collectors of data but what the developer does with that information is unknown.

"As a digital health company based in Germany, we take data privacy and security extremely seriously and we treat all information shared with us with utmost care," said Ada in a statement. "Ada's users can remain confident no personal or individual medical data is used for commercial gain directly or indirectly."

What we do know is that the 24 apps were all among the top rated and most popular Android apps on the Google Play store under the medical category for the UK, US, Canada and Australia.

Featured Resources

How inkjet can transform your business

Get more out of your business by investing in the right printing technology

Download now

Journey to a modern workplace with Office 365: which tools and when?

A guide to how Office 365 builds a modern workplace

Download now

Modernise and transform your sales organisation

Learn how a modernised sales process can drive your business

Download now

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now
Advertisement

Most Popular

Visit/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn
cloud computing

Google Cloud snaps up multi-cloud analytics platform for $2.6bn

13 Feb 2020
Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020
Visit/security/cyber-attacks/354747/apple-mac-malware-detections-overtake-windows-the-first-time
cyber attacks

Apple Mac malware detections overtake Windows the first time

11 Feb 2020