The pitch
Health data brokers wrap themselves in wellness rhetoric. They promise to connect your fitness tracker data with research, improve public health, or personalize your experience. The language is clean, aspirational, and deliberately vague. What they rarely say is that the business model depends on aggregating your heart rate, sleep, and activity data and selling it to insurers, employers, or marketers. Free at point of sale rarely is. The economics typically depend on aggregated health data being sold, often through partnerships disclosed in dense terms-of-service updates. This is legal in most jurisdictions and not, by itself, a scandal. It is, however, a thing the buyer should know before agreeing.
What they collect
The data points start innocently: steps, active minutes, maybe sleep duration. But the profile deepens quickly. A broker might combine your fitness app data with purchase history, public records, and location pings from your phone’s advertising identifier. An investigation by Atlas Data Privacy Corp found that a service called Locate X could track a phone’s movements using that identifier, showing whereabouts on a map. When health metrics are layered on top, the portrait becomes intimate: your stress patterns, your exercise habits, even when you are likely at home alone. The FTC has noted that data brokers operate with minimal transparency, selling information for marketing, risk mitigation, and people search. And the scale is vast—one broker might hold thousands of data points on hundreds of millions of people.
What they don’t tell you
The quiet part is about resale and model training. Your health data doesn’t just sit in one broker’s database. It gets packaged, licensed, and fed into algorithms that score you for insurance risk or employment screening. The FTC’s 2014 report on data brokers called for legislation to address the lack of transparency, and yet in 2020, 25 data broker companies spent $29 million on lobbying, rivaling the efforts of Facebook or Google. Meanwhile, opt-out mechanisms are often buried. An investigation by The Markup and CalMatters, copublished by WIRED, found at least 35 firms hiding opt-out pages from search results, making it harder for people to exercise their privacy rights. US senator Maggie Hassan is now pressing those firms to explain their practices and improve access. If the device or app offers an option to opt out of data sharing without losing functionality, take it on day one. But finding that option is the first battle.
Your move
Start with the app permissions on your phone. Remove anything the function does not require—a step counter does not need your contacts. Then check the app’s privacy settings for data-sharing toggles; turn off anything labeled “third-party sharing,” “research,” or “personalization.” If the app links to a data broker’s opt-out page, follow it. If you cannot find one, search “[company name] opt-out” and be prepared to verify your identity. The process is designed to be cumbersome, but it is the only lever you have. For location data, turn off ad tracking in your phone’s settings and reset your advertising identifier regularly. Under GDPR, you have additional rights, but enforcement is uneven. In the US, the FTC is beginning to sue location data brokers, but legislation lags. The most effective move is to treat every health app as a potential broker until proven otherwise. Read the privacy policy—clause eleven is where the real story hides.
FAQ
How do I find a data broker’s opt-out page if it’s hidden from search results?
Start by searching “[company name] opt-out” in a privacy-focused search engine. If that fails, comb through the privacy policy—look for sections titled “Your Choices” or “Data Sharing.” Some brokers require you to submit a request via email or a web form; be ready to provide identifying details to verify your identity.
Will opting out stop all data collection from my health apps?
No. Opting out typically stops the sale or sharing of your data with third parties, but the app itself may still collect and use your data for its own purposes. To limit collection at the source, revoke unnecessary app permissions and disable ad tracking in your phone’s settings.
Are health data brokers legal in the US?
Yes, with few restrictions. There is no comprehensive federal privacy law governing health data from apps and wearables—HIPAA generally doesn’t apply to these companies. The FTC has taken some enforcement actions, but the industry largely operates on a self-regulatory basis, which means your data is fair game unless you actively opt out.



