Someone Is Selling Your Medical Secrets — Here's Who, How, and How to Stop Them
Most Americans assume their medical records are private. They trust that the information shared with a physician — a diabetes diagnosis, a prescription for antidepressants, a genetic test ordered by a specialist — remains confined to the clinical relationship. That assumption is largely wrong.
A sophisticated and largely invisible industry has built a multi-billion-dollar business around the collection, aggregation, and resale of health-related data. These companies operate legally, exploit gaps in federal privacy law, and profit from information that most people would consider deeply personal. Understanding how this system works is not merely an exercise in outrage — it is a prerequisite for protecting yourself.
How Health Data Brokers Acquire Your Information
The Health Insurance Portability and Accountability Act, commonly known as HIPAA, is frequently cited as the bedrock of medical privacy in the United States. And within its defined scope, it does provide meaningful protections. The critical limitation, however, is that HIPAA applies only to what regulators call "covered entities" — hospitals, insurers, and healthcare providers — and their direct business associates.
A staggering volume of health-related data flows outside that regulatory perimeter entirely.
When you purchase over-the-counter medication at a pharmacy, that transaction is typically captured by loyalty program tracking. When you use a fitness application to log symptoms or monitor a chronic condition, that data may be governed by the app's terms of service rather than HIPAA. When you submit a DNA sample to a consumer genealogy service, the resulting genetic profile enters a commercial ecosystem with its own privacy rules — rules that the company itself wrote.
Data brokers acquire information through several overlapping channels: purchasing transaction records from retailers and pharmacies, licensing data from app developers, aggregating public records including insurance claim filings, and buying datasets from other brokers in a practice known as data layering. The result is a remarkably detailed composite portrait of an individual's health status — often more comprehensive than any single physician's records.
The Major Players You Should Know
Several companies dominate this space, and naming them is important. Transparency is one of the few tools available to individuals navigating this landscape.
Acxiom is among the largest data brokers in the world, maintaining profiles on hundreds of millions of Americans. The company offers a consumer opt-out portal at acxiom.com/optout, though the process requires submitting personal information — an irony that is not lost on privacy advocates.
LexisNexis Risk Solutions aggregates data from public records and commercial sources, including health-adjacent information. Consumers can submit data access and deletion requests through the company's consumer center.
Experian — better known as a credit bureau — also operates a significant data brokerage division that includes health and lifestyle categorizations. Its marketing services opt-out is accessible through optoutprescreen.com for credit-related data, with additional opt-out mechanisms available through Experian's own consumer portal.
IQVIA (formerly IMS Health) is a specialized health data broker that works primarily with pharmaceutical and healthcare industry clients, trading in prescription-level data sourced from pharmacies. Consumer-facing opt-out mechanisms here are limited, but the company does maintain a privacy inquiry process.
Epsilon maintains extensive lifestyle and health-interest profiles and offers a consumer opt-out through its website.
The Data & Marketing Association's Digital Advertising Alliance also operates a centralized opt-out tool at optoutmachines.com that covers numerous participating companies simultaneously — a useful starting point, though not comprehensive.
What the Law Currently Allows — and Doesn't
Federal law has not kept pace with the data brokerage industry. HIPAA's limitations are structural: it was designed to govern clinical data flows, not the commercial marketplace that has developed around health-adjacent information.
State law, however, is beginning to fill some of these gaps. California's Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), grant state residents the right to know what data a company holds, request deletion, and opt out of sale. Virginia, Colorado, Connecticut, Utah, and Texas have enacted similar frameworks, with varying degrees of strength.
For residents of states without comprehensive privacy legislation, the Federal Trade Commission Act provides a narrower avenue — the FTC has pursued enforcement actions against data brokers for deceptive practices, though its authority to mandate opt-out rights is constrained.
Genetic data deserves separate consideration. Several states, including California, Texas, and Illinois, have enacted specific genetic privacy statutes. Before submitting a DNA sample to any consumer service, reviewing both the company's privacy policy and your state's applicable law is strongly advisable.
A Practical Action Plan
Knowing that the problem exists is insufficient. The following steps represent a structured approach to limiting health data exposure.
Step 1: Audit your digital health footprint. Compile a list of every health-related application, loyalty program, wearable device, and consumer genetics service you have used. Each represents a potential data source.
Step 2: Submit opt-out and deletion requests. Using the portals identified above — Acxiom, LexisNexis, Experian, Epsilon — submit formal requests. If you reside in a state with a comprehensive privacy law, explicitly invoke your statutory rights in the request. Companies are legally required to respond within defined timeframes under applicable state statutes.
Step 3: Leverage the National Opt-Out Registry for certain data types. The Direct Marketing Association's consumer assistance program at dmachoice.org allows opt-out from certain categories of marketing data use.
Step 4: Review pharmacy loyalty programs. Major pharmacy chains including CVS, Walgreens, and Rite Aid operate loyalty programs that capture prescription purchase behavior. Review the privacy policies of any program you participate in and consider whether the benefits justify the data exchange.
Step 5: Scrutinize health app permissions. Under iOS and Android settings, audit what data health applications are permitted to access and share. Delete applications whose data practices are opaque or whose terms of service permit broad commercial use of health information.
Step 6: Consider a consumer genetics moratorium. If you have not yet submitted a DNA sample to a consumer service, the privacy calculus is worth careful consideration. If you have, review the company's current data retention and sharing policies and exercise any available deletion rights.
The Broader Stakes
The consequences of health data exposure extend well beyond inconvenience. Health information can influence insurance underwriting decisions, affect employment screening, and in some cases inform credit evaluations. The correlation between a person's medical profile and their economic vulnerability is not theoretical — it is a documented risk.
Privacy in the context of health is not a luxury preference. It is a condition for genuine autonomy. The industry that has developed around monetizing medical information operates with legal permission but without moral clarity. Closing the gap between what is permitted and what is acceptable requires both individual action and sustained regulatory attention.
In the meantime, the steps outlined above represent the most effective tools currently available to American consumers. Using them is an act of self-determination in a landscape designed to discourage it.