THE INDUSTRY FILES

Healthcare

Medical records run on two clocks, and only one of them is yours: clinical retention law keeps the file for years to decades regardless of what you ask. Around the clinical core, what you looked up can become a shopping interest, and a deletion request comes back in two halves.

TRACKING PRIORITY HIGH

The record of your health; keeping the list is strongly worthwhile.

IF IT LEAKS SEVERE
EXPECT IT KEPT INDEFINITELY

Medical-records law holds clinical files for years to decades; an app is bound only by what its own policy says.

IDENTITY DEMANDED OPTIONAL

A clinic or pharmacy verifies who you are; a wellness app often asks for nothing.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

A diagnosis does not expire and cannot be reissued. Leaked, it reaches employers, insurers and family in a form you cannot deny, and the tracking cases show this data escaping without any breach at all.

What repeats in the policies

WHAT COUNTS AS MEDICAL

Health data is not one thing here

At a surgery, an online doctor or a pharmacy, the consultation and what was dispensed sit behind a medical record and, they say, stay confidential. The visit around it, your device, the pages you opened, the identifiers that follow you, lives under the ordinary commercial policy. Apps built for the same body data promise that protection only where the medical-privacy law reaches them, and where it does not, a mood log or a cycle log is ordinary company data.

WHERE IT GOES

What you looked up becomes a shopping interest

The identifiers from your visit can move to ad networks and analytics vendors. Accept the advertising cookies and the pages you opened travel with them, so the condition you looked up becomes an advertising signal rather than a medical fact. Where an employer pays for the app, the policy can hand them your name and when you last used it, and one large online pharmacy reserves your details for marketing on behalf of other organisations entirely.

WHAT STAYS

Two clocks, and only one of them is yours

How long the everyday data stays is their claim, and most name no end at all, only 'as long as necessary'; where a number appears it runs to years after your last sign-in. The medical record keeps a separate clock set by law, which in the UK reaches ten years after death for a GP record. Closing the account can clear the sign-up data within months while that record stays. An app outside those rules has no second clock, and nothing but a request ends the first.

WHEN YOU ASK

A deletion here comes back in two halves

Providers commonly clear the marketing and account data and refuse the clinical record, on continuity-of-care or records-law grounds; one says plainly that the account cannot be deleted, only suspended. The refusal is the useful half, because it names what they are keeping and why. Where no clinical record exists there is nothing to refuse, and what comes back is whatever they judged necessary.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileHealth Identity Documents maybeMessages maybePurchases maybeLocation maybeFinancial maybePhotos & Biometrics maybe

Identity documents sit at a maybe because an app asks for none. At a surgery, an online doctor or a pharmacy the ID check is routine, and the file it opens is the one kept longest.

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Health HIGHLY LIKELY

Diagnoses, prescriptions, and visits are the record itself.

Mental health LIKELY

Therapy notes and mood tracking sit in the same file.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

medical records 8 TO 25 YEARS LAW SETS IT

Health-records law sets long minimum retention for clinical data.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

Independent testers found advertising trackers on a third of the largest US hospital websites, firing when a person booked an appointment, and inside the password-protected patient portals of several health systems. In those documented cases the tracking reached the records the confidentiality promise is meant to cover.

SOLD OR SHARED POSSIBLE

Regulated care rarely sells you, but wellness apps have shared health data with advertisers.

AI TRAINING MODERATE

Clinical notes and app data train diagnostic and wellness models; documented, and sensitive.

Even anonymised, this can still be you

Anonymised is their word, and health data is where that word first failed: in 1997 a researcher re-identified a US governor's supposedly anonymous hospital record using only his postcode, date of birth, and sex (Sweeney, 2000).

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Payment patterns SOMETIMES

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write SOMETIMES

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice SOMETIMES

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“to the extent any data is considered protected health information, under HIPAA where applicable”

Only the data inside the consultation is treated as medical and kept confidential. The sign-up forms, the intake questions, the browsing and the app usage all fall under the ordinary commercial policy instead. The wording borrows the US medical-privacy law's name while limiting how much of your data it actually covers.

THE MOVE A request makes them state, in their own words, which of your data they treat as medical and which they do not. Their reply goes on your record.

“following the Records Management Code of Practice and the NHS records retention schedule”

The retention promise points away from the policy to a separate NHS schedule the reader never sees on the page. That schedule keeps medical records for years, a GP record for ten years after death, so the record outlives the account and any request to close it.

THE MOVE A request puts the period, and what it covers, in their own words on your record.

“we keep a document which tells us how long we need to keep this information”

The retention answer exists and is not on the page. The policy points at an internal schedule and offers it if you get in touch, so how long your dispensing or consultation record is held is not something reading the policy can tell you.

THE MOVE Asking for that schedule is a request of its own, and it is answered in writing. Their reply goes on your record.

From the Dispatch

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →