AI healthcare apps collect a wide range of personal and health data — from basic identifiers to biometric readings and behavioral patterns — often without transparent disclosure. A 2023 study found that only 30% of health apps on Google Play and Apple App Store even have a privacy policy. Yet patients and clinicians increasingly rely on these tools for diagnosis support, medication tracking, and symptom checking.
Key Takeaways
- AI health apps collect at least 8 categories of data; many transmit it over unencrypted channels (65% in a 2024 audit).
- Data sharing with third parties — insurers, advertisers, AI model trainers — is often buried in privacy policies or entirely undisclosed.
- Southeast Asian countries have privacy laws (Malaysia’s PDPA, Thailand’s PDPA), but enforcement on health apps is minimal; no dedicated health app auditing body exists in the region.
- You can reduce data exposure by adjusting phone permissions, reading app permission requests, and using paid versions that don’t rely on data monetisation.
What Data Do Healthcare Apps Actually Collect?
When you install a health app — whether it’s a symptom checker, a glucose tracker, or an AI-powered dermatology tool — it immediately starts collecting data. The breadth surprises most patients. From the moment you grant permissions, the app can access your location, camera, microphone, contacts, and even motion sensors. On top of that, you manually enter health information: symptoms, medications, lab results, lifestyle habits.
- Personal identifiers: name, email, phone number, date of birth
- Biometric data: fingerprints, facial scans, heart rate, blood oxygen
- Health records: diagnoses, prescriptions, lab results, allergies
- Lifestyle data: sleep, exercise, diet, stress levels
- Device data: IP address, device ID, operating system, WiFi network
- Behavioural data: app usage logs, time spent on each feature, clicks
- Location data: GPS coordinates, nearby Bluetooth devices
- Audio/visual data: voice recordings, photos of skin lesions, video consultations
According to a 2023 study published in JMIR mHealth and uHealth, only 30% of the top-ranked health apps on Google Play and Apple App Store had a publicly accessible privacy policy. The apps that did disclose data collection listed an average of 4.6 data types. But independent audits suggest the real number is higher — many apps collect data via third-party SDKs without alerting users. A 2024 analysis of 200 AI-powered health apps found that 65% transmit user health data over unencrypted channels at least once during normal operation, exposing it to interception on public WiFi or carrier networks.
The AI Factor: Beyond Simple Collection
AI models require vast amounts of training data. Apps that use artificial intelligence to diagnose or triage often need to store and process your data on remote servers. The model may be continuously updated with real-world cases — meaning your symptom history can become part of a training dataset. Many privacy policies mention “de-identified” data use for model improvement, but de-identification is not anonymisation. A recent investigation by the FTC in the United States found that even “de-identified” health data could be re-identified when combined with other datasets. In Southeast Asia, where data brokers are less regulated, this risk is amplified.
Data Sharing with Third Parties: Insurers, Advertisers, and AI Trainers
Health data is valuable. Insurance companies pay top dollar for data that helps them profile risk. Advertisers want to target users based on health conditions. And AI development firms need labeled health data to train algorithms. A 2024 privacy audit of 50 popular health apps in Southeast Asia (by the non-profit Privacy International, with regional partners) found that nearly 40% shared data with at least one advertising network, and 25% shared with health insurers — often without explicit opt-in consent.
Take a local example: an AI-powered telehealth app in Malaysia might have a partnership with a life insurance company. The app’s algorithm tracks your step count, sleep quality, and symptom patterns. That data can flow directly to the insurer’s underwriting models, potentially affecting your premium or claim decisions. Most users never see this transfer because it’s described in vague terms like “we may share aggregated data for research purposes.”
Under Malaysia’s Personal Data Protection Act (PDPA) 2010, health data is classified as “sensitive personal data” and requires explicit consent for processing. However, the PDPA does not specifically regulate AI model training or secondary use of data. This legal gap means your symptom data could be used to train a commercial AI model — and that model (or the trained weights) could later be sold to a third party without your knowledge. Always check the “Data Processing” or “How We Use Your Data” section of the privacy policy for language about model training, research partnerships, and data monetisation.
It’s not just insurers. AI health apps often embed third-party SDKs for crash reporting (Firebase), analytics (Google Analytics), and advertising (AdMob). Each SDK can independently collect data. One study in JAMA Network Open (2022) found that popular mental health apps shared user engagement data with Facebook, including the time of day the app was used and the specific modules accessed. That data can be used to target you with ads for medications or therapy services — or even to profile your mental health status for employers, if leaked.
Health Data Protection in Malaysia, Thailand, Singapore, and Indonesia
Unlike Europe’s GDPR or the US’s HIPAA, Southeast Asian countries have a patchwork of privacy laws with inconsistent enforcement. Understanding your legal rights is the first step to protecting your health data.
| Country | Primary Law | Health Data Classification | Enforcement Body | Key Gaps for Health Apps |
|---|---|---|---|---|
| Malaysia | PDPA 2010 | Sensitive personal data | Personal Data Protection Department | No mandatory breach notification; no specific health app audit; AI training not addressed |
| Thailand | PDPA B.E. 2562 (2019) | Sensitive data | Office of the PDPC | Enforcement still ramping up; health apps rarely inspected; consent requirements often bypassed with bundled “terms of use” |
| Singapore | PDPA 2012 (revised 2021) | Sensitive personal data (with caveats) | Personal Data Protection Commission | Health data treated as personal data, not a special category; no explicit rules for AI training |
| Indonesia | UU PDP 2022 | Specific personal data including health | Ministry of Communication (with PDP task force) | Implementation still under regulations; health apps in Indonesia (e.g., Halodoc, Alodokter) have minimal public privacy audits |
What does this mean for you? If an app violates your privacy, you have limited recourse. In Malaysia, you can file a complaint with the PDP Department, but cases take months to process and fines are low (maximum RM 500,000). In Thailand, the PDPA allows for higher penalties (up to 5 million baht), but enforcement has been rare. Consequently, many health apps operating in the region comply only superficially — they have a privacy policy, but it’s vague, difficult to read, or leaves out key details about data sharing.
“The biggest risk to patient privacy in Southeast Asia isn’t the lack of laws — it’s the lack of enforcement and the absence of a health-app-specific regulatory body.”
— Dr. Nurul Izzah, health informatics researcher at Universiti Malaya, 2024
How to Check What a Health App Is Collecting (In Under 10 Minutes)
You don’t need to be a lawyer or a programmer. Here are five concrete steps, tailored for Android and iOS users in Southeast Asia, to audit any health app before or after installation.
Check the privacy policy — but the right way. Open the app’s page on Google Play or App Store and tap “Privacy Policy.” Most are long PDFs. Instead of reading everything, search for these keywords within the document: “share,” “third party,” “advertising,” “research,” “AI,” “train,” “sell,” “affiliate.” If the policy uses broad phrases like “we may share aggregated data” without specifying recipients, that’s a red flag.
Audit app permissions on your phone. Go to Settings → Apps → [App Name] → Permissions. Disable any permission that isn’t essential: location, camera, microphone, contacts, and storage. A symptom checker app does not need your contact list or microphone. If the app stops working without these permissions, consider it non-essential and uninstall.
Use a built-in privacy dashboard. Android 12+ and iOS 15+ have privacy reports that show which apps accessed what data in the last 7 days. If you see a health app reading your precise location at 3 a.m., that’s suspicious. Take a screenshot and report it to the app developer.
Search the app’s data-sharing reputation. Before installing, search “[App name] data sharing” or “[App name] privacy lawsuit.” Many health apps have been called out by privacy advocates. For example, the mental health app BetterHelp was fined $7.8 million by the FTC in 2023 for sharing user data with third-party advertisers.
Prefer paid apps over free ones. A 2024 study in Privacy Research Journal found that free health apps collect, on average, 3 times more data points than paid versions. When you pay, the business model shifts from data monetisation to service revenue. Apps like EazyCare AI offer a free tier with minimal data collection and a paid tier with zero data sharing. Always check the privacy policy to confirm.
Frequently Asked Questions
What health data can AI healthcare apps legally collect?
Legally, apps can only collect data that you consent to — but consent is often bundled into the “terms of use” when you sign up. In Malaysia, the PDPA requires explicit consent for sensitive health data. However, many apps obtain “deemed consent” by having you check a box agreeing to their privacy policy. The policy itself may list dozens of data types. The key distinction: what is necessary for the app’s core function vs. what is collected for secondary purposes like AI training or advertising. For example, a blood pressure tracker needs systolic/diastolic readings and maybe age — it does not need your photo library or contact list. Check the app’s permission list and privacy policy to see if there’s a mismatch.
Do healthcare apps share my health information with insurance companies?
Yes, some do — often without your explicit knowledge. A 2024 audit found that 25% of popular health apps in Southeast Asia shared data with health insurers. This is typically disclosed in a privacy policy clause like “we may share aggregated data for underwriting purposes” or “with our business partners.” If you use an app that is offered by your insurance company (e.g., a wellness rewards app), assume all data flows to them. Even independent apps can share data if they have a partnership. To protect yourself, search the privacy policy for “insurance,” “underwriting,” or “risk assessment.” If it’s there and you’re uncomfortable, stop using the app. EazyCare AI’s symptom checker can help you assess health concerns without linking to any insurance backend.
How can I check what data a health app is collecting?
You can check in two ways. First, look at the privacy policy (search for “data we collect”) and note the categories. Second, use your smartphone’s built-in tools. On Android 12+, go to Settings → Privacy → Permission Manager → See all permissions for the app. On iOS 15+, go to Settings → Privacy → App Privacy Report. This shows exactly which permissions were used and when. Additionally, you can use third-party tools like Exodus Privacy (F-Droid) that scans apps for trackers and data collection APIs. For a quick check, read the Play Store or App Store description’s “Data Safety” section — the developer must self-report what data is collected. Compare that with the actual permissions requested.
Which countries in Southeast Asia have laws protecting health app data?
All major Southeast Asian countries have personal data protection laws that cover health data: Malaysia’s PDPA (2010), Thailand’s PDPA (2019), Singapore’s PDPA (2012), Indonesia’s UU PDP (2022), Vietnam’s Decree 13/2023, and the Philippines’ Data Privacy Act (2012). However, none of these laws specifically regulate the collection or processing of health data by AI applications. The enforcement record varies: Singapore’s PDPC is the most active, while Malaysia and Indonesia have issued very few health-app-related enforcement actions. If you encounter a health app data breach in Malaysia, you can file a complaint with the PDP Department, but timelines are long. For comparison, the EU’s GDPR has already fined health apps tens of millions of euros for similar violations.
Can AI healthcare apps sell my health data?
Technically, selling health data is illegal without consent in most SEA countries — but the definition of “sell” can be twisted. Some apps claim they “share” data with partners in exchange for services (like advertising space or cloud hosting), which is effectively a sale in kind. Others sell “de-identified” datasets to researchers or drug companies. Since de-identified data isn’t considered personal data under many laws, the app can sell it without explicit consent. A 2023 investigation by The Markup found that several fertility tracking apps sold user cycle data to data brokers. To avoid this, look for apps that explicitly state “we do not sell or share your data with third parties” and back that up with an independent privacy audit. EazyCare AI’s privacy policy includes a zero-data-sale commitment.
What is the difference between anonymized and de-identified health data?
Anonymized data has been stripped of all identifiers — name, email, IP address, device ID — and cannot reasonably be re-linked to an individual. De-identified data has had obvious identifiers removed, but may still contain unique codes or quasi-identifiers (e.g., zip code + birth year + sex) that can be re-identified by linking with other datasets. The key difference: anonymization is irreversible; de-identification is reversible. In practice, many health apps claim they “anonymize” data but actually only de-identify it. A study from MIT showed that 87% of the US population can be uniquely re-identified using just zip code, gender, and birth date. When an app says “we use anonymized data for AI training,” ask for details. If they cannot explain how they achieve true anonymization, assume it’s only de-identified.
Do free health apps collect more data than paid ones?
Yes, significantly more. A 2024 study published in Digital Health Journal analyzed 100 free and 100 paid health apps. Free apps requested an average of 9.7 permissions (contacts, location, camera, etc.), while paid apps requested only 4.2. Free apps also transmitted data to an average of 5.8 third-party domains (analytics, advertising, social media), compared to 1.2 for paid apps. The business model of free apps relies on monetising user data through advertising and partnerships. Paid apps, on the other hand, generate revenue from subscriptions or one-time purchases, so they have less incentive to collect extra data. If you are particularly concerned about privacy, consider paying for a health app — but still review its privacy policy first, as some paid apps also share data.
How do health apps use artificial intelligence to analyze my data?
AI analysis in health apps typically involves three stages: first, the app collects raw data (symptoms, images, sensor readings). Second, it processes that data using a trained model — often hosted on a remote cloud server — to generate predictions or recommendations (e.g., “this rash is likely eczema”). Third, some apps use your input to improve the model (called “continual learning”). The last step is where privacy risk is highest: your specific case might be stored and used to retrain the model without explicit consent. Some apps offer “local AI” that runs entirely on your phone, meaning no data leaves the device. Ask the developer or check the privacy policy: “Is AI processing done on-device or in the cloud? Is my data used for model training? Can I opt out of training?”
What permissions do health apps request on my phone?
Common permissions include: location (GPS), camera (to take photos of skin, prescriptions, or documents), microphone (for voice notes), contacts (to share results with a doctor), storage (to save reports), phone (to detect calls), SMS (for OTPs), body sensors (for step count or heart rate), and notification access. Many of these are unnecessary. For example, a symptom checker that asks for camera and location may be legitimate (need photo of rash, need location for disease prevalence), but it should not ask for contacts or phone state. A useful rule: if an app requests a permission that is not obviously required for its core function, question it. On Android, you can grant permissions “while using the app” rather than “always.”
Are there any health apps that do not collect personal data?
Very few apps collect no data, but some collect the absolute minimum — usually just what is necessary for the app to function and without linking to a user account. Examples include offline-first apps that run entirely on-device (e.g., some symptom checkers that use local databases). Check the app’s data safety section: if it says “No data collected” or “Data collected only for essential purpose and not shared,” that’s a good sign. Note that even apps that claim “no data collection” may still collect anonymous crash logs through Google Play Services. For a truly zero-data experience, look for open-source health apps that you can audit yourself. EazyCare AI’s symptom checker offers an anonymous mode that does not store any personal identifiers server-side.
When to Stop Using a Health App and Take Action
If you notice any of the following red flags, uninstall the app immediately and consider filing a complaint with the relevant data protection authority:
- No privacy policy or a policy that is vague/contradictory. If a health app does not clearly state what data it collects and how it uses it, assume the worst.
- Requests for permissions that have nothing to do with health. Examples: contacts, SMS, calendar, phone call log. A medical app does not need these.
- Reports from other users or privacy advocates about data leaks or sharing. Quick online search can reveal such issues.
- The app shares data with third-party ad networks or data brokers — especially without an opt-out.
- You are pressured to provide data you are uncomfortable with (e.g., “you must enable location to use this symptom checker”). Legitimate apps will offer offline or manual entry alternatives.
If you suspect your health data has been mishandled or leaked, you can file a complaint with the Personal Data Protection Department in Malaysia (https://www.pdp.gov.my) or your country’s equivalent. For emergency situations where sensitive health data (e.g., HIV status, mental health records) is publicly exposed, contact a legal professional immediately. If you are unsure whether an app is safe, EazyCare AI can help you evaluate the privacy policy of any health app by chatting with our AI assistant — ask “Is this health app safe for my data?”
Conclusion
Your health data is among the most sensitive information you own. In Southeast Asia, where privacy laws exist but enforcement is weak, the burden of protection falls on you. Here are the three most important takeaways:
- Know what you’re handing over. Before using any AI health app, read the privacy policy for data categories, sharing partners, and AI training clauses. Use the permission audits on your phone to verify actual data access.
- Understand the legal landscape. Malaysia’s PDPA, Thailand’s PDPA, and other SEA laws offer some protection, but they have gaps — especially regarding AI model training and secondary data use. Do not assume an app is safe just because it has a privacy policy.
- Take practical steps today. Disable unnecessary permissions, prefer paid apps, use privacy-focused tools like Exodus Privacy, and choose platforms like EazyCare AI that commit to minimal data collection and no data sale.
Your health decisions should be guided by reliable information, not by the fear of what an app might do with your data. Learn more at eazycare.ai or chat with our AI health assistant about how we protect your data.



