What happens when people assume their health data is protected, but it isn’t? That question launched a team of researchers into multiple projects exploring privacy expectations versus reality in mobile health apps.
Led by researchers in ICSI’s Usable Privacy and Security Group, the project focuses on the dissonance between what users believe apps do with their sensitive health information and what apps actually do. In an era where digital health tools—from period trackers to telehealth apps—are widely used but unevenly regulated, these mismatches can leave users unknowingly exposed.
When Expectations Don’t Match Reality
“Our goal was to map the disconnects,” says Alisa Frik, a Research Scientist at ICSI. “Many people assume that any health-related data is protected under HIPAA, but that’s not always true, especially with apps that are not involved in covered transactions such as insurance claims.”
With funding from the NSF’s Secure and Trustworthy Cyberspace (SaTC) program, the team designed a study to discover these gaps. The researchers recruited adult study participants who were Android users, showed them app descriptions, and asked participants to infer what kinds of data the apps collected and how it was used. The researchers then compared these perceptions with findings from a traffic analysis of actual app behaviors. They examined what data was collected and whether it was shared with third parties. Read the abstract here.
One of the key takeaways? People generally expected better privacy protections from the apps that mentioned healthcare provider affiliations, even if those apps didn’t meet stricter privacy standards. Users often assumed health apps are required to comply with HIPAA, when in fact, most did not. “Even when users thought they knew what was going on, their confidence didn’t match the actual practices,” Julia Bernd, a Research Scientist at ICSI. Finally, Data Safety sections in Google Play that aim at informing users about data practices increased many participants’ confidence in that they understand what data is being collected, shared and used, but they did not necessarily improve the accuracy of those expectations. In other words, the current implementation of the existing transparency mechanisms for mobile telehealth apps still fail at effectively informing users’ privacy decisions.
Tackling Complexity with Collaboration
To better understand the developers’ side of the equation, the team collaborated with computer scientists at the University of Bristol to analyze hundreds of posts on Stack Overflow—a popular public forum where developers seek and share technical advice—and conducted interviews with legal professionals led by Primal Wijesekera in collaboration with a UTSA student and industry partner Mohsin Khan. Read about the abstract here. These efforts explored how app developers grapple with privacy compliance in real-world scenarios. Results showed that developers face a confusing patchwork of requirements and often struggle to find actionable guidance, especially when developing for different platforms like iOS and Android.
The team’s interdisciplinary approach that combined behavioral surveys, technical traffic analysis, and developer ethnography, allowed for a holistic understanding of the ecosystem. “This was one of the most diverse and collaborative teams I’ve worked with,” Bernd notes. “We had social scientists, technologists, legal scholars—it really took all of us to tackle the complexity of this space.”
Students and postdocs also played a critical role in the research. Priyasha Chatterjee, a visiting graduate student from the Max Planck Institute for Security and Privacy in Germany, and UC Berkeley undergraduate Subham Mitra contributed to the expectations study. UC Berkeley PhD student Alex Thomas is working on a related, in-progress study comparing health apps with other types of apps. Collaborators from The University of Texas at San Antonio (UTSA), St. Mary’s University, and international institutions supported the project’s technical and regulatory analyses.
The work is already shaping conversations about digital health privacy and was featured at the SOUPS and EuroUSEC security conferences. The team hopes to influence both app design and policy by pushing for clearer privacy labeling, platform accountability, and better transparency for users. The team is now expanding their research into the highly sensitive area of female health apps, where data privacy risks are of particular concern to many users.
This story was published in January 2026 as part of a retrospective series highlighting ICSI’s accomplishments and impacts over the years. To learn about our ongoing work, explore our Core Research Themes.
