Connect with us

Technology

Your health data is being sold without your consent

Published

on

Your health data is being sold without your consent

NEWYou can now listen to Fox News articles!

Your health information might feel private and secure with your doctor, but the reality is far more complicated. Data brokers collect a wide range of sensitive health data, from diagnoses and prescription details to personal identifiers, and sell this data to marketers, insurers, and other third parties. These buyers use the information to target ads, adjust insurance premiums, or even for purposes you might not expect. Understanding who holds your health data and how it’s used and shared is crucial to protecting your privacy.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join.

A woman viewing her health app. (Kurt “CyberGuy” Knutsson)

Massive health data breaches are fueling the data broker industry

You might think your health data is safe with your doctor. But what if I told you total strangers might know when you last Googled “early signs of dementia” or filled a prescription for anxiety meds, and they’re selling that to whoever is willing to pay for it? A recent data breach at Yale New Haven Health, Connecticut’s largest healthcare system, exposed sensitive information on 5.5 million people. And it’s not an isolated incident; new research shows that since 2020, approximately 94.5 million Americans may have had their Social Security numbers stolen during health data breaches. The scary part is that data brokers collect and sell the names, addresses, and prescribed medications of patients diagnosed with mental health disorders to marketers on a large scale. How much is your medical information worth? Data brokers can sell it for as little as $0.06 per record. Let’s break down what these data brokers know, who they’re selling it to, and why it matters for you, your family, and especially vulnerable groups like seniors.

Advertisement

Illustration of a medical record. (Kurt “CyberGuy” Knutsson)

CUSTOM DATA REMOVAL: WHY IT MATTERS FOR PERSONAL INFO ONLINE

What types of health information are data brokers selling?

There’s a difference between protected health information, the kind your doctor and health insurer have to keep private, thanks to HIPAA, and the health-adjacent data you leave behind everywhere else.

Data brokers typically don’t have access to your official medical records. But they’re not regulated under HIPAA or any other laws, so they can legally collect:

  • Fitness app data: Step counts, heart rate, calories burned.
  • Symptom-related Google searches: Even “early signs of dementia” or “knee pain at night.”
  • Pharmacy purchases: Both prescriptions and over-the-counter medications.
  • Wellness quizzes and online forms: Those “What’s your biological age?” surveys aren’t just for fun.
  • Social media posts and likes: Public posts about health topics, comments in support groups.
  • Location data: Visits to clinics, pharmacies, or addiction recovery centers.

And it doesn’t stop there. Non-health data, like where you shop or the ads you click, gets combined to build a disturbingly accurate health profile.

A woman using a health app to keep track of pills (Kurt “CyberGuy” Knutsson)

Advertisement

WHAT HACKERS CAN LEARN ABOUT YOU FROM A DATA BROKER FILE 

Why selling your health data is more dangerous than you think

This isn’t harmless marketing data. When health information lands in the wrong hands, it creates real risks:

  • Higher insurance premiums or limited coverage based on inferred health risks.
  • Scams targeting seniors and vulnerable groups use lists of people flagged for dementia, heart disease, or other conditions.
  • Privacy violations, exposing sensitive details like mental health struggles or fertility treatments.
  • Discrimination in hiring, housing, or services based on health-related data.
  • Resale to unknown third parties, making it impossible to control once it’s out there.

And it’s not just marketers. A recent government-backed autism study led by Robert F. Kennedy Jr. sparked outrage after it was revealed that private health data was collected from federal and commercial databases without clear safeguards.  Security experts warn that this kind of large-scale data collection runs the risk of exposing deeply personal information with little oversight.

A healthcare professional looking at health data on a tablet. (Kurt “CyberGuy” Knutsson)

THINK YOU CAN DELETE YOUR OWN DATA? WHY IT’S HARDER THAN YOU THINK 

8 ways to protect your health data from data brokers

Worried about who has access to your health data? While you can’t control every breach or broker, you can take steps to limit what’s collected, shared, and sold. Here’s how to take back control of your digital health footprint-starting today.

Advertisement

1) Use a personal data removal service: Data brokers collect and sell sensitive health information, including diagnoses, prescriptions, and personal identifiers, to marketers, insurers, and other third parties. This means details about your pharmacy purchases, symptom-related searches, and more could be circulating without your knowledge. A personal data removal service can help you take back control. This is one of the most effective ways to safeguard your privacy and protect yourself and your family from risks like scams, higher insurance premiums, and discrimination.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice.  They aren’t cheap – and neither is your privacy.  These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites.  It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet.  By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you. Check out my top picks for data removal services here.

Get a free scan to find out if your personal information is already out on the web

2) Audit your apps and privacy settings: Health and fitness apps collect more than you realize. Delete the ones you don’t trust and check permissions on the rest

3) Be wary of free health quizzes and symptom checkers: If a site asks for personal details in exchange for “insights,” assume it’s monetizing your answers. Consult your doctor, not a clickbait quiz.

Advertisement

4) Limit data sharing beyond healthcare providers: Only provide necessary information when signing up for health-related services or apps. Be wary of sharing health details on social media or in public forums, as these can be scraped by data brokers.

5) Request data minimization from providers: Ask your healthcare providers to collect and store only the minimum amount of personal information necessary for your care, reducing the risk if their systems are compromised.

6) Use strong antivirus software: Strong antivirus software acts as a shield, protecting your devices from malware, ransomware, and other cyber threats that could compromise your personal health data. Choose a reputable solution that offers real-time threat detection, regular updates, and robust protection for all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Keeping your antivirus up to date is crucial for blocking malicious links and downloads before they can do harm. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices.

7) Regularly update your software: Cyber threats targeting health data are constantly evolving, and outdated software can leave your devices vulnerable to attacks that expose your sensitive information. Keeping your operating system, apps, antivirus, and security tools up to date ensures you have the latest protections against malware, ransomware, and other exploits that data brokers or hackers might use to access your health information. Regular updates patch security holes before they can be exploited, helping to prevent breaches like those that have exposed millions of Americans’ health details in recent years.

8) Use strong and unique passwords: Your health data is often protected by passwords on apps, portals, and devices. Using strong, unique passwords for each account reduces the risk that a single breach could give someone access to multiple sources of your personal information. Avoid common or reused passwords, and consider using a password manager to generate and store complex passwords securely. This step is crucial because once your login credentials are compromised, data brokers or cybercriminals can gather and sell your health-related data, leading to privacy violations, discrimination, or targeted scams. Consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed Password Managers of 2025 here

Advertisement

Kurt’s key takeaways

Your health should be personal, but in today’s digital world, that privacy is constantly under threat. Even if you’re cautious, your health-related information can be collected, analyzed, and sold without your clear consent. The good news is that you can take real steps to reduce your exposure and protect what matters. This isn’t about fear; it’s about staying informed and taking control of your digital footprint.

Should lawmakers and tech companies be doing more to protect our health data, or is it all on us to safeguard our own privacy? Let us know by writing to us at Cyberguy.com/Contact

For more of my tech tips & security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels

Advertisement

Answers to the most asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Technology

Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

Published

on

Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026.

– Connection and authentication failures in remote connection applications: This issue affects multiple platforms including Windows 11, version 25H2; Windows 10, version 22H2 ESU; and Windows Server 2025. See the bottom of this message for the complete list of affected products.

-Devices with Secure Launch might fail to shut down or hibernate: This issue only affects Windows 11, version 23H2.

Continue Reading

Technology

Fiber broadband giant investigates breach affecting 1M users

Published

on

Fiber broadband giant investigates breach affecting 1M users

NEWYou can now listen to Fox News articles!

Brightspeed, one of the largest fiber broadband providers in the United States, is investigating claims that hackers stole sensitive data tied to more than 1 million customers.

The allegations surfaced when a group calling itself the Crimson Collective posted messages on Telegram warning Brightspeed employees to check their email. The group claims it has access to over 1 million residential customer records and threatened to release sample data if the company does not respond.

At this point, Brightspeed has not confirmed a breach. However, the company says it is actively investigating what it calls a potential cybersecurity event.

DATA BREACH EXPOSES 400,000 BANK CUSTOMERS’ INFO

Advertisement

Fiber networks carry massive amounts of personal data, which makes internet providers attractive targets for extortion groups. (Philip Dulian/picture alliance via Getty Images)

Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter 

What the hackers say they stole

According to Crimson Collective, the stolen data includes a wide range of personally identifiable information. The group claims it has access to:

  • Customer names, email addresses and phone numbers
  • Home and billing addresses
  • User account details linked to session or user IDs
  • Payment history and partial payment card information
  • Appointment and order records tied to customer accounts

If accurate, that combination of data could create serious identity theft and fraud risks for affected customers.

Brightspeed responds to the allegations

Brightspeed says it takes the situation seriously, even as it continues to verify the claims.

In a statement shared with BleepingComputer, the company said it is rigorously monitoring threats and working to understand what happened. Brightspeed added that it will keep customers, employees and authorities informed as more details become available.

Advertisement

So far, there has been no public notice on Brightspeed’s website or social media channels confirming customer data exposure.

Who Brightspeed is and why this matters

Brightspeed is a U.S. telecommunications and internet service provider founded in 2022 after Apollo Global Management acquired local exchange assets from Lumen Technologies.

Headquartered in Charlotte, North Carolina, the company serves rural and suburban communities across 20 states. It has rapidly expanded its fiber footprint, passing more than 2 million homes and businesses and aiming to reach over 5 million locations.

Because Brightspeed focuses on underserved areas, many customers rely on it as their primary internet provider. That makes any potential breach especially concerning.

A closer look at Crimson Collective

Crimson Collective is not new to high-profile targets. In October, the group breached a GitLab instance tied to Red Hat, stealing hundreds of gigabytes of internal development data.

Advertisement

That incident later rippled outward. In December, Nissan confirmed that personal data for about 21,000 Japanese customers was exposed through the same breach.

More recently, researchers say Crimson Collective has targeted cloud environments, including Amazon Web Services, by abusing exposed credentials and creating rogue access accounts to escalate privileges.

In other words, the group has a track record that makes its claims hard to ignore.

What this could mean for customers

Even though Brightspeed has not confirmed a breach, the claims alone are enough to raise red flags. If customer data was accessed, it could be used for phishing scams, account takeovers or payment fraud.

Cybercriminals often move fast after breaches. That means customers should stay alert even before an official notice appears.

Advertisement

CyberGuy reached out to Brightspeed for comment, and a spokesperson told us,

“We take the security of our networks and protection of our customers’ and employees’ information seriously and are rigorous in securing our networks and monitoring threats. We are currently investigating reports of a cybersecurity event. As we learn more, we will keep our customers, employees, stakeholders and authorities informed.”

JANUARY SCAMS SURGE: WHY FRAUD SPIKES AT THE START OF THE YEAR

How to protect your personal data and online accounts

Even if this Brightspeed investigation does not end up impacting your account, these steps are worth following. Most data breaches lead to the same downstream risks, like phishing scams, account takeovers and identity theft. Building these habits now can help protect you across all your online accounts.

Cybercriminals often use public posts and countdowns to pressure companies into responding quickly. (Sebastian Kahnert/picture alliance via Getty Images)

Advertisement

1) Watch for phishing attempts

Scammers often take advantage of breach headlines to create panic. Be cautious with emails, calls or texts that mention your internet account billing problems or service changes. If a message pushes urgency or pressure, pause before responding.

2) Avoid suspicious links and attachments

Do not click links or open attachments tied to account notices or payment issues. Instead, open a new browser window and go directly to the company’s official website or app. Strong antivirus software adds another layer of protection against malicious downloads.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

3) Update your account passwords

Change your Brightspeed account password and review passwords on other important accounts. Use strong, unique passwords that you do not reuse elsewhere. A trusted password manager can generate and store complex passwords, which makes account takeovers much harder.

Advertisement

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com/Passwords) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com

4) Reduce your data footprint

Personal data spreads quietly across data broker sites. Using a data removal service can help limit how much of your information is publicly available. Less exposed data means fewer opportunities for scammers to target you.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Advertisement

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

5) Turn on account alerts

Brightspeed lets customers turn on account and billing alerts through the My Brightspeed site or app. You can choose which notifications you receive by email or text. Alerts can help you catch unusual activity early and respond before more damage occurs.

6) Monitor your financial accounts closely

Check bank and credit card statements often. Look for small or unfamiliar charges since criminals sometimes test stolen data with low-dollar transactions before attempting larger fraud.

7) Consider fraud alerts or a credit freeze

If sensitive information may have been exposed, placing a fraud alert or credit freeze can add protection. These steps make it harder for criminals to open new accounts in your name. To learn more about how to do this, go to Cyberguy.com and search “How to freeze your credit.” 

You may also want to consider an identity theft protection service that monitors for suspicious activity and sends alerts. Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number, and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

Advertisement

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com

When personal and billing information is exposed, the risk extends beyond one company to everyday customers. (Pixelfit/Getty Images)

Kurt’s key takeaways

Brightspeed’s investigation is still unfolding, and the company says it will share updates as it learns more. Until then, the claims highlight how valuable customer data has become and how aggressively extortion groups are targeting infrastructure providers. For customers, caution is the best defense. For companies, transparency and speed will matter if these claims turn out to be real.

Do you feel companies are doing enough to keep your personal data safe? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter 

Copyright 2026 CyberGuy.com.  All rights reserved.  

Advertisement
Continue Reading

Technology

The Setapp Mobile iOS store is shutting down on February 16th

Published

on

The Setapp Mobile iOS store is shutting down on February 16th

Setapp Mobile was a bold, breakthrough project that aimed to provide EU iOS users with access to alternative app marketplaces – creating a new app ecosystem where both developers and users could thrive. We are proud of what we have accomplished with it over the past two years and still believe passionately in this vision.

As a result of still-evolving commercial conditions, we have determined that it is not viable to continue development or support for Setapp Mobile within Setapp’s current business model.

While we are disappointed to discontinue Setapp Mobile, we are looking forward to pursuing the development of other innovations. We are excited to focus efforts on various projects that will launch later this year. This includes Eney, a first-of-its-kind AI assistant native to macOS, and new enhancements to Setapp Desktop.

Continue Reading

Trending