What we found
23andMe DNA Kit: FWent bankrupt. 7 million people's genetic data is now an asset to be sold to the highest bidder.
When 23andMe filed for bankruptcy in March 2025, the genetic data of 15 million customers became a corporate asset in bankruptcy proceedings. The company was sold to TTAM Research Institute for $305 million, including all customer genetic data. State AGs in NY, CA, VA, and MA issued emergency alerts urging users to delete data. The privacy policy's own change-of-ownership clause permitted data transfer in acquisition scenarios.
Talkspace: FYou told your therapist about your marriage.
Former Talkspace employees revealed the company shared de-identified therapy transcript data with outside companies for marketing purposes. Therapy transcripts -- even stripped of names and identifiers -- contain deeply personal mental health disclosures: descriptions of trauma, relationship problems, substance abuse, suicidal ideation. De-identification under HIPAA's safe harbor requires removing 18 specific identifiers, but a person describing their specific life circumstances in therapy creates a unique narrative fingerprint that no amount of identifier removal can anonymise. A therapy session about "my divorce from my husband of 15 years, my daughter's eating disorder, and my mother's death last March" is identifiable to anyone who knows the patient, regardless of whether a name is attached. Internal concerns raised by therapists were reportedly dismissed by management. The platform that promised therapy was confidential shared the substance of that therapy with marketing companies.
Headspace: FYou downloaded Headspace to try meditation.
In 2021, Headspace merged with Ginger, an on-demand therapy and psychiatric care platform that provides text-based therapy, video sessions, and medication management. The merged entity, Headspace Health, combined 70 million meditation users' behavioural data with clinical mental health records from therapy sessions. Ginger provided actual psychiatric care -- therapists, psychologists, and psychiatrists treating diagnosed conditions. Headspace provided meditation usage patterns that reveal anxiety levels, sleep quality, and emotional states. The merger created a single corporate entity holding both the casual data ("I tried a 10-minute meditation") and the clinical data ("I told my therapist about my childhood trauma"). The company rebranded back to just "Headspace" in 2024, but the clinical data infrastructure remained. Users who started by meditating and later used therapy through the same platform may not realise their data protections differ depending on which part of the app they're using.
BetterHelp: FYou go to BetterHelp because you're struggling with depression.
The FTC charged BetterHelp with sharing sensitive mental health data with Facebook, Snapchat, Criteo, and Pinterest for targeted advertising. Shared data included email addresses, IP addresses, and responses from therapy intake questionnaires. BetterHelp agreed to a $7.8 million settlement in March 2023, with funds directed to partial refunds for affected users. The FTC found BetterHelp had deployed tracking pixels from Facebook and Snapchat on its intake questionnaire pages, transmitting mental health data to advertising platforms in real time. BetterHelp denied wrongdoing while paying $7.8 million.
Calm: FYou downloaded Calm because you couldn't sleep.
Exodus Privacy analysis found Facebook SDK, Google Analytics, Adjust, and AppsFlyer trackers embedded in the Calm Android app. The Facebook SDK transmits app usage events to Meta's advertising infrastructure -- meaning your meditation sessions, sleep stories accessed, and anxiety management exercises are potentially feeding Facebook's ad targeting system. Adjust and AppsFlyer are mobile attribution platforms that track which advertisements brought you to the app and monitor your in-app behavior for advertising optimisation. Calm's privacy policy permits sharing data with "analytics providers," "advertising networks," and "business partners." A person who downloads a meditation app because they're struggling with anxiety is generating advertising data for the company that profits from anxiety-inducing social media. The meditation app and the anxiety machine share the same data pipeline.
Medibank: FRussian hackers stole 9.7 million Medibank records.
Russian hackers linked to the REvil ransomware group stole 9.7 million Medibank customer records in October 2022. The stolen data included not just names, dates of birth, and Medicare numbers, but detailed health claims data: specific medical procedures, diagnoses, and treatment histories. The hackers published the data on the dark web in batches, sorting victims into categories they called "good-list" and "naughty-list." The "naughty-list" contained the most sensitive records: abortion procedures, mental health treatment, HIV status, drug and alcohol rehabilitation. Patients who had sought treatment for the most stigmatised health conditions -- conditions they may not have disclosed to family, employers, or partners -- had their medical histories published on the internet, sorted by how damaging the information was. Medibank refused to pay the ransom, citing advice from cybersecurity experts that payment wouldn't guarantee data deletion. The decision was defensible. The consequence was that millions of Australians' most intimate health secrets were published permanently.
Phonak Audeo Lumity: FA security flaw means Bluetooth devices like hearing aids can be connected to by strangers without any pairing process or notification to the wearer.
The vulnerability class affects BLE audio devices — attackers can connect to BLE GATT services without pairing. Phonak's SWORD 3.0 supports both Bluetooth Classic and BLE. The chip integrates binaural VoiceStream for real-time data exchange between left and right hearing aids. FCC ID KWC-MRP certifies Bluetooth operation at 2402-2480 MHz. A hearing aid classified as a Class IIa medical device by the TGA has wireless interfaces that could be connected to by unauthorized parties without the wearer's knowledge.
Change Healthcare: FOne hundred million Americans' medical records stolen.
In February 2024, the ALPHV/BlackCat ransomware gang attacked Change Healthcare -- a subsidiary of UnitedHealth Group -- causing the largest healthcare data breach in US history. Over 100 million patient records were exposed, including: diagnoses, medications, treatment plans, Social Security numbers, insurance details, and financial information. The attack was possible because multi-factor authentication (MFA) was not enabled on the compromised Citrix remote access portal. A $400 billion healthcare company did not enable MFA on a critical system. UnitedHealth CEO Andrew Witty testified before Congress that the company paid a $22 million ransom. The attack caused nationwide healthcare disruption: pharmacies couldn't process prescriptions for days, hospitals couldn't file insurance claims, and small medical practices faced bankruptcy from cash flow interruptions. The single point of failure for American healthcare lacked a basic security measure that most email accounts require.