Every time you use a health app, a disability-related device, an AI assistant, or an accessible technology platform, you’re generating data. Data about your condition, your symptoms, your movements, your communication patterns, your location, your daily routines.
That data is valuable to companies. It’s also sensitive in ways that have real-world implications for people with disabilities, implications around insurance, employment, credit, and the algorithmic systems that increasingly shape access to services.
This isn’t an argument for avoiding technology. It’s an argument for understanding what you’re trading when you use it and making decisions about that trade with clear information rather than by default.
No spam. No inspiration porn.
Our best writing for adults with disabilities, weekly and free.
Get the newsletterWhat disability data is
Disability data is broader than most people think. It includes:
Medical and diagnostic data: Your diagnosis, your prescriptions, your healthcare visits, your test results. This is what most people think of as “health data” and it’s the most obviously sensitive.
Functional and behavioural data: How far you travel, what time of day you’re most active, when you use mobility aids, how often you use a voice assistant versus typing, your communication patterns. Apps and devices collect this data continuously. It reveals functional status in ways that are often more granular than a medical record.
Device data: Power wheelchair usage patterns (logged by the chair itself in many modern models), hearing aid usage and audio environment data, continuous glucose monitor readings, CPAP compliance data. Adaptive medical devices increasingly log their own usage and transmit it.
Communication data: If you use AAC (augmentative and alternative communication) technology, voice recognition software, or AI writing assistants, your communication is being processed and often stored. This includes very personal content.
Location data: Navigation apps, transit apps, and ride-sharing services all know where you go. For a wheelchair user, that record shows which places are accessible and which routes get used, which implicitly reveals disability status.
Each of these data categories carries specific risks.
Why disability data is sensitive
Insurance. In Canada, health insurance is publicly funded and disability status can’t be used to deny coverage in the public system. Private insurance, life insurance, disability insurance, critical illness insurance, is a different matter. Private insurers can and do consider health and disability status in underwriting decisions, and access to your health and functional data could influence these assessments.
Employment. While human rights legislation prohibits disability discrimination in employment, employers are motivated to minimize accommodation costs and sick leave. Disability data in the wrong context, accessible to employers through data brokers or poorly secured platforms, creates real risk.
Algorithmic systems. AI-driven systems increasingly make decisions about credit, housing, service access, and more. These systems are trained on data that reflects existing inequalities. Disability-related data patterns fed into these systems can result in discriminatory outcomes that are opaque and difficult to challenge.
Data breaches. Medical and disability data is targeted in breaches because of its sensitivity and its resale value. The arithmetic is simple: the more separate systems hold a copy of your health data, the higher the chance it turns up in at least one breach.
Third-party sharing. App privacy policies almost universally include clauses allowing data sharing with “partners,” “affiliates,” and “third parties for research and analytics purposes.” Reading these policies carefully reveals that “your data stays private” often means something much weaker than it sounds.
The specific case of health apps
Consumer health and wellness apps sit outside the medical device rules in Canada. Software sold for a medical purpose, to diagnose, treat, monitor or prevent a condition, is a medical device and needs a licence. Health Canada’s Software as a Medical Device guidance sets out its “longstanding position” that “software intended for maintaining or encouraging a healthy lifestyle, such as general wellness apps” does not meet the definition of a medical device and is “therefore not subject to the Regulations.” Symptom trackers, period trackers, mood trackers, sleep apps and most chronic illness management apps sit on the unregulated side of that line. An app can cross the line depending on how its maker labels and markets it, so the regulatory status turns on the marketing copy rather than on how sensitive your data is.
A health app can promise privacy in its marketing, store your detailed symptom history in unencrypted cloud storage, sell aggregated (and sometimes not-so-aggregated) data to pharmaceutical companies and data brokers, and have no regulatory penalty for doing so under current Canadian law.
This isn’t hypothetical. In January 2021 the US Federal Trade Commission settled allegations that Flo Health, a period and fertility tracker used by more than 100 million people, promised to keep users’ health data private and then disclosed it to Facebook’s analytics division, Google’s analytics division, Google’s Fabric service, AppsFlyer and Flurry. The FTC’s complaint says the disclosures included the fact of a user’s pregnancy, and that Flo put no limits on what those third parties could do with the data. Flo did not stop until a news article exposed the practice in February 2019.
The disability-specific version of this risk is that symptom data, functional status data, and condition management data from chronic illness and disability apps is precisely what insurance companies, employers, and other actors would pay for.
What to do: Before installing a health or disability management app, look up its privacy policy on its website (not just the app store summary). Specifically look for: what data is collected, who it’s shared with, whether it’s sold, how it’s stored, and whether you can delete your data and how. If the privacy policy is vague on these points or says data is shared with “partners” without specifying them, treat that as a red flag.
CPAP and adaptive device data
This one is specific enough to deserve its own section, because it affects a large number of people with disabilities and the implications aren’t widely understood.
Modern CPAP machines are internet-connected and report compliance data continuously to the cloud. This data, how often you use the machine, for how long, at what pressure settings, your apnea-hypopnea index, is transmitted to your equipment provider and often to your insurance company.
Coverage can depend on that record. Medicare in the United States pays for a 12-week trial and continues coverage only if a clinician documents in your medical record that you meet certain conditions and that the therapy is helping you, which in practice means the machine’s own usage data. Canadian funding runs through provincial equipment programs and private insurers instead, each setting its own conditions, but the data collection is the same. Your CPAP data is being collected, and the entities with access to it extend beyond your sleep doctor. Ask your provider what your machine transmits, to whom, and what it gets used for.
What you can do: Know what you agreed to when you got your CPAP device. Review the terms of your equipment provider. If your machine is internet-connected, you can often disable the cellular transmitter, ask your equipment provider about this option and whether it affects your coverage terms.
Similar considerations apply to other connected adaptive devices: hearing aids with cloud connectivity, smart prosthetics with usage logging, continuous glucose monitors. Know what your device transmits and who receives it.
AI assistants and communication privacy
If you use voice assistants (Alexa, Google Assistant, Siri) or AI-based assistants as adaptive tools, for communication, for memory support, for navigation, you’re generating significant data.
Voice recordings processed in the cloud mean your voice is being transmitted to and processed on company servers. Most major voice assistants allow you to review and delete your voice history in their settings, this is worth doing regularly if voice assistants are a significant part of your daily life.
AI writing and communication assistants (including Claude and similar tools) have privacy policies governing how they handle input data. Review these policies for the specific tools you rely on.
Locally processed tools, those that run on your device rather than in the cloud, offer meaningfully better privacy. Apple’s on-device processing for Siri and Live Captions, Android’s on-device voice recognition, and certain AAC apps that process locally are worth seeking out when privacy matters for the content being processed.
What you can actually do
Some practical steps worth taking:
Audit your health and disability apps. List every app that knows anything about your disability, condition, or health. Review the privacy policy of each. Delete the ones where the data trade isn’t worth it.
Use incognito or private browsing for health research. Your browser history is data. Searching your conditions and symptoms creates a profile that advertising systems (and, depending on your jurisdiction, potentially other systems) can access.
Know which privacy law covers you, and who to complain to. Two different regimes are in play and the difference decides where you go. Records held by your doctor, hospital or pharmacy fall under provincial health privacy law, Ontario’s PHIPA or its equivalent elsewhere, which gives you a right of access to your records and, in many cases, a right to restrict certain disclosures. A commercial app is a different animal. It is not a health information custodian; it is a business, so the federal Personal Information Protection and Electronic Documents Act applies. The Office of the Privacy Commissioner of Canada investigates PIPEDA complaints everywhere except Quebec, British Columbia and Alberta, which have their own substantially similar laws and their own commissioners. PIPEDA also “applies to all personal data that flows across provincial or national borders, in the course of commercial transactions,” which is what a health app does every time it syncs. You can file a complaint about an app. Almost nobody knows that.
Consider whether connected features are necessary. For many adaptive devices, the connected/cloud features are optional. A CPAP without the cellular transmitter still works as a CPAP. An app with location permissions denied still functions for most purposes. Before enabling a feature, ask whether you actually need it and what it costs in privacy terms.
Use strong, unique passwords and two-factor authentication for health and disability-related accounts. A breach of your password manager is less damaging than a breach of your health data.
This isn’t paranoia. It’s informed participation in a digital environment that’s making decisions about your data whether or not you’re paying attention.
Sources
Health Canada, Guidance Document: Software as a Medical Device (SaMD): Definition and Classification, published 18 December 2019.
US Federal Trade Commission, Developer of Popular Women’s Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health Data, 13 January 2021.
Office of the Privacy Commissioner of Canada, Guide to the PIPEDA complaint process.
Office of the Privacy Commissioner of Canada, PIPEDA complaints and enforcement process.
US Centers for Medicare and Medicaid Services, Continuous Positive Airway Pressure (CPAP) therapy.
Living Unlimited Team
