Research and Sources: What Are These Apps Asking Me to Agree To?
Last reviewed: August 4, 2026.
The sources behind "What Are These Apps Asking Me to Agree To?" and the companion checklist, "Before You Tap Agree: Five Questions to Ask."
This page exists because a source list that only names sources is not much of a check. Where a source is under review, disputed, or partly vacated by a court, we say so. Where our own article simplified something, we say that too. Where we dropped a claim or a quotation, it is recorded here rather than quietly removed.
What the agreement screens mean
HIPAA authorization. 45 CFR 164.508. The rule requires six core elements: a specific and meaningful description of the information, who is authorized to release it, who may receive it, a description of each purpose, an expiration date or event, and the individual's signature and date. It also requires three statements: the right to revoke, whether treatment or benefits may be conditioned on signing, and the potential for the recipient to pass the information along outside HIPAA's protection. It must be in plain language.
Notice of Privacy Practices acknowledgment. HHS, quoted directly in the article. The related obligation is at 45 CFR 164.520(c)(2)(ii): a provider with a direct treatment relationship must make a good faith effort to obtain written acknowledgment of receipt, and where it is not obtained, document that effort and the reason. This does not apply in emergency treatment situations, and health plans have no such obligation. Our article simplified this to keep it readable.
Consent versus authorization under HIPAA. HHS FAQ 264. Consent under 164.506 is optional and covers treatment, payment, and health care operations. Authorization under 164.508 is required for uses the rule does not otherwise permit.
Research consent versus authorization. HHS FAQ 313. Informed consent under the Common Rule is consent to participate in the study as a whole. HIPAA authorization is permission to use or disclose the health information. The two may be combined into one document in some circumstances under 164.508(b)(3).
Online contract formation. Courts apply a two part test: reasonably conspicuous notice of the terms, and unambiguous manifestation of assent. Meyer v. Uber Technologies, 868 F.3d 66 (2d Cir. 2017) is the canonical statement. Companies do not reliably win: the Ninth Circuit declined to enforce terms twice at the appellate level in 2025, in Chabolla v. ClassPass, 129 F.4th 1147 (9th Cir. 2025), and Godun v. JustAnswer, 135 F.4th 699 (9th Cir. 2025). Edmundson v. Klarna, 85 F.4th 695 (2d Cir. 2023) and Keebaugh v. Warner Bros., 100 F.4th 1005 (9th Cir. 2024) come out the other way on better designed flows.
Which rules apply to health apps
Who HIPAA covers. HHS, Covered Entities and Business Associates. Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction. Business associates have been directly covered since the HITECH Act.
Health Breach Notification Rule. Rule page, 16 CFR Part 318. The FTC finalized amendments in April 2024, effective July 29, 2024, clarifying that the rule reaches health apps and similar technologies not covered by HIPAA, and that a "breach of security" includes unauthorized disclosure, not only a security failure.
Washington My Health My Data Act. RCW ch. 19.373; Washington Attorney General overview. Two tiers: consent to collect or share consumer health data beyond what is necessary to deliver a requested service, and a separate signed authorization to sell it. RCW 19.373.010 defines consent as "a clear affirmative act that signifies a consumer's freely given, specific, informed, opt-in, voluntary, and unambiguous agreement," and provides it may not be obtained through general terms of use, passive action, or deceptive design. Violations are enforced by the Attorney General and, through the Washington Consumer Protection Act, by private plaintiffs. Nevada SB 370 and Connecticut's health data amendments are close analogues; neither has Washington's private enforcement route.
Rewriting terms to permit new uses. FTC staff, February 13, 2024. Quoted in the article. This is a staff blog post, not a rule or an enforcement action, and we describe it that way.
Guidance for health app developers. FTC, Mobile Health App Developers: FTC Best Practices. Recommends data minimization, just in time notices, privacy protective defaults, and affirmative express consent obtained separately from the privacy policy or terms.
A note on currency. Several new state privacy laws took effect in 2025 and 2026, and definitions differ between them. We deliberately avoided a state by state list because it would be out of date within months. Two cautions for anyone extending this work: a federal court vacated most of the 2024 HIPAA reproductive health privacy rule in June 2025, though the Code of Federal Regulations still displays the vacated text; and the FTC's Click to Cancel rule was vacated in full by the Eighth Circuit in July 2025 and has not been replaced.
Why the current model fails
The reading burden. Aleecia M. McDonald and Lorrie Faith Cranor, "The Cost of Reading Privacy Policies," I/S: A Journal of Law and Policy for the Information Society 4(3):543-568 (2008). Repointed on publication day from the author draft at lorrie.cranor.org, which we could not reach when we link-checked this page. We could not tell from one vantage point whether that host was down or blocked on our side, so we did not call it dead; we moved to the journal's institutional repository at Ohio State because it is the more durable home either way. The paper's summary estimate is approximately 201 hours a year per person, with a national opportunity cost near $781 billion. A separate point estimate for reading policies word for word is 244 hours; skimming is 154. The figure most often quoted in the press is 244, which is why we used 201 instead. The underlying traffic data is from March 2008.
Policies since then. Ryan Amos, Gunes Acar, Elena Lucherini, Mihir Kshirsagar, Arvind Narayanan, and Jonathan Mayer, "Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset," WWW 2021. Over roughly two decades, policies approximately doubled in length and rose about a full grade level in reading difficulty.
Privacy fatigue. Hanbyul Choi, Jonghwa Park, and Yoonhyuk Jung, "The role of privacy fatigue in online privacy behavior," Computers in Human Behavior 81:42-51 (2018). Defines privacy fatigue through emotional exhaustion and cynicism, and reports that it predicted privacy behavior more strongly than privacy concern did. One cross sectional survey of 324 Internet users in Korea, which is why the article says "one survey found" rather than "research shows."
Design changes the answer. Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal, "Dark Patterns after the GDPR," CHI 2020. Of 680 consent pop-up designs sampled from the UK's 10,000 most visited sites, 11.8 percent met the authors' minimum requirements under European law. In a field experiment with 40 participants, removing the opt-out button from the first page increased consent by 22 to 23 percentage points, and adding granular controls to the first page decreased it by 8 to 20 points. Notification style, banner versus barrier, had no measurable effect.
What people end up with. Hana Habib, Megan Li, Ellie Young, and Lorrie Faith Cranor, "Okay, whatever: An Evaluation of Cookie Consent Interfaces," CHI 2022. Across 1,109 participants and 12 interface variants, only 45.3 percent ended up with their preferred option. About half of those who chose "allow all" said their goal was to dismiss the interface. In the non-blocking corner-button condition, no participant made any consent decision at all.
Whether the choice is even recorded. Célestin Matte, Nataliia Bielova, and Cristiana Santos, "Do Cookie Banners Respect my Choice?" IEEE S&P 2020. Of 1,426 sites using the IAB Europe consent framework, 141 registered positive consent before the user made any choice and 27 stored consent after an explicit opt-out. In extensive testing of 560 sites, 54 percent had at least one suspected violation. These are counts, not rates, and the denominators differ between the crawl and the tested subset.
Dark patterns. FTC, "Bringing Dark Patterns to Light," Bureau of Consumer Protection staff report, September 2022. Quoted in the article. California Privacy Protection Agency Enforcement Advisory No. 2024-02, September 4, 2024: "Dark patterns are about effect, not intent," and the path to the more privacy protective option must not be longer or more difficult than the path to the less protective one. The CPPA applied that directly in its March 2025 order against American Honda, finding that one click to accept cookies against at least two clicks to opt out was not symmetrical.
On consent standards from outside the US. UK guidance defines valid consent as freely given, specific, informed, and unambiguous, given by a clear affirmative action. We did not cite it in the article, because it does not govern US apps and the ICO's guidance is currently marked as under review following the UK Data (Use and Access) Act 2025. It remains a useful description of what a real choice looks like.
Electronic Frontier Foundation
All EFF material on eff.org is published under Creative Commons Attribution 4.0 International (CC BY 4.0), per EFF's copyright policy. Quotations here are attributed accordingly. The license does not cover EFF's trademarks or logo, and nothing in our article implies EFF endorses ChartQuest.
On consent design and manipulation. Gennie Gebhart, "EFF's Recommendations for Consumer Data Privacy Laws," June 17, 2019, updated October 28, 2020. Licensed CC BY 4.0. Source for three quotations in the article:
- "research suggests companies are becoming skilled at manipulating consent and steering users to share personal data"
- "The default should be against collecting, using, and sharing personal information."
- users "gain new rights only to effectively lose them when they 'agree' to terms of service and end user license agreements that they haven't read and aren't expected to read"
The third sits under EFF's heading "Some Things To Avoid" and argues that privacy laws should bar the waiver of rights through terms of service. We quote it in full rather than truncated, because the clause about what people are not expected to read is the reasoning, not decoration.
This document is EFF's 2019 framework, revised in 2020. It has not been retracted, and its positions on opt-in consent and deceptive design carry forward into "Privacy First: A Better Way to Address Online Harms" (November 2023) and "EFF to Congress: Here's What A Strong Privacy Law Looks Like" (April 2025). We cite the 2019 page because it states the principles most directly, not because it is EFF's most recent word.
On business models. Cooper Quintin and Soraya Okuda, "How to Assess a Vendor's Data Security," January 8, 2018. Licensed CC BY 4.0. Source for "How does the vendor make money? Do they make money by selling access to, or products based on, your private data?" and for the qualification on the familiar aphorism. EFF's full sentence is: "It is often said that 'if the software is free, then you are the product'-this is true of any company that has targeted advertising as a business model." Note that EFF presents the saying as a common one it is qualifying, not as its own claim, and that the page is a practical vetting checklist for organizations choosing vendors rather than a general statement about the advertising industry. Our article reflects both limits.
On location data brokers. EFF, "Location Data Brokers." Licensed CC BY 4.0. An undated issue page, accessed August 4, 2026. Source for the quoted phrase about what location data can reveal, and for the description of how app permissions feed brokers through SDKs and real-time bidding. For a dated treatment of the same problem, see Karen Gullo, "Location Data Tracks Abortion Clinic Visits," March 15, 2024.
Claims now paraphrased rather than quoted. The article attributes three points to EFF without quoting: that the "free product" aphorism holds where targeted advertising is the business model; that interface design steers people into sharing more than they intended; and that terms can be used to waive rights people did not realistically know they were giving up. All three come from the two pages above. We paraphrased them to keep the article in our own voice, and the exact EFF wording is preserved here.
A claim we narrowed. An earlier draft said personal information can "make the company more valuable to investors and partners." That is widely believed and probably true, but we could not point to a source for it at the standard this page sets, so we cut it. The article now says only that a company may sell, share, target, train on, or predict from your information, each of which the sources above support.
A quotation we did not use. An earlier draft of our research attributed to EFF the line "Companies that profit from surveillance are skilled at deploying dark patterns to manufacture phony 'consent.'" We could not find it anywhere on eff.org. It appears to be a paraphrase of the "manipulating consent" sentence above that hardened into a quotation somewhere along the way. We dropped it. It was the most quotable line we had, which is exactly why it deserved checking.
What we left out, and why
Enforcement examples. The FTC and state authorities have brought several health privacy cases since 2023 involving apps that shared health information with advertising platforms. We kept them out of the main article for three reasons: describing each one accurately takes more space than the point is worth there, naming other companies in our own writing invites a reading we do not intend, and at least one current matter involves allegations that have not been decided. We would rather link you to the rules themselves than to a list of other people's trouble.
Substance use disorder records. Records held by federally regulated substance use treatment programs carry a separate and stricter consent regime than HIPAA, under 42 CFR Part 2, whose compliance date was February 16, 2026. We cut it from the article for length. It is accurate and it strengthens the point that not all health information is governed the same way, but it is the one item in our taxonomy most readers will never personally encounter. It belongs in a piece about sensitive record categories, which we have not written.
A state by state guide. Out of date too quickly to be honest.
Accessibility of consent screens. A real gap, and a longer piece. Screen reader behavior, the number of decisions on one screen, whether the translated version of a consent screen matches the underlying policy, and what it means to ask someone for a durable decision on the day they were diagnosed. We have not written it yet.
Something here wrong or out of date? privacy@humanviablelabs.com