Imagine a health agency could track the spread of a dangerous disease in real time, but only by accessing your location, medical history, and daily habits. Would you agree to that? This question sits at the center of a major ethical debate in public health: when does protecting the population justify collecting personal data, and where should limits exist?
Why Public Health Needs Data
Public health relies heavily on data to track diseases, detect outbreaks, and plan responses. In many cases, surveillance data is collected without individual consent, because it is considered part of a government’s responsibility to protect population health. During the COVID-19 pandemic, this became especially clear. Health agencies used electronic health records, mobile apps, search trends, and even wearable devices to monitor infection rates and understand transmission patterns in real time. This allowed for faster, more proactive responses instead of delayed reactions. However, while the benefits were significant, the scale of data collection raised important privacy concerns.
What Privacy is at Stake?
The data collected for public health purposes often includes highly sensitive information: location history, travel patterns, health conditions, and vaccination status. In some cases, individuals were not fully aware of how much data was being collected or how it would be used. A major concern is what happens after a public health emergency ends. Once collected, digital health data can be stored indefinitely and sometimes shared or repurposed by third parties, including private companies. Experts warn that these “digital health footprints” may be used for purposes unrelated to their original intent, often with limited oversight.
Ethical Tension
At the core of this issue is a tension between individual rights and the collective good. Public health aims to protect entire populations, but doing so may require limiting personal control over data. During COVID-19, different countries approached this balance differently. Some prioritized strict privacy protections, limiting contact tracing effectiveness, while others collected broader datasets in the name of public safety. These decisions also highlighted the “digital divide,” where individuals without smartphones or digital access were underrepresented in data systems. Consent is another challenge. In many public health settings, participation is required or implied, leaving individuals with little real choice.
Laws, Gaps, and Moving Forward
In the U.S., HIPAA provides baseline protections for health data, and other public health laws regulate surveillance use. However, gaps remain, especially as technology evolves faster than policy. Efforts to update privacy regulations have faced delays, and states are increasingly creating their own rules, resulting in uneven protections.
Finding the Balance
The goal is not to eliminate public health surveillance, it saves lives, but to ensure it is ethical, transparent, and trustworthy. Strategies like data anonymization, strong oversight, and clear communication can help protect privacy while still allowing effective public health action. Ultimately, balancing privacy and public good is not just a technical challenge, it is a human one.
Written by Special Guest Eric with contributions from cambridge.org, cdc.gov, govinfosecurity.com, pubmed.gov, pubmed.gov, pubmed.gov and pubmed.gov



Warming Up: Why and How?