About this tool
Audit sensitive-data permissions, cloud backup and default sharing settings in health record and ABHA apps.
The Health Records App Permission Audit scores a personal health record, ABHA or lab-report app across sixteen permissions and privacy settings, because the biggest leak in this category is rarely a runtime prompt — it is a sharing toggle that defaults to on or an analytics SDK that reports screen names like 'HIV test result'. Health Connect and HealthKit access, background reads, cloud backup and default sharing with partner clinics are each weighted by sensitivity, and a biometric app lock is scored as a core control because it reduces risk rather than adding to it.
Open Health Records App Permission Audit on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Cloud backup, default sharing and analytics are scored as first-class items, not footnotes.
A biometric app lock counts as core, so the audit rewards the one setting that most reduces exposure.
Recommendations point at the consent ledger and the specific, revocable consent the ABDM policy requires.
It depends far more on the sharing defaults than on the permissions. Under India's DPDP Act 2023 and the ABDM Health Data Management Policy, health data may only be shared on your specific, revocable consent — so check the app's consent ledger and turn off any blanket sharing with partner clinics or insurers before uploading anything.
A read grant lets the app pull records while you are using it; background read (added in Android 15) lets it keep pulling when the app is closed, with no visible session. Deny background read unless you rely on automatic syncing, and refresh by opening the app instead.
Because screen names are diagnoses. Even if a third-party SDK never sees the record contents, knowing you opened a screen for a particular test or condition reveals it. Turn off usage or diagnostics sharing in the app's privacy settings.
Revoking a permission only stops future access, so use the app's account deletion or data erasure request as well. This is informational, not legal or medical advice — talk to your provider before changing anything that affects your care.