Earlier quoted context omitted.
The HIPPA rules on health data are fairly strict, otherwise your doctor, hospital and so on could already be doing wrong. Personally I have a dumb TV, car, doorbell and fridge so not much spying there. The phone I'm less sure of.
HIPPA rules are easily circumvented unless you as a patient are paying attention: I can't tell you how many forms I've opted out of that wanted to explicitly export my data to third parties and partners that are not HIPPA compliant. And at least for my healthcare providers that use MyCharts, they like to make it part of the echeckin workflow, with no option to refuse. So you're forced to go up to the desk to check in…
I had to ask for a paper copy of the form I was signing, which was handed to me. That document said that "I acknowledge receiving the privacy notice ..." Was that given to me? Of course not. Asking for that - well let's just say I think I was the first person to ever ask for any of this documentation. I'm sure my information has been shared with 30 other entities - for a strep test. It's insane and unenforceable as a patient who just wants to get shit done.