Skip to content
Make AI Good

Graph · Message

Reproductive surveillance

01 · In focus

One message, in the field.

The structured facts the source records about Reproductive surveillance, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

message

5 declared connections

Kind
Message
Status
active
Confidence
high
Entity ID
msg-abortion-surveillance
Network
View in network

Tags us, national, framing, analytical-frame, reproductive-rights, abortion-access, data-privacy, surveillance, period-tracking-apps, dobbs, location-data, data-brokers, healthcare-data, hipaa-loophole, abortion-criminalization, digital-rights, surveillance-capitalism, eff, aclu, digital-defense-fund, pregnancy-criminalization, menstrual-surveillance, abortion-providers, safe-harbor, my-health-my-data

Reproductive surveillance · 5 direct neighbours visible

02 · Connections

5 adjacencies, by relation.

Split by direction. Direct links are the ones Reproductive surveillance’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

Reproductive surveillance is the civil-society and digital-rights framing that names commercial data infrastructure — menstrual-tracking applications, smartphone location history, data-broker markets, search-engine query logs, and digital communications — as an apparatus capable of tracking and enabling the criminal prosecution of abortion seekers, providers, and helpers. The framing's central structural claim is that this risk is not an incidental misuse of commercial data systems but a direct consequence of how those systems were designed: the same data-broker infrastructure that sells consumer-preference profiles to advertisers can sell the location history of a person who visited a Planned Parenthood clinic, at a price competitive with a basic court filing. Where the data held by medical providers is governed by HIPAA and comes with warrant requirements and institutional privacy obligations, the data generated through period-tracking apps, health-adjacent consumer applications, and general-purpose platforms sits almost entirely outside those protections — subpoenable, purchasable, and often shared with analytics firms under user agreements few people read. The framing crystallised as a distinct movement message in the 48 hours following the May 2, 2022 Politico leak of the draft Dobbs v. Jackson Women's Health Organization Supreme Court opinion, propagated primarily by digital-rights organizations — Electronic Frontier Foundation, American Civil Liberties Union — and operationalised into direct grassroots guidance by reproductive-rights security organizations. Its legislative crystallisation arrived with the Washington State My Health My Data Act (April 2023), the first state law to close the HIPAA-loophole gap for consumer health applications.

The structural vulnerability

The HIPAA framework that governs healthcare providers does not extend to consumer-facing technology applications. A physician's office holding a patient's reproductive health records faces strict limits on disclosure, warrant requirements before law enforcement access, and civil and criminal penalties for unauthorized sharing. A period-tracking application, by contrast, faces none of these obligations: its data is commercial data, governed by its own privacy policy and by general consumer-protection law rather than by HIPAA's medical-privacy architecture. The gap between these two frameworks is structural — Congress enacted HIPAA in 1996 against a healthcare landscape in which digital health data was largely held by medical providers; the consumer health-app market of the 2010s and 2020s grew entirely outside that structure.

The FTC's June 2021 enforcement action against Flo Health — the leading menstrual-tracking application, with over 100 million users — documented what this gap meant in practice. Flo's privacy policy promised users that personal health information "may be shared with" only limited parties. In practice, Flo shared menstrual cycle data, pregnancy status, and fertility information with Facebook, Google, Flurry (Yahoo), and AppsFlyer, enabling targeted advertising against users' most intimate health states. The FTC action established the data-sharing norm as documented fact: period apps, at scale, were sharing intimate reproductive health data with advertising infrastructure as an ordinary business practice, under privacy policies whose actual terms were inconsistent with what users were told. The case's significance to the post-Dobbs framing was not primarily its regulatory outcome but its factual record — it made the data-sharing architecture concrete before the legal landscape that would make that architecture dangerous was in place.

Location data sits in a parallel structural gap. Location history, unlike medical records, is commercial data generated by smartphones through ordinary use and sold by data brokers without legal restriction. A Motherboard / Vice investigation, published after the Dobbs decision, documented that the location-data broker SafeGraph sold aggregated location data for visitors to abortion clinics, including Planned Parenthood facilities, for less than $200 — a price point any law enforcement agency, anti-abortion activist, or private investigator could meet without a warrant and without a court order. The investigation made the theoretical data-broker risk into a catalogue entry: SafeGraph's data included the home census-tract origin of visitors to specific clinic locations, enabling inference about individual identities even from aggregated data.

Crystallisation around Dobbs

The reproductive surveillance framing already existed as a civil-liberties concern before May 2022 — HIPAA's consumer-app gap was documented, the FTC had acted on Flo Health, and digital-rights organizations had noted the location-data risk in reproductive-health contexts. The Dobbs draft leak converted a latent concern into an urgent organizing framing. The shift from Roe's constitutional protection to a legal landscape in which fourteen states would criminalize abortion within months meant that data generated through consumer applications could become prosecutorial evidence. The Electronic Frontier Foundation published "Reproductive Privacy Requires Data Privacy" within days of the leak, establishing the data-privacy angle as the central civil-liberties register: the article named the specific data categories at risk (period-app data, location history, search queries, text messages), the specific legal mechanisms by which that data could reach law enforcement (subpoenas to platforms, data-broker purchases, voluntary disclosure), and the specific legislative response it endorsed (California's A.B. 2091, extending medical-provider privacy protections to abortion-related records).

The framing's grassroots propagation ran through the Digital Defense Fund, which distributed practical digital-security guidance to abortion seekers and providers under the title "Keep Your Abortion Private & Secure". The guide's six-category framework — device security, search privacy, location data, communications, payments, and healthcare records — translated the structural data-privacy argument into specific behaviour changes accessible to people without technical backgrounds: use a privacy-focused browser, turn off location services, use Signal for communications about abortion, pay cash. The guide's distribution through reproductive-rights networks rather than through digital-rights policy channels gave the framing its reach into the communities most directly affected.

From data to evidence

The Nebraska prosecution of Jessica Burgess in 2022 — in which the state obtained Facebook Messenger communications between a mother and her 17-year-old daughter about obtaining abortion medication and used them as the evidentiary basis for felony charges — became the documented case the reproductive surveillance framing cited to make the mechanism concrete. The case illustrated a scenario the framing had named: digital communications, generated through a commercial platform, accessed by law enforcement through legal process directed at the platform rather than at a medical provider, used to reconstruct a reproductive decision and prosecute it as a crime. The framing's claim — that the data-privacy infrastructure of the commercial surveillance economy is the infrastructure of reproductive enforcement in a post-Dobbs legal landscape — was no longer theoretical.

The National Partnership for Women & Families' October 2024 report documented the full range of data types at issue: location history (visits to clinics), search queries ("how to get an abortion," "abortion pills near me"), period-app data (menstrual cycle, pregnancy status, fertility intentions), payment records (purchases associated with abortion medication), digital communications (texts, emails, messaging-app conversations about reproductive decisions), and insurance and billing records that flow through healthcare administration systems. Each category represents a different exposure surface; together they constitute what the report frames as a total-environment surveillance risk for anyone seeking or providing abortion services in a state where doing so is criminalized.

Legislative response

The reproductive surveillance framing's most consequential legislative product is the Washington State My Health My Data Act, signed by Governor Jay Inslee on April 27, 2023. The Act is the first state-level privacy law explicitly covering consumer health-application data outside the HIPAA framework — targeting the specific statutory gap the framing named. It requires consumer health-technology companies collecting health data on Washington residents to obtain affirmative consent before sharing that data with third parties and prohibits the use of geofencing around healthcare facilities to collect health data. The Act's passage provided the framing with a concrete legislative reference point, demonstrating that the gap between HIPAA-governed medical-provider data and HIPAA-excluded consumer-app data was legally closeable at the state level.

Federal legislative proposals — including the "My Body, My Data Act" introduced by Representative Sara Jacobs and Senators Wyden and Hirono — have named the same structural gap in federal legislation, without passage as of mid-2026. The framing has carried both the state-level legislative strategy (targeted health-data privacy laws, data-sanctuary provisions in pro-access states) and the federal strategy (comprehensive health-data privacy covering consumer applications) as parallel live campaigns.

Connection to the broader surveillance ecology

The reproductive surveillance framing sits inside the broader surveillance capitalism framing — it names one sector of the commercial surveillance economy (consumer health applications, location data brokers, platform communications) and one legal-landscape shift (the criminalization of abortion in a third of US states) as producing a convergence that surveillance capitalism's general architecture enables. Where data is a civil rights issue names the general claim that data collection and use is a domain of rights rather than pure commerce, reproductive surveillance names the specific enforcement mechanism: the aggregation of consumer data becomes the evidentiary basis for prosecuting reproductive choices. The framing extends the data-rights analysis from the abstract to the prosecutorial — the risk is not primarily the chilling effect of mass surveillance (though that is named) but the concrete criminal exposure of people who trusted that their health applications were governed by the same rules as their doctors.

04 · Sources

Where this came from.

6 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. eff.org

    Checked 2026-06-10

    EFF, "Reproductive Privacy Requires Data Privacy," May 2022 — foundational civil-liberties articulation of the data-privacy angle on reproductive rights; establishes that reproductive health data generated through commercial applications sits outside HIPAA protections, can be subpoenaed by law enforcement in states that have criminalized abortion, and represents a distinct civil-liberties risk; the first major organizational framing of the period-app / location-data exposure as a reproductive-rights issue following the Dobbs draft leak

  2. vice.com

    Checked 2026-06-10

    Motherboard / Vice, "Data Broker Is Selling Location Data of People Who Visit Abortion Clinics" — primary source documenting that the location-data broker SafeGraph sold aggregated location data of visitors to abortion clinics, including Planned Parenthood facilities, for less than $200; makes the data-broker mechanism concrete and provides the factual anchor for the reproductive surveillance framing's claim that commercial surveillance infrastructure can become cheap prosecutorial evidence

  3. digitaldefensefund.org

    Checked 2026-06-10

    Digital Defense Fund, "Keep Your Abortion Private & Secure" — grassroots digital-security guide for abortion seekers and providers; primary source for the framing's operationalization into six practical risk categories (device security, search privacy, location data, communications, payments, and healthcare records) and the distribution of the reproductive surveillance framing through reproductive-rights community networks rather than digital-rights policy channels

  4. nationalpartnership.org

    Checked 2026-06-10

    National Partnership for Women & Families, "Data Privacy & Reproductive Freedom: How Digital Surveillance Increases the Risk of Pregnancy Criminalization Post-Dobbs," October 2024 — comprehensive movement document connecting commercial data surveillance to pregnancy criminalization risk; documents the full range of data types at issue (location history, search queries, period-app data, payment records, digital communications) and the specific statutory gap — the HIPAA loophole — that makes consumer health-app data available to law enforcement without the constraints governing medical-provider records

  5. ftc.gov

    Checked 2026-06-10

    FTC press release on the finalized order against Flo Health, June 2021 — primary source for the enforcement action against the leading menstrual-tracking application for sharing users' fertility, pregnancy, and menstrual data with Facebook, Google, Flurry (Yahoo), and AppsFlyer despite explicit privacy promises; establishes the documented data-sharing norm in the period-app market that the post-Dobbs reproductive surveillance framing cited as prior art

  6. app.leg.wa.gov

    Checked 2026-06-10

    Washington State Revised Code § 19.373, My Health My Data Act, signed April 27, 2023 — primary source for the first state-level privacy law explicitly covering consumer health-application data outside the HIPAA framework, targeting period-tracking apps, fertility apps, and related consumer digital-health products; the legislative codification of the core structural gap the reproductive surveillance framing identified

Source: entities/messages/msg-abortion-surveillance.md — movement-graph pin 5d136ad.