Health & Digital Sovereignty Toolkit: How to Cut the Cord in CMS’s New Patient Ecosystem and Beyond

Aug 02, 2025

Many have asked me for ways to opt-out and protect your data sovereignty. Below is a list of action steps you can take. These steps can seem overwhelming, but if you go step-by-step, it is possible to regain more of your data and digital sovereignty. Please understand, I am not an expert—I just do a ton of research and personally want to do my part to resist and help others.

The U.S. Centers for Medicare & Medicaid Services (CMS), backed by over 60 tech and healthcare corporations, has unveiled a sweeping new “digital health ecosystem.” It promises streamlined care, predictive AI, and seamless access to your health data across apps and systems.

What it doesn’t promise: privacy, consent, or any meaningful control over what happens to the most intimate data your body generates. This initiative isn’t just about modernizing healthcare. It’s about consolidating power — creating a centralized pipeline of behavioral, biometric, and medical data that flows directly to tech conglomerates and federal systems.

We are not being asked. We are being folded in. Feel free to add any additional tips to the comments section.

But you still have a choice. You can step back. You can cut the cord. You can seal your sovereignty.

What’s Inside This Toolkit:

  • Why Health Data Sovereignty Matters

  • Rapid-Action Technical Steps

  • Hidden Opt-Out Paths (Legal & Structural)

  • Surveillance Protection Beyond Health

  • Sample Scripts & Letters

  • Advocacy & Watchdog Groups

  • Additional Resources & References

  • Resist The Palantir Growing Monopoly

1. Why Health Data Sovereignty Matters

Health data (fitness, reproductive, biometric, behavioral) is being pooled into a centralized CMS-led ecosystem—including participation by over 60 tech and healthcare firms. Once connected, companies not bound by HIPAA may use, share, or commercialize your data beyond clinical care.

Opting out isn’t just privacy protection—it’s reclaiming your autonomy and resisting surveillance.

2. Rapid-Action Technical Steps

  • Revoke portal app access: Log into hospital/PMS portals (e.g., MyChart, DrChrono), and remove all syncing agents.

  • Delete tracking apps: Remove apps like Flo, Clue, Fitbit. Replace with offline alternatives (pen/paper, Euki).

  • Stop wearable syncing: Disable auto-sync for Fitbit, Garmin, Apple Health, and Sleep Number or similar IoT-connected sleep systems.

  • Use privacy tools: Brave or Firefox browser + uBlock Origin; Signal messaging; ProtonMail or Tutanota; VPNs like ProtonVPN or Mullvad.

3. Hidden Opt-Out Paths (Legal & Structural)

What to Do:

File a HIPAA Restriction Request: Ask provider to block PHI disclosure to CMS or third-party networks. Stronger if paying out-of-pocket.

Decline TEFCA/QHIN Participation: Ask providers/insurers to exclude your data from QHIN-aligned networks.

Data Revocation Letter: Write to CMS’s Office of Enterprise Data & Analytics to block data ecosystem participation.

Avoid Digital Intake Platforms: Refuse tools like Zocdoc, Phreesia. Schedule by phone. Use in-person paperwork.

Refuse Predictive Programs: Formally decline AI-based health scoring or behavioral outreach.

Limit Pharmacy-Insurance Syncing: Pay in cash (if possible) and ask pharmacies not to auto-sync prescription data.

4. Surveillance Protection Beyond Health

  • Email: Use end-to-end encrypted email services like ProtonMail or Tutanota.

  • Messaging: Use Signal with disappearing messages. Avoid WhatsApp, Facebook Messenger, and SMS for sensitive communications.

  • Web Browsing: Use Brave or Firefox with privacy extensions. Use Tor for maximum anonymity.

  • VPN: Choose no-log VPNs like Mullvad or IVPN.

  • Cloud Storage: Avoid cloud syncing sensitive data like Google Drive, Dropbox, Icloud. Use encrypted local storage or encrypt files before uploading. Get an external hard drive instead.

  • Devices: Enable full-disk encryption (FileVault on Mac, BitLocker or Veracrypt on Windows). Use strong alphanumeric passcodes.

  • Disable Biometrics: Temporarily disable FaceID or fingerprint access in high-risk situations.

  • Metadata: Turn off location tagging in photos and remove metadata before sharing.

  • Sleep & Smart Devices: Disable tracking features in IoT devices like Sleep Number beds, smart fridges, and health scales.

  • Use Faraday Bags: When traveling or in sensitive spaces, use Faraday pouches to block device signals.

  • Financial Privacy: Use cash. Avoid linking financial tools to health purchases. Be cautious with crypto; prefer privacy coins like Monero for transactions.

5. Sample Scripts for Providers and Insurers

"I request a formal HIPAA restriction on the use and disclosure of my medical information, including export into CMS-led digital health ecosystems, TEFCA/QHIN networks, and third-party applications."

"Please remove all integrations between my patient portal and third-party apps, including Apple HealthKit, Fitbit, Google Fit, or digital intake platforms. I revoke consent for any health tracking sync."

"Under HIPAA, I request an accounting of all disclosures of my data to any third-party or digital health networks. I also request that my identifiable health data be withheld from future ecosystem participation."

6. Who Has Signed On (So Far)

Tech & Digital Health Companies:

  • Amazon

  • Apple

  • Google

  • OpenAI

  • Anthropic

  • Microsoft AI

  • Oracle Health

  • Epic Systems

  • athenahealth

  • DrChrono

  • Hippocratic AI

  • Zocdoc

  • Oura

  • Samsung

  • b.well Connected Health

  • Virta Health

  • Noom

  • Welldoc

Payers & Health Systems:

  • UnitedHealth Group

  • CVS Health (Aetna / Elevance)

  • Cleveland Clinic

  • Intermountain Health

  • Providence Health

Infrastructure & Digital Identity:

  • CLEAR (TSA)

  • CommonWell Health Alliance

  • eClinicalWorks

  • Surescripts

  • Continua Health Alliance

These organizations are building the infrastructure where your body becomes a data stream — tracked, inferred, and scored. To stay updated on new adopters: CMS Early Adopters List

 

7. Advocacy & Watchdog Groups (USA-Based)

  • Electronic Privacy Information Center (EPIC) – Fights government overreach and privacy violations, with a strong focus on health data.

  • Center for Democracy & Technology (CDT) – Advocates for digital rights and transparency in health surveillance.

  • Confidentiality Coalition – Tracks CMS ecosystem participants and supports patients in asserting privacy rights.

  • Consumers United for Evidence-based Healthcare (CUE) – Ensures consumer voice in healthcare technology and data use.

8. Resources & References

9. Resist The Palantir Growing Monopoly

Palantir operates at the core of the U.S. surveillance state. Its platforms are used by ICE for raids and deportations, by police for predictive crime mapping, by hospitals to monitor patients in real-time, and by the military for lethal targeting. This is not theoretical—it is live infrastructure used to track bodies, movements, and behaviors at scale.

Palantir’s power doesn’t come from the best technology. It comes from unchecked contracts, unregulated access to public data, and a closed loop of government ties. Without transparency, accountability, or competition, they’ve become the invisible architecture of digital authoritarianism in America.

Disrupting their dominance isn’t just about one company. It’s about dismantling the silent machinery of techno-authoritarian control before it becomes irreversible.

What You Can Do Now

  • Demand transparency: Write to local representatives and federal agencies to oppose sole-source contracts with Palantir. Public data should not be privately weaponized.

  • Boycott where possible: Urge clinics, cities, schools, or local governments not to work with Palantir or to review contracts tied to surveillance.

  • Support direct action: Join or share protests like “Purge Palantir” that challenge the company’s ties to ICE and military surveillance.

  • Uplift whistleblowers: Follow and amplify the voices of former employees and insiders speaking out against Palantir’s abuses.

  • Push watchdog agencies: Donate to or support U.S.-based groups like EPIC, CDT, or Amnesty USA, which track and challenge Palantir’s influence.

  • Stay informed: Follow updates from civil liberties coalitions and journalists exposing Palantir’s role in the growing surveillance-industrial complex.

 

I didn’t write this because I had all the answers—I wrote it because I couldn’t stay quiet. Like so many of you, I’ve been watching the rapid erosion of our privacy, our autonomy, and our right to live untracked.

I’m not a cybersecurity expert or a policy wonk—I’m someone who cares deeply about what it means to be free in body and mind.

I’m someone who still believes that choice, truth, and sovereignty matter.

This substack was born out of late nights, heavy questions, and a refusal to let silence win. If it helps you take even one step closer to reclaiming your space, then it’s done its work.

You’re not alone in this insanity. None of us are. -Bernadette

Find out how I can help you. 

Email

Stay connected with news and updates!

Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.

We hate SPAM. We will never sell your information, for any reason.