Data should not be sold or used outside its 1 purpose. It should not be available to the original company at all to look at or have access to. Accessing data should only be allowed through court issued warrants and only on the devices in the proximity and time of the incident. As someone who is an admin to systems that deal with patient data information I can tell you without a doubt we dont even have access to this data, just the setup of everything else around it. It also has a full audit log of everyone who even views the data. This isnt anything new, they just decided to change the rules to see how far they can get away with doing whatever they want for personal gain.