Skip to main content
Skip to the tools
The Internet Safety Toolkit

Privacy tools for patients and support communities.

Eight tools you can set up in an afternoon. Free or low cost, from named nonprofits and independently audited projects, chosen by patient advocates. A companion to the Light Collective Internet Safety Guide.

Why this matters

Patient communities are watched, tracked, and sold, often by the same companies they turn to for care.

Support groups, diagnosis searches, and patient forums do not stay between people and their communities. Advertising trackers, social platforms, and even hospital and telehealth websites collect that activity and sell access to it. The Markup found the Meta Pixel on the websites of a third of the top 100 US hospitals, sending patient data to Facebook. GoodRx was fined $1.5 million by the FTC for sharing prescription information with Google and Facebook.

On the sites you visit

Health sites leak sensitive information

The Markup’s Blacklight tool has documented ad trackers, session recorders, and Meta and Google pixels embedded on hospital, telehealth, and patient advocacy websites. Data can leave before anyone hits “submit.”

On your own accounts

One reused password unlocks a whole life

Password reuse and unencrypted messaging mean one leaked login can expose years of private conversations, patient portal history, and community admin access. The EFF’s Surveillance Self-Defense guide walks through what actually helps.

Why the stakes are high

Privacy is patient safety

Leaked health details can affect insurance, employment, immigration, family relationships, and access to care. Communities cannot organize freely when their conversations can be surveilled or sold. Read more in the Patient AI Rights Initiative.

The eight tools below are what patients and support communities can put in place today. No jargon. Free or low cost. Set up in an afternoon.

The toolkit

Here are the basic tools for protecting your health privacy online.

Work through the cards from 01 to 08. Each one takes fifteen minutes or less. Everything here comes from a named nonprofit, an independently audited project, or a research group with a public record. If you want the outside references first, Privacy Guides and the EFF Surveillance Self-Defense guides are where we cross-check our picks.

Do this first 01
Talk privately

Signal

Free messaging run by a nonprofit foundation. End-to-end encryption means the messages are readable only on the sending and receiving devices. Not even Signal can see them. Works for one-on-one and group chats, with disappearing messages when you want them. Invite your inner circle first, then your community. EFF’s how-to guide walks through setup.

Free Nonprofit iPhone, Android, desktop
Pick a browser 02
Browse with protection

Firefox

Firefox comes from Mozilla, which is backed by a nonprofit foundation. It blocks many known trackers by default through Enhanced Tracking Protection. Using a browser that is not made by an advertising company is a strong first switch. Pick either Firefox or Brave. You do not need both.

Nonprofit-backed Tracker blocking Good default choice
Or pick this browser 03
Browse with protection

Brave

Brave blocks more by default than most browsers, including many ads and cross-site trackers, without changing settings. If you want the strongest out-of-the-box protection, use Brave. The company is not funded by advertising, and its privacy notice is unusually direct.

Strong defaults Blocks ads and trackers Non-ad company
Change your search engine 05
Search without a profile

DuckDuckGo

DuckDuckGo does not save or profile your searches. Health questions you type into a search engine should not follow you around the internet as ads. Set it as your default search engine, or install the app for a single-tap browser with tracking protection built in.

No search profile Default search ready App available
Audit any website 06
Inspect what a site is doing

Blacklight

A free real-time inspector from The Markup, a nonprofit newsroom. Paste any website address and it scans for ad trackers, third-party cookies, session recorders, and pixels reporting to Facebook and Google. Run it on a health site before you sign up. Then run it on your own community site.

Nothing to install Run before sign-up Audit your own site
Fix your passwords 07
Manage passwords

Bitwarden

A password manager creates and remembers a strong, unique password for every account, so one leaked password cannot unlock the rest of your life. Bitwarden is free, open source, and independently audited. 1Password is a well-regarded paid alternative. Either way, turn on multi-factor authentication for email, banking, and community admin accounts. EFF’s password guide explains why.

Open source Independently audited Turn on MFA
Cover your network 08
Pick a trustworthy VPN

A trustworthy VPN

A VPN, or virtual private network, hides what you do online from the network you are on (hotel, airport, clinic) and from your internet provider. Know its limits. A VPN does not make you anonymous, and it does not block trackers on its own. Skip free VPNs, which often make money by selling the data you are trying to protect. The three below are recommended by Privacy Guides, publish independent audits, and keep no activity logs.

Proton VPN, start here Mullvad, privacy purist IVPN, long audit record
Why these tools

Every tool has a source we can name.

We pick tools with public accountability. The Light Collective has no financial relationship with any product on this list. We cross-check our picks against Privacy Guides, EFF Surveillance Self-Defense, and Consumer Reports’ Digital Lab.

Nonprofit-run

Built to serve users, not advertisers

Signal Foundation, Mozilla, the Electronic Frontier Foundation, and The Markup all run tools on this list. None of them make money by profiling you.

Independently audited

You do not have to take their word for it

Bitwarden, Proton, Mullvad, and IVPN publish outside security audits and keep no activity logs. The results are public.

Patient-vetted

Reviewed by advocates in our network

Every recommendation was reviewed by advocates and community leaders in the Light Collective network. If a tool changes ownership, gets acquired, or stops publishing audits, we drop it. Send suggestions to hello@lightcollective.org.

Keep going

Share this with the community who needs it.

Patient communities are welcome to adapt and share this resource with attribution. Pair it with the Internet Safety Guide, run it inside a bootcamp, or send it to the next advocate learning how to organize online. Read more of our work on our roadmap.

Sources

  1. Todd Feathers, Simon Fondrie-Teitler, Angie Waller and Surya Mattu, “Facebook Is Receiving Sensitive Medical Information from Hospital Websites,” The Markup, June 16, 2022. themarkup.org
  2. Federal Trade Commission, “FTC’s First-of-Its-Kind Health Breach Notification Rule Case,” February 2023. ftc.gov
  3. Electronic Frontier Foundation, Surveillance Self-Defense guides. ssd.eff.org
  4. The Markup, “Blacklight: A Real-Time Website Privacy Inspector.” themarkup.org/blacklight
  5. Mozilla, “Enhanced Tracking Protection in Firefox,” support article. support.mozilla.org
  6. DuckDuckGo Privacy Policy. duckduckgo.com/privacy
  7. Bitwarden security audits. bitwarden.com
  8. Privacy Guides, “VPN Services” (Proton VPN, Mullvad, IVPN). privacyguides.org/en/vpn

Prepared by The Light Collective. Facts checked and updated in July 2026. Patient communities are welcome to adapt and share this resource with attribution. The Light Collective has no financial relationship with any tool listed here. This resource is educational and is not legal advice.