Skip to main content
Skip to the tools
The Internet Safety Toolkit

Privacy tools for patients and support communities.

Nine tools you can set up in an afternoon. Free or low cost, from named nonprofits and independently audited projects, chosen by patient advocates. A companion to the Light Collective Internet Safety Guide.

Why this matters

Patient communities are watched, tracked, and sold, often by the same companies they turn to for care.

Support groups, diagnosis searches, and patient forums do not stay between people and their communities. Advertising trackers, social platforms, and even hospital and telehealth websites collect that activity and sell access to it. The Markup found the Meta Pixel on the websites of a third of the top 100 US hospitals, sending patient data to Facebook. GoodRx was fined $1.5 million by the FTC for sharing prescription information with Google and Facebook.

On the sites you visit

Health sites leak sensitive information

The Markup’s Blacklight tool has documented ad trackers, session recorders, and Meta and Google pixels embedded on hospital, telehealth, and patient advocacy websites. Data can leave before anyone hits “submit.”

On your own accounts

One reused password unlocks a whole life

Password reuse and unencrypted messaging mean one leaked login can expose years of private conversations, patient portal history, and community admin access. The EFF’s Surveillance Self-Defense guide walks through what actually helps.

Why the stakes are high

Privacy is patient safety

Leaked health details can affect insurance, employment, immigration, family relationships, and access to care. Communities cannot organize freely when their conversations can be surveilled or sold. Read more in the Patient AI Rights Initiative.

The nine tools below are what patients and support communities can put in place today. No jargon. Free or low cost. Set up in an afternoon.

The toolkit

Here are the basic tools for protecting your health privacy online.

Work through the cards from 01 to 09. Each one takes fifteen minutes or less. Everything here comes from a named nonprofit, an independently audited project, or a research group with a public record. If you want the outside references first, Privacy Guides and the EFF Surveillance Self-Defense guides are where we cross-check our picks.

Do this first 01
Talk privately

Signal

Free messaging run by a nonprofit foundation. End-to-end encryption means the messages are readable only on the sending and receiving devices. Not even Signal can see them. Works for one-on-one and group chats, with disappearing messages when you want them. Invite your inner circle first, then your community. EFF’s how-to guide walks through setup.

Free Nonprofit iPhone, Android, desktop
Pick a browser 02
Browse with protection

Firefox

Firefox comes from Mozilla, which is backed by a nonprofit foundation. It blocks many known trackers by default through Enhanced Tracking Protection. Using a browser that is not made by an advertising company is a strong first switch. Pick either Firefox or Brave. You do not need both.

Nonprofit-backed Tracker blocking Good default choice
Or pick this browser 03
Browse with protection

Brave

Brave blocks more by default than most browsers, including many ads and cross-site trackers, without changing settings. If you want the strongest out-of-the-box protection, use Brave. The company is not funded by advertising, and its privacy notice is unusually direct.

Strong defaults Blocks ads and trackers Non-ad company
Change your search engine 05
Search without a profile

DuckDuckGo

DuckDuckGo does not save or profile your searches. Health questions you type into a search engine should not follow you around the internet as ads. Set it as your default search engine, or install the app for a single-tap browser with tracking protection built in.

No search profile Default search ready App available
Audit any website 06
Inspect what a site is doing

Blacklight

A free real-time inspector from The Markup, a nonprofit newsroom. Paste any website address and it scans for ad trackers, third-party cookies, session recorders, and pixels reporting to Facebook and Google. Run it on a health site before you sign up. Then run it on your own community site.

Nothing to install Run before sign-up Audit your own site
Fix your passwords 07
Manage passwords

Bitwarden

A password manager creates and remembers a strong, unique password for every account, so one leaked password cannot unlock the rest of your life. Bitwarden is free, open source, and independently audited. 1Password is a well-regarded paid alternative. Either way, pair it with an authenticator app (tool 09) and turn on multi-factor authentication for email, banking, and community admin accounts. EFF’s password guide explains why.

Open source Independently audited Turn on MFA
Cover your network 08
Pick a trustworthy VPN

A trustworthy VPN

A VPN, or virtual private network, hides what you do online from the network you are on (hotel, airport, clinic) and from your internet provider. Know its limits. A VPN does not make you anonymous, and it does not block trackers on its own. Skip free VPNs, which often make money by selling the data you are trying to protect. The three below are recommended by Privacy Guides, publish independent audits, and keep no activity logs.

Proton VPN, start here Mullvad, privacy purist IVPN, long audit record
Add a second lock 09
Protect your logins

Google Authenticator

An authenticator app shows a six-digit code that changes every 30 seconds. Once multi-factor authentication is on, someone who steals your password still cannot get in without the code on your phone. Google Authenticator is free, works without a cell signal, and keeps the codes on your device. It is made by Google, so if you prefer an open-source option, Privacy Guides recommends Ente Auth and Aegis. Whichever you choose, set it up on your email account first, then your social media. See the account protection steps below.

Free Works offline Android and iPhone
Account takeover

Keep your social media accounts in your own hands.

Account takeover is when someone else gets into your Facebook, Instagram, X, TikTok, or other account and locks you out. For a patient community the damage goes beyond one person. A hijacked admin account can expose a private group, send scams to every member, or delete years of shared history. Most takeovers start the same way: a reused password, a fake login page, or an email account with no second lock. These six habits close those doors.

1

Lock down your email first

Your email is the master key. Anyone who controls it can click “forgot password” on your social media and take everything else. Give your email account its own long password that you use nowhere else, and turn on multi-factor authentication there before you do anything else.

2

One password per account, never reused

Use a long, unique password for every account. If one site leaks it, the rest stay safe. You do not have to remember them: a password manager like Bitwarden (tool 07) creates and stores them for you. Never use your email password on social media.

3

Add a second lock, then save the spare keys

Multi-factor authentication, or MFA, asks for a code from your phone on top of your password, so a stolen password alone is not enough. Use an authenticator app (tool 09) when the site offers one. Text-message codes are the fallback if that is the only option. When you turn MFA on you will get recovery codes. Store them in your password manager or on paper somewhere safe, not in a screenshot or a notes app.

4

Do not sign in from a link you did not expect

Phishing is a fake message or email built to capture your password. Never log in through a link in an unexpected text, email, or DM, even if it looks like it came from the platform or a friend. Open the app or type the address yourself. Check the sender’s address carefully. No real company will ever ask you for your login code, authenticator code, or recovery codes.

5

Check who and what has access

Once a month, open your account’s security settings and look at where you are logged in. Sign out of any session you do not recognize. Remove old phones and browsers, and revoke any third-party apps, quizzes, or services you no longer use or never knowingly approved.

6

Keep your devices locked and updated

Install updates for your phone, computer, browser, and apps as soon as they arrive. Updates fix the security holes attackers use. Turn on a screen lock, stick to reputable security software, and avoid signing in to your accounts on shared or public computers.

Step-by-step help: EFF’s guide to turning on two-factor authentication and CISA’s More than a Password. If you run a patient group, walk every admin and moderator through these six steps together.

Why these tools

Every tool has a source we can name.

We pick tools with public accountability. The Light Collective has no financial relationship with any product on this list. We cross-check our picks against Privacy Guides, EFF Surveillance Self-Defense, and Consumer Reports’ Digital Lab.

Nonprofit-run

Built to serve users, not advertisers

Signal Foundation, Mozilla, the Electronic Frontier Foundation, and The Markup all run tools on this list. None of them make money by profiling you.

Independently audited

You do not have to take their word for it

Bitwarden, Proton, Mullvad, and IVPN publish outside security audits and keep no activity logs. The results are public.

Patient-vetted

Reviewed by advocates in our network

Every recommendation was reviewed by advocates and community leaders in the Light Collective network. If a tool changes ownership, gets acquired, or stops publishing audits, we drop it. Send suggestions to hello@lightcollective.org.

Keep going

Share this with the community who needs it.

Patient communities are welcome to adapt and share this resource with attribution. Pair it with the Internet Safety Guide, run it inside a bootcamp, or send it to the next advocate learning how to organize online. Read more of our work on our roadmap.

Sources

  1. Todd Feathers, Simon Fondrie-Teitler, Angie Waller and Surya Mattu, “Facebook Is Receiving Sensitive Medical Information from Hospital Websites,” The Markup, June 16, 2022. themarkup.org
  2. Federal Trade Commission, “FTC’s First-of-Its-Kind Health Breach Notification Rule Case,” February 2023. ftc.gov
  3. Electronic Frontier Foundation, Surveillance Self-Defense guides. ssd.eff.org
  4. The Markup, “Blacklight: A Real-Time Website Privacy Inspector.” themarkup.org/blacklight
  5. Mozilla, “Enhanced Tracking Protection in Firefox,” support article. support.mozilla.org
  6. DuckDuckGo Privacy Policy. duckduckgo.com/privacy
  7. Bitwarden security audits. bitwarden.com
  8. Privacy Guides, “VPN Services” (Proton VPN, Mullvad, IVPN). privacyguides.org/en/vpn
  9. Google, “Get verification codes with Google Authenticator,” Google Account Help. support.google.com
  10. Privacy Guides, “Multifactor Authentication” (Ente Auth, Aegis). privacyguides.org/en/multi-factor-authentication
  11. Electronic Frontier Foundation, “How to: Enable Two-factor Authentication,” Surveillance Self-Defense. ssd.eff.org
  12. Cybersecurity and Infrastructure Security Agency, “More than a Password.” cisa.gov/MFA

Prepared by The Light Collective. Facts checked and updated in September 2026. Patient communities are welcome to adapt and share this resource with attribution. The Light Collective has no financial relationship with any tool listed here. This resource is educational and is not legal advice.