ProBackend
cloud security incidents
2 hours ago6 min read

Why Every Security & Compliance Analyst Should Care About Neko Health’s Body Scans

How a body-scanning startup’s multimodal health platform reveals vulnerabilities in human data collection — and why it matters for compliance and risk assessment.

Why Every Security & Compliance Analyst Should Care About Neko Health’s Body Scans

I didn’t think a body scanner would make me rethink data governance until Alex Tew showed up on X with a photo of a mole he’d never noticed — and a thank you note to Neko Health.

That’s not a cybersecurity incident. Not yet.

But it’s the kind of thing that turns into one if we keep pretending health data is just ‘personal’ — not a compliance liability, not a regulatory minefield, not a new vector for identity theft.

Neko Health’s tech is simple: 2,000+ high-res images of your skin, paired with bloodwork, to map physiological signals you didn’t even know were measurable. They’re not reading your DNA. They’re reading your sweat, your capillaries, your heartbeat’s rhythm through your epidermis. And they’re stitching it all together with Apple Health data — your sleep, your steps, your heart rate variability — to build what they call a ‘360° health profile.’

It’s not magic. It’s machine learning trained on millions of data points.

And it’s being sold to people who think they’re getting a wellness upgrade.

They’re not.

They’re handing over a biometric fingerprint more unique than their SSN.

The Scan Isn’t Just a Scan — It’s a Data Pipeline

Let’s be clear: this isn’t a spa treatment. It’s a data ingestion pipeline with a human in the chair.

The scanner doesn’t just capture surface texture. It measures perfusion, thermal gradients, microvascular density, things even your dermatologist can’t see without a dermoscope. Then it correlates that with hemoglobin levels, glucose trends, cortisol markers from your blood panel. The system doesn’t diagnose. It flags anomalies. And then it sends the raw data, not just the report, to clinicians.

That’s the problem.

Because that data isn’t protected by HIPAA.

Not yet.

Neko Health isn’t a covered entity. It’s a ‘health tech’ startup. That means it doesn’t have to encrypt data at rest, doesn’t need to log every access, doesn’t have to report breaches under 500 records.

And yet, this data? It’s more sensitive than your credit score. More persistent than your password. More identifiable than your face.

A single scan can reveal:

  • Whether you’re diabetic before your HbA1c rises
  • If you’re hiding a melanoma under a mole you thought was benign
  • Whether your stress levels are chronic, not situational
  • If your body composition suggests you’re overtraining or under-eating

All of it, linked to your Apple Health ID. All of it, potentially tied to your name, your location, your insurance.

This isn’t a health product.

It’s a new class of personal data infrastructure.

And we’re not regulating it.

Apple Health Isn’t the Bridge, It’s the Backdoor

Here’s what’s really dangerous: Neko doesn’t just use Apple Health. It depends on it.

The TechCrunch article quotes co-founder Hjalmar Nilsonne: “It gives our clinicians real-world data to use in its assessments.”

Real-world. Meaning: your Apple Watch recorded your resting heart rate at 2 a.m. while you were stressed. Your iPhone logged your sleep efficiency at 68%. Your fitness app recorded three missed workouts last week.

That’s not health data.

That’s behavioral surveillance.

And Neko is stitching it together with your skin’s thermal signature.

What happens when someone breaches Neko’s database?

They don’t get your password.

They get your body’s narrative.

They get the story of your anxiety, your exhaustion, your hidden illness, all tied to your real name, your real Apple ID, your real location.

That’s not a breach. That’s a reconstruction.

And it’s not hypothetical.

We’ve seen this before.

In 2021, Clearview AI scraped facial data from social media to build a biometric database. Regulators called it a violation.

Neko Health is doing the same thing, but with your body’s internal signals, and you’re signing up for it voluntarily.

The Alex Tew Effect, When Prevention Becomes a Liability

Alex Tew’s story is beautiful.

He found a malignant mole. He got it removed. He’s alive.

That’s the headline.

But here’s the footnote no one’s talking about:

What if someone else’s scan had flagged a mole, but they didn’t have the money to follow up?

What if their data got leaked, and their insurer saw the anomaly before they did?

What if their employer found out their cortisol levels were off the charts?

We’ve seen this script before in insurance underwriting. We’ve seen it in hiring.

Now it’s happening in preventive health, and no one’s asking who owns the data, who’s liable if it’s misused, or what happens when the algorithm gets it wrong.

Neko’s tech is brilliant.

But brilliance without governance is just a new kind of risk.

Growth Isn’t Progress, It’s Scale Without Safeguards

100,000 scans. 350,000 on the waitlist.

They’re opening in New York.

They’re raising $700 million.

And yet, their privacy policy? Barely a paragraph.

No mention of data retention. No opt-out for research use. No third-party audit.

They’re scaling faster than their compliance team can keep up.

That’s not innovation.

That’s negligence dressed as disruption.

Daniel Eks’ recent reporting on Neko’s latest funding round highlights how venture capital is pouring into unregulated biometric infrastructure. $700 million isn’t just funding; it’s validation that the market believes this data is valuable. And when capital flows that fast, security audits get cut to meet launch dates.

We’ve seen this with Fitbit. With 23andMe. With Every. Each time, the same pattern: rapid adoption, weak governance, eventual breach, then a slow, reactive regulatory response.

Neko Health is the next one.

And if you’re a security analyst? You’re already behind.

Because your org doesn’t even know this data exists.

The Real Risk Isn’t the Scan, It’s the Assumption

The biggest danger isn’t that Neko Health will get hacked.

It’s that we assume their tech is ‘just health.’

That it’s not subject to the same controls as our HR systems.

That it doesn’t need DLP rules.

That it doesn’t belong in our data classification matrix.

It does.

Your job isn’t to stop innovation. It’s to map the attack surface before the attackers do. That means classifying Neko’s output as PII, demanding data processing agreements, and forcing your legal team to review vendor contracts for biometric data clauses. If your current policy treats wellness apps as ‘low risk,’ you’re already failing your compliance checklist.

This isn’t a health story.

It’s a security story.

And if you’re waiting for a breach to wake you up, you’re already too late.

Start asking:

  • Where is this data stored?
  • Who has access?
  • Is it encrypted?
  • What’s the retention policy?
  • Is it shared with third parties?
  • Has anyone audited their compliance controls?

If you can’t answer those questions, you’re not a security & compliance analyst.

You’re just waiting for the next headline.

And trust me, the next headline won’t be about a mole.

It’ll be about 350,000 people whose bodies were mapped, and then sold.

And you? You’ll be the one who didn’t see it coming.

More blogs