Apple says it stores Health data in a protected way on the device.
In reality, health data is leaked through logs and can be accessed by any other app. It is impossible to tell whether or not this data has been accessed in the wild.
Since Apple failed to implement their claimed security features properly and you need to assume exploitation by apps in the wild in the worst case, this would require a disclosure to GDPR authorities. Did they do it? Were they fined yet?