Doable to some extent, but would they really learn much that we haven't already told them, given our propensity to Google for symptoms and diseases?
Personally, my worry here, if I had some embarrassing medical history that I wouldn't want people to know about, would be some malicious party gaining access to de-anonymized data and using it to blackmail, or just simply making it public.
Edit: Come to think of it, insurance companies could probably have a field day with a data set like this.
I'm not sure that getting caught using such data would be sufficiently bad news to be not worth it.
I've been in Europe two decades and aside from health insurance being key to more than a few countries, private health insurance is relatively common in tandem with public health services.
Outside of those countries, it's still somewhat common to have private health insurance (not just dental), such as Mapfre or Regina Maria. Heck, even in Germany something like 1 out of 10 people have private health insurance (again, not just dental).
"Estimating the success of re-identifications in incomplete datasets using generative models" - https://www.nature.com/articles/s41467-019-10933-3
"...We here propose a generative copula-based method that can accurately estimate the likelihood of a specific person to be correctly re-identified, even in a heavily incomplete dataset. On 210 populations, our method obtains AUC scores for predicting individual uniqueness ranging from 0.84 to 0.97, with low false-discovery rate. Using our model, we find that 99.98% of Americans would be correctly re-identified in any dataset using 15 demographic attributes. Our results suggest that even heavily sampled anonymized datasets are unlikely to satisfy the modern standards for anonymization ..."
https://systems.cs.columbia.edu/private-systems-class/papers...
It's well known within the sphere that anonymization is hard and deanonymization is trivial. The original Netflix prize around their recommender system also had issues with deanonymization.