Allow me to put on my tin foil hat and attempt to blue-sky some ideas that could be used for governments / large corporations / Lex Luthor to exploit this system. I'm going to imbue this imaginary bad guy with some sweeping powers, but please bear with me.
From the article, one of the images, insert:
Alice's phone periodically downloads the broadcast beacon keys of everyone who has tested positive for COVID-19 in her region.
This implies the API is able to give you the keys based on region. Is this lat/long and radius? Is this some other way, like FEMA regions? I can't say I know. Suffice it to say, this data can be retrieved specific for some kind of location. This also implies that location is then sent, at least upon a positive test, to the API. Furthermore, these keys and their locations are public by necessity.
Your phone is broadcasting beacon keys. These keys could then be easily "slurped up" by any number of sensors, such as those large retailers have for tracking Bluetooth ID's around the stores. Lex Luthor could then conceivably keep an entire list of beacon keys broadcasted anywhere he can put sensors, which, because he's Lex Luthor, will from here on out be everywhere you are, up to and including your apartment building / house / place of residence and - why not - your vehicle or person.
Lex Luthor now has every key generated by every phone, and then also every positive key by region. It could be noted here that Lex Luthor could realistically be a government and simply request these keys from whatever cloud provider(s) are presently hosting the data.
He could coordinate your location based on your keys. Further, he could track all your frequent contacts. If you and/or your contacts are up to no good, he comes in his black helicopters and sweeps you ne'er-do-well's away to who-knows-where.
Thing is, Lex Luthor could already do this based on your currently operating radios on your devices, your wifi adapter and bluetooth adapter for example. And in those cases it's even easier because he doesn't have to do best-guess logic to know which is you. He knows which is you because your hardware ID does not change.
What Lex Luthor can now do that he couldn't do before is know if you or anyone with whom you associate is COVID-19 positive.
The only danger, if you could call it such, that this adds is that it "normalizes" sharing health data with those around you, even if anonymously. It will be argued that this can be used as a pivot point for future violations. If it will or not, I don't know. Governments do not have a great track record and have earned distrust from many people, especially marginalized and disenfranchised populations.
Realistically speaking, people with such concerns (valid or not, that's not for me to judge) have really the only option of at least deferring backward to a non-smart phone and turning off unnecessary radios if their concerns are around the tracking. Best of all for those so concerned is ridding oneself of any mobile personal device that broadcasts any signal on any frequency whatsoever.
I see this system as saving lives. I also see this system as potentially a slippery slope. I also see it as nothing new to Lex Luthor's concerns or capabilities. If you want to make Mr. Luthor's job harder, your only real option is to abandon all personal devices that broadcast.