In my case it was for mobile wireless signaling traffic (all the coordination for creating a mobile internet connection, handing the connection off between towers, etc), and I'd credit it as one of the reasons you're mobile internet connection is so stable. When LTE first came out, myself and many others solved all sorts of bugs in the equipment and protocols by using or building these sorts of tools.
80% of the relevant outcome was typically to get a true-to-the-wire sniffer capture (switch mirrors won't always mirror 100% of packets for various reasons) for troubleshooting performance of whatever the complaint of the day from the server team was.
19% was for feeding a security monitoring systems which looked for abnormal flow patterns to let us know a server was compromised.
1% was for the call recording system compliance requirement for the emergency department.
0% was because I was a cool superspy tasked by the government to siphon info to them or trying to sell medical records on the black market or something. I mean, you can try to something nefarious with such tools... but one could say the same about a generic server, SAN, application, etc as well. People are just used to understanding what those would typically be used for so they don't assume it must be for the scary thing they've heard about.
That said, it doesn't rule it out either. But again, the concern shouldn't be sourcing from their usage of normal infrastructure tools it should be sourcing from... well, all of the user analytics Google very publicly does directly in the server.
https://www.cisa.gov/sites/default/files/2023-02/TLP%20CLEAR...