Your Wearable Health Data Has No Legal Shield

Advertisements

Most people assume their health information is protected the same way their medical chart is. It isn’t, at least not when that information comes from a smartwatch or a fitness ring instead of a doctor’s office. Wearable health data sits in a legal gray zone that most users never think to check, and the company on the other end of your sync button gets to decide most of what happens next.

person checking smartwatch health data next to blurred legal documents symbolizing HIPAA gap

What HIPAA Actually Protects (and What It Skips)

Advertisements

The Health Insurance Portability and Accountability Act sounds like it should cover anything medical, but it only applies to a specific list of organizations called covered entities. These are hospitals, doctors, health insurers, and the vendors those groups directly hire to handle patient records. Apple, Fitbit, Garmin, Oura, and Whoop are not on that list unless they’re working directly with your doctor or insurer on your behalf, according to a legal overview from the Law Office of Jeffrey Hall.

That distinction matters more than it sounds like it should. A blood pressure reading typed into your doctor’s chart is locked down by federal law. The same reading, logged automatically by your smartwatch, is governed by whatever terms of service you clicked through without reading. Here’s a quick side-by-side of what actually falls under HIPAA:

Data SourceCovered by HIPAA?
Hospital recordsYes
Insurance claimsYes
Doctor’s office notesYes
Apple Watch heart rateNo
Oura Ring sleep scoreNo
Fitbit step countNo
Whoop recovery dataNo

The wearable market has grown from $20 billion in 2015 to over $109 billion in 2023, and almost none of that growth came with matching privacy regulation.

Where Your Wearable Health Data Actually Goes

Once your smartwatch syncs, your data typically moves to a company’s cloud servers, then potentially to whoever that company’s privacy policy allows as a “partner,” “affiliate,” or “service provider.” Those categories are broad enough to include advertisers, data analytics firms, and sometimes actual data brokers. That same aggregated profile is exactly what an entire industry built around reselling personal information has been doing with far less sensitive data for years.

Most companies say they don’t sell your health data outright, and that’s often technically true. What they don’t always say clearly is how long they keep it, whether it survives an account deletion, or what happens to it if the company gets acquired. If you’ve ever wondered whether closing an account actually erases anything, the honest answer is usually no, since the data doesn’t disappear just because your account does.

digital illustration of health data flowing from wearable device to unprotected cloud storage

What’s Actually at Stake When the Law Doesn’t Apply

Without HIPAA-level protection, three things can happen that would be illegal for a hospital to do with the same information.

Insurance and employer access. Wellness programs run through employers or insurers sometimes ask you to connect a wearable in exchange for discounts. Nothing stops that same data from eventually informing risk assessments, since the legal wall that protects your medical chart doesn’t extend to a step count you volunteered.

Data used against you legally. Wearable data has already surfaced as evidence in personal injury and insurance dispute cases, because a continuous stream of biometric readings is exactly the kind of detailed timeline that lawyers look for.

Breach exposure. Health-related cybersecurity breaches increased more than 4,000% between 2009 and 2023, according to Mozilla Foundation research covered by Government Technology, and body-centric data is projected to become a market worth more than $500 billion by 2030. More companies handling this data means more places where it can leak.

None of this requires a company to act in bad faith. It just requires the current legal framework to keep treating a hospital’s blood test differently than a smartwatch’s heart rate, even when both numbers describe the same body.

The One State Law Trying to Close the Gap

Washington passed the My Health My Data Act in 2023, becoming the first state to specifically extend privacy protections to health data that HIPAA leaves out. The law gives residents the right to see what health data has been collected, request deletion, and block third-party sales without explicit consent, and roughly 76% of Washingtonians expressed support for it according to the Washington State Attorney General’s office.

Most states still have nothing comparable. That absence is worth noticing on its own, since it means your legal protection for wearable health data can depend entirely on your zip code rather than the sensitivity of the data itself.

What I Actually Found

Reading through wearable privacy policies for this piece, the pattern that stood out wasn’t secretive language. It was the opposite. Most companies are upfront that they share data with “service providers” and “business partners,” and most users skip past that section because it sounds routine. The real gap isn’t hidden disclosures, it’s that disclosure alone does almost nothing when there’s no regulatory floor underneath it.

If I were setting up a new wearable today, I’d skip the general privacy policy and go straight to the account settings menu to check data retention and third-party sharing toggles individually, since those controls are usually more restrictive than the default. I’d also treat any employer or insurer wellness program request to connect a device as a negotiation, not a formality, and ask in writing whether that data could ever affect a claim or premium before agreeing to anything.

Wearable health data isn’t inherently more dangerous than what a hospital collects. It’s just collected by companies that were never required to protect it the same way.

Frequently Asked Questions

Check the FAQ section below for quick answers on HIPAA coverage, data sales, and state-level protections.

Does HIPAA protect data from my Fitbit or Apple Watch?

No. HIPAA only applies to covered entities like hospitals, doctors, and insurers. Consumer wearable makers such as Apple, Fitbit, Garmin, Oura, and Whoop fall outside that definition unless they’re working directly with a healthcare provider on your behalf.

Can my wearable health data be sold to third parties?

Most major wearable companies state they don’t sell data outright, but many privacy policies allow sharing with broadly defined “partners” or “service providers,” which can include advertisers and analytics firms.

What is the Washington My Health My Data Act?

It’s a 2023 state law that extends privacy protections to health data not covered by HIPAA, giving Washington residents the right to see, delete, and block the sale of their consumer health data.

Can insurance companies access my wearable health data?

If you voluntarily connect a wearable to an employer or insurer wellness program, that data can inform risk assessments since HIPAA’s protections don’t extend to data you share outside a medical provider relationship.

How can I limit what my wearable company does with my data?

Check your account’s privacy settings directly rather than relying on the general privacy policy, disable unnecessary third-party sharing toggles, and confirm in writing what happens to your data if you delete your account.

About the author

Lucas

Lucas writes about privacy, security, AI, and the everyday tech problems people actually run into. He self-hosts his own servers, builds automation for his own crypto and trading workflows, and uses AI tools daily for real work — not demos. Most of what's here he figured out by testing it himself, then wrote down what actually worked.

More from Lucas →

2 thoughts on “Your Wearable Health Data Has No Legal Shield”

Comment form introduction