Cybersecurity

Who Owns Your Wearable Health Data? US Law Has Gaps

Who Owns Your Wearable Health Data? US Law Has Gaps
Illustration · Newzlet

Updated 21 August 2026 — this article was rewritten with primary sources added and unsupported claims removed.

The common way to describe wearable health data — that no law protects it — is not quite right, and the way it’s wrong matters. There is a federal tool that reaches the heart-rate, sleep, and cycle data your smartwatch collects. But it only fires when a company breaks a promise it made to you, not when it quietly collects and sells the data in the first place. Understanding that distinction is the difference between knowing what recourse you actually have and assuming you have none.

Why HIPAA stops at the clinic door

HIPAA is narrower than almost everyone assumes. It binds only “covered entities” — health plans, health-care clearinghouses, and health-care providers — and their business associates — a set of terms fixed in the regulation itself (45 CFR § 160.103). A company that sells you a fitness tracker or a smart ring is none of those things. So the identical data point — an irregular heart rhythm, a night of poor sleep — is tightly regulated when your cardiologist records it and completely unregulated when your watch does. The information didn’t change; the entity holding it did, and HIPAA follows the entity, not the sensitivity.

That is the gap. What most coverage misses is that a different agency has been quietly filling part of it — with a rule almost nobody names.

The one federal lever that actually fires

Since 2023 the Federal Trade Commission has been enforcing its Health Breach Notification Rule against exactly the apps HIPAA ignores. It barred the prescription-discount service GoodRx from sharing users’ health data for advertising after finding it had passed prescription and condition data to Facebook and Google despite promising it never would, with a $1.5 million penalty (Federal Trade Commission). It reached a $200,000 settlement with the fertility app Premom over similar data-sharing, and fined the therapy service BetterHelp $7.8 million for handing user data to Facebook and Snapchat. In 2024 it updated the rule to explicitly cover health apps and connected devices (FTC guidance).

Read what those cases have in common, though, and the limit becomes clear. Every one turned on deception — a company saying it would not share data and then doing so. The FTC’s power here is to punish the broken promise, not the collection itself. A wearable maker that discloses, in its privacy policy, that it shares your biometric data with advertisers and partners has made no false promise to break. It can collect and monetise the same data GoodRx got fined over, and stay entirely within the law, simply by telling you it does. The federal protection you have is real, but it is a truth-in-advertising protection, not a health-privacy one.

Washington built the law that’s actually missing

One state wrote the statute the federal government hasn’t. Washington’s My Health My Data Act — the first U.S. law built specifically to protect health data that falls outside HIPAA — took effect on 31 March 2024 for larger companies and 30 June 2024 for small businesses (Washington State Attorney General). It does what a privacy law is supposed to do rather than what a fraud law does: it requires prior, opt-in consent to collect consumer health data, a separate consent to share it, and a distinct consent to sell it — one that a consumer must sign and that expires after a year. It regulates the act of taking the data, not merely lying about it.

The catch is jurisdiction. My Health My Data protects people in Washington. A resident of a state with no equivalent statute has neither Washington’s consent regime nor a federal one — only the FTC’s did-they-lie backstop. The strength of your rights over your own heart-rate history depends, arbitrarily, on which state line you happen to live inside.

Washington is not the only state to have moved. Virginia took a narrower run at an adjacent problem, banning the sale of precise geolocation data while leaving a loophole in the word “monetary”. And the sharpest test of health data outside HIPAA is not a smartwatch at all — it is the reproductive-health app whose records a court can subpoena.

Why “anonymized” is doing less work than it sounds

Wearable makers routinely reserve the right to share “anonymized” or “aggregated” data, and that word is meant to reassure. It shouldn’t, not entirely. Researchers have shown that individuals can be re-identified from supposedly anonymous datasets with high accuracy when those datasets are cross-referenced against other available information — one widely cited study estimated that 15 demographic attributes are enough to re-identify 99.98% of Americans in a de-identified set (Rocher, Hendrickx & de Montjoye, Nature Communications). Biometric time-series — the shape of your sleep, the rhythm of your heart — is unusually distinctive, which makes stripping a name off it a weaker safeguard than the label implies.

What that actually leaves you holding

Put the pieces together and the real position is specific, not vague. Outside Washington, the data your wearable collects is governed mainly by the privacy policy you agreed to, backed by a federal rule that only bites if the company contradicts that policy. Two features of that arrangement deserve more weight than buyers give them. First, acquisitions carry your data with them: when a wearable brand is bought, your years of history move to an owner operating under its own, possibly looser, terms — Fitbit users saw this when Google acquired the company. Second, breaches are permanent in a way passwords are not; you can reset a password, but you cannot un-share a five-year record of your resting heart rate once it has been copied off a server.

So the useful questions to ask before buying are narrow ones the marketing won’t answer: does the company sell health data to third parties; does your consent transfer automatically if the company is acquired; and can you truly delete every record, or only close the account. If a maker processes sensitive metrics on the device rather than uploading raw data to the cloud, that materially shrinks the exposure — but you will usually have to dig through technical specifications to find out, because it rarely appears in an ad. None of this is the protection a health-privacy law would give you. Until Congress writes one, it is the protection you have.

AI-Assisted Content — This article was produced with AI assistance. Sources are cited below. Factual claims are verified automatically; uncertain claims are flagged for human review. Found an error? Contact us or read our AI Disclosure.

More in Cybersecurity

See all →