Cybersecurity

Who Owns Your Wearable Health Data? US Law Has Gaps

Beyond Step Counting: The Surprising Depth of Data Modern Wearables Collect Your Apple Watch or Oura Ring does a lot more than log your morning run. These devices now continuously monitor heart rate variability, blood oxygen saturation, skin temperature fluctuations, respiratory rate, menstrual cycles, and sleep architecture — including how long you spend in REM ... Read more

Who Owns Your Wearable Health Data? US Law Has Gaps
Illustration · Newzlet

Beyond Step Counting: The Surprising Depth of Data Modern Wearables Collect

Your Apple Watch or Oura Ring does a lot more than log your morning run. These devices now continuously monitor heart rate variability, blood oxygen saturation, skin temperature fluctuations, respiratory rate, menstrual cycles, and sleep architecture — including how long you spend in REM versus deep sleep each night. The Oura Ring Gen 3, for example, tracks over 20 biometric signals around the clock. Apple Watch Series 9 can detect atrial fibrillation, a serious cardiac irregularity, and flag it directly to users and, potentially, third parties.

That data paints an intimate physiological portrait of your body — one far more revealing than most people grasp when they tap “agree” on a terms-of-service screen at setup. Fertility signals, for instance, aren’t abstract wellness metrics. In a post-Roe v. Wade legal landscape, menstrual cycle data stored on a corporate server carries real-world legal exposure. Irregular heart rhythm readings could affect insurance underwriting decisions. Stress indicators derived from heart rate variability data could theoretically be used by employers or data brokers.

The collection is also passive by design. Unlike posting a photo or filling out a health survey, wearable data generation requires no conscious action from the user. You sleep, and the device records. You sit through a stressful meeting, and the device records. You never made a deliberate choice to disclose that information in any given moment — the disclosure happens automatically, continuously, 24 hours a day.

This always-on surveillance model creates a data trail that accumulates for months or years. Smartwatch and smart ring users rarely stop to calculate what that means in aggregate — that a single year of wearable use can generate a granular biometric timeline of their body, moods, and reproductive health. That timeline lives on company servers, governed not by federal health privacy law but by whatever the company’s privacy policy currently says — and policies change.

The Legal Vacuum: Why US Federal Law Barely Protects Your Wearable Health Data

When your doctor stores your blood pressure readings or cholesterol results, federal law protects that information. HIPAA — the Health Insurance Portability and Accountability Act — governs how hospitals, clinics, and insurers handle medical records, giving patients defined rights and companies strict obligations. Your Fitbit, Apple Watch, or Oura Ring operates in an entirely different legal universe.

Consumer health data collected by wearable devices falls outside HIPAA’s scope. The law applies to covered entities: healthcare providers, health plans, and their business associates. A tech company selling you a fitness tracker is none of those things. The heart rate variability data your smart ring captures every night, the menstrual cycle patterns your smartwatch logs, the stress scores your device calculates — none of it carries federal protection once it leaves your body and lands on a private company’s servers.

No comprehensive federal consumer health data privacy law exists in the United States. That absence gives wearable manufacturers and the third parties they share data with wide latitude to store, monetize, and transfer your most intimate biometric information. Many privacy policies permit sharing data with advertisers, research partners, and data brokers. Users typically consent to this when they accept terms and conditions during setup — agreements most people never read.

Some states have moved to close the gap. Washington State’s My Health MY Data Act, which took effect in 2024, is the most aggressive state-level response, requiring explicit consumer consent before companies collect or share personal health data. California’s consumer privacy laws offer additional protections for state residents. But state-by-state legislation creates an uneven patchwork. Americans in states without specific health data statutes have no meaningful legal recourse if a wearable company misuses their sleep data, fertility tracking records, or cardiovascular metrics.

The practical result: the sensitivity of your wearable health data bears no relationship to how well the law protects it.

What the Privacy Policies Actually Say — and What They Don’t

Wearable companies publish privacy policies, but reading them closely reveals how much latitude those documents grant the companies themselves. Fitbit, Apple, and Garmin all reserve the right to share “anonymized” or “aggregated” health data with third-party partners, including advertisers and researchers. The problem with that framing is substantial: academic studies have repeatedly demonstrated that anonymized datasets — particularly those containing biometric patterns, sleep cycles, and movement data — can be re-identified with surprising accuracy when cross-referenced with other commercially available information. Stripping a name from a heart rate log does not make that log untraceable.

The language in these policies is also engineered for flexibility, not transparency. Broad clauses allow companies to update data-sharing practices with minimal notice — often a single email or a banner notification buried in an app update. Users who don’t actively opt out within a narrow window are treated as having consented. That structure hands companies near-permanent permission to expand how they monetize personal health information, including menstrual tracking data, blood oxygen readings, and stress scores.

Consumer behavior makes this worse. Research consistently shows that the overwhelming majority of people never read privacy policies before purchasing a connected fitness device or smartwatch. The average privacy policy runs to thousands of words written at a post-graduate reading level, and companies face no regulatory penalty for complexity. The result is that informed consent — the foundational principle underlying most data privacy frameworks — functions as a legal fiction in the wearables market.

The gap matters because the data is genuinely sensitive. A fitness tracker monitoring sleep disruption, heart rate variability, and reproductive cycles builds a detailed physiological profile over months or years. That profile has obvious value to insurers, employers, and data brokers, and the policies users scroll past without reading do little to prevent it from reaching them.

The Missing Context: Real-World Risks Most Coverage Glosses Over

Most wearable buyers focus on features and battery life. They skip the part where their heart rate variability, sleep cycles, and menstrual patterns become assets on someone else’s balance sheet.

The United States has no federal law governing consumer health data collected outside clinical settings. HIPAA protects your hospital records. It does not protect the stress scores and ovulation windows your fitness tracker logs every day. That gap is not theoretical — it exposes your data to insurers looking for behavioral risk signals, employers monitoring workforce health, and law enforcement agencies that can subpoena private health records without your knowledge. In a post-Roe legal landscape, menstrual and fertility data logged by apps like Clue, Natural Cycles, or Apple Health carries direct legal weight in states where abortion access is restricted or criminalized.

Company acquisitions create a specific exposure point that almost no one considers at purchase. When a wearable brand sells or merges, your historical biometric data transfers to the new owner. That new owner operates under its own privacy terms, which may be significantly looser than the policy you originally agreed to. Fitbit users experienced exactly this dynamic when Google acquired the company in 2021. Years of sleep, activity, and heart data moved under Google’s data umbrella — with a user base that had no meaningful option to stop the transfer retroactively.

Data breaches compound the problem permanently. Strava, MyFitnessPal, and Garmin have all suffered significant security incidents affecting tens of millions of users. Once biometric data leaves a breached server, deletion requests become irrelevant. You cannot un-share five years of resting heart rate history, GPS running routes, or fertility cycle logs after attackers have copied them. Unlike a compromised password, biometric and health data cannot be reset.

The practical reality is that accepting a wearable device’s terms of service means accepting every future version of that company’s relationship with your body’s data — including versions that don’t exist yet.

What Consumers Can Actually Do Right Now

Law hasn’t caught up to the wearable health data industry, so consumers have to protect themselves. That starts before you ever unbox the device.

When researching a smartwatch, fitness tracker, or smart ring, pull up the company’s full privacy policy and ask three specific questions: Does the company sell your health data to third parties? What happens to your data if the company gets acquired — does your consent transfer automatically to the new owner? Can you permanently delete your account and every record associated with it, or does the company retain biometric and health data after you leave?

These answers aren’t always easy to find, and that’s deliberate. Companies that profit from health data have little incentive to advertise it.

Once you own a device, use the data controls that already exist inside the platform. Most major wearable apps — including those from Fitbit, Apple, and Garmin — offer data export and account deletion tools that the vast majority of users never touch. Exporting your data periodically gives you a personal record. Deleting your account when you switch devices or platforms removes the company’s legal basis for holding your information in most states with active data protection laws.

Hardware choice matters too. A small number of devices process sensitive health metrics directly on the device rather than uploading raw biometric data to a cloud server. On-device processing keeps your heart rate variability, sleep stages, and menstrual cycle data off remote servers that can be breached, subpoenaed, or sold. This capability rarely appears in product marketing materials, so you have to search the technical specifications or contact the manufacturer directly to confirm how data flows from sensor to storage.

None of these steps eliminate risk entirely. But reading privacy policies with targeted questions, actively managing your wearable health data, and choosing hardware that limits cloud dependency are three concrete actions that shift meaningful control back to you.

The Bigger Picture: Why This Moment Demands a Smarter Consumer Conversation

Millions of people strap on a smartwatch or slip on a smart ring every year without reading a single line of the privacy policy they just agreed to. The global wearables market is expanding at a pace that outstrips any meaningful regulatory response, which means fresh waves of users are entering these health data ecosystems with almost no understanding of what they are surrendering in exchange for a sleep score or an irregular heartbeat alert.

The legal landscape offers little reassurance. The United States has no comprehensive federal law governing consumer health data collected outside traditional medical settings. HIPAA protects records held by hospitals and insurers — not the fitness tracking data sitting on a private company’s servers. Advocacy organizations and a handful of legislators have pushed for stricter biometric data privacy standards, but that legislation remains stalled in Congress. Until something changes, individual consumers carry the full burden of protecting themselves, armed only with privacy policies written by corporate lawyers.

The stakes are climbing alongside the technology. Wearable manufacturers are embedding AI-powered analysis into their platforms, pulling inferences from heart rate variability, blood oxygen levels, skin temperature, and sleep architecture. The more sophisticated the algorithm, the more sensitive the conclusions it can draw — including predictions about chronic illness, mental health status, and reproductive health. Data that once told a company how many steps you walked now has the potential to reveal information you haven’t shared with your doctor.

This convergence of rapid market growth, absent federal protection, and increasingly powerful AI analysis creates a specific kind of consumer vulnerability. The people buying smart rings and fitness trackers today are making decisions with long-term consequences they cannot fully anticipate, because the uses of that biometric data will evolve long after the purchase is complete. Informed consent in this environment is not a checkbox — it requires active, ongoing attention to how personal health information is stored, shared, and monetized.

AI-Assisted Content — This article was produced with AI assistance. Sources are cited below. Factual claims are verified automatically; uncertain claims are flagged for human review. Found an error? Contact us or read our AI Disclosure.

More in Cybersecurity

See all →