Most people assume that because a wearable measures medical-sounding things — heart rate, blood oxygen, sleep, sometimes an ECG — the data it collects is protected the way their doctor's records are. It is not. HIPAA, the law most Americans have vaguely heard of, does not apply to your watch, your ring, or the app they pair with. That gap is bigger than the industry advertises, and it is worth understanding before you strap on a sensor that will produce years of physiological data about you.
This article is a plain walk-through of what protects your wearable data, what does not, how the HSA and FSA reimbursement rules actually work, and what to do about all of it.
The HIPAA misconception
HIPAA — the Health Insurance Portability and Accountability Act — is a 1996 US law that regulates how covered entities handle protected health information. Covered entities are a narrow group: healthcare providers who bill electronically, health plans (insurers), healthcare clearinghouses, and their business associates. That is the entire list.
Your Apple Watch is not a covered entity. Neither is Fitbit, Garmin, Withings, Oura, Whoop, or the smartphone app any of them syncs to. The device makers are consumer electronics companies. The data they collect from you is not, in the eyes of federal law, protected health information. It is consumer data governed by whatever the terms of service and privacy policy say.
There is one exception worth naming. If your employer's wellness program buys the wearable, syncs the data to a group health plan, and uses it in benefits decisions, that data can fall under HIPAA at the plan side. But the flow from device maker to you is not covered, and neither is any personal purchase you make.
What device makers can legally do with your data
In the absence of HIPAA coverage, what a manufacturer can do with your heart rate, sleep, temperature, cycle, and location data is determined entirely by their privacy policy and by state law where you live. In practice that means:
- They can share it with advertisers unless the policy explicitly says they do not. Aggregated or "de-identified" health data is a real market.
- They can sell it in a corporate acquisition. A privacy policy usually reserves the right to transfer data to a successor company. Your data is an asset on the balance sheet.
- They can license it to researchers. Sometimes this is genuinely academic; sometimes it is a pharmaceutical dataset being licensed for money.
- They can share it with law enforcement in response to a subpoena, and depending on jurisdiction, sometimes without one.
- They can change the policy. Nearly every consumer privacy policy reserves the right to update terms with notice, and "notice" often means an email you may not read.
None of this makes device makers villains. Some are noticeably better than others; Withings, for example, is a French company operating under GDPR-influenced defaults and has cleaner disclosures than several US-based competitors. But the baseline for the category is that the protection you assume you have does not exist unless you read the policy and confirm it.
The insurance discount trade
The clearest illustration of what your data is actually worth is the life-insurance-plus-wearable model, pioneered by John Hancock through their Vitality program and copied by several other insurers. The pitch: get an Apple Watch or comparable device for a small upfront cost, share your step count, workout data, and general activity with the insurer, and earn premium discounts of up to fifteen percent over the life of the policy.
This is not a scam. It is a straightforward transaction. You are handing over a continuous physiological data feed and getting a financial discount in return. For someone who exercises consistently and does not mind the surveillance, it can be a legitimately good deal. For someone whose health trajectory might change — a new diagnosis, a rough year, a period of low activity while caring for a family member — the same program can become a monitoring layer that quietly raises your risk category. There is no such thing as a free premium reduction. You are paying with data.
Before you enroll, read what happens if you stop wearing the device, what triggers a premium adjustment, and whether the insurer can share the data with affiliates. These are all things the policy is required to say, and the questions device sellers usually elide.
The regulatory patchwork: GDPR, CCPA, and the American gap
Where you live matters a lot here.
In the European Union and the United Kingdom, the General Data Protection Regulation gives users strong statutory rights over their data by default. Health-related data receives an extra tier of protection as a "special category" under Article 9. Companies operating in Europe have to obtain explicit consent to process it, and users have concrete rights to access, correct, delete, and export their data.
In California, the California Consumer Privacy Act and its 2023 successor the California Privacy Rights Act provide a narrower but still meaningful set of rights: to know what is collected, to delete it, to opt out of sale or sharing, and to correct inaccuracies. A dozen other states have followed with similar frameworks — Virginia, Colorado, Connecticut, Utah, and more — but coverage across the US is uneven.
At the federal level in the United States, there is no comprehensive privacy law. There have been draft bills for years. None have passed. That means if you live in a state without a state privacy law, your rights over your wearable data are whatever the terms of service grant you, and no more.
The FTC precedents worth knowing
Two enforcement actions show what happens when things go wrong. Both involved women's health apps rather than wearables specifically, but the legal principle applies directly.
Flo Health was investigated by the FTC in 2019 for sharing detailed cycle and pregnancy data with Facebook, Google, and other third-party analytics providers, despite public assurances that the data was private. The FTC's 2021 settlement required Flo to obtain explicit user consent before sharing health data and to notify affected users. There was no financial penalty, which many advocates argued was the point: the case established the precedent but not the deterrent.
Easy Healthcare, maker of the Premom cycle tracker, settled with the FTC in 2023 for similar conduct, disclosing user data to advertising SDKs. That settlement included a $100,000 civil penalty and stronger prohibitions on future disclosures. Ovia has faced comparable state-level scrutiny.
The pattern is consistent. Consumer health apps have repeatedly been caught sharing sensitive data despite public claims otherwise, and enforcement has been slow, small, and after-the-fact. The FTC has authority under Section 5 of the FTC Act to pursue "unfair or deceptive" practices, but it is a reactive tool, not a preventive one.
The 23andMe cautionary tale
The genetics testing company 23andMe is not a wearable, but its recent history is directly relevant.
In 2023, 23andMe suffered a large credential-stuffing breach that exposed data on nearly seven million users, including in some cases the ancestry information of relatives who had never used the service directly. The company's stock collapsed. In 2024 the CEO proposed taking the company private. By 2025 the question circulating in privacy circles was uncomfortable: if 23andMe files for bankruptcy or is sold for parts, what happens to the genetic profiles of fifteen million customers?
The privacy policy allows for corporate transfer. There is no bright line preventing the data from being licensed or sold to a new owner with different intentions. Under HIPAA this could not happen, because HIPAA does not permit protected health information to be transferred in a corporate sale without patient consent. But 23andMe is not a HIPAA-covered entity. Neither is your wearable.
This is the pattern to remember. A company you trust today can be sold tomorrow, and unless a statute forces the buyer to honor the seller's promises, they usually do not have to.
HSA and FSA reimbursement rules, briefly and honestly
Health Savings Accounts and Flexible Spending Accounts let you pay for qualified medical expenses with pre-tax dollars. Whether a wearable qualifies depends on the device, the category, and whether you have documentation.
The general rules under IRS Publication 502:
- Continuous glucose monitors — including OTC devices — are increasingly reimbursable without special documentation as of 2024 IRS guidance. Some administrators still ask for a Letter of Medical Necessity; many no longer do.
- Blood pressure monitors are broadly reimbursable as medical equipment.
- General-purpose fitness watches and rings — Apple Watch, Fitbit, Garmin, Whoop, Oura in their standard form — are typically not reimbursable without a Letter of Medical Necessity from a licensed provider stating that the device is for treatment or diagnosis of a specific condition.
- Sleep-tracking devices may be reimbursable with an LMN if used in evaluation or management of a diagnosed sleep disorder.
The Letter of Medical Necessity is the mechanism that converts a consumer device into a qualified medical expense. It is not a rubber stamp — a doctor has to actually write it and stand behind the clinical rationale — but for many chronic conditions the paperwork is straightforward.
One quiet consequence: when you submit an LMN for a wearable, you are also creating a paper trail that ties your device use to a specific medical condition. That paper trail lives in your HSA administrator's records and in your provider's chart, and both are HIPAA-covered environments. The device data itself remains outside HIPAA, but the fact that you use the device for a diagnosed condition may become part of your medical record. This is worth knowing, not necessarily worth avoiding.
A practical checklist before you buy
None of the above should stop you from wearing a device. The value of good sleep and cardiac data is real, and the risk profile is manageable if you take it seriously. Before you commit, five steps.
- Read the privacy policy. Actually. Skip the marketing pages and go to the policy itself. Search for the words "sell," "share," "advertise," "third-party," and "acquisition." You will learn most of what matters in ten minutes.
- Disable location sharing at the OS level unless a feature you actually use requires it. Most sleep and heart rate features do not need location.
- Know your export and delete rights. If you live in California or the EU, exercise them at least once so you know what the process looks like. Do not wait until you actually need to leave the platform.
- Separate your accounts. If a wearable app also does social features, do not connect it to your primary social identity. A separate email and a name that is only "first name last initial" reduces the surface area of any breach.
- Reconsider insurance-linked programs. Read what happens to the discount if you stop wearing the device, what triggers a premium change, and what happens to your data if you cancel the policy.
The honest bottom line
Consumer wearables are useful. They also collect the most intimate physiological dataset most people will ever generate about themselves, and the legal protection around that dataset is thinner than the packaging suggests. HIPAA is not a magic word that follows the sensor onto your wrist. The law that governs your watch is whatever the privacy policy says, plus whatever your state has passed, minus whatever the FTC gets around to enforcing.
That does not mean you should not wear one. It means you should choose manufacturers who take privacy seriously by construction rather than as an afterthought, use HSA and FSA reimbursement carefully and with full knowledge of the paper trail it creates, and treat any offer that trades data for money — insurance discounts most obviously — as the negotiation it actually is.
If you assume your wearable data will one day be somewhere it should not be, you will make better choices today than if you assume it is safe. That is the honest posture.