Key Takeaways
- Wearables collect biometric, location, and behavioral data that is far more sensitive than most users realize.
- Data typically flows from the device to a companion app and then to manufacturer cloud servers, often with third-party sharing.
- Most health data collected by consumer wearables is not covered by HIPAA in the United States.
- Users can meaningfully reduce exposure by auditing app permissions, disabling unused features, and reading privacy policies.
- Balancing health insight with data privacy is an active, ongoing choice — not a one-time setup decision.
What Wearables Actually Collect
Modern fitness trackers and smartwatches are sophisticated sensing platforms. At the most basic level they log step counts, distance, and active minutes. But contemporary devices routinely go much further, capturing data across several categories:
- Biometric signals: Continuous or periodic heart rate, blood oxygen saturation (SpO2), skin temperature, electrodermal activity, and — on some devices — ECG readings.
- Sleep patterns: Duration, estimated sleep stages (light, deep, REM), and overnight respiratory rate.
- Location and movement: GPS coordinates, elevation, and route mapping during workouts.
- Behavioral patterns: Stress scores derived from heart-rate variability, menstrual cycle tracking, calorie estimates, and sedentary time.
- Device and account metadata: App usage frequency, notification interaction, Wi-Fi and Bluetooth proximity data.
The breadth of this collection means a single device can build a detailed, longitudinal portrait of your physiology and daily routine. For context on what those biometric readings actually mean — and where they fall short — see our guide to smartwatch health metrics.
~537M
Wearable devices shipped globally in 2023
According to IDC's Worldwide Quarterly Wearable Device Tracker, global wearable shipments reached approximately 537 million units in 2023.
72%
Adults concerned about app data privacy
A 2023 Pew Research Center survey found that roughly 72% of U.S. adults say they feel their personal data is less secure than it was five years ago.
Not HIPAA
Coverage status of most consumer wearable data
The U.S. Department of Health and Human Services has clarified that HIPAA does not generally apply to consumer health apps or wearable manufacturers outside a covered-entity relationship.
Where Your Data Goes After It Leaves Your Wrist
Data rarely stays on the device itself. The typical flow is: wearable → companion smartphone app → manufacturer cloud servers. From there, several secondary paths are possible.
Manufacturer Cloud Storage
Most platforms store your historical data on their servers to enable trend analysis, cross-device sync, and app functionality. Retention periods vary widely and are disclosed (with varying levels of clarity) in privacy policies. Some manufacturers aggregate anonymized or de-identified data for product research.
Third-Party Integrations
When you authorize connections to other apps — nutrition trackers, coaching platforms, insurance wellness programs, or employer wellness incentives — you extend data access beyond the original manufacturer. Each integration operates under its own privacy terms, and those terms may permit uses you haven't explicitly considered.
Research and Commercial Partnerships
Some wearable platforms explicitly describe data-sharing agreements with research institutions or commercial partners in their terms of service. These arrangements are usually opt-in, but default settings and the clarity of consent flows vary considerably between companies.
Most Consumer Wearable Data Is Not HIPAA-Protected
A widely held assumption is that health data from fitness trackers and smartwatches falls under HIPAA. In reality, HIPAA generally applies to healthcare providers, insurers, and their designated business associates — not to consumer wearable manufacturers or app developers. This means the legal protections governing your biometric data are typically the company's own privacy policy and applicable state laws, which vary significantly. Understanding this gap is essential before sharing wearable data with third-party services.
Understanding how syncing works across your devices is also relevant here. Managing wearable sync across platforms can inadvertently expand which services receive your data.
The Legal Landscape: What Protections Exist
A common misconception is that health data from consumer wearables is protected under the Health Insurance Portability and Accountability Act (HIPAA). In the United States, HIPAA generally applies to covered entities such as healthcare providers, health plans, and their business associates — not to consumer app developers or device manufacturers acting outside that relationship. That means the biometric data logged by a fitness tracker is typically governed by the company's own privacy policy rather than HIPAA's strict framework.
Other regulations do apply, however:
- FTC Act: The Federal Trade Commission can take action against companies that engage in unfair or deceptive data practices, including misrepresenting how data is used.
- State laws: California's Consumer Privacy Act (CCPA) and its successor, the CPRA, grant California residents rights to know, delete, and opt out of the sale of personal data. Washington State's My Health MY Data Act, effective 2024, extends specific protections to consumer health data for Washington residents.
- Sector-specific rules: Certain uses — such as data shared with insurers — may trigger additional regulatory scrutiny depending on context.
Regulatory coverage of consumer health data is an evolving area, and protections vary significantly by state. Consulting a qualified legal professional is advisable if you have specific concerns about your rights. For a broader look at how the apps on your phone handle permissions, this overview of smartphone privacy settings is a useful companion.
Practical Steps to Limit Your Exposure
You cannot eliminate data collection and still use a connected wearable, but you can reduce the surface area meaningfully. The following steps are broadly applicable regardless of the platform you use.
After any companion app update, revisit its permissions in your phone's settings — apps frequently request new access during updates, and the prompts are easy to accept without reading.
App updates are a common vector for permission expansion; a periodic check costs seconds but can prevent unintended data access from persisting indefinitely.
Before connecting your wearable to an employer wellness program or insurer incentive, read the data-sharing agreement, not just the summary — particularly what data they receive and how long they retain it.
Employer and insurer wellness integrations can access more granular biometric data than users expect, and retention policies in these contexts may differ significantly from the wearable manufacturer's own terms.
Review App Permissions
On both iOS and Android, you can inspect and restrict the permissions granted to a companion app — including location access, contacts, camera, and background data refresh. Periodically auditing these prevents permission creep as apps update. A practical pre-setup checklist walks through this process for new devices specifically.
Disable Features You Don't Use
Features like always-on location tracking, third-party app integrations, or continuous blood oxygen monitoring collect data continuously. If you're not actively using a feature, turning it off in the wearable's settings or companion app reduces collection without sacrificing core functionality.
Read the Privacy Policy — Especially the Data Sharing Section
Privacy policies are long, but the sections covering third-party data sharing, research partnerships, and data retention are the most consequential. Most platforms allow you to request data deletion or account closure, which typically triggers deletion of stored records — though timelines and completeness vary.
Be Selective With Third-Party Integrations
Authorizing a wellness app or employer program to access your wearable data is an active consent decision. Review what data each integration requests and whether the benefit justifies the exposure before connecting.
Use Your Device's Privacy Dashboard
Both iOS and Android include privacy dashboards that show which apps accessed sensitive permissions — like location or health data — in recent days. Checking this monthly takes under two minutes and quickly reveals whether any app is accessing data more frequently than expected. It's one of the most efficient auditing habits you can build.
Balancing Utility and Privacy
Wearables offer genuinely useful health insight — consistent sleep data, heart rate trends, and activity patterns can surface information worth discussing with a healthcare provider. But the utility is bundled with a continuous data relationship that many users haven't fully examined.
The core trade-off is not unique to wearables. As noted in our practical guide for new wearable shoppers, understanding what a device does before committing is always worthwhile. Privacy is part of that evaluation.
When assessing any wearable, consider:
- Does the device offer meaningful on-device data processing, reducing what's sent to the cloud?
- Does the manufacturer provide clear, plain-language privacy documentation?
- Are data deletion and export options accessible and well-documented?
- How long does the company retain your data after account closure?
Privacy and health insight are not mutually exclusive, but they require deliberate choices. Reviewing your settings annually — and after any major app update — keeps those choices current rather than outdated.
For a different angle on connected-device privacy, the considerations around home security cameras and data storage share several overlapping principles worth knowing.
“Health data is among the most sensitive categories of personal information because it can reveal details about individuals that they may not have chosen to disclose — and because it can be used in ways that affect their lives in consequential and sometimes irreversible ways.”
— Federal Trade Commission, U.S. consumer protection and antitrust regulatory authority
This article is for informational purposes only and does not constitute legal, medical, or financial advice. Regulations vary by location and change over time; consult a qualified professional regarding your specific situation.
