The Data Your Doctor Can’t Sell But Your Fitness App Can
When you share health information with a physician, that information is protected by HIPAA — the Health Insurance Portability and Accountability Act. Your doctor cannot sell your diagnosis to a marketing company. Your hospital cannot share your lab results with your employer or your insurer’s risk assessment team without your explicit authorization. There are rules, enforcement mechanisms, and penalties for violations.
When the same information is generated by a fitness tracker, a smartwatch, or a consumer wellness app, HIPAA does not apply.
The company behind the app is not a “covered entity” under HIPAA in the statutory sense. The data is not classified as “protected health information.” It can be sold to data brokers. It can be purchased by insurers making risk assessments. It can be acquired by employers. It can be bought by law enforcement agencies without a warrant, because no law prohibits its commercial sale or restricts its transfer.
This is the HIPAA gap — and in 2026, as wearable health monitoring becomes more sophisticated and more widespread, the gap is becoming harder to defend.
What Modern Wearables Actually Know About You
The gap matters because the data generated by consumer health devices in 2026 is not superficial fitness information. It is clinically meaningful health data.
A contemporary consumer smartwatch tracks:
- Resting heart rate and heart rate variability: predictive of cardiovascular risk and autonomic nervous system health
- Blood oxygen saturation (SpO2): relevant to respiratory and cardiovascular conditions
- Sleep duration and architecture: associated with neurological health, mental health conditions, and metabolic disease risk
- Activity patterns and caloric estimates: associated with metabolic syndrome and obesity-related conditions
- Stress scores and recovery metrics: proxies for physiological stress response
- Skin temperature: relevant to infection, hormonal cycles, and illness detection
- Electrodermal activity: a proxy for emotional stress and arousal
An increasing number of consumer devices now include continuous blood glucose estimation, blood pressure approximation, and fall detection with emergency alert capabilities. Some track menstrual cycles and fertility windows.
This data streams continuously. It accumulates over months and years. It tells a longitudinal story about your health that may be more accurate and more complete than the snapshot a physician gets from a biannual check-up.
There is a coherent argument that this data — more than most data protected by HIPAA — should be treated as sensitive health information deserving legal protection. The statutory framework, written before consumer health wearables existed, provides none.
Where the Data Goes
The commercial data flows from consumer health apps are extensive and often opaque.
A July 2026 analysis by the Foundation for Defense of Democracies titled “Protected in Name Only: HIPAA’s Health Data Gap Is Becoming a National Security Risk” documented the pathways: consumer health data can flow from wearable manufacturers to app developers, from app developers to analytics platforms, from analytics platforms to data brokers, and from data brokers to anyone willing to pay — including foreign intelligence services, which can legally purchase commercially available health data on US citizens and government employees.
The FDD’s national security framing may seem dramatic applied to individual consumers, but it captures something real about how broadly this data distributes once it leaves the device. Law enforcement agencies in the United States have already purchased commercial data from wearable ecosystems to conduct location tracking and individual profiling — legally, because no statute prohibits the transaction.
For most individuals, the more immediate concern is insurance discrimination and employment effects. The data on your wrist can, legally and without your knowledge, be sold to an insurer assessing coverage risk or an employer evaluating workforce health costs. HIPAA protects against those uses when the data flows through the healthcare system. It does not protect against them when the data flows through a consumer app.
The Legislative Response: What HIPRA Would Do
In July 2026, the Senate Committee on Health, Education, Labor and Pensions voted 22-0 to advance an amended version of the Health Information Privacy Reform Act, known as HIPRA.
A 22-0 vote in a Senate committee in 2026 is unusual. It signals bipartisan agreement on the underlying principle that extends well beyond what most privacy legislation achieves at the drafting stage.
HIPRA as advanced would:
Extend coverage to consumer health apps and wearable manufacturers. Companies that collect health information — even if they are not hospitals, clinics, or insurance companies — would face privacy and security requirements comparable to those HIPAA imposes on covered entities.
Require explicit consent for commercial data sharing. Health information collected by consumer wellness companies could not be sold or disclosed for commercial purposes without affirmative user consent. Opt-out consent buried in terms of service would likely not meet the standard.
Create consumer rights over health data. Users would gain the right to access what health data a company holds about them, the right to correct inaccuracies, and the right to request deletion — rights that do not currently exist under federal law for non-HIPAA health data.
Mandate breach notification. Consumer wellness companies that experience unauthorized access to health data would be required to notify affected users, bringing them in line with requirements that HIPAA-covered entities have faced for years.
What HIPRA Would Not Do
Understanding what the legislation wouldn’t change is as important as understanding what it would.
It would not create a private right of action. Individual consumers couldn’t sue companies directly for HIPRA violations. Enforcement would run through the FTC and, in states with conforming laws, state attorneys general. This is a significant limitation: without private litigation as an enforcement mechanism, the practical deterrent against violations depends entirely on agency resources and prioritization.
It would not retroactively undo existing data sales. Data that has already been sold to brokers, aggregated into profiles, and distributed through commercial channels would remain in circulation. HIPRA would constrain future flows, not recover past ones.
It would not reach companies outside the US. An app headquartered in a jurisdiction without equivalent protections, used by US consumers, sits in a complex regulatory space. The FTC has some reach through the FTC Act’s deceptive practices provisions, but comprehensive coverage of international actors is not what HIPRA provides.
It would not address the state-level patchwork. Several states — California, Washington, Texas, and others — have enacted their own consumer health data privacy laws with varying requirements. HIPRA would establish a federal floor, but the interaction with stronger state laws remains to be worked out in implementation.
The Road Ahead
A Senate committee vote, even a unanimous one, is not a law. HIPRA still requires a floor vote in the Senate, passage in the House, and a presidential signature. In a crowded legislative calendar, health data privacy competes with dozens of other priorities.
The FDD’s national security framing is one source of potential acceleration. Legislators who might not prioritize privacy legislation in the abstract may respond differently when the issue is framed as a foreign intelligence risk affecting federal employees and military personnel. The argument that adversaries can legally purchase sensitive health data on US government workers through commercial channels is not a subtle one.
A second source of momentum is the consistency of the data. Research from the University of Cincinnati Law Review and other academic sources has documented for years that HIPAA does not adequately protect health information in the modern data environment. The policy gap is well-documented. The legislative will to close it has historically been absent. The 22-0 vote suggests that calculus may be changing.
Protecting Yourself Now, Before Legislation Arrives
Legislative timelines are uncertain. Here’s what you can do in the meantime.
Review app permissions for every health and fitness application on your device. Mobile operating systems provide granular permission controls. Does your running app actually need your heart rate history, or just your GPS track? Does your sleep tracker need access to your contacts or your camera? Permissions granted at installation are often broader than what the app’s core function requires.
Read the privacy policy before granting access to health data — specifically looking for commercial disclosure clauses. The relevant question is not “does this app protect my data?” It’s “does this app sell my data, and to whom?” These are different questions. Privacy policies answer the second one, usually in careful legal language, if you read closely. Look for phrases like “research partners,” “analytics providers,” “third-party service providers,” and “de-identified data” — these often describe commercial data flows that are technically permissible but functionally equivalent to selling health information.
Understand what “de-identified” actually means in practice. Many apps claim they only share de-identified data — data with personal identifiers removed. Research has repeatedly demonstrated that health data combined with demographic information can be re-identified at high rates. De-identification is not anonymization.
Export your health data periodically. Most health apps allow export of your complete health history. Do this regularly. If you decide to delete the app and request data erasure, you retain a local copy of your own health record.
Store sensitive health records in storage you control. A clinical report, a genetic test result, a specialist’s assessment, or a continuous glucose monitoring export is sensitive personal information. It belongs in private storage with explicit data practices, not in a consumer app’s cloud infrastructure with commercial data sharing provisions. You should be able to answer “where does this document live, and who has access to it” for every sensitive health record you have.
daftei stores files including health records and personal documents with AES-256 encryption at rest. The service is GDPR and CCPA compliant and never sells data or uses content to train AI systems. Personal health records are not an app — they’re documents, and they deserve the same care as any other sensitive personal archive.
Why This Debate Matters Beyond Health
The HIPRA debate is, at its core, about where legal protection follows data versus where it follows the type of company that collects data.
HIPAA was written around the healthcare system as it existed in 1996: insurance companies, hospitals, billing clearinghouses. It protects health information when it flows through that system. The same information, generated by a consumer device and flowing through a consumer app, is outside the protected zone entirely.
That gap was a design limitation of the original legislation, not an intentional policy choice. In 1996, the idea that a consumer wristwatch would continuously monitor blood oxygen and heart rate variability — and transmit that data to commercial third parties who could sell it to anyone — was not the scenario the drafters were addressing.
The scenario is real now. The data is sophisticated, continuous, and commercially valuable. The legal protection remains where it was in 1996.
The 22-0 Senate committee vote says there is broad agreement, at least at the committee level, that this needs to change. Whether the broader legislative process produces a law, and when, remains to be seen. But the direction is clear: health data that belongs to consumers should receive meaningful protections regardless of whether a doctor or a device collected it.