Somewhere on your wrist, or on your nightstand charging, there’s a device that knows more about your body than most of your doctors do. It knows how long you slept and when you woke up. It knows your resting heart rate and how it changed during a stressful week. It knows your blood oxygen levels at 3 a.m. If you’re using a smart ring, it may also be tracking your temperature, your breathing rhythm, and whether your menstrual cycle is shifting.
That data is intimate in a way that most people don’t fully reckon with. And yet it receives meaningfully less legal protection than the medical records in your doctor’s office.
This isn’t a bug that got missed. It’s a gap that exists by design — or rather, by the failure of the law to keep up with a category of device that didn’t exist when the law was written. Understanding it helps you make clearer decisions about what you’re sharing, with whom, and what you can expect in return.
The HIPAA Gap
The Health Insurance Portability and Accountability Act covers health data — but only when it’s held by covered entities: healthcare providers, health insurance companies, and their business associates. The Act was designed to govern the flow of medical records through the healthcare system.
Consumer wearable companies are not healthcare providers. They’re consumer electronics and software companies. The data they collect — your sleep stages, heart rate variability, respiratory rate, blood oxygen levels — isn’t generated in a clinical setting and doesn’t flow through healthcare channels. It’s generated by a device you bought from an app store and uploaded to a cloud platform operated by the manufacturer.
This means that the data your doctor collects about your heart is subject to HIPAA’s strict rules about consent, use, sharing, and breach notification. The data your smartwatch collects about your heart is governed by the wearable company’s privacy policy — which you agreed to, in the usual way, when you set up the app.
The Mozilla Foundation reviewed the Oura Ring specifically and noted this distinction clearly: wearable health data has fewer federal privacy protections than data your doctor’s office holds. The health information is comparable in sensitivity. The legal framework around it is not.
What Wearables Actually Collect
The data collected by modern wearables is more comprehensive than many users realize. Beyond the step counts and exercise logs that launched the category, today’s devices track:
Sleep architecture. Smart rings and advanced smartwatches can estimate your time in light, deep, and REM sleep each night. Over months, this builds a detailed record of your sleep patterns — including disruptions, quality trends, and changes that correlate with stress, illness, or behavioral changes.
Heart rate variability (HRV). HRV — the variation in time between heartbeats — has become a proxy metric for stress, recovery, and autonomic nervous system function. It’s one of the more revealing metrics these devices collect, because it correlates with a wide range of health and mental states.
Blood oxygen saturation (SpO2). Continuous blood oxygen monitoring can flag respiratory issues, altitude effects, and sleep apnea. It’s data that has clinical significance well beyond step-counting.
Skin temperature. Ongoing temperature monitoring can detect fever, ovulation, and other physiological changes. Oura’s cycle-tracking features use temperature data as a primary signal.
Stress and readiness scores. Aggregated scores derived from multiple physiological inputs — resting heart rate, HRV, respiratory rate, temperature trends — produce composite wellness assessments that companies like Oura, Garmin, and Apple sell as core features.
All of this lives in the cloud. The device is the sensor; the platform is where the data goes, accumulates, and is processed.
How These Companies Use Your Data
Most major wearable companies publish privacy policies that describe reasonable practices: data is encrypted in transit and at rest, users can export or delete their data, and the company doesn’t sell personal data to third parties for marketing.
Oura, for example, encrypts data using TLS 1.2 or higher in transit and AES-256 at rest, according to their published support documentation. They state that users can download a CSV of their data or request deletion.
But privacy policies have layers. The statements in the prominent sections describe the company’s current practices. The language in the full policy, and the ways those practices can evolve, deserve more attention:
Research partnerships. Several wearable companies have entered data-sharing agreements with research institutions and pharmaceutical companies. Participation is typically opt-in, but the option to opt in is prominently featured during onboarding and the data involved can be deeply personal.
Third-party integrations. When you connect your wearable data to Apple Health, Strava, a third-party nutrition app, or a health coaching platform, data flows from the wearable’s ecosystem to a new one — with its own terms, its own data practices, and potentially its own commercial relationships. The consent you gave to the wearable company doesn’t carry into the apps you connect it to.
Model changes over time. A company’s privacy policy is not a permanent commitment. Companies are acquired, business models shift, and privacy policies change. The company you bought your ring from may not be the same company that controls your data in five years.
Law enforcement requests. Wearable health data has been used in legal proceedings. A fitness tracker’s movement and location data has been cited in criminal cases. The data that feels private because it lives in a health app on your phone can become evidence under the right legal circumstances.
The “Always On” Nature of the Data
Most medical tests capture a snapshot. A blood pressure reading, a blood draw, an ECG — each represents a moment in time. Wearable data is different in a structural way: it’s continuous.
A device worn 24 hours a day collects thousands of data points per day, building a longitudinal record of your physiological state over months and years. That record has a kind of intimacy that point-in-time clinical measurements don’t. It reflects your responses to stress, your sleep when you’re anxious, your recovery when you’re sick, the physiological correlates of events in your life.
This data is not static. It accrues value over time. A year of continuous heart rate data is more revealing than a single reading. Five years is more revealing still. The companies holding these records hold something that becomes more comprehensive and more sensitive the longer you wear the device.
What You Can Do
Using a wearable for health tracking doesn’t require accepting every privacy tradeoff. A few practical measures:
Read the data-sharing section of your wearable’s privacy policy. Specifically: who does the company share data with, under what circumstances, and under what consent model? Look for language about research partnerships, third-party service providers, and law enforcement requests.
Be selective about integrations. Every app you connect to your wearable data is another privacy policy to trust. Health coaches, nutrition apps, and third-party dashboards may offer useful features while adding data-sharing risk. Only connect integrations you’ve vetted.
Download your data periodically. Most major wearable platforms offer a data export option. A personal copy of your data — stored somewhere you control — is insurance against account loss, service discontinuation, or data retention changes.
Understand your deletion rights. If you stop using a wearable platform, understand what happens to your historical data. Does the company delete it within a specific window? Does deletion extend to all processing systems? The specifics vary by company and jurisdiction.
Consider HIPAA-adjacent alternatives for clinical data. If a health metric matters clinically — blood pressure, cardiac rhythms, oxygen levels — devices that share data directly with healthcare providers enter the HIPAA framework on the provider side. Consumer devices operating independently do not, regardless of the sophistication of what they measure.
The Offline Copy Problem
Most wearable platforms are cloud-first by design. The device is a sensor; the insight is generated in the cloud. Heart rate variability scores, sleep stage estimates, and readiness scores aren’t calculated on the device — they’re calculated on the company’s servers, using your raw sensor data as input.
This means the product doesn’t work without the cloud connection. Your most intimate physiological data lives on servers operated by a company you have a subscription relationship with, not on hardware you own.
There’s no straightforward “local-first” wearable option for the features that make these devices useful. Changing this would require a fundamental redesign of how the products work. But understanding it helps calibrate expectations about control.
The closest analogy to maintaining some independent record is downloading your own data exports regularly — a personal copy stored in a location you control, separate from the platform’s cloud. That doesn’t change what the wearable company holds, but it means you have your own record regardless of what happens to the service.
Keeping Sensitive Personal Records Under Your Control
Beyond wearable-specific data, the broader question — where does health-adjacent personal information live, and who can access it — applies to a wider category of files. Medical documents, lab reports, prescriptions, insurance records, and the notes you keep about your own health are worth storing somewhere that isn’t subject to the data practices of a health tech company whose business model may not align with your privacy interests.
A storage service that encrypts files at rest and in transit, doesn’t sell data, doesn’t use content to train AI models, and gives you a clear deletion mechanism handles these records differently than a platform built around aggregating health data for research partnerships or feature development.
daftei stores files encrypted with AES-256 at rest and TLS 1.3 in transit. It doesn’t sell data, doesn’t run advertising, and doesn’t use stored content to train AI models. A 5 GB free tier is available on iOS, Android, and at /app. For health records and personal documents that don’t belong in a wearable company’s cloud, a storage service whose business is storage — not health data aggregation — makes the separation clear.
The wearable data will continue living in the wearable platform’s cloud as long as you wear the device. That’s the tradeoff the product requires. The other personal health information you maintain doesn’t have to live under the same terms.