privacy

What Your Employer Sees Through Your Wellness App

Corporate wellness programs collect detailed health data that sits outside HIPAA protections. What your employer's wellness app actually knows about you.

Your employer’s wellness program offers cash rewards for hitting step counts, completing health risk assessments, and enrolling in chronic condition management. The mechanism is an app. You connect a fitness tracker, answer questions about your health history, log activity, and accumulate points toward a premium discount.

Who sees that data? The answer is more complicated than the program description suggests.


The HIPAA Gap in Wellness Programs

Most employees assume that because their wellness program is connected to their employer, it is protected by HIPAA — the federal law that restricts how health information can be used and shared. This assumption is often wrong in ways that matter.

HIPAA applies to “covered entities”: health care providers, health plans, and health care clearinghouses. It also applies to their “business associates” — vendors who handle protected health information on their behalf.

A corporate wellness program offered directly by an employer — not administered through the company’s group health plan — may not qualify as a covered entity or as a business associate of one. In that case, HIPAA does not protect the health data it collects.

The Department of Health and Human Services has published explicit guidance on this: when a wellness program is administered by an employer outside of a group health plan, the health information collected is not protected health information under HIPAA Rules. The employer governs that data under its own policies and whatever contracts exist with the wellness vendor.

This means the most common assumption employees make about their wellness app’s data — that HIPAA protects it — may simply be incorrect.


What Wellness Programs Collect

Comprehensive corporate wellness programs gather significant health information. The categories depend on which features are enabled.

Health Risk Assessments

Self-reported questionnaires about medical history, current conditions, lifestyle factors, family health history, mental health status, and substance use. These are often the gateway to the program — employees complete them to enroll or to qualify for financial incentives. They’re also the most sensitive data category: detailed self-reported health information that may include conditions, medications, and personal behaviours an employee would never share with an employer in any other context.

Biometric Screening Results

Many programs include or require biometric screenings — blood pressure, cholesterol, blood glucose, BMI, and other measurements. These are often conducted at employer-sponsored health fairs or with partnered clinics and the results are uploaded to the wellness platform.

Wearable Device Data

When employees connect fitness trackers — Fitbit, Apple Watch, Garmin, Whoop — the wellness platform receives activity data: steps, workouts, sleep patterns, heart rate, and on more recent devices, stress scores, respiratory rates, and blood oxygen levels. The data can be considerably more granular than the wellness program’s visible interface suggests.

Chronic Condition Management Data

Programs that include coaching for diabetes, hypertension, or other conditions collect ongoing health data — measurements, medication adherence tracking, symptom logs — as part of the coaching relationship. This is operationally useful but represents some of the most sensitive information a person can share.

Mental Health Data

Some wellness platforms include mental health components: mood tracking, stress assessments, therapy referral programmes, and EAP integrations. This data may be stored by the primary wellness vendor, by a specialist mental health subcontractor, or in some implementations, across both.


What the Employer Can Access

The answer depends on the programme structure and contract.

For programmes administered through a group health plan, HIPAA applies and limits employer access. Employers acting as plan sponsors may access only the minimum necessary protected health information for plan administration purposes defined in plan documents. Using identifiable health data for employment-related decisions requires specific authorisation.

For programmes administered directly by the employer or through a wellness vendor that isn’t a covered entity, the protections depend on the contract between the employer and the vendor. Employers may receive aggregate data — the health risk profile of the workforce as a group — for benefits planning and insurance cost management. Whether individually identifiable data reaches HR or management depends on the contract and the employer’s internal policies.

The wellness vendor’s own data practices are a separate layer. Vendors retain health data as long as their contracts and privacy policies allow. They may share data with insurance partners, analytics vendors, or research organisations. Some vendors reserve the right to sell de-identified data. Employees rarely have visibility into the employer-vendor contract that governs these practices.


The Incentive Pressure Problem

Corporate wellness programmes regularly offer financial incentives: premium discounts, cash rewards, gift cards, additional paid time off. The value can be substantial — several hundred dollars annually in some programmes.

This creates pressure that undermines any genuine voluntariness. An employee who declines to participate in order to protect their privacy absorbs the cost of that decision in their total compensation.

Under the ADA and GINA, wellness programmes must be “voluntary,” and incentives for incentive-based programmes cannot exceed certain thresholds of coverage cost. But these limits have been subject to ongoing regulatory interpretation and challenge, and a meaningful financial penalty for non-participation can coexist with a technical finding that the programme is “voluntary.”

The pressure is most acute for health risk assessments — the questionnaires that ask about conditions, mental health, family history, and lifestyle. An employee who has a condition they would prefer not to disclose to any party connected to their employer has limited practical options when participation is financially incentivised.


Third-Party Vendors and Their Data Practices

The wellness vendor is the company you’re actually giving your health data to. It operates under its own privacy policy, not just the employer’s HR policies.

Third-party vendors delivering wellness programmes frequently retain the right to use aggregated or de-identified data for product development, research, and in some cases, sale to data brokers. What “de-identified” means in the context of a health risk assessment that includes your age, gender, known conditions, and specific risk factors is a meaningful question — de-identification that meets a technical standard isn’t always meaningful re-identification prevention in practice.

Wellness vendors also use sub-processors. Your data touching the primary platform means it may also touch the vendor’s analytics provider, their cloud infrastructure provider, their customer support tools, and any health coaching or clinical services they’ve contracted. The privacy policy of the primary vendor may disclose this in general terms without naming specific sub-processors.


State-Level Protections

Where federal protections are limited, some states have stepped in.

California’s Confidentiality of Medical Information Act (CMIA) applies to employers in California and restricts their ability to access, use, or disclose medical information obtained from employees, including through wellness programmes. It extends meaningful protections that HIPAA doesn’t reach in the direct-employer context.

Washington’s My Health My Data Act imposes requirements on entities that collect health data, including wellness vendors operating in the state. It gives consumers rights to access, delete, and withdraw consent from health data collection.

Other states are developing similar frameworks. Coverage is inconsistent, and the wellness vendor you’re interacting with may be based in a different state from the one you work in, adding jurisdictional complexity.


Practical Guidance

Before Enrolling

Read the wellness programme’s privacy notice and the vendor’s standalone privacy policy. The key questions: Who is the vendor? Does the employer receive individual or only aggregate data? How long is data retained? What are your deletion rights? What third parties does the vendor share data with?

If the programme description doesn’t answer these questions, they’re worth asking HR directly before providing health information.

Participate Selectively

You can often capture some programme benefits — activity points, step-count rewards — without submitting the most sensitive data. Detailed health risk assessments and biometric screenings are more sensitive than step tracking. If you need the financial incentive but have reservations about the most personal data categories, participating in lower-sensitivity programme elements is a practical middle ground.

Separate Your Wearable Data

If you connect a wearable to a wellness platform, consider whether that same wearable is also connected to your personal health apps. The data footprint of a device connected to both a personal health tracking app and your employer’s wellness vendor is larger than either connection alone. Some wearables allow you to share specific data types with specific apps, limiting what the wellness platform receives while maintaining your personal health tracking.

Treat Mental Health Data Separately

Mental health data in employer wellness programmes carries elevated risk. Disclosure of mental health conditions through a platform connected to your employer sits in a different category from other wellness data.

If your employer offers EAP services, it’s worth understanding whether the EAP vendor is entirely separate from the general wellness platform and what the data firewall between them actually looks like. “Confidential” in programme marketing language and “protected from employer access by contract” are not the same thing.

Keep Your Own Records

Health information that matters to you — records from wellness screenings you’ve completed, test results, insurance correspondence — is worth storing somewhere that operates under your control rather than depending on a wellness vendor’s platform as the primary record.

Vendor account access typically ends or becomes limited when employment ends. Some platforms lock or delete accounts on termination. If your health records exist only in the wellness platform and you lose access when you leave the job, you lose the records.


The Bigger Picture

Employer wellness programmes create a situation where access to financial benefits requires sharing personal health data with a third party that is structurally connected to your employment relationship, operating under data practices that most employees have never read, with protections that are materially weaker than most people assume.

That’s not an argument against using wellness programmes. The financial incentives are real. But the health data you share through them is worth the same considered scrutiny you’d apply to any other health platform — with the added context that an employment relationship makes the privacy implications more concrete.

What you store privately, separate from platforms connected to your employer, is the category of health-related information where you retain full control.

daftei stores files — including health records, documents, and personal notes — with AES-256 encryption at rest and TLS 1.3 in transit. No advertising, no AI training on your content, no data selling. Available on iOS, Android, and web at /app. GDPR and CCPA compliant, with a 5 GB free tier and unlimited storage on Pro.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts