Every morning, your smartwatch records your heart rate, sleep stages, and blood oxygen levels. Your fitness app logs every run, every calorie, every menstrual cycle. Your health insurance portal holds your diagnoses, prescriptions, and lab results. Combined, these data streams paint an extraordinarily intimate portrait of your body — a portrait that, in most jurisdictions, you do not fully control.
The Wearable Data Loophole
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) provides strong protections for medical records held by doctors, hospitals, and insurers. But here is the critical gap: HIPAA does not cover data generated by consumer health devices or apps. The heart rate variability data your Apple Watch collects, the sleep score your Oura ring calculates, the glucose trends your continuous monitor tracks — none of this is legally protected health information under federal law.
Instead, this data falls under the much weaker framework of consumer privacy policies and state-level laws. A 2023 study by Duke University researchers found that 87% of health apps shared user data with third parties, including analytics companies, advertisers, and data brokers — often without meaningful user consent. Your step count and sleep patterns can legally be packaged, sold, and cross-referenced with other data sets to build detailed behavioral profiles.
The Digital Health Record Ecosystem
Electronic Health Records (EHRs) were designed to improve care coordination, not to protect privacy. A single hospital visit can scatter your data across dozens of entities: the hospital, your primary care physician, your insurer, the lab that processed your blood work, the pharmacy that filled your prescription, and the health information exchanges that connect them all. Under HIPAA, each of these entities can share your data for "treatment, payment, and healthcare operations" — a deliberately broad category that includes everything from billing to quality improvement to, in some cases, marketing.
The 21st Century Cures Act, implemented in 2021, mandates that patients have electronic access to their health records. While this is a genuine win for patient autonomy, it also expands the attack surface: every patient portal, every API connection, and every third-party app that accesses your records creates a potential vector for data leakage.
Who Profits from Your Health Profile?
The market for health data is vast and largely opaque. Data brokers aggregate de-identified health information — prescription histories, medical claims, wearable data, and even social media activity — into consumer profiles sold to pharmaceutical companies, insurers, employers, and financial institutions. While HIPAA requires de-identification, computer scientists have repeatedly demonstrated that supposedly anonymous health data can be re-identified with alarming ease. A landmark 2018 study re-identified 99.98% of Americans in a supposedly anonymized dataset using just 15 demographic attributes.
Practical Steps to Protect Your Health Data
First, audit your app permissions. Most health apps request far more data access than their core functionality requires. Disable background data sharing, limit ad tracking through your device's privacy settings, and regularly review which third-party services have access to your health accounts. Second, read privacy policies — specifically the sections on data sharing and third-party access. If a policy is vague or absent, treat the app as though it sells your data, because it probably does. Third, use end-to-end encrypted health platforms when available, particularly for sensitive data like mental health records or genetic information. Finally, support legislative efforts to close the consumer health data loophole — the American Data Privacy and Protection Act and similar state-level bills represent the first serious attempts to give individuals real control over their digital health footprint.