Almost certainly not. HIPAA follows the provider, so data your doctor holds is covered while the same reading on a consumer app generally is not.
As Wearable Technology Advances, So Do the Data Risks Behind It

In November 2017, Strava published a global heatmap built from more than a billion uploaded activities. It was a marketing piece.
Two months later, an Australian student named Nathan Ruser looked at Syria, Afghanistan and Somalia, where almost nobody uses the app, and found bright loops glowing in the dark. They were military bases, traced by the jogging routes of the people stationed inside them.
Nothing had been stolen. The map was working exactly as designed.
That gap between a working product and a bad outcome is the real subject here, and it explains most of what goes wrong.
Aggregation Is the Mechanism
Most software systems describe different cases of attack in the same way: as a notification. For example, a hacker, a stolen database, and a breach are almost described the same way in most wearable risk detectors. That framing is the reason why most of these devices do not carry out the purpose they were actually designed for.
Individual records on their own do not tell anything; it is those records documented over a period of time and then shown as patterns that do the job.
One heart rate or one step count on a random day tells no one anything about any individual. These are just random things the device detected throughout the day and hence no meaning can be attached to them. That’s why the value of all of these recordings only appears when these recordings are stacked regularly.
For instance, Strava, a healthcare app which monitors the kilometers you run or the calories you burn during a workout, had no names of places on its map. This means that the app’s map was anonymised in the ordinary sense of the word, yet somehow the app could draw the outline of a base in Helmand because enough people ran the same perimeter often enough.
This is what a good anonymisation does for the user. While it removes the label, it does not remove the pattern, and that is the difference between a risk detector app which works and one that only exists.
Consider what a location history contains once it runs for a few months. There is a place the device rests every night and a different place it sits on weekday afternoons. Those two points alone narrow a person to a very small group, and everything else in the log then attaches to that pair.

What the Sensors Actually Log
There are various things that a good risk detector device should tell you, and all of those things work together to document patterns which then help you figure out exactly the kind of lifestyle and habits that particular user has.
| What the device measures | What a continuous log of it reveals |
|---|---|
| Step count and movement | Sleep and waking times, days away from home |
| Heart rate | Exertion, stress, the onset of an illness |
| GPS position | Home address, workplace, daily routine, who is nearby |
| Skin temperature | Fever, and on some devices, menstrual cycle |
| Device ID and timestamps | How to tie every row above to one person across years |
Read down the left column and each item looks harmless. Read down the right and the picture changes, which is the entire argument in two columns.
Device ID and timestamps do more work than people give them credit for because it is this identity which is put in the system that helps document patterns, but these identities rarely work as a name. Though identities work as a device identifier that helps show or find out where a particular device is during what time of the day. This is then attached to every record so that a log of patterns can be assembled over a course of time.
Moreover, new features have further helped in improving the risk-identifying factors because of an upgrade in the sensor quality. This is improving faster than its surrounding policy because a device that could count steps a few years ago can now also give an estimate of a person’s blood oxygen levels, or it can flag an irregular rhythm and track his body temperature overnight. None of these start a separate file but add a new column to the same row, which helps tell more about a person and helps us predict risk factors faster.
The Rules Were Written for Hospitals
Certain software, like HIPAA, covers the information that can be used by doctors, hospitals, and insurers. This means that when the rules were drafted for risk-identifying software, these systems were placed only where health data already existed, and back then consumer wearables were simply not in that category.
This gap is quietly being bridged by the Health Breach Notification rule launched by the FTC in 2024. This rule states that all the Health apps and wearable risk detector software that were earlier excluded from HIPAA should now be covered by it as a safety measure. In fact, these rules are so strict that a breach is not defined as a hack, but it is defined as any disclosure that was unauthorized by either the doctor or the hospital.
DID YOU KNOW
Under the updated rule, a company that shares users’ health information with an advertising platform without proper authorisation has had a reportable breach, even though no attacker was ever involved and no system was compromised.
So the regulator has landed roughly where the evidence is. The threat model is disclosure, not intrusion.
This makes it easier for a buyer to understand what he is actually giving consent to. This means that now, instead of reading the security page that describes the software encryption policies that will prevent a hack, users can simply read the sharing and partner disclosures, and they will get to know who all have access to their information. And these disclosures are usually much shorter, vaguer, and easier to understand.
Where the Records Physically Go
Location data does not travel as a dot on a map.
A tracking device assembles a record, sometimes called a ping or a breadcrumb, that carries the coordinate plus speed, a device identifier, and a timestamp. DataRecovee’s own breakdown of location-device pipelines describes a single active unit producing thousands of these in a day.
When the signal drops, well-built devices do not discard anything. They hold the records in onboard memory and send the batch once the connection returns, which is why a tunnel produces a gap of seconds rather than a hole in the history.
That design is sensible engineering. It also has a consequence worth stating plainly: the record is complete by default, retained by default, and uploaded by default, and every one of those defaults was chosen by somebody other than the person wearing the device.
Deletion is the part people assume and rarely check. Removing a workout from an app view does not necessarily remove the underlying records from backups or from whatever the vendor has already passed to a partner.

The Devices Bought for Children
Children’s trackers deserve separate treatment, because the person wearing the device is not the person who agreed to the terms.
A parent buys a watch so a seven-year-old can be located between home and school. The device logs position continuously, and the account sits with the parent.
The child, meanwhile, has no practical way to review what was kept or for how long, and will not be the one reading the terms. Independent prep schools such as Blue Coat School Edgbaston take pupils from nursery through to age eleven, which is exactly the band where these watches start appearing on wrists.
Buying one can still be the right call. Worth knowing, though, that a child’s location history is among the most sensitive records a family will ever generate, and it usually lives on a server chosen for price.

The Takeaway
Ask a different question about any wearable.
The one worth asking is what the product does with the record while everything is working exactly the way its designers intended.
Check the defaults before the features. Strava’s privacy controls existed in 2017 and worked; hardly anyone had ever touched them.
Sensors will keep getting better. The defaults are the part that has to.
Frequently Asked Questions
Is my fitness tracker covered by HIPAA?
Does anonymised data actually protect me?
Only partly. Removing names is easy; removing patterns of movement and routine is much harder, which is what the Strava heatmap demonstrated.
Which setting should I change first?
Whatever controls public or aggregate sharing. That single toggle accounts for most real-world wearable exposure, and it is usually on by default.
Should I avoid wearables altogether?
No. Most people get real value from them, and the sensible response is to treat the account settings as part of the purchase rather than an afterthought.
Buying model work before the data work is the most expensive order to do it in. The pilot shows well,…
In September 2026, GoodFirms listed 853 software development companies in California. The group had a median hourly rate of $37,…
A blockchain explorer is a searchable interface for viewing data recorded on a public blockchain. You can look up a…
With the growth and expansion of business operations, CRM management gets complex. New things, workflows, integrations, and custom rules often…
Due to advanced neural rendering models, the landscape of digital photography, graphic layout, and commercial design has changed fundamentally. Now…
In this digital era, businesses are cutting their staff and relying more on automated systems. One great example of this…
Data visualization is no longer just about normal charts. In this modern era, they make no sense. Dashboards that are…
SEO is not just limited to optimising your website pages and adding relevant keywords in the content. Here is much…
The data analytics courses are made for employers who want practical job skills, including SQL, data preparation, a digital competence…







