As Wearable Technology Advances, So Do the Data Risks Behind It

Mr Kumar
Reviewed By :
Mr Kumar
Mahima Dave Written by Mahima Dave
Updated on
Jul 24, 2026
A fitness smartwatch on a wrist displaying a heart rate reading and a map of a running route.

In November 2017, Strava published a global heatmap built from more than a billion uploaded activities. It was a marketing piece.

Two months later, an Australian student named Nathan Ruser looked at Syria, Afghanistan and Somalia, where almost nobody uses the app, and found bright loops glowing in the dark. They were military bases, traced by the jogging routes of the people stationed inside them.

Nothing had been stolen. The map was working exactly as designed.

That gap between a working product and a bad outcome is the real subject here, and it explains most of what goes wrong.

Aggregation Is the Mechanism

Most software systems describe different cases of attack in the same way: as a notification. For example, a hacker, a stolen database, and a breach are almost described the same way in most wearable risk detectors. That framing is the reason why most of these devices do not carry out the purpose they were actually designed for. 

Individual records on their own do not tell anything; it is those records documented over a period of time and then shown as patterns that do the job. 

One heart rate or one step count on a random day tells no one anything about any individual. These are just random things the device detected throughout the day and hence no meaning can be attached to them. That’s why the value of all of these recordings only appears when these recordings are stacked regularly.  

For instance, Strava, a healthcare app which monitors the kilometers you run or the calories you burn during a workout, had no names of places on its map. This means that the app’s map was anonymised in the ordinary sense of the word, yet somehow the app could draw the outline of a base in Helmand because enough people ran the same perimeter often enough. 

This is what a good anonymisation does for the user. While it removes the label, it does not remove the pattern, and that is the difference between a risk detector app which works and one that only exists.

Consider what a location history contains once it runs for a few months. There is a place the device rests every night and a different place it sits on weekday afternoons. Those two points alone narrow a person to a very small group, and everything else in the log then attaches to that pair.

A heat map showing dense overlapping running routes forming a loop around a compound.

What the Sensors Actually Log

There are various things that a good risk detector device should tell you, and all of those things work together to document patterns which then help you figure out exactly the kind of lifestyle and habits that particular user has. 

What the device measuresWhat a continuous log of it reveals
Step count and movementSleep and waking times, days away from home
Heart rateExertion, stress, the onset of an illness
GPS positionHome address, workplace, daily routine, who is nearby
Skin temperatureFever, and on some devices, menstrual cycle
Device ID and timestampsHow to tie every row above to one person across years

Read down the left column and each item looks harmless. Read down the right and the picture changes, which is the entire argument in two columns.

Device ID and timestamps do more work than people give them credit for because it is this identity which is put in the system that helps document patterns, but these identities rarely work as a name. Though identities work as a device identifier that helps show or find out where a particular device is during what time of the day. This is then attached to every record so that a log of patterns can be assembled over a course of time. 

Moreover, new features have further helped in improving the risk-identifying factors because of an upgrade in the sensor quality. This is improving faster than its surrounding policy because a device that could count steps a few years ago can now also give an estimate of a person’s blood oxygen levels, or it can flag an irregular rhythm and track his body temperature overnight. None of these start a separate file but add a new column to the same row, which helps tell more about a person and helps us predict risk factors faster.

The Rules Were Written for Hospitals

Certain software, like HIPAA, covers the information that can be used by doctors, hospitals, and insurers. This means that when the rules were drafted for risk-identifying software, these systems were placed only where health data already existed, and back then consumer wearables were simply not in that category.

This gap is quietly being bridged by the Health Breach Notification rule launched by the FTC in 2024. This rule states that all the Health apps and wearable risk detector software that were earlier excluded from HIPAA should now be covered by it as a safety measure. In fact, these rules are so strict that a breach is not defined as a hack, but it is defined as any disclosure that was unauthorized by either the doctor or the hospital.

 DID YOU KNOW

Under the updated rule, a company that shares users’ health information with an advertising platform without proper authorisation has had a reportable breach, even though no attacker was ever involved and no system was compromised.

So the regulator has landed roughly where the evidence is. The threat model is disclosure, not intrusion.

This makes it easier for a buyer to understand what he is actually giving consent to. This means that now, instead of reading the security page that describes the software encryption policies that will prevent a hack, users can simply read the sharing and partner disclosures, and they will get to know who all have access to their information. And these disclosures are usually much shorter, vaguer, and easier to understand. 

Where the Records Physically Go

Location data does not travel as a dot on a map.

A tracking device assembles a record, sometimes called a ping or a breadcrumb, that carries the coordinate plus speed, a device identifier, and a timestamp. DataRecovee’s own breakdown of location-device pipelines describes a single active unit producing thousands of these in a day.

When the signal drops, well-built devices do not discard anything. They hold the records in onboard memory and send the batch once the connection returns, which is why a tunnel produces a gap of seconds rather than a hole in the history.

That design is sensible engineering. It also has a consequence worth stating plainly: the record is complete by default, retained by default, and uploaded by default, and every one of those defaults was chosen by somebody other than the person wearing the device.

Deletion is the part people assume and rarely check. Removing a workout from an app view does not necessarily remove the underlying records from backups or from whatever the vendor has already passed to a partner.

A diagram showing a wearable device sending buffered records through a phone to a cloud server.

The Devices Bought for Children

Children’s trackers deserve separate treatment, because the person wearing the device is not the person who agreed to the terms.

A parent buys a watch so a seven-year-old can be located between home and school. The device logs position continuously, and the account sits with the parent.

The child, meanwhile, has no practical way to review what was kept or for how long, and will not be the one reading the terms. Independent prep schools such as Blue Coat School Edgbaston take pupils from nursery through to age eleven, which is exactly the band where these watches start appearing on wrists.

Buying one can still be the right call. Worth knowing, though, that a child’s location history is among the most sensitive records a family will ever generate, and it usually lives on a server chosen for price.

Devices for Children

The Takeaway

Ask a different question about any wearable.

The one worth asking is what the product does with the record while everything is working exactly the way its designers intended.

Check the defaults before the features. Strava’s privacy controls existed in 2017 and worked; hardly anyone had ever touched them.

Sensors will keep getting better. The defaults are the part that has to.

Frequently Asked Questions

Is my fitness tracker covered by HIPAA?

Almost certainly not. HIPAA follows the provider, so data your doctor holds is covered while the same reading on a consumer app generally is not.

Does anonymised data actually protect me?

Only partly. Removing names is easy; removing patterns of movement and routine is much harder, which is what the Strava heatmap demonstrated.

Which setting should I change first?

Whatever controls public or aggregate sharing. That single toggle accounts for most real-world wearable exposure, and it is usually on by default.

Should I avoid wearables altogether?

No. Most people get real value from them, and the sensible response is to treat the account settings as part of the purchase rather than an afterthought.

Sources
  • TechCrunch, Strava heatmap and military base locations, January 2018
  • Federal Trade Commission, updated Health Breach Notification Rule, 2024
  • DataRecovee, GPS tracking data: how location devices capture, store and track data



Related Posts
Best 7 AI Development Companies for Data AI Solutions for Your Project: Guide for…

Buying model work before the data work is the most expensive order to do it in. The pilot shows well,…

Top Software Development Companies Backed by GoodFirms Reviews
Top Software Development Companies Backed by GoodFirms Reviews

In September 2026, GoodFirms listed 853 software development companies in California. The group had a median hourly rate of $37,…

What Is a Blockchain Explorer? How to Track Crypto Transactions
What Is a Blockchain Explorer? How to Track Crypto Transactions

A blockchain explorer is a searchable interface for viewing data recorded on a public blockchain. You can look up a…

How AI Is Changing the Way Businesses Configure and Manage CRM Systems
How AI Is Changing the Way Businesses Configure and Manage CRM Systems

With the growth and expansion of business operations, CRM management gets complex. New things, workflows, integrations, and custom rules often…

AI Photo Editors for Modern Image Editing in 2026 for Social Media and E-commerce
AI Photo Editors for Modern Image Editing in 2026 for Social Media and E-commerce

Due to advanced neural rendering models, the landscape of digital photography, graphic layout, and commercial design has changed fundamentally. Now…

Top 6 Automated Calling Software Options for Businesses
Top 6 Automated Calling Software Options for Businesses 

In this digital era, businesses are cutting their staff and relying more on automated systems. One great example of this…

Data Visualization Team: What It Takes to Build One That Delivers
Data Visualization Team: What It Takes to Build One That Delivers

Data visualization is no longer just about normal charts. In this modern era, they make no sense. Dashboards that are…

What Google Trusts More Than Your Own Copy
What Google Trusts More Than Your Own Copy

SEO is not just limited to optimising your website pages and adding relevant keywords in the content. Here is much…

data-analytics-employer-hiring-courses-ftd-img
Top 3 Data Analytics Courses That Match What Employers Are Hiring For

The data analytics courses are made for employers who want practical job skills, including SQL, data preparation, a digital competence…