HydraWatch All articles
Account Security & Privacy

Body as Data: How Fitness Wearables and Health Apps Are Selling Your Most Intimate Information to the Highest Bidder

HydraWatch
Body as Data: How Fitness Wearables and Health Apps Are Selling Your Most Intimate Information to the Highest Bidder

Photo: fitness tracker wearable smartwatch health data privacy, via thumbs.dreamstime.com

The pitch is always the same: wear this device, install this app, and live a healthier, more informed life. Tens of millions of Americans have accepted that bargain without reading the fine print. What that fine print describes — buried in privacy policies that routinely exceed ten thousand words — is a data-sharing apparatus of remarkable scope and troubling consequence.

Fitness trackers, smartwatches, period-tracking applications, sleep monitors, and calorie-logging platforms collectively harvest an inventory of biometric signals that would have been impossible to compile outside a clinical setting just fifteen years ago. Resting heart rate. Blood oxygen saturation. Menstrual cycle length and predicted ovulation windows. Hours of REM sleep. Step count correlated with GPS location. Stress scores derived from heart-rate variability. Taken individually, each data point seems benign. Assembled into a longitudinal profile, they constitute something closer to a medical dossier — one that exists almost entirely outside the protections of the Health Insurance Portability and Accountability Act.

The HIPAA Blind Spot

This is the central legal reality that most users do not understand: HIPAA governs the handling of health information by covered entities — hospitals, insurers, and their direct business associates. A consumer wellness app is not a covered entity. When Fitbit, Apple Health, or a menstrual-tracking service collects your biometric data, that information is generally governed only by the platform's own privacy policy and whatever state-level consumer protection law applies to your place of residence.

That distinction carries enormous practical weight. In 2021, the Federal Trade Commission issued a warning to health apps and connected device makers, noting that the agency would pursue enforcement actions under Section 5 of the FTC Act against companies that misrepresent their data practices. The warning did not create new substantive rights for consumers. It simply signaled that the FTC was watching — a posture that privacy advocates describe as inadequate given the volume and sensitivity of data in circulation.

"The average American using a fitness tracker has no meaningful way to audit where their data goes after it leaves the app," said one digital rights researcher who has studied wellness platform privacy policies for several years. "The consent framework is theatrical. You click 'agree,' and you have effectively signed a contract whose terms you were never expected to read."

From the Wrist to the Underwriter

The insurance industry's appetite for behavioral and biometric data is well-documented. Several life and health insurers in the United States have piloted programs that offer premium discounts to policyholders who share fitness-tracker data, framing the arrangement as a reward for healthy behavior. John Hancock's Vitality program, one of the most prominent examples, integrates directly with Apple Watch and Fitbit to monitor physical activity.

The voluntary nature of such programs does not resolve the underlying concern. Privacy advocates argue that as data-sharing programs become normalized, the practical pressure on consumers to participate will intensify — and that the same data used to reward healthy individuals today can be used to penalize or exclude less healthy ones tomorrow. While the Affordable Care Act prohibits health insurers from using health status as a rating factor in most contexts, life and disability insurers operate under different constraints.

Beyond the insurance sector, a secondary market for wellness data has matured quietly. Data brokers purchase, aggregate, and resell consumer health information to marketers, employers, and financial institutions. A 2023 investigation by the Duke University Sanford Cyber Policy Program found that data brokers were willing to sell detailed mental and physical health information — including data derived from app usage — with minimal verification of the buyer's identity or intended use.

When Criminals Enter the Picture

The same richness that makes biometric profiles valuable to insurers and marketers makes them attractive to criminal operators. The threat materializes in several distinct ways.

First, health and wellness platforms represent high-value breach targets. A compromised database containing years of biometric history, combined with the account credentials and payment information that typically accompany a premium subscription, gives attackers a detailed portrait of a victim that can support highly personalized phishing campaigns. An attacker who knows a target's average resting heart rate, their approximate sleep schedule, and the neighborhood where they run every morning possesses social-engineering ammunition that most credential dumps cannot match.

Second, period-tracking applications have emerged as a particular concern following the Supreme Court's 2022 decision in Dobbs v. Jackson Women's Health Organization. Security researchers and civil liberties organizations noted almost immediately that menstrual cycle data stored by apps such as Flo, Clue, and Period Tracker could potentially be subpoenaed by state authorities in jurisdictions that have enacted abortion restrictions. Flo subsequently introduced an "Anonymous Mode" feature, and several other platforms issued revised data minimization commitments — but the underlying architecture of data collection remained largely unchanged.

Third, location data embedded in fitness activity logs presents a deanonymization risk that the industry has consistently underestimated. In 2018, analysts examining data published by the fitness platform Strava identified the patrol routes of military personnel at classified overseas installations — a consequence of soldiers using fitness trackers during their routines. While that episode involved a specific population, the methodological lesson applies broadly: aggregated movement data, even when stripped of names, can be reverse-engineered to identify individuals and reveal behavioral patterns they had no intention of disclosing.

What Users Can Do

The structural asymmetry between platform and user is real, but it does not render individuals entirely powerless. Several concrete steps can meaningfully reduce exposure.

Review and restrict data-sharing permissions. Most fitness platforms provide, somewhere within their settings, the ability to opt out of data sharing with third-party partners. These options are rarely surfaced prominently, but they exist. Navigate to your app's privacy or data settings and audit every toggle.

Understand what your platform's privacy policy actually permits. Tools such as the nonprofit Terms of Service; Didn't Read project assign letter grades to major platforms based on their data practices. Before committing biometric data to any new service, consult available summaries.

Enable two-factor authentication on every wellness account. A compromised fitness account is not merely an inconvenience — it is a breach of an intimate data archive. Treat it with the same security posture you would apply to a financial account.

Consider what you actually need to share. Many fitness platforms function adequately with location permissions disabled or set to "while using." Calorie-tracking apps do not require access to your contact list. Apply the principle of minimum necessary disclosure: grant only the permissions a feature genuinely requires.

Regularly delete historical data. Most major platforms provide a mechanism to purge historical activity records. Doing so periodically limits the depth of the profile any single breach could expose.

The wellness technology industry has built its business model on the proposition that personal data shared in the pursuit of health is a fair exchange for the insights and features it enables. Whether that exchange is genuinely fair depends on a transparency and user control that the current ecosystem does not consistently provide. Until the regulatory framework catches up — and there is meaningful legislative movement in several states, including California, Colorado, and Washington — the burden of protection falls largely on the individual.

All articles

Related Articles

Silent Tenant: How Stalkerware Colonizes Your Smartphone and What It Takes to Remove It

Silent Tenant: How Stalkerware Colonizes Your Smartphone and What It Takes to Remove It

Connected and Compromised: The Hidden Threat Lurking on Every Public Wireless Network You Trust

Connected and Compromised: The Hidden Threat Lurking on Every Public Wireless Network You Trust

Permanent Damage: Why a Breach at Your DNA Testing Company Is Unlike Any Hack You Have Ever Survived

Permanent Damage: Why a Breach at Your DNA Testing Company Is Unlike Any Hack You Have Ever Survived