The most common misconception we hear from readers about wearables is that their health data has some kind of medical-grade legal protection. It does not. The heart-rate trace from your Apple Watch, the sleep score from your Oura ring, the menstrual cycle log in your Flo or Clue app, the GPS route from your Garmin run — all of that lives outside HIPAA, outside any equivalent specific to consumer health data in most US states, and inside whatever the manufacturer’s privacy policy currently says. Privacy policies change. HIPAA does not.

This article exists because the gap between what readers think is happening and what is actually happening is wide enough to matter. Some of the matter is mundane (your step count being used for ad targeting), some of it is geopolitical (US service members’ running routes mapping out a forward operating base), and some of it is personal in a way that has become much sharper since 2022 (cycle-tracking data and post-Roe legal exposure in certain states). We will walk through the legal framing, the cases that should worry you, what each major manufacturer actually does, and the handful of practical things any reader can do this afternoon.

The HIPAA misconception

HIPAA, the Health Insurance Portability and Accountability Act of 1996, does not protect “health data.” It protects “protected health information” held by “covered entities.” Those covered entities are healthcare providers, health insurers, and healthcare clearinghouses, plus their business associates under contract. The text matters because the wearable industry sits entirely outside it.

Fitbit, Garmin, Apple, Oura, Withings, Whoop and Samsung sell consumer devices direct to you, take your data into their own accounts under their own terms, and are not your healthcare provider. There is no covered entity in the loop. Your blood-oxygen trend, your resting heart rate, your VO2 estimate and your sleep stages are, legally, the same category as your shopping history.

There are narrow exceptions. If your employer’s group health plan or your insurer is paying for the device as part of a regulated wellness program, the records sitting with the plan may pick up HIPAA protection, but only the records the plan actually holds. The copy on the manufacturer’s servers is still under the manufacturer’s privacy policy. The FTC has authority over deceptive data practices and has used it (see Flo Health, below), and several states — California with CCPA/CPRA, Washington with the My Health My Data Act of 2023, Connecticut with its data privacy act — now provide some coverage. But the headline is that your wearable data has weaker legal protection than your medical records, and most readers do not realize this.

For context on how this interacts with cloud-only devices that can disappear overnight, see our piece on wearable cloud dependency.

The cases worth knowing

Four episodes from the last several years are the clearest evidence that the abstract legal gap has concrete consequences.

The Strava heatmap, January 2018. Strava published a global activity heatmap aggregated from anonymized user data. Open-source intelligence researchers, most prominently Nathan Ruser, noticed that in regions with low background activity (northern Syria, parts of Afghanistan, the Sahel), the brightest activity lines outlined the perimeters and internal jogging loops of US and allied military bases. The data was not “personal” in the conventional sense; nobody’s name was on it. But the aggregate pattern was operationally sensitive. Strava restricted the heatmap’s resolution and made opt-out more prominent in the months that followed, and the Pentagon issued revised guidance on personal electronics. The lesson is that “anonymized” and “aggregated” do not always mean “harmless.”

The Flo Health FTC settlement, 2021. Flo, the period-tracking app with hundreds of millions of users, was alleged by the FTC to have shared sensitive data, including pregnancy status, with third-party analytics and advertising services such as Facebook and Google, despite Flo’s public privacy assurances. Flo settled. There was no admission of wrongdoing and no financial penalty, but the consent order required an independent privacy review and barred future misrepresentations. The case is the cleanest US precedent for “the privacy policy said one thing and the SDK integrations did another.” It is also the case that motivated the post-Dobbs scrutiny of cycle-tracking apps.

The Google–Fitbit acquisition. Google announced its $2.1 billion acquisition of Fitbit in November 2019, closed it in January 2021, and spent the intervening period under antitrust review on both sides of the Atlantic. The EU Commission cleared the deal in December 2020 after Google offered binding commitments, including a ten-year promise not to use Fitbit health and wellness data for Google Ads targeting in the European Economic Area, and to maintain data interoperability with rival fitness platforms. The Australian competition regulator declined to accept similar undertakings. The US Department of Justice closed its review without conditions. In August 2023, Google migrated existing Fitbit accounts onto Google accounts, which means Fitbit health data now sits in the Google account ecosystem under Google’s broader terms. The EU commitments still apply where they apply; the global reassurance is thinner.

Post-Dobbs legal exposure. The Supreme Court’s June 2022 decision in Dobbs v. Jackson Women’s Health Organization returned abortion regulation to the states. Several states moved quickly to criminalize procedures and, in some cases, the act of seeking or facilitating them. Health-tracking apps (period trackers especially, but also general fitness apps that log “pregnant” as a state) store data that could in principle be subpoenaed. This is not a hypothetical: civil and criminal subpoenas for app data are routine. Several apps responded by moving cycle storage to on-device only, or by stripping identifying metadata. Many did not.

What each major manufacturer actually does

Privacy postures across the major manufacturers are not equivalent. Some companies have done meaningful engineering work to limit what they themselves can see; others have not. The summaries below are not exhaustive — privacy policies run to thousands of words and change quarterly — but the high points reflect each company’s actual product behavior as of mid-2026.

Apple. The strongest privacy posture in the consumer wearable category, by a meaningful margin. Health data captured on the Apple Watch flows into the Health app on the iPhone and is stored locally with hardware-backed encryption. iCloud sync is encrypted in transit and at rest by default, and on iOS 16.2 and later, turning on Advanced Data Protection moves the encryption keys off Apple’s servers entirely. Apple has publicly stated that it cannot decrypt health data in that mode even under subpoena. Third-party apps requesting access to Health data must ask category-by-category, and you can revoke any single category at any time. Apple does not sell health data, does not use it for advertising, and the Health app explicitly lists no advertising as a design constraint. The catch is that all of this only protects you to the degree you have an iPhone and you have configured iCloud properly. Anyone running a third-party fitness app on an iPhone is still subject to that app’s policy, not Apple’s.

Fitbit (Google). Fitbit accounts were migrated onto Google accounts on a rolling basis through 2023 and into 2024, and since August 2023 new Fitbit devices require a Google account at setup. Google’s binding EU commitment that Fitbit health and wellness data will not be used for Google Ads in the EEA continues to apply, and Google has stated it does not use Fitbit health data for ads globally. We take that at face value while noting that the data nonetheless lives in the Google account ecosystem and is subject to Google’s broader retention, legal-request and product-integration practices. This is the platform shift readers should pay attention to: a Fitbit account in 2026 is a Google account, with everything that implies about cross-product visibility. Our Apple Watch vs Fitbit comparison gets into this in more detail.

Garmin. Garmin Connect is the data home for everything from a Forerunner 55 to a Fenix 8. Garmin’s privacy policy commits to no use of personal data for advertising, and the company sells hardware and subscriptions rather than monetizing your runs. The reputational dent worth knowing about is the July 2020 ransomware incident. The WastedLocker attack, reportedly attributed to the Evil Corp group, took Garmin Connect, flyGarmin and several other services offline for roughly five days, with synchronization disruptions stretching longer. There is no public evidence that user data was exfiltrated, but the recovery process and the company’s communications during the outage were criticized at the time. Garmin’s privacy posture is sound on paper; the operational record is mixed. The Fitbit vs Garmin comparison covers the day-to-day differences.

Oura. Oura keeps ring data inside its own systems and its privacy policy explicitly states the company does not sell personal data and does not use health data for advertising. Oura is a Finnish company, and EU users have meaningful data-residency commitments under GDPR. Oura’s Insights and research-partnership features are opt-in by default in most regions, which is the right default but easy to miss when setting up the ring. The membership-fee model (almost everything beyond raw step counts sits behind a $5.99/month membership) is a different concern, but it does at least clarify the business model: you are paying for the software, not being monetized through it.

Withings. Withings markets European-grade GDPR privacy as a product feature. The company is headquartered in France, hosts EU user data in EU data centers under the Withings Cloud terms, and offers a paid Health+ tier rather than monetizing the free data. Withings has published a data-processing addendum that explicitly addresses GDPR Article 28 sub-processor obligations, which is more than most US-based competitors do. For European readers in particular, Withings is the closest the industry comes to a “privacy-first” mainstream wearable. For US readers the practical difference is smaller, but the policy posture is still clearly better than the US norm.

A separate question for any of these companies is what happens to the data if the device or the service goes away — which brings us to the cautionary tale.

The Basis Peak warning

The Basis Peak is the wearable case study every reader should keep in mind when evaluating a privacy claim, because it makes the central point: the strongest privacy policy in the world is only as durable as the company offering it.

Intel acquired Basis Science in March 2014, reportedly for between $100 million and $150 million. The Basis Peak launched in November 2014. In June 2016, after reports of skin burns, the device was recalled (formal CPSC notice 16-235 followed on August 4, 2016) and on December 31, 2016 the Basis Peak service was shut down for good. Around 200,000 units were affected. The hardware became a paperweight when the cloud went dark, and the data went with it. Anyone who had been tracking heart rate, sleep and skin temperature for two years on a Peak lost the entire archive unless they had exported it.

There was nothing wrong with Basis’s privacy stance. It was a reasonable company with a reasonable policy. The problem was that the entire data model assumed the company would continue to exist, and when it didn’t, the policy was irrelevant. Our longer Basis Peak post-mortem goes into the recall mechanics, and whether the Peak is still usable is a separate page (short answer: no, and don’t try). The point we want to anchor here is that you should not store anything in a wearable cloud that you would be upset to lose, and you should periodically pull a local copy.

If you are choosing a new tracker with privacy or export in mind, these pages go deeper:

Things to do this afternoon

Most of the practical work of wearable privacy is not technical. It is administrative, and it adds up to maybe an hour a year.

Export your data, on whatever device you own, at least once a quarter. Every major platform offers a data download: Apple’s iOS export, Google Takeout for Fitbit, Garmin Connect’s data export, Oura’s data download, Withings’s data export under account settings. The files are usually CSV or JSON inside a ZIP, which is enough to keep your trend lines alive if the service ever changes hands or goes away. Treat the export like a household task, not a project.

Walk through the privacy settings inside each app once a year. The defaults shift over time, and “Insights,” “Community” or “Research” features that share aggregated data with third parties tend to be opt-in only at setup. Turn them off if you have no specific reason to share. Look for “personalized advertising” and “third-party data sharing” toggles in particular — those are the ones manufacturers tend to hope you do not notice.

Audit which third-party apps are connected to your health data. Apple Health shows this under Sources and Apps. Fitbit shows it under Account Settings → Third Party Apps. Garmin shows connected apps under Connect IQ. Disconnect anything you do not use. Each connected app is a separate privacy policy you are implicitly accepting.

Close old accounts. The Garmin Forerunner 235 you stopped wearing in 2019 has an associated account that is still online, and the password is probably from a breach by now. Export the data, delete the account, move on. Our no-subscription tracker roundup and the broader health tracker guide both have specific export instructions for the devices we recommend.

The legal landscape will keep moving. The technical state of your accounts is what you can fix today.