The watch on your wrist counts your steps, tracks your sleep, watches your heart rhythm, and for many people with chronic conditions it does real work: catching an irregular heartbeat, flagging a fall, tracking glucose around the clock. Wearables can be genuinely useful for managing health. The catch is that the same devices generate a detailed, continuous record of your body, and a lot of that record does not stay with you. Before you strap one on, it is worth knowing where the data goes.
The gap most people do not know about
Here is the part that surprises almost everyone. The health data from your Apple Watch, Fitbit, Oura Ring, or Garmin is usually not protected by HIPAA, the law most people assume covers anything health-related. In the United States, consumer wearable companies generally fall outside HIPAA unless they are working directly with a health-care provider or insurer on your behalf. The data is “health data” in every sense that matters to you, and in the sense that matters legally it often is not.
That gap is the whole story. It means the information about your heart rate, sleep, activity, stress, and cycle can move through a network of advertisers and data brokers in ways that genuinely protected medical records cannot. A 2025 study in npj Digital Medicine found that many companies did not clearly report how they shared user data with governments and third-party apps, and most lacked clear breach-notification processes. You are often trusting a privacy policy, not a law.
No spam. No inspiration porn.
Our best writing for adults with disabilities, weekly and free.
Get the newsletterWhat actually applies in Canada
HIPAA is American. It has never applied here, and a Canadian reader who stops at the paragraph above is left thinking there is no rule at all. There is. A consumer wearable company is not a health information custodian under provincial health privacy law, the way a hospital or a doctor is. It is a business, so the federal Personal Information Protection and Electronic Documents Act applies to what it collects about you in the course of commercial activity. PIPEDA also applies to personal data that flows across provincial or national borders in the course of commercial transactions, which is what a wearable does every time it syncs to a server in another country.
That gives you something the American framing does not: a complaint route. The Office of the Privacy Commissioner of Canada takes complaints about how a company handles your personal information, and it investigates PIPEDA complaints everywhere except Quebec, British Columbia and Alberta, which have their own substantially similar laws and their own commissioners. You can complain about an app or a device maker. Almost nobody knows that, and it costs nothing to do.
Where the data can go
Several destinations are worth naming plainly.
Advertisers and data brokers. Many wellness brands share data with advertisers or brokers, sometimes without clear consent. The transfer happens through a chain of intermediaries that makes it nearly impossible for a person to understand who ends up holding what. A 2025 investigation by The Markup and CalMatters found state-run health exchanges sending sensitive user data to Google and LinkedIn, which gives you a sense of how routine this kind of leakage has become even in places you would expect to be careful.
Insurers. This is the one that hits the disability and chronic-illness community hardest. Privacy experts have warned that health data can be used to adjust insurance premiums or deny coverage, and that compromised wearable data could mean higher rates for people deemed less healthy, or even feed into employment discrimination. For a person already living with a condition, a continuous stream of body data sitting outside HIPAA is not a neutral convenience.
Continuous glucose monitors. For people with diabetes, CGMs from Dexcom and Abbott (FreeStyle Libre) are life-changing tools, and the data sharing here is mostly designed for care: platforms like Dexcom Clarity and Abbott’s LibreView let you share readings with your health-care team, and apps like LibreLinkUp let family and caregivers follow your levels and alarms. That is the upside, and it is a large one. The thing to check is the secondary path: which third-party apps you have connected, and what each of those is permitted to do with the glucose data once it leaves the medical platform.
The rules are starting to change, mostly elsewhere
Lawmakers have noticed the gap. In November 2025, the Health Information Privacy Reform Act was introduced in the United States Senate to extend HIPAA-like protections to data from devices like Apple Watches and Oura Rings. Whether it passes is an open question, but it signals that the current free-for-all is being recognized as a problem rather than a feature.
In Canada, wearable health data generally falls under the federal Personal Information Protection and Electronic Documents Act and, in clinical contexts, provincial health privacy law. As with brain data and so many other technologies, the law was not written with continuous body-monitoring in mind, and a device sold directly to consumers can sit in a grey zone. The practical takeaway is the same on both sides of the border: do not assume the strongest health privacy protections apply just because the data is about your health.
What to check before you wear it
None of this is a reason to give up a device that helps you manage a real condition. It is a reason to set it up with your eyes open. Before you commit, check the following.
- Read the data-sharing section, not just the privacy policy headline. Look specifically for whether the company sells or shares data with advertisers, brokers, or “partners,” and whether you can turn that off.
- Find the opt-outs and use them. Many devices default to the most permissive sharing. Turn off ad tracking, data sales, and any “improve our products” sharing you do not want.
- Check every connected third-party app. The risk often is not the watch; it is the fitness, sleep, or wellness app you linked to it. Disconnect ones you do not use and review what the rest can access.
- Look for breach-notification language. If the policy does not say how they will tell you about a breach, treat that as a warning sign.
- Ask whether your device is HIPAA-covered in any way. If it connects to your clinic or insurer, parts of it may be protected. If it is purely consumer-facing, assume it is not.
- For CGMs specifically, separate the medical platform from the extras. Sharing with your care team is the point. Audit any lifestyle apps you have bolted on, and remove the ones you do not need.
- Decide what you actually need. If a feature requires sharing data you would rather keep private and you do not use the feature, turn it off.
Wearables are a real tool for self-determination in health, and for many people the benefit clearly outweighs the cost. But the benefit is yours by design, and the data should be too. Right now it often is not, and the only person positioned to close that gap, until the law catches up, is you, working through the settings before the device starts collecting. Spend the twenty minutes. It is your body’s data.
Sources
- Privacy Pitfalls in the Push for Wearables, Captain Compliance
- Whispers from the Wrist: Wearable Health Monitoring Devices and Privacy Regulations, Cryptography (MDPI)
- How State Laws Shape Digital Health Privacy, Censinet
- Privacy in the Age of the Smartwatch, Duke Pratt School of Engineering
- Love Your Wearable Technology? Know What You’re Sharing, ElderLawAnswers
- Unlocking Real-Time Data Access in Diabetes Management, PMC
- Privacy in consumer wearable technologies: a living systematic analysis of data policies across leading manufacturers, npj Digital Medicine (2025)
- U.S. Senate Introduces the Health Information Privacy Reform Act (introduced November 2025), Inside Privacy
- Office of the Privacy Commissioner of Canada, PIPEDA complaints and enforcement process
- Office of the Privacy Commissioner of Canada, Guide to the PIPEDA complaint process
- We Caught 4 More States Sharing Personal Health Data With Big Tech, The Markup and CalMatters (2025)
