Hub
Deep Dive
Your Health Data Is Leaking: The Threat Beneath the Wearables
Neurotech & Cognitive LibertyDeep Dive

Your Health Data Is Leaking: The Threat Beneath the Wearables

Wearables promise self-knowledge, but their data trails are building a hidden market in bodily inference.

AI AssistedSociety OS Research11 July 202611 min read read

Key Insight: A fitness tracker does not merely record steps; over time, it can reveal pregnancy, depression, arrhythmia, location, routines and vulnerability.

At 2am, your watch is still talking

A smartwatch on a bedside table records far more than a morning run. Through the night it may log pulse variability, skin temperature, blood oxygen, movement, sleep stages and wakefulness. By breakfast, those signals may have travelled from wrist to phone, from phone to cloud, and from cloud to a thicket of software development kits, analytics providers, advertisers or research partners. The owner often sees a clean dashboard and a reassuring score. What they do not see is the supply chain.

That gap between perception and reality is now one of the defining problems in digital health. Wearables, fertility trackers, glucose monitors, smart scales, mental-health apps and connected exercise platforms generate the most intimate data most people will ever produce continuously. They do so outside the older clinical setting, where duties of confidentiality are clearer and legal protections, while imperfect, are at least recognisable. In the consumer market, the rules are patchier, consent is thinner, and commercial incentives are stronger.

For those entrusted with care, safety and longevity, this is not a side issue. It goes to the heart of professional judgement. A generation of products has trained people to believe that health data gathered on the body is naturally treated like medical data gathered in a hospital. Often it is not.

Where the data actually goes

The modern health-data economy is built on a simple but underappreciated distinction: not all health-revealing data is legally treated as health data.

In the United States, the Health Insurance Portability and Accountability Act, or HIPAA, applies chiefly to healthcare providers, insurers and their business associates. Much of the data produced by consumer wearables and health apps sits outside that perimeter unless it is handled by a covered entity in a covered context. A period-tracking app, a fitness wearable, or a mood journal may reveal deeply medical facts while falling into a much looser regime.

That is not a technicality. It is the commercial opening.

A wearable company may collect data directly. Its mobile app may embed third-party code for analytics, crash reporting, attribution, product optimisation or targeted advertising. Those third parties may combine identifiers across apps and devices. Location data brokers can enrich movement patterns. Retail data can suggest purchases related to pregnancy, supplements or medical conditions. Over time, signals that seem banal in isolation become startlingly revealing in combination.

In 2023 the US Federal Trade Commission settled with BetterHelp over allegations that the online counselling platform shared users' email addresses, IP addresses and health questionnaire information with Facebook, Snapchat, Criteo and Pinterest for advertising purposes, despite assurances about privacy. BetterHelp did not admit wrongdoing, but the case illustrated the central problem: intimate disclosures can be repurposed through ordinary ad-tech plumbing.

The year before, the FTC reached a settlement with Flo Health, the period-tracking app, over allegations that it shared users' health information with third parties for analytics and marketing after promising privacy. Flo also did not admit the allegations. Again, the broader lesson was not confined to one firm. Reproductive data, among the most sensitive categories imaginable, had moved through commercial pipes many users scarcely knew existed.

Good intentions do not neutralise this architecture. Even where a company is not overtly selling named records to brokers, it may still be enabling inference, audience matching, ad targeting or model training in ways the individual never meaningfully contemplated.

The breach is not the only breach

Public discussion often narrows the issue to cyber security: was there a hack, and how many records were exposed? That matters. Health systems have been repeatedly hit by ransomware and mass data theft. But with wearables and health apps, the more common danger is subtler. The system may be behaving exactly as designed.

A person can be perfectly "secure" in the narrow sense of using a well-encrypted service and still be extensively surveilled through terms they nominally accepted. That is why focusing only on data breaches misses the larger structural leak.

The clearest modern example came not from a wearable company but from a broker. In 2024 the FTC banned data broker X-Mode's successor, Outlogic, from selling sensitive location data and from collecting such data without consent for certain purposes. The agency had already acted in 2024 against InMarket over the use of location data for advertising and targeting. Location data may seem adjacent to health rather than part of it. Yet repeated visits to an oncology clinic, a fertility centre, an addiction service or a mental-health practice can be as revealing as a diagnosis code.

The old boundary between "health data" and "everything else" is collapsing under the weight of inference.

Why biometric data is different

The draft intuition is exactly right: biometric data is permanent and predictive.

The old boundary between health data and everything else is collapsing under the weight of inference.

A password can be reset. A credit card can be cancelled. But a long-run record of resting heart rate, irregular rhythm, menstrual cycles, temperature variation, gait, sleep disruption or glucose spikes cannot be recalled from the world once copied. Nor is it static. Longitudinal biometric data grows in value because patterns emerge over time.

This is what makes wearables qualitatively different from a single medical form. They create moving portraits.

Research has shown how much can be inferred from those portraits. Data from wearables has been used to detect atrial fibrillation and other cardiac irregularities; Apple's Apple Heart Study, published in the New England Journal of Medicine, helped establish both the promise and the complexity of large-scale remote screening. Numerous studies have explored the use of sleep, heart-rate variability and activity patterns as indicators of stress, mood disorders and infection. During the Covid-19 pandemic, several research groups investigated whether wearable signals could flag illness before people felt unwell.

That is the upside. The downside is the same predictive power in less benevolent hands.

Employers may not receive a formal diagnosis, but wellness-platform data can shape views about productivity, reliability or risk. Insurers may not need a medical file if proxies are good enough. Advertisers do not require certainty; they only need an increased probability that someone is pregnant, anxious, exhausted, sedentary or seeking treatment. In high-trust domains, probabilistic judgement can still do real harm.

And because biometrics tie closely to identity, revocation is unusually hard. You cannot change your sleep history, your menstrual history, your characteristic gait or your chronic stress signature. You may stop using the device, but the past remains extractable.

Reproductive surveillance is the sharpest warning

If anyone still doubts the stakes, they should look at reproductive data.

After the overturning of Roe v Wade in the United States, privacy scholars, clinicians and civil-liberties groups warned that period-tracking data, search histories, location traces and message logs could become relevant in investigations or civil actions related to pregnancy outcomes. Mozilla's Privacy Not Included project has repeatedly found troubling privacy practices across period and pregnancy apps, while digital-rights organisations have documented how ordinary mobile data can become evidentiary material.

The anxiety was not hypothetical. In Nebraska, Facebook messages were used in a case involving abortion-related charges in 2022. The point is not that wearables alone create legal jeopardy, but that intimate digital traces, once normalised, become available to processes far removed from care.

Reproductive data is merely the clearest case because it combines bodily intimacy, political contestation and timing. But the same pattern applies elsewhere. Fertility tracking can reveal attempts to conceive. Sleep disruption can correlate with anxiety or caring burdens. GPS and heart-rate patterns can reveal attendance at addiction support meetings. Data gathered for self-knowledge can be re-read as evidence.

The companies are not all the same

It would be too simple to treat every device maker as equally reckless. The market is uneven.

Apple has positioned privacy as a product differentiator and has kept significant health processing on device, while publishing detailed privacy disclosures and expanding encrypted protections across parts of its ecosystem. Google, after acquiring Fitbit, made commitments to the European Commission in relation to Fitbit user data and advertising in order to secure regulatory approval, including limitations on the use of certain health and wellness data for Google Ads for a period.

Yet even comparatively privacy-conscious firms sit inside broader infrastructures of cloud processing, app permissions, account recovery, law-enforcement requests and cross-device ecosystems. Moreover, many consumers do not remain within a single firm's carefully controlled environment. They export data, link third-party apps, connect to wellness programmes, sync with employer benefits portals or join online communities that sit far outside the original manufacturer's safeguards.

Then there is the long tail: small app developers, venture-backed optimisation platforms, niche fertility products, direct-to-consumer diagnostics firms and insurers' wellness partners. These are often less scrutinised, less resourced and more dependent on monetisation through partnerships. The risk is not confined to one scandalous actor. It is systemic because the incentives are systemic.

Law is catching up, slowly and unevenly

Regulators have begun to recognise the problem, but the landscape remains fragmented.

In the European Union, the General Data Protection Regulation classifies data concerning health as a special category deserving higher protection. In principle, that is a stronger starting point than the American patchwork. In practice, enforcement remains uneven, legal interpretations are contested, and many consumers still face manipulative consent design and excessive data collection.

A person can be perfectly secure in the narrow sense and still be extensively surveilled through terms they nominally accepted.

The UK's Information Commissioner's Office has issued guidance on health data and app privacy. The US Federal Trade Commission has increasingly used its Health Breach Notification Rule, including in the GoodRx case in 2023, where the company agreed to settle allegations that it shared users' health information with advertising platforms despite privacy promises. Washington State's My Health My Data Act goes further than many US laws by covering consumer health data beyond HIPAA's narrow scope, and Nevada has adopted a similar law.

These are important developments. But they remain reactive. They punish the most visible abuses after the fact. They do not by themselves redesign the technical and contractual defaults under which intimate data is gathered in the first place.

The core failure is architectural: we built continuous health sensing on top of the commercial internet, then acted surprised when the commercial internet behaved commercially.

The hidden social costs

Health-data leakage is often discussed as an individual privacy problem. It is that, but it is also a social one.

When people lose confidence in how their bodily data will be used, they change behaviour. Some stop tracking altogether. Others withhold symptoms from apps or clinicians. Some avoid searching for information, joining support groups or using digital tools during vulnerable periods. The result is not just private discomfort but degraded public benefit.

Digital health works only if trust is thick enough to support disclosure. Remote monitoring for heart failure, post-operative recovery, diabetes management or elder care can be clinically valuable. Passive sensing may reduce avoidable admissions and improve continuity of care. But if people reasonably suspect that every signal can become a commodity, adoption will tilt towards the affluent and the privacy-literate, while others will either opt out or submit without understanding.

That creates a cruel asymmetry. Those most likely to benefit from preventive monitoring are often those least equipped to audit opaque data ecosystems: older patients, people in financial distress, adolescents, new parents, or those with chronic conditions. Convenience then becomes a mechanism for extraction.

What a Guardian must do now

The draft's practical point deserves expansion: guardians of health have a dual duty, to secure what they hold and to interpret the risks of what others collect.

For clinicians, therapists, carers, health coaches and safety professionals, this means moving beyond generic privacy assurances.

Start with data minimisation

If a service does not need continuous location, contacts, microphone access or indefinite retention, it should not ask for it. Many organisations still collect because storage is cheap and future use is tempting. That is no longer defensible with intimate biometrics.

Map the vendors

Most privacy failures occur through third parties. Practices and health-adjacent businesses should know which analytics tools, cloud hosts, customer-support platforms, payment processors and software development kits touch user data. If nobody can draw the data flow, nobody truly controls it.

Distinguish care from marketing

The line between patient engagement and behavioural advertising must be bright. If a mental-health or reproductive-health service uses ad-tech tools that transmit sensitive signals to platforms optimised for targeted advertising, it has already crossed into dangerous territory.

Treat consent as a process, not a button

Meaningful consent requires clear explanation of downstream uses, retention periods, sharing partners and risks of re-identification. This matters especially for adolescent users, older adults and anyone using a product during crisis or illness.

To protect health in a digital society is to protect not only the biological body but the data body that shadows it everywhere.

Prepare for deletion and exit

People should be able to leave with a usable export and a credible deletion pathway. In practice, deletion across backups, processors and downstream partners is difficult. That is precisely why systems should be designed with narrow collection from the start.

From privacy policy to governable systems

This is where a deeper governance approach becomes useful. Privacy policies are descriptive; they tell users what may happen. They rarely constrain execution in real time.

A more serious model begins before data moves. Within The Sovereign Standard, the relevant technical discipline is F-ACT, the Framework for Agent Conformance & Trust. Its core principle is simple: govern before execution — not after. For health-adjacent AI systems, that means setting explicit controls around who is authorised to act, what scope they have, which data they may access, what audit trails exist, and how access can be revoked. F-ACT summarises that normative core as ASDAR: Authority, Scope, Data, Audit, Revocation.

In plain terms, a governed agent network in health should not be free to ingest every available signal because the API allows it. It should be constrained by purpose, identity and provable policy. The broader umbrella for this way of thinking is The Sovereign Standard: not a legal right granted by a state, but a practical and moral principle that the most intimate data a person generates should remain under their meaningful control by default.

The 42 Protocols offer one implementation path for such a model, including the Human-Twin-Agent identity layer for establishing who acts, on whose behalf, and under what authority. But the essential point is larger than any one stack. Health systems need technical architectures in which consent, scope limitation and revocation are enforceable properties, not decorative language around business as usual.

What individuals can do, realistically

Responsibility should not be dumped on consumers. Still, individuals are not powerless.

  • Prefer devices and apps with clear privacy documentation, limited third-party sharing and strong on-device processing where possible.
  • Review app permissions, especially location, contacts, microphone and background access.
  • Avoid linking health apps to advertising-heavy social platforms unless the benefit is unmistakable.
  • Use platform privacy controls on iOS and Android to limit tracking and unnecessary data access.
  • Be cautious with reproductive, mental-health and condition-specific apps that lack a credible clinical or institutional steward.
  • Ask a plain question before using any service: who else gets this data, in what form, and for how long?

This is not a complete defence. The burden is still too high. But better questions change markets over time.

The next frontier: prediction without permission

The threat beneath wearables is no longer just collection. It is inference at scale.

As foundation models and health AI mature, raw data need not remain obviously medical to become medically revealing. A mixture of accelerometer traces, purchase records, geolocation, audio features and sleep disruption can generate risk scores for depression, frailty, pregnancy, substance use or cognitive decline. Those scores may be wrong, but they do not need to be perfect to influence pricing, access or opportunity.

This is the coming contest in bio-digital sovereignty. It is not only about secrecy; it is about agency. Who gets to convert bodily traces into predictions? Under whose authority? For whose benefit? With what recourse when the model is mistaken?

If society answers those questions badly, the result will be a health economy that knows people intimately while remaining answerable to them only superficially.

Guarding health now means guarding the data body

The first era of wearables sold motivation: count your steps, close your rings, know yourself. The second sold prevention: detect the arrhythmia, flag the sleep disorder, catch the change early. The third era, now arriving, is about inference and power. It will determine whether continuous sensing becomes a tool of care or a permanent layer of extraction.

For Guardians, that makes the obligation clear. To protect health in a digital society is to protect not only the biological body but the data body that shadows it everywhere. That means securing records, yes, but also challenging business models, procurement habits and technical designs that treat intimate human signals as ambient raw material.

The principle worth holding is straightforward: an individual's biometric data should remain under their control by default, shared deliberately rather than harvested silently. In the years ahead, that will not be a slogan. It will be the dividing line between digital health that deserves trust and digital health that merely demands it.

Sources & Further Reading

  1. 1.Federal Trade Commission: BetterHelp to pay $7.8 million to settle FTC allegations of revealing consumers’ sensitive data
  2. 2.Federal Trade Commission: Flo Health settles FTC allegations of sharing users’ health data
  3. 3.Federal Trade Commission: GoodRx settles allegations over sharing consumers’ sensitive health information
  4. 4.Federal Trade Commission: X-Mode/Outlogic sensitive location data case
  5. 5.Federal Trade Commission: InMarket prohibited from selling or licensing precise location data
  6. 6.New England Journal of Medicine: Large-Scale Assessment of a Smartwatch to Identify Atrial Fibrillation
  7. 7.European Commission: Google/Fitbit merger commitments
  8. 8.Mozilla Foundation: Privacy Not Included buyer’s guide
  9. 9.Information Commissioner's Office: Health data guidance
  10. 10.Washington State Legislature: My Health My Data Act
health-dataprivacywearablesbiometricsdata-brokerssecurity
The engine behind the Signal

Where this connects to Society OS

The Sovereign Intelligence Hub is the free, open front door of Society OS — the sovereign operating system that turns the ideas you just read into working governance. Where this piece names a problem, Society OS is building the machinery to solve it: AI agents that act with your authority, trust you can verify, and compliance that runs as code.

The 42-Protocol Stack

The governance engine beneath every article — led by the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank trust, and WISE Contracts that execute law, not just code.

F-ACT — the open agent standard

The vendor-neutral framework for governing AI agents before they act: Authority, Scope, Data, Audit, Revocation — free to read, cite and implement.

The Sovereign Platform

Put it to work: govern a fleet of AI agents with verifiable authority, tamper-evident evidence, and compliance-as-code across your whole operation.

Explore membershipRead the F-ACT standard

Continue Reading

More from the Sovereign Intelligence Hub

From DNA Databases to Brain Signals: How the Body Became a Governance Problem
Neurotech & Cognitive Liberty

From DNA Databases to Brain Signals: How the Body Became a Governance Problem

10 min read
The Next Sovereignty Fight Will Be Over Inference, Not Data
Neurotech & Cognitive Liberty

The Next Sovereignty Fight Will Be Over Inference, Not Data

11 min read
The Next Sovereignty Dispute Will Happen Inside the Clinic
Neurotech & Cognitive Liberty

The Next Sovereignty Dispute Will Happen Inside the Clinic

11 min read
The Coming Fight Over Inference Rights From Breath, Gait and Voice
Neurotech & Cognitive Liberty

The Coming Fight Over Inference Rights From Breath, Gait and Voice

11 min read
The race to govern the last private frontier
Neurotech & Cognitive Liberty

The race to govern the last private frontier

12 min
How neurotechnology turned the mind into a policy frontier
Neurotech & Cognitive Liberty

How neurotechnology turned the mind into a policy frontier

14 min

Never miss a signal

Weekly intelligence, no noise

The Sovereign Intelligence Hub — Society OS

© 1989–2026 Society OS Pty Ltd. All rights reserved.