Wearable technology can improve care while creating new tensions around ownership, consent, and personal privacy. A watch, glucose sensor, smart ring, or home monitor may record the body continuously, send measurements to an app, create predictions in the cloud, and deliver selected results to a clinician. Each transfer creates a different relationship and a different form of control.

Asking who owns the data is understandable but incomplete. Ownership does not by itself explain who may access a record, correct an error, authorize a new use, receive a copy, or require deletion. A better framework separates these rights and assigns responsibility throughout the data lifecycle.

Device Data Is A Chain, Not A Single Record

A health device can generate raw sensor signals, calculated measurements, activity summaries, alerts, location or time metadata, and model-derived inferences. The user may see only a dashboard while the provider holds much more. If information enters a medical record, another copy may be governed and retained by the health system.

Control begins with a data map: what the device collects, what is calculated, where each element travels, who can retrieve it, and how long it remains. This exercise often reveals software analytics, cloud hosting, customer support, advertising tools, or research partners that are invisible from the screen. It also distinguishes data needed for the service from information collected because it may be commercially useful.

Legal Protection Depends On Context

People often assume that all health-related data receives the same protection. In the United States, the HIPAA Privacy Rule generally applies to covered health plans, many health care providers, clearinghouses, and their business associates.[1] A consumer app or device company may fall outside that relationship even when its data is intimate.

The route matters. Data sent by a clinician through a contracted platform may be subject to different obligations from the same type of reading entered directly into a consumer app. When a patient directs a covered provider to send information to an independent app, the provider’s HIPAA obligations do not automatically follow the data everywhere it goes.

Other rules may still apply. The U.S. Federal Trade Commission explains that its Health Breach Notification Rule covers certain vendors of personal health records and related entities that are not covered by HIPAA, requiring notification after breaches of unsecured identifiable health information.[2] Protection should nevertheless be clear in product design, not left for a user to infer from overlapping laws.

Consent Should Be Specific And Usable

A long privacy policy accepted during setup rarely produces meaningful control. People need a concise explanation of essential collection, optional features, recipients, retention, and consequences of declining. Choices should appear when they matter, such as before enabling precise location, sharing with a third party, or contributing identifiable data to research.

Consent should be granular enough to distinguish care from marketing and service operation from unrelated research. It should be as easy to withdraw an optional permission as to grant it. Withdrawal cannot always retrieve information already used in a completed analysis, but it can stop future collection and sharing. The interface should say exactly what will and will not happen.

Access And Correction Are Core Controls

People should be able to obtain their information in a practical, machine-readable form rather than only as screenshots. Access supports continuity of care, independent interpretation, migration to another service, and the ability to spot mistakes. The U.S. Department of Health and Human Services describes the right of individuals under HIPAA to inspect or obtain copies of protected health information maintained by covered entities, subject to defined limits.[3]

Correction is more complicated when a value is produced by a sensor or algorithm. The system may need to preserve the original reading for clinical integrity while attaching a correction, dispute, or context. Users should know whether a corrected profile changes prior alerts or model outputs. A device that influences treatment should provide a clear route for reporting malfunctions and clinically significant discrepancies.

Control Also Means Limiting Secondary Use

Device data can be valuable for research and product improvement, but beneficial purpose does not eliminate the need for boundaries. Data collected for heart monitoring should not quietly become a resource for unrelated advertising, employee evaluation, or insurance profiling. Aggregation and de-identification can reduce risk, although distinctive movement patterns and combinations of datasets may permit re-identification.

Organizations should collect the minimum data necessary, restrict each recipient to a stated purpose, and prohibit onward transfer that defeats the user’s choice. Contracts should cover subcontractors, model training, sale of the company, and closure of the service. Public transparency reports can describe categories of requests and sharing without exposing individuals.

The Organisation for Economic Co-operation and Development frames trustworthy data governance around the entire data lifecycle and the balance between openness, safeguards, and public benefit.[4] That lifecycle view prevents a narrow focus on the moment of collection.

Security Must Follow The Sensitivity Of The Data

Continuous health information can expose routines, location, sleep, pregnancy, disability, or a developing illness. Safeguards should include encryption in transit and storage, secure update mechanisms, tested authentication, role-based access, and logs that can reconstruct an incident. A device should remain safe when connectivity is lost and should not require unsupported software for essential functions.

Security also includes organizational preparation. Providers need a way to receive vulnerability reports, assess supplier risk, detect unusual access, and notify affected people promptly. Users should be told what happened, what information was involved, what protective steps are available, and what the company has changed. Vague reassurance does not restore control after a breach.

Deletion And Exit Need Honest Definitions

A delete button may remove an account without erasing backups, medical records, research datasets, or information another recipient already obtained. Some retention may be legally or clinically required. A trustworthy service describes these distinctions and gives a timetable for deletion or irreversible de-identification.

Exit also requires continuity. People should be able to export records before closing an account, disconnect integrations, and learn whether the device will continue functioning locally. When a company is acquired or discontinues a product, users should receive advance notice and a fresh choice before data is transferred to a new controller with materially different purposes.

A Patient-Centered Control Charter

A credible device program should make seven commitments:

  1. Clarity: Identify every important data type, inference, destination, and purpose.
  2. Necessity: Collect only what the feature or care pathway genuinely requires.
  3. Choice: Separate essential processing from optional research, personalization, or sharing.
  4. Access: Provide usable copies, explanations, and a route to correct or annotate errors.
  5. Security: Maintain safeguards, updates, incident response, and accountable suppliers.
  6. Boundaries: Limit secondary use and onward transfer through technical and contractual controls.
  7. Exit: Explain retention, deletion, portability, acquisition, and service closure in advance.

Control Should Travel With The Data

Health-device data can support earlier intervention and more continuous care, but its value depends on trust. People do not need exclusive possession of every clinical record. They do need meaningful authority over collection and reuse, reliable access, protection against unexpected consequences, and institutions that remain answerable for harm.

The strongest model treats control as a set of enforceable capabilities rather than a claim buried in terms of service. Wherever the data travels, purpose, security, transparency, and accountability should travel with it.

Control must remain coherent as information moves between devices and care systems. Patient privacy in connected care traces those exchanges, and meaningful consent in digital medicine explains what an understandable choice requires.

Sources

  1. U.S. Department of Health and Human Services, The HIPAA Privacy Rule.
  2. U.S. Federal Trade Commission, Complying With The Health Breach Notification Rule.
  3. U.S. Department of Health and Human Services, Individuals’ Right Under HIPAA To Access Their Health Information.
  4. Organisation for Economic Co-operation and Development, Data Governance.