AI Wearables and Health Data Privacy: What's Really Happening to Your Biometrics in 2026
Your Oura ring logged your heart rate variability at 2:14 AM last Tuesday. Your AI earbuds tracked your stress response during a difficult phone call. Your smartwatch flagged a possible atrial fibrillation event and quietly noted the timestamp.
None of that is covered by HIPAA. Not a word of it.
This is the central contradiction of the AI wearables boom: devices sophisticated enough to detect cardiac arrhythmias, predict illness onset, and monitor reproductive health exist in a legal gray zone so wide that the companies collecting your most intimate biological data can sell it, license it, or share it with third parties — and, in most states, aren't required to tell you they're doing it.
In January 2026, the FDA made that gray zone significantly wider. This piece examines how we got here, what it means for the 200 million Americans wearing biometric tracking devices, and what a soon-to-be-unveiled OpenAI hardware product could mean for the next chapter of health data privacy.
HIPAA — the Health Insurance Portability and Accountability Act — was written in 1996, when the internet was still a novelty and wearable health devices didn't exist. It covers health information collected by healthcare providers, insurers, and their business associates. It does not cover data collected by your Oura ring, Apple Watch, Garmin, Whoop, or Fitbit — because those companies are not healthcare providers.
This is not a gray area or a technicality. It is an explicit, deliberate gap in the law, and it has become the defining feature of the AI wearables industry.
According to a 2025 report from the Future of Privacy Forum, approximately 72% of health and wellness app developers are not subject to HIPAA at all. That number climbs higher when you factor in AI-native wearable devices, which often operate entirely outside the medical device regulatory framework as well.
The FDA’s January 2026 Deregulation: “Silicon Valley Speed”
On January 6, 2026, FDA Commissioner Marty Makary stepped onto the stage at the Consumer Electronics Show in Las Vegas and announced that the agency would ease its oversight of digital health products — specifically AI-enabled devices and wellness wearables.
The announcement followed through on Trump administration commitments to deregulate artificial intelligence. Makary framed it explicitly in investor terms, saying one of the FDA’s priorities is “fostering an environment that’s good for investors” and that regulation needs to move “at Silicon Valley speed.”
The FDA issued two updated guidance documents that day. The General Wellness: Policy for Low Risk Devices guidance clarified that “general wellness products,” including wearables that promote healthy lifestyle goals, are not subject to the Federal Food, Drug, and Cosmetic Act’s device regulations. A second guidance on Clinical Decision Support Software softened the agency’s approach to AI-enabled tools that help clinicians navigate diagnoses and treatment options.
The practical effect: blood pressure monitoring features on consumer wearables — the kind that previously earned WHOOP a warning letter from the FDA — now fall outside the agency’s enforcement priorities.
Critics noted what Makary did not say at CES: removing FDA oversight does not reduce the clinical risks of consumer-grade health sensors, and patients acting on inaccurate AI-generated health data have no meaningful recourse when the device generating those readings was never properly validated. As law firm Troutman Pepper observed in a February 2026 analysis: “The absence of FDA oversight does not make these technologies low risk.”
What the announcement accomplished, quietly, was removing one of the few external checkpoints between wearable hardware companies and the mass market — at the precise moment the market is accelerating fastest.
The HIPAA Gap: A 30-Year-Old Law in a Biometric World
HIPAA was enacted in 1996. The iPhone launched in 2007. The first Fitbit shipped in 2009. The Oura Ring’s second generation, which introduced continuous heart rate monitoring, came out in 2018.
None of the data these devices generate existed when Congress wrote the law governing health information privacy. And that gap — a structural gap, not an oversight — defines the legal landscape today.
HIPAA applies to “covered entities”: hospitals, insurers, healthcare providers, and their direct business partners. It does not apply to consumer technology companies. Your physician’s notes about your heart condition are protected. The heart rate data your $300 ring collected during your last anxiety attack is not.
“Unlike traditional medical records, data from wearables often falls outside the scope of HIPAA, which leaves consumers vulnerable,” wrote University of Cincinnati law student Katie Bunch in a March 2026 law review analysis.
The wearable market has grown from $20 billion in 2015 to over $109 billion in 2023, and 82% of U.S. residents now express concern about health data privacy outside clinical settings. But concern does not equal protection.
The Cassidy Bill: A Congressional Attempt to Close the Gap
On November 5, 2025, Senator Bill Cassidy (R-LA), chair of the Senate HELP Committee, introduced the Health Information Privacy Reform Act (S.B. 3097). It represents the most serious congressional attempt to modernize health privacy rules since HIPAA’s original passage.
The bill would require wearable and health app companies to disclose exactly how user data is used and give consumers a clear opt-out mechanism. Cassidy argued that step counts, heart-rate trends, and medication reminders “did not exist when HIPAA was written in 1996, leaving millions of Americans exposed to silent data harvesting.”
As of May 2026, the bill has not passed. The data remains unprotected at the federal level.
In the absence of federal action, state laws have partially filled the vacuum. Washington’s My Health My Data Act and Nevada’s Consumer Health Data Privacy Law are currently the most expansive state-level protections for consumer health data. OpenAI explicitly references both in its Health Privacy Notice, published on January 7, 2026 — one day after the FDA’s CES announcement. The timing was not accidental.The path from your wrist to an actuarial table is not always direct. There are three documented data channels, each with different legal frameworks and different levels of consumer disclosure.
Channel 1: Voluntary Wellness Programs
This is the disclosed channel. Employers and insurers offer premium discounts or cash incentives in exchange for fitness data. You opt in, you share your step count, you get a lower rate. The arrangement is disclosed, the consent is explicit, and it is legal under existing frameworks.
The problem is behavioral: once consumers normalize trading biometric data for financial rewards, the disclosed exchange obscures how the undisclosed ones work.
Channel 2: Data Broker Pipelines
Most wearable device privacy policies include language authorizing data sharing with “third-party partners” for “business purposes.” That language is broad enough to permit data sales to brokers who aggregate biometric data with other consumer data sets — location history, purchase records, demographic profiles — and sell the enriched profiles to insurers, employers, and other buyers.
Data brokers have cost American consumers more than $20 billion through breaches alone, per a February 2026 Congressional investigation triggered by The Markup. The figure covers identity theft from four major broker breaches — it does not account for the financial harm from data used lawfully to reprice insurance or deny coverage.
Channel 3: Embedded Third-Party Trackers
In August 2025, a class action lawsuit — Lomeli v. Whoop — was filed in the Northern District of California. The complaint alleges that Whoop embedded Segment, a third-party analytics tracker owned by Twilio, inside its fitness app. That tracker allegedly collected and transmitted sensitive health metrics — heart rate, blood oxygen, stress levels, and sleep patterns — without meaningful user consent.
Whoop has not been found liable, and the case is ongoing. But the mechanism it describes — a wellness device transmitting health data to a third party through an embedded code library — is an industry-standard software architecture. Segment’s tracking SDK is used by thousands of apps.
What Insurers Can Actually Do With It
A February 2025 study by reinsurance giant Munich Re and analytics firm Klarity, using data from the UK Biobank’s 500,000-participant dataset, found that smartwatch metrics — daily step counts, periods of inactivity, vigorous movement, average heart rates, sleep duration — provide statistically significant signals for mortality risk assessment. The study’s explicit purpose: modeling how wearable data could improve life insurance underwriting accuracy.
Auto insurance companies already do exactly this. Telematics devices monitor driving behavior in real time — speed, acceleration, braking — and translate that data into individualized pricing. Behavior-based insurance is now expanding to health, life, and disability coverage. The data infrastructure exists. The actuarial models are being validated. The only thing missing is federal law that would require disclosure or limit use.
The OpenAI Device: The Biggest Health Privacy Question of 2026
In May 2025, OpenAI acquired Jony Ive's hardware startup io for $6.5 billion. Ive, the legendary designer of the iPhone and MacBook Pro, was brought in to lead the design of OpenAI's first consumer hardware product.
What they're building has been described in fragments through leaks, court filings, and carefully worded executive statements. Reports describe it as screen-free and pocketable, contextually aware — meaning the device perceives its environment and decides when to engage the user rather than waiting to be summoned — and possibly earbuds, per TechCrunch reporting from January 2026.
The timeline has shifted. OpenAI Chief Global Affairs Officer Chris Lehane told Axios at Davos in January 2026 that the company was on track for a second-half 2026 unveiling. A subsequent court filing revised that: the device won't ship before February 2027.
Sam Altman has described the device as "more peaceful and calm than an iPhone" — a deliberate contrast to the attention-maximizing design philosophy that defined the smartphone era. Developer testing suggests the device may use ambient audio or environmental sensing to understand your context without you actively interacting with it.
OpenAI published its Health Privacy Notice on January 7, 2026 — the day after the FDA's CES announcement. The notice explicitly acknowledges that some collected data may qualify as "Consumer Health Data" under Washington's My Health My Data Act and Nevada's law. That is notable because most technology companies publishing privacy policies do not proactively invoke state-level health privacy frameworks unless their product is actively collecting health-relevant data.
If the OpenAI device includes ambient biometric sensing, it will arrive into a regulatory environment the FDA just cleared of meaningful oversight, in a legal framework HIPAA does not reach, at a moment when data brokers have established infrastructure to monetize exactly this kind of continuous biometric signal. The HIPAA gap is not a regulatory quirk. It is a profit center.
What Consumers Should Know and Do Right Now
The regulatory environment is broken. That is not hyperbole — it is the consensus of consumer advocates, legal scholars, and privacy researchers who have spent the past decade watching HIPAA age out of relevance while the wearable health market grew from a niche curiosity into a $109 billion global industry.
While federal legislation stalls, there are steps you can take to limit your exposure:
Read your app's privacy policy — specifically the data sharing and third-party sections. Look for language authorizing data sharing with "partners," "affiliates," or for "business purposes."
Opt out of wellness incentive programs unless the premium discount is significant and you fully understand what data is being shared and with whom.
Review your wearable's data export settings. Many platforms allow you to download your health data and delete it from their servers — a right that may have legal force in Washington and Nevada even if your home state doesn't have equivalent protection.
Treat your health data like your financial data. Assume it will be sold. Plan accordingly.
If you live in Washington or Nevada, the My Health My Data Act and Nevada's Consumer Health Data Privacy Law give you explicit rights to access, correct, and delete your health data held by technology companies. These are the only two states with comprehensive consumer health data protections as of May 2026.
The Larger Picture
The AI wearables industry is, at its core, a data industry that happens to sell fitness products. The devices are often loss-leaders or low-margin hardware designed to generate high-margin recurring data streams. Understanding that dynamic is the first step toward navigating it.
Biometric data is not like other personal data. Your email address can be changed. Your health metrics — your heart rate patterns, your sleep architecture, your stress responses, your reproductive cycles — cannot. Once this data exists in a broker's database, it exists permanently. There is no effective right to deletion that survives a complex chain of data broker transactions.
The combination of factors converging in 2026 — FDA deregulation, the Cassidy bill stalled in committee, a new wave of ambient AI hardware about to enter the market, and data broker infrastructure already in place to monetize continuous biometric signals — represents a structural shift in health privacy, not a temporary gap.
The devices on your wrist, in your ear, and soon in your pocket are not neutral. They are sensors in a surveillance economy. Knowing that doesn't mean you shouldn't use them. But it means you should use them with the same awareness you'd bring to any financial product: understanding who profits from your data, how, and at what eventual cost to you.
References
1. FDA Commissioner Marty Makary, remarks at Consumer Electronics Show, Las Vegas, January 6, 2026
2. FDA General Wellness: Policy for Low Risk Devices, updated guidance, January 2026.
3. FDA Clinical Decision Support Software, updated guidance, January 2026.
5. Munich Re and Klarity, smartwatch mortality risk assessment study, February 2025.
6. TechCrunch, reporting on OpenAI device form factor, January 2026.

