Smartwatch Health History and Who Really Owns It

Smartwatch Health History. That smartwatch you have? It knows you better than your own Dr. It has your every heartbeat, step and sleep pattern recorded. Who really owns it? Good question. The answer may be surprising and could change your thinking about that smartwatch.

What Your Smartwatch is Collecting

Take a look at what it is doing for you here. (1)

  • Heart rate and heart rhythm (ECG)
  • Sleep patterns and quality
  • Blood oxygen levels
  • Physical activity and location
  • Stress indicators
  • Calories and metabolic data (calorie burn number)
  • hormone and glucose levels coming soon

That’s your personal data generated every day you wear the watch.

Nola’s Note–Curious minds wanted to know how accurate that calorie burn number was. It was found that the smartwatch estimates can vary by 20 to 40 percent. A 2025 University of Mississippi study reviewed 56 research studies and found smartwatch calorie burn estimates had a nearly 28 percent error rate. (4)

So Where Does That Data Go?

First of all, it doesn’t stay with you and you don’t control it. How? When you agreed to the “terms of service.” Did you read it? The technology companies fall outside of the protection of your health history. You use the watch, they keep the information and can sell it to anybody. (See table below.)

Why? Because the Health Insurance Portability and Accountability Act (HIPAA) was signed into law in 1996. No Smartwatches then and the Internet was fairly new, too. It means no one saw into the future.

Therefore, the law does not include the tech companies that collect health history data through wearable devices. Currently, Congress is aware of the need. There are two bills that have been introduced. One has bi-partisan support and is named The SMARTWATCH Data Act. The second one was introduced in November 2025 and is named the Health Information Privacy Reform Act. Neither has passed.

Top Brands of Smartwatches with Health History Options

Here is a table that was sourced from Claude.ai. It presents three different columns with, Brand, Privacy Level and Data Ownership and Portability as I asked. It gives the meaning of High Privacy and Lower Privacy at the bottom.

Here is how that looks for the top brands below.

CompanyPrivacy LevelData Ownership & Portability
AppleHighYou own it. Data is encrypted on your device. Easy “Health PDF” exports for doctors.
WithingsHighMedical focus. Designed for clinical sharing. Strict European privacy (GDPR) rules.
GarminMedium-HighYou control it. Very transparent. Easy to download your raw data or sync with doctors.
Fitbit/GoogleMediumGoogle manages it. You can export it, but it’s part of the broader Google data ecosystem.
SamsungMediumEcosystem-heavy. Easy to show a doctor, but they use “anonymized” data for their own AI research.
AmazfitLowerCompany-centric. Harder to get clean reports for doctors; privacy policies are more “murky.”
  • High Privacy. You are the boss. The company is just a locked filing cabinet for your records. You have the only key.
  • Lower Privacy. You get to see your data, but the company is also looking over your shoulder and using your “trends” to build their own products or sell to “partners.”

What Does HIPAA Cover?

It does three things well.

  • Protects your medical records and your health information.
  • Doctors, insurance companies and hospitals have to keep your data private. (No sharing without permission.)
  • You have the right to see and control your own medical records.

What Does HIPAA Not Cover?

Let’s think of what they don’t cover as a swamp with sinkholes. You have the swamp represented as MD2 (Modern Digital Data). It has two types. The Yes-Islands and the No-Sinkholes.

Smartwatch Health History and Who Owns It-the swamp of Modern Digital Data (MD2).

The Yes-Islands are small places of solid islands of HIPAA protection. The No-Sinkholes are all the sinkholes that are the unregulated apps located in MD2’s world. They look solid with pretty icons and helpful tools in this world. But, they show as illusions and have no bottom to the sinkhole.

The Result of the No-Sinkhole Choice

Where do you land, then? Once your steps have gone into the No-Sinkhole, you drop straight through the swamp into the Dark Web. You may surface, but your own Health History lives forever and is accessed for a price by anyone. In these waters, your record is a high-value target. It is worth more than a stolen credit card.

The Dark Web values it up to $250.00 per record. (3) The No-Sinkhole also includes the following:

  • Consumer Apps and Wearables. Purchase a smartwatch or download a fitness app directly. Its data is not protected by HIPAA. These are your “non-covered entities” and are No-Sinkholes.
  • Employment and Education. (The Muck) If you are sick and give your boss a doctor’s note for sick leave, that’s No-Sinkholes. It falls under employment law, not HIPAA. Similarly, your school records live in the FERPA Muck (Family Educational Rights and Privacy Act). (5) These aren’t medical Yes-Islands but they are No-Sinkholes.
  • Data brokers can do Multi-Sale Cycles with your information. An insurance researcher, a marketing firm and even a “Shadow Record” can be repackaged from your information on the Dark Web.

The information stream that started the swamp never stops. It is smart because it watches your habits or searches history and creates an Inferred Medical Diagnosis for you. An educated guess which creates that evolving picture and it belongs in No-Sinkholes territory.

Survival Guide in the Modern Digital Data (MD2) World

The Safe Zones (The Yes-Islands). You want to keep yourself and your Health history safe. This is where the HIPAA has full protection and safety for you. Doctors and hospitals are able to look out for you and your Health history. This is the shield of protection.

The HIPAA Illusions (The No-Sinkholes) Maybe you have run across these apps on your computer. What they have is a Privacy Policy (you must read this!) that gives them your permission to do what they want to do. They are Silent because they don’t have to tell you what they won’t do. HIPAA doesn’t apply and therefore they are silent and sell your data on the Dark Web.

A white cross symbolizes health, but is actually a trap door to the Dark Web for the information.

Like a Halloween Disguise, they dress up their site with medical-type symbols for you to assume you are safe, give you a trap door to go through and continue your usage. The end result is that your information now lives forever in the Dark Web from this No-Sinkhole.

The FERPA Muck (Ugh!). School records are a middle-ground, because health notes made by a nurse are treated differently because a doctor is not present. (Individual state requirements for nurses vary on the K-12 levels.) (2) A No-Sinkhole situation. (5)

The Unprotected No-Sinkholes. (Immediate data drop into the Dark Web). Three things that help you choose confidently when checking out a site:

The swirl of Health history on the Dark Web.
  • Does the app have the HIPAA Seal? Check the “Legal ” Section. If it does not state and comply with HIPAA, it’s a No-Sinkhole wearing a medical Halloween Disguise.
  • Does it list Marketing Leaks? Look for “Third-Party Sharing” or “Marketing Partners” in the Privacy Policy. Also, there is not a “No-Sale” guarantee. They can share your “anonymized” data and you are on a “thin ice” situation of Dark Web.
  • Does it have an “Undo” button? You cannot permanently “pull your data back” once it’s been sold to a broker. It swirls forever in the whirlpool.

The Multi-Sale Cycle. Brokers deal in Auctions. Each Health History goes to the highest bidder. The bounty for the broker, $250.00 per item. (3) Remember, it can be sold numerous times.

The AI Shadow (the Inferred Diagnoses). The swamp feeds other information that applies to the Health History and “gossips” about an Inferred Diagnsis for that specific Health History. It is an educated guess with the additional information. It has value once again.

The Final Survival Rule (The “Free” Rule)

If the app is Free, Your Data is the Fee. If you find a health app that is free and it is not from your regular doctor’s office, the company makes its money selling your Health history. (3) It is a No-Sinkhole site.

The Exception. You know the “My Chart” that comes from your Doctor? It’s free because it is part of the covered medical service you pay for. It is a Yes-Island.

Your Final Step

The information stream that started the swamp never stops. You can be diligent and check the Privacy Policy, look for the shield of protection and navigate the MD2 with confidence. You won’t fall into the Dark Web and it can benefit your computer world.

References

(1) Compliancy Group. (2024, May 15). FERPA and HIPAA: What is the difference? compliancy-group.cCompliancy Group. (2024, May 15). FERPA and HIPAA: What is the difference? compliancy-group.com–

(2) Compliancy Group. (2024, May 15). FERPA and HIPAA: What is the difference? compliancy-group.com

(3) Electronic Privacy Information Center. (2024). A health privacy check-up: How modern business practices leave your data ripe for sale. epic.org

(4)

(5) U.S. Department of Education. (2024). What is FERPA? Protecting student privacy. ed.gov——U.S. Department of Education, Student Privacy Policy Office. (n.d.). What is FERPA? Protecting student privacy. studentprivacy.ed.gov. https://studentprivacy.ed.gov/faq/what-ferpa

Disclaimer. The information in this article is for educational purposes only and is not intended as medical advice. Always consult your healthcare provider before making decisions based on smartwatch health data.

Thank you for visiting Nola’s Global Skies!
Curiosity brought you here and there is always more to discover. Whether you are exploring health, travel, beauty, or building something new for yourself, this community grows with you. When you are ready to connect, Contact Us and let’s find out what is possible together. More is waiting inside when you are ready.