Step Counts, Sleep Scores, and Denied Claims: The Insurance Industry's Quiet Appetite for Your Fitness Data
Photo: Mantelmoewe, CC BY-SA 4.0, via Wikimedia Commons
Every morning, tens of millions of Americans clip on a fitness band, tap a smartwatch, or slip a continuous-monitoring ring onto their finger. The ritual feels personal — a private conversation between a person and their own body. What most wearers do not fully appreciate is that a third party is often listening in, and that listener may one day have a direct say in whether a health insurance application is approved, a premium is adjusted upward, or a claim is flagged for additional scrutiny.
The intersection of wearable fitness technology and the insurance industry has quietly matured into one of the more consequential privacy frontiers in American consumer life. And the legal architecture designed to protect individuals has not kept pace.
How the Data Leaves the Device
When a user activates a fitness tracker and agrees to the accompanying app's terms of service, they typically grant the manufacturer permission to collect, store, and — in many cases — share granular health data with affiliated partners. These partners can include wellness platforms, pharmaceutical companies, employers offering incentive programs, and, critically, data brokers who aggregate health signals across millions of users and package them for resale.
The data points involved are not trivial. Modern wearables capture resting heart rate, heart rate variability, blood oxygen saturation, sleep duration and quality scores, menstrual cycle patterns, stress indicators derived from skin conductance, and daily step counts measured with considerable precision. Individually, each metric may seem benign. Aggregated over months or years, they compose a detailed physiological portrait — one that actuaries and underwriters find enormously valuable.
Insurers have historically relied on self-reported health questionnaires and physician records to assess risk. Passively collected biometric data offers something far more attractive from an underwriting perspective: continuous, behavioral, and largely unfiltered observation of how a person actually lives.
The Incentive Programs That Open the Door
The entry point for many consumers is not a shadowy data sale they never knew about. It is a wellness incentive program they voluntarily joined.
Several major U.S. health insurers and employer-sponsored benefit platforms have, in recent years, offered premium discounts, gift cards, or reduced deductibles in exchange for wearable data sharing. Programs marketed under names emphasizing vitality, wellness, or activity rewards invite policyholders to connect their fitness devices directly to insurer-affiliated platforms. The value proposition is straightforward: share your steps, lower your costs.
What the fine print frequently omits is the downstream life of that data once it enters the insurer's ecosystem. In documented cases, data shared under wellness program agreements has been retained beyond the program's term, transferred to affiliated subsidiaries, or sold to third-party analytics firms whose client lists are not publicly disclosed.
The individual who joined a rewards program to earn a discount on their monthly premium may have inadvertently created a longitudinal health record accessible to parties well beyond the original transaction.
Legal Gray Areas and the Limits of HIPAA
Many consumers assume that the Health Insurance Portability and Accountability Act — HIPAA — shields their fitness data from commercial exploitation. That assumption is materially incomplete.
HIPAA governs the handling of protected health information by covered entities: hospitals, clinics, insurers acting in a clinical capacity, and their direct business associates. Fitness tracker manufacturers and the wellness apps that aggregate wearable data typically do not qualify as HIPAA-covered entities. The data generated by a consumer wearable and transmitted to a commercial app exists largely outside HIPAA's protective perimeter.
State-level protections vary considerably. California's Consumer Privacy Act grants residents certain rights to know what data is collected and to request deletion, though enforcement has been inconsistent and exceptions are numerous. Most other states offer far weaker statutory protections. At the federal level, proposed legislation specifically addressing health data generated outside clinical settings has repeatedly stalled.
The Federal Trade Commission has taken enforcement actions against companies that misrepresented their data practices to consumers, but the agency's authority to proactively restrict the commercial use of health data is constrained. The result is a regulatory environment in which the commercial exploitation of biometric data proceeds largely on terms set by the industry itself.
What Researchers and Advocates Have Found
Academic researchers and consumer advocacy organizations have documented a range of outcomes that illustrate the practical stakes. In one pattern identified by health policy researchers, individuals participating in employer wellness programs saw their risk classifications adjusted following the introduction of wearable data into the insurer's actuarial models — without any direct notification that the recalibration had occurred.
In another documented scenario, life insurance applicants discovered during the underwriting process that insurers had accessed third-party data profiles containing inferences derived from fitness and wellness app activity. The applicants had not consented to this specific use; the data had been purchased through broker intermediaries.
Advocates at organizations focused on digital rights have raised particular concern about the inferential power of aggregated wearable data. A sleep score alone may appear innocuous. Combined with irregular heart rate patterns, elevated resting pulse trends, and declining step counts over a twelve-month period, those signals can yield actuarial inferences about chronic disease risk, mental health status, or substance use — none of which the individual disclosed, and some of which may be factually incorrect.
What Consumers Should Consider Before Syncing
The practical calculus for fitness tracker users involves tradeoffs that are rarely spelled out at the point of purchase or app installation. Several considerations are worth examining carefully.
Review data-sharing settings before connecting any device to an insurer or employer platform. Many apps offer tiered sharing options. Limiting the scope of data transmitted — choosing to share only aggregate step counts rather than full biometric streams, for example — reduces exposure without necessarily forfeiting all program benefits.
Read the terms of service for wellness incentive programs with specific attention to data retention and third-party sharing clauses. Language permitting data sharing with "affiliated partners" or "service providers" without naming those parties specifically is a signal that the data's ultimate destination is not fully disclosed.
Treat fitness app accounts with the same credential discipline applied to financial accounts. Strong, unique passwords and two-factor authentication reduce the risk that a breach of the app's systems exposes years of biometric history to criminal actors, in addition to commercial ones.
Investigate whether your state provides rights to request deletion of data held by data brokers. Several states now maintain opt-out registries or require brokers to honor deletion requests. The process is rarely effortless, but it can limit the persistence of historical health profiles in commercial databases.
Consider whether the financial benefit of a wellness program is proportionate to the data it requires. For many consumers, the premium discount offered is modest relative to the breadth of information being exchanged.
The Broader Implication
The fitness tracker was designed to empower its wearer — to make health data visible and actionable for the individual generating it. The architecture that has grown around these devices increasingly serves a different set of interests. The same data stream intended to motivate a morning run can, through a series of commercially routine transactions, become an input in a decision about whether someone pays more for health coverage or qualifies for life insurance at a standard rate.
That outcome is not inevitable. But it becomes more likely with every sync that happens without scrutiny, every terms-of-service agreement accepted without reading, and every incentive program joined without understanding what the incentive actually costs.