Protecting Health Data When Grandma’s Watch Knows Everything

Millions of seniors use wearable devices without realizing who actually owns their health data.

Millions of older adults are buying smartwatches to track their heart rates in 2026. But most don't realize consumer wearable data isn't protected by HIPAA.
Takeaways
Fitness trackers are not medical devices.
Health privacy laws ignore consumer apps.
Data brokers buy your daily habits.
You do not own your wearable data.
Turn off data sharing in settings.
You buy a smartwatch to keep an eye on your heart, but you might want to ask who else is watching it. I've noticed a major shift in the past couple of years. We used to think of fitness trackers as toys for marathon runners. Now they're everyday tools for older adults.

A recent survey shows that tech adoption among seniors is surging in 2026[1]. People over fifty are buying smartwatches, smart rings, and continuous glucose monitors[2]. They want to track their sleep. They want to monitor their blood pressure. And honestly, it makes perfect sense.
But there's a catch. The information these gadgets collect is deeply personal. And it's completely exposed.
The Appeal of Tracking
It's easy to see why families love this technology. A good smartwatch can tell you if your resting heart rate is suddenly spiking. Some devices even have fall detection. If an older adult slips in the kitchen, the watch notices the impact and automatically calls for help.

And the hardware is getting much more advanced. We aren't just talking about counting steps anymore. Modern wearables track sleep architecture, blood oxygen levels, and even irregular heart rhythms[3]. People are patching continuous glucose monitors to their arms to watch their blood sugar react to meals in real time.
That peace of mind is incredibly valuable for families. A daughter living three states away can pull up an app and see that her dad slept well and went for his morning walk. Technology helps older adults stay in their own homes longer. They feel safer knowing a device is quietly keeping watch on their daily routine.
So what's the problem?
The problem starts the moment that data leaves the watch and travels to the phone app.
The Privacy Gap
Here's the thing most people misunderstand. When you go to the doctor, a federal law called HIPAA locks down your medical file. Your doctor can't legally sell a list of your medications to a marketing company.

But your smartwatch company isn't a doctor. They're a consumer electronics business[4]. This means HIPAA doesn't apply to them at all[5].
Once your heart rate data or sleep schedule hits that company's app, it falls under their specific terms of service. I think we just assume the law protects us automatically. It doesn't.
Many major wearable manufacturers have incredibly weak privacy policies. A recent analysis found that 76 percent of major wearable companies scored as a high risk for transparency[5]. That means they hide exactly what they do with your data.
They often share your daily habits with third-party data brokers.
The True Cost of Free Apps
Why would a broker care about your grandmother's step count? Because health data is very profitable.

If an app knows an older adult is suddenly walking less and sleeping poorly, that information tells a story. It might indicate a new illness or a reaction to a new medication. That highly specific profile of a user's physical decline is gold to insurance companies. It's valuable to pharmaceutical advertisers who want to target ads for joint pain relief or sleep aids directly to that user's social media feed.
And they do it legally because the user agreed to the tiny print in the app store.
The risk goes beyond annoying targeted ads. Some lawmakers are starting to pay attention to the national security side of this issue. We're seeing new pushes for investigations into foreign-made wearables[6].
There are worries that overseas companies could collect the biometric data of millions of American seniors and store it on foreign servers.
But right now, the rules are mostly a patchwork of state laws[4]. Broad federal protections don't exist for consumer health gadgets. Laws like the California Consumer Privacy Act are some of the only real tools consumers have to fight back if their data is mishandled[3]. That leaves a huge portion of the country totally unprotected.
Taking Back Control
We shouldn't just throw our devices in the trash. The health benefits are real. We just have to get smarter about how we use them.
If you're setting up a watch for yourself or an older parent, you have to dig into the privacy settings. Turn off any options that mention sharing data with marketing partners. Tell the app to stop tracking location data unless it's absolutely necessary for an emergency feature. And stick to major brands that have faced public scrutiny, as they tend to have slightly better security habits than cheap knockoffs.
We need stronger federal privacy laws to catch up with this technology. Until then, we're on our own to protect our information. That's just the reality of wearing a computer on your wrist.
FAQs
Are smart rings treated differently than smartwatches?
Most consumer smart rings fall under the exact same weak privacy terms as wrist devices.
Does Medicare provide free fitness trackers?
Medicare Advantage plans sometimes offer free trackers as a wellness perk, but standard Medicare does not.
Can I delete my data from a fitness app?
Yes, most major apps let you delete your account data, though it usually requires navigating complex settings menus.
Are medical alert necklaces better for privacy?
Traditional emergency buttons collect far less biometric data than modern smartwatches.
Does Bluetooth sharing expose my health data?
Leaving your phone's Bluetooth connection open can expose your device to nearby snooping, so it is best to turn it off in crowded public areas.
Citations
AARP. (2026, July 20). Tech use and adoption keeps surging among older adults. AARP. https://www.aarp.org/research/topics/technology/info-2026/tech-use-and-adoption.html
Dietz, C., & Warburton, J. (2026, March 26). Steps, sleep, safety: Rethinking privacy for wearable health devices. Hastings Science & Technology Law Journal. https://repository.uclawsf.edu/hastings_science_technology_law_journal/
HosTalky. (2026, August 24). Understanding data privacy risks of wearable devices. HosTalky. https://www.hostalky.com/blog/data-privacy-risks-of-wearables
Scott, R. (2026, June 19). Chairman Rick Scott calls for investigation into CCP-linked wearable tech. U.S. Senate. https://www.rickscott.senate.gov/2026/6/chairman-rick-scott-calls-for-investigation-into-ccp-linked-wearable-tech
The Lyon Firm. (2026, February 27). Wearable device data privacy: Your legal rights & how to fight back. The Lyon Firm. https://www.thelyonfirm.com/blog/wearable-device-data-privacy-your-legal-rights/
Sourceshelp




