
Rosen.senate.gov
The Oura Ring on your finger is logging your body temperature as you sleep. The Garmin on your wrist is recording every GPS coordinate of your morning run. The Whoop band around your forearm is reading your heart rate at 2 a.m. That data is intimate, continuous — and for the roughly 40 percent of Americans who own a consumer wearable health device, almost entirely unprotected by federal law when law enforcement comes asking, according to EFF's July 2026 investigation.
That is the finding at the center of a sweeping investigation published July 15 by the Electronic Frontier Foundation, which reviewed the publicly available policies of ten of the most popular consumer wearable companies — Amazfit, Apple, Coros, Garmin, Google (which owns Fitbit), Hume, Oura, Polar, Suunto, and Whoop — then followed up with each company by email. The results were stark: most vendors publish no transparency reports on how often they hand data to law enforcement, virtually none offer end-to-end encryption for stored health data, and five companies did not respond to the EFF's questions at all.
Surveillance firm Penlink — whose clients include U.S. Immigration and Customs Enforcement — already markets fitness trackers and wearables as an overlooked investigative resource, specifically because they establish movement patterns and changes in heart rate. A Citizen Lab investigation published in April 2026 found that Penlink's Webloc system monitors hundreds of millions of people using data purchased from consumer apps and digital advertising networks.
Read more: Smartwatch Market Hits 37M Units in Q1: Fitness Wristbands Shrink as Galaxy Watch 9 Nears
Of the ten companies the EFF surveyed, only Apple and Google currently publish transparency reports showing how often government agencies request user data, of what type, and how the company responds.
Apple, Google, and Whoop all publicly commit to notifying users about law enforcement requests wherever legally permissible. Oura joined that group, but only after updating its privacy policy in June 2026 — a change the EFF noted may have been prompted by persistent questions from journalist Zack Whittaker. Oura said in an email to the EFF that it is "actively evaluating ways to provide greater visibility" into how it handles requests, "like through a transparency report."
Suunto told the EFF it "continuously evaluates" its transparency practices and may eventually publish such a report. That leaves Garmin, Amazfit, Coros, Hume, and Polar with no publicly stated notification policy and no response to EFF inquiries.
Transparency reports are not ceremonial. Without one, a wearable user has no way of knowing whether their device maker received a government request last month, last year, or ever — and no way of knowing whether they were told. For companies holding continuous biometric records of millions of people's sleep, menstrual cycles, stress levels, and daily movements, that silence is not a minor omission.
End-to-end encryption — E2EE — is the specific architectural choice that determines whether a government subpoena reaches your health data.
When a wearable syncs to the cloud, it typically uses Bluetooth to send data to a companion app on your phone, which then encrypts that data in transit (using TLS) and sends it to the company's servers, where it is stored encrypted at rest. Both steps sound protective. Neither is E2EE. The critical distinction is key custody: in the industry-standard model, the company holds the decryption keys. That means the company can read your data — and when law enforcement serves a valid subpoena, so can they.
End-to-end encryption works differently: the decryption keys live only on the user's devices. The company stores only ciphertext it cannot read. A subpoena returns nothing useful because the company genuinely cannot produce readable data.
Apple is the only major wearable maker that implements this for health data — specifically, data stored in the Apple Health app, which is end-to-end encrypted by default and requires two-factor authentication. Every other major wearable platform — Garmin, Oura, Whoop, Fitbit/Google, and the rest — stores health data using the company-readable industry standard.
This creates a structural condition, not just a risk: any company without E2EE can be compelled by legal process to produce fully readable health data. No backdoor required. No court battle over decryption. Just a subpoena and a response.
There are real trade-offs to E2EE for wearables. Health AI features — sleep analysis, stress inference, predictive wellness scores — typically require server-side computation, which requires readable data. E2EE would push that computation onto the device itself, constraining what is technically possible. The EFF acknowledged this honestly while arguing that users should at least have the option to choose privacy over AI features.
Partial alternatives exist. Some Garmin and Polar models can operate without any cloud sync. Apple Watch can be configured to disable iCloud sharing in Apple Health, keeping data only on the phone. Both options require users to manually seek out settings that most buyers will never find.
HIPAA — the Health Insurance Portability and Accountability Act of 1996 — was written to protect medical records held by healthcare providers, insurers, and their business associates. Consumer wearable companies are none of those things, and the law's drafters in 1996 could not have anticipated devices that did not exist yet.
The practical consequences of that exclusion are substantial. There is no federal requirement for wearable companies to cap how long they retain user data. There is no mandate to obtain specific consent before sharing data with third parties. There is no obligation to notify users if their data is sold in a corporate acquisition. And there is no special legal protection against government data requests beyond the ordinary legal process available for any third-party records.
Under the Electronic Communications Privacy Act and the third-party doctrine established by the Supreme Court in Smith v. Maryland (1979), data that users voluntarily share with a third party loses Fourth Amendment protection. The Supreme Court's Carpenter v. United States ruling (2018) created a narrow exception for cell-site location information but did not broadly overturn the doctrine. Consumer wearable health data fits squarely within the traditional third-party framework.
Several wearable makers already share or sell data with third parties for marketing, to inform insurance rates, or to train AI models — all without breaching any federal statute, as the EFF investigation documents. The FTC's amended Health Breach Notification Rule, effective July 29, 2024, now applies to consumer health apps outside HIPAA and requires notification for certain breaches — but it does not provide the deeper privacy and data-use protections that HIPAA offers covered entities.
One company in the EFF survey carries an additional layer of legal exposure. Amazfit, manufactured by Zepp Health Corporation, traces its operational origins to Huami, a spinoff of Chinese electronics giant Xiaomi. Under China's National Intelligence Law (2017), all organizations and citizens must support, assist, and cooperate with national intelligence work — an obligation that applies regardless of where a company is incorporated or where its data is stored. Amazfit's own privacy documentation explicitly acknowledges that national security requests can result in disclosure of user data, as confirmed by the Mozilla Foundation's Privacy Not Included review. Buyers of Amazfit devices should treat that legal obligation as a fixed condition, not a variable to weigh against price or features.
Wearable health data has appeared in criminal investigations and civil lawsuits. Step counts and heart-rate readings have been used to dispute alibis and establish timelines — in at least one documented Pennsylvania case, a Fitbit's record directly contradicted a suspect's account of where they were and what they were doing when a crime occurred. Fitbit data has also been used in civil personal injury litigation (Bartis v. Biomet) to challenge plaintiffs' accounts of how much their activity declined after an accident.
The National Institute of Justice has published research specifically on the forensic value of wearable fitness app data, noting that Garmin Connect records detailed activity information and location data that can be recovered in investigations. The same data that gives wearers a continuous picture of their own health gives investigators an equally continuous picture of their movements and physiological state.
Read more: Flock Safety Kills Screaming Detector After EFF Pressure, Cameras Still Listen
The EFF investigation arrived against a policy backdrop moving in two directions at once — and neither is toward more protection for consumers.
On January 6, 2026, the FDA updated its General Wellness Policy, expanding the category of wearable devices classified as "general wellness" products — a designation that exempts devices from FDA regulatory review. The change means more devices, collecting increasingly intimate physiological data, will operate without FDA oversight.
At the same time, HHS Secretary Robert F. Kennedy Jr. has stated his goal of having every American wear a health wearable within four years, describing it as one of the largest advertising campaigns in HHS history, according to a Cato Institute analysis from March 2026. The federal government is separately funding the ARPA-H Delphi program to develop biosensors capable of detecting cytokines and hormones — markers of pregnancy, immune response, stress, and drug metabolism — while the regulatory framework governing data from those same devices is being weakened, not strengthened.
This combination is not a static gap. It is a gap that federal policy is actively widening. More Americans wearing more devices generating more intimate data, with no additional federal privacy protection and a Congress that has not yet acted.
Two federal bills would meaningfully address the HIPAA exclusion. Neither has moved to a floor vote.
The bipartisan Smartwatch Data Act — introduced by Sens. Jacky Rosen (D-Nev.) and Bill Cassidy (R-La.) — would require consumer consent before wearable health data can be sold or shared. Cassidy separately introduced the Health Information Privacy Reform Act in November 2025, which would extend HIPAA-like protections to wearable devices by directing HHS and the FTC to draft corresponding regulations. The American Bar Association reviewed the bill in early 2026; legal analysts described it as the most significant proposed expansion of federal health privacy law since HIPAA itself. Neither bill has advanced.
State-level coverage exists but is uneven. Illinois's Biometric Information Privacy Act and California's Consumer Privacy Act offer the most substantial protections and have produced real enforcement actions and settlements. Washington's My Health My Data Act, effective in 2024, extended to data "collected, derived, or inferred" — including wearable metrics. Indiana and Kentucky activated new comprehensive privacy acts in 2026. These protections apply only to residents of their respective states, and enforcement varies, as the UC Law Review analysis documents.
The EFF's report ends with two asks directed at companies: publish transparency reports, and offer end-to-end encryption or robust local-only storage options as user choices.
For readers who want to act before those changes materialize, the options are narrower. Apple Watch users who store health data exclusively in Apple Health — and do not share it with third-party apps like Strava or pair data with other wearables — benefit from genuine end-to-end encryption. Disabling iCloud sharing in Apple Health limits data to the device and phone only. For every other major wearable, the underlying architecture means that a legally valid subpoena produces readable data.
Users who want to push companies toward change can file feature requests through the dedicated portals that Garmin, Polar, Suunto, and Whoop maintain, or reach Amazfit and Oura through their general contact pages. The mechanism is the same one that prompted Oura's June 2026 policy update: sustained, specific user demand.
Until federal law fills the HIPAA gap that was designed in 1996 for a world without wearables, the most intimate details of your sleep, your heart rate, and your daily movements remain just a subpoena away from disclosure — and most of the companies holding that data still will not tell you when someone asks.
No. HIPAA applies to "covered entities" — healthcare providers, health plans, and healthcare clearinghouses, plus the vendors who handle protected health information on their behalf. Consumer wearable companies are not covered entities. Unless you are using a device that has been explicitly integrated into a clinical care program under a Business Associate Agreement with a covered entity, your wearable data falls entirely outside HIPAA. That means no federal cap on data retention, no mandatory consent before data sharing with third parties, and no special legal obstacle to a government subpoena.
In most cases, law enforcement can obtain wearable health data stored with a third-party company using a subpoena — a lower legal threshold than a warrant. Under the third-party doctrine established by the Supreme Court in Smith v. Maryland (1979), data voluntarily shared with a company generally lacks full Fourth Amendment protection. The Carpenter v. United States ruling (2018) created a limited exception for comprehensive cell-site location records but has not been broadly extended to health data. Because no major wearable maker except Apple uses end-to-end encryption, a subpoena directed at the company returns fully readable heart rate, sleep, GPS, and activity data.
Apple Watch, when used exclusively with Apple Health (without syncing data to third-party apps), is the only major consumer wearable that implements end-to-end encryption for stored health data. Apple also publishes a transparency report disclosing government data requests and commits to notifying users when legally permitted. That E2EE protection ends the moment health data is shared with a third-party app, paired with another wearable, or synced outside Apple Health. Every other major wearable — Garmin, Oura, Whoop, Fitbit/Google, and others — stores data using company-readable encryption, meaning the company can read it and law enforcement can compel it, as the EFF investigation confirms.
Amazfit is manufactured by Zepp Health Corporation, which traces its operational origins to Huami, a spinoff of Xiaomi. China's National Intelligence Law (2017), Article 7, legally requires all organizations and citizens to support, assist, and cooperate with national intelligence work. That obligation applies regardless of where a company is incorporated, where its servers are located, or what its stated privacy policy says. Amazfit's own documentation acknowledges that national security requests can result in disclosure of personal information, as noted in the Mozilla Foundation's Privacy Not Included review. Zepp Health's website privacy policy explicitly states it does not cover data collected by the company's actual devices and apps. No independent security audit of Amazfit's data transmission practices has been publicly released.
