Who can see your health data when AI touches it?
Who can see your health data when AI touches it depends on who is holding it. The federal health privacy rule covers exactly three kinds of holder: a health plan, a clearinghouse, and a provider who bills electronically. A watch company is none of them, and a different agency’s rule picks up the gap.
A watch on a wrist records a heartbeat. The reading goes to a company. The same reading goes to a doctor.
One copy is protected by federal health privacy law. The other is not. Nothing about the heartbeat changed.
That is the whole subject, and almost every explanation of it starts in the wrong place. People ask how sensitive the information is. The law asks who is holding it.
Contents
Who can see your health data when AI touches it?#
It turns on the holder, and the list of holders is short.
The Health Insurance Portability and Accountability Act (HIPAA) is the federal health privacy law people mean when they say their information is protected. Its rules define who they bind, and the definition is not a description of sensitive data. It is a list of organisations.
Artificial Intelligence (AI) does not change that test. A model reading your record is a tool used by whoever holds the record. The question stays the same.
So when a system touches your information, the useful question is never how clever the system is. It is whose hands the information was in when the system reached it.
Which rights you hold at all, and which have actually started, is the frame this page sits inside.
Answer that and the rest follows.
Is data from a smartwatch covered by HIPAA?#
Usually not, and the regulation says so with unusual plainness.
The definition sits in title 45 of the Code, the standing book of federal rules. A covered entity means a health plan, a health care clearinghouse, and a health care provider who transmits health information in electronic form in connection with a covered transaction.
Three things. That is the list.
A watch manufacturer is none of them. A step counter is none of them. A sleep app you downloaded on a Sunday is none of them.
There is a second door in, and it is narrower than it sounds. A company can be pulled in as a business associate, but the definition binds it only where it handles protected information on behalf of one of those three. The relationship is the trigger, not the data.
So an app with no connection to your doctor or your plan sits outside, whatever it knows about you.
Think of it like a safe deposit box. The bank’s duties attach because the bank is a bank. Not because your ring is precious. Leave the same ring with a neighbour and the ring is unchanged. The duties are gone.
That is the shape of the thing. It surprises people. It is the opposite of how privacy feels.
Feelings run on sensitivity. Law runs on custody.
Notice what follows from that. A reading you would never say out loud can sit in the least protected hands on the list. A routine number in your doctor’s chart carries the full weight of the rule. Neither position was chosen for you and neither is obvious from where you sit.
There is a practical version of this. Before you worry about what a device knows, find out where it sends things. The destination decides the law. The sensor never does.
When does wearable data become a medical record?#
The moment a covered holder takes it in.
If your doctor pulls readings from a device into their system, those readings sit in a record held by a covered entity. The rule now applies to them there. Nothing about the numbers changed and everything about their status did.
That produces a result worth holding onto. The same information can exist in two places under two regimes at once.
On the manufacturer’s servers it may be outside the rule. In your provider’s chart it is inside. Deleting one copy does nothing to the other.
Families discover this at awkward moments. A daughter asks a monitoring company to erase her mother’s data and is told, correctly, that the clinic’s copy is a separate matter. Both answers are true and neither is the whole picture.
So track the copies, not the device. Ask who has received the readings, not only who collected them.
There is a version of this that catches careful people. A monitoring service sold through a clinic feels like part of the clinic. It may not be. The clinic recommended it. A separate company runs it.
Ask who sends the bill. Ask whose name is on the account. Those two questions can find the holder faster than reading a privacy notice does.
And ask it again after a year. Companies get bought. Contracts get reassigned. The holder on the day you signed may not be the holder today, and nothing will write to tell you.
None of this is paranoid. It is the same care anyone takes with a bank or a landlord. The information happens to be a heartbeat rather than money, and the habits transfer intact.
Can health app data be sold or used to train AI?#
At the federal level, less stands in the way than most people assume.
The health privacy rule does not reach an app that is neither a covered entity nor a business associate. That is not a loophole somebody found. It is the boundary the definition draws.
A second rule does reach many of those apps, and it is worth knowing precisely because most coverage I have read stops one step earlier. The Federal Trade Commission (FTC) wrote the Health Breach Notification Rule, and its own definitions begin by carving out anyone already covered by the health privacy rule.
Read that carve-out twice. A vendor of personal health records means an entity other than a covered entity, or a business associate of one, that offers or maintains a personal health record.
The second rule is defined by exclusion from the first. That is how you know the two were built to interlock.
Now the limit, and it matters. What that rule requires is notification after a breach. It obliges somebody to tell you when your information has been exposed. It is not a general ban on collecting, using or selling it.
So the federal floor is lower than the seriousness of the subject suggests.
Real limits are appearing elsewhere. In state consumer health data laws. In whatever you agreed to on the day you installed the thing.
That second one deserves more respect than it gets. The terms you accepted are doing more work here than any federal rule. Nobody reads them. Everybody is bound by them.
Which is a familiar shape. A protection exists, and it lands on the people best placed to use it rather than the people who need it most.
A reader who wants a real hold on this has one reliable move. Find out what was agreed, in writing, and keep it.
How does consent work for monitoring in a care setting?#
Differently, because the holder is usually a covered one.
A monitoring programme run through a clinic or a plan sits inside the health privacy rule from the start. The information goes into a record held by an organisation the rule already binds. That is a stronger position than a consumer app, and it is worth knowing which one you are in.
What the rule does not settle is the practical question families actually face. Who agreed, on whose behalf, and to what.
That question is answered by state law about capacity and representatives rather than by federal privacy law, and it varies. This page will not pretend otherwise.
The habit that survives the variation is simple. Get the arrangement in writing, name the person who agreed, and keep a copy with the date on it.
Like a spare key given to a neighbour, the arrangement is only as clear as the conversation that set it up. Nobody remembers the terms a year later, and paper does.
There is a second thing worth settling early, and it is easier to settle before it matters. Who receives the alerts.
A monitoring service that notices a fall has to tell somebody. That somebody can be configured once, at installation, by whoever happened to be in the room. Months later nobody can remember what was chosen.
Ask for that list. Ask to see it rather than to be told about it. Then check that the people on it still hold the phone numbers written beside them.
It is a small piece of housekeeping and it is the piece that decides whether an alert reaches a person or an old voicemail box. The privacy question and the safety question turn out to share an answer here, because both are settled by knowing exactly who is on the other end.
Continuous sensing in a home is new, and it is cheap now in a way it never was. Sensors got cheap enough to watch a whole battlefield from the air. The same drop in price put them in a living room. Consent is how a household keeps a say in it.
None of that requires reading a regulation. It requires asking who, and writing the answer down.
What should you ask before you sign?#
Four questions, before the signature rather than after.
- Who holds it.
- Who sees it.
- Can it be sold.
- Can you delete it.
The first is the one this whole page turns on, and it may not be the brand on the box. A device sold under one name can be operated by another company, and the operator is the holder.
The second reaches further than people expect. Partners, contractors and analytics providers can all sit behind a single friendly interface.
The third has a follow-up that is usually the real answer. Ask whether the position changes if the company is bought, because a promise made by one owner is worth what the next owner decides it is worth.
The fourth is where a good service separates itself from a careless one. Deletion you can verify beats deletion you were assured of.
If the person selling the service cannot answer all four from the document in front of them, that is an answer too.
Write down what you were told and the day you were told it. Names, not job titles. A note beats a memory in any conversation that turns difficult later.
A parent holding that note is in a far better position than one relying on a conversation nobody wrote down.
