Let's begin with a fundamental question: What is a wearable device? The answer is, in typical legal fashion, “It depends.” The reason it depends is if it is a device that is U.S. Food and Drug Administration (FDA) approved, then the Food, Drug, and Cosmetic Act (FD&C Act) applies. The FD&C Act § 201(h) includes an “instrument, apparatus, implement, machine, contrivance, implant, in vitro reagent, or other similar or elated article, including any component, part, or accessory, which is … intended for use in the diagnosis of disease or other conditions, or in the cure, mitigation, treatment, or prevention of disease, in man … or intended to affect the structure of any function of the body of man… [and] does not include software functions excluded pursuant to FD&C Act § 520(o).”
Within FDA devices, there are various categories including general wellness products (GWPs). The FDA assigns levels of risk associated with GWPs. An illustrative example highlighted by the FDA in its recent publication, “General Wellness: Policy for Low Risk Devices” (Jan. 2026, fda.gov), is a wrist-worn wearable product.
As Illustrative Example 7 highlights:
A wrist-worn wearable product intended to assess activity and recovery that outputs multiple biomarkers, among with are hours slept, sleep quality, pulse rate, and blood pressure. Sleep is measured via accelerometer, while pulse rate and blood pressure are measured via photoplethysomogram [a non-invasive technique used to detect blood volume changes in peripheral circulation].
The claim relates to general wellness and does not refer to a specific disease or medical condition, and thus is a general wellness claim. In addition, the technology for monitoring these biomarkers does not pose a risk to the safety of users and other persons if specific regulatory controls are not applied. Therefore, this product meets both factors for a low risk general wellness product, provided the product has validated values for blood pressure.
Note: However, if the claims made about any of the product's functionality implied the product's use in a medical or clinical context, the product would not be a low-risk general wellness product. (p. 9; emphasis added)
Needless to say, determining whether or not the device is implanted, external but not a GWP, or a low or high risk GWP is the first step to assessing marketing compliance and the type of approval sought and required by the FDA.
In today's world, it goes without saying that if a device—including a continuous glucose monitor (CGM), a pacemaker, or a CPAP respiratory device—creates, receives, maintains, or transmits health data, it is considered individually identifiable health information (IIHI) that poses cybersecurity risks and breach notification requirements, whether under the Health Information Portability and Accountability Act of 1996 (HIPAA) or the Federal Trade Commission's (FTC) Health Breach Notification Rule.
The remainder of this article focuses on practical considerations for patients and legal considerations for companies and providers.
Practical Considerations for Consumers, Some of Whom Are Patients
While all patients are consumers, not all consumers are patients. Additionally, GWPs or software apps that enable the user to directly input data (i.e., Flo Health, Inc.'s fertility-tracking app) illustrates that privacy and security vulnerabilities exist even when there is no connectivity between the device/GWP and an app or a device/GWP and a company. The FTC honed in on this with its June 22, 2021, enforcement action and settlement with Flo Health, Inc. for the company's failure to obtain consumer consent before sharing their personal health information with other companies for remuneration and failing to obtain an independent review of their privacy practices.
As the FTC noted in “FTC Warns Health Apps and Connected Device Companies to Comply with Health Breach Notification Rule” (Sept.15, 2021), “Health apps and other connected devices that collect personal health data are not only mainstream—and have increased in use during the pandemic—but are targets ripe for scammers and other cyber hacks. Yet, there are still too few privacy protections for these apps.” (emphasis added)
Even today, there are inadequate privacy and security protections on many apps.
Consumers and patients should be vigilant and can mitigate risk by doing the following:
- If a provider prescribes and/or implants a device, even if it is a GWP, then a shared responsibility exists and the patient needs to understand that software updates will occur and may require that they are involved in the timing of the update (e.g., Apple iPhone software updates by way of analogy where the user needs to plug in their phone at night);
- Check the respective app store for software updates; and
- Read the user agreements closely.
Consumers in particular should be mindful of the app that they are downloading. Is it a known entity that they did due diligence on or did they just download any app because they thought it would meet their needs?
Legal Considerations
Companies and providers that create, receive, maintain, or transmit PHI or IIHI must comply with HIPAA when patients are involved. This means meeting HIPAA Privacy Rule and Security Rule requirements. Additionally, companies whose devices require approval by the FDA must ensure that they are disclosing and filing as required by the FD&C Act, the Medical Device Act of 1976, and other related laws and regulations. If artificial intelligence and other algorithms are involved, there may be additional submission requirements for medical devices. Providers and companies should work together to educate patients on how the device works.
Similarly, companies that sell fitness tracking devices and apps should be mindful of similar obligations under the FTC's Breach Notification Rule and the need to obtain consumer consent before sharing data.
The FTC states:
The Commission policy statement notes that apps and connected devices such as wearable fitness tracking devices that collect consumers' health information are covered by the Health Breach Notification Rule if they can draw data from multiple sources, and are not covered by a similar rule issued by the Department of Health and Human Services. For example, a health app would be covered under the FTC's rule if it collects health information from a consumer and has the technical capacity to draw information through an API that enables syncing with a consumer's fitness tracker. Companies that fail to comply with the rule could be subject to monetary penalties of up to $43,792 per violation per day. (ftc.gov)
The two main take-aways are complying with relevant laws and regulations depending on the type of device, app, or item and how it is classified, obtaining either patient or consumer consent per the respective regulations before either marketing or selling data for downstream remunerative purposes (in other words serving as a data broker) and ensuring adequate technical safeguards to mitigate the risk of an attack that either impedes the device from working and/or corrupts the confidentiality, integrity, or availability of the health information.
Additionally, the HHS-OIG and DOJ's Working Group announced on July 2, 2025, that materially defective medical devices that impact patient safety and the manipulation of electronic health records to drive inappropriate utilization of Medicare covered products and services are enforcement priorities. Since GWPs and other FDA approved devices connect directly into an electronic health record system, this is an area to be mindful.
Conclusion
In sum, GWPs, devices, and apps—whether FDA regulated or consumer minded—is an area to watch in terms of government enforcement actions. Privacy and security concerns, as well as manipulation of the data to achieve certain outcomes, and false statements to the FDA and other government agencies, are trends to keep a pulse on. The greatest concern is adverse patient or consumer outcomes, with a close second being the marketing and selling of the health data without the appropriate consent.
Source: Rachel V. Rose, JD, MBA, has a unique background, having worked in many different facets of healthcare throughout her career including: work in acute care hospitals including the operating room and dietary department; consultative work as a top performing representative for the pharmaceutical and medical device industry; work for the Chairman of the Reform and Oversight Committee on Capitol Hill; intern at the Department of Health and Human Services; and compiling policy papers at the Royal College of Nursing in London. She has worked on Wall Street and at one of the Big Four consulting firms. Prior to opening her law firm, she was Director of Business Development and Assistant General Counsel for a healthcare advisory company. She is published and presents on a variety of healthcare topics including: the False Claims Act, the Foreign Corrupt Practices Act, physician reimbursement, ICD-10, access to care, Anti-Kickback and Stark laws, U.S. Supreme Court cases impacting the medical device industry, international comparative healthcare laws, and the HIPAA/the HITECH Act. Her practice focuses on a variety of healthcare and securities law issues related to industry compliance and Dodd-Frank.
Ms. Rose holds an MBA with minors in healthcare and entrepreneurship from Vanderbilt University, and a law degree from Stetson University College of Law, where she graduated with various honors, including the National Scribes Award and The William F. Blews Pro Bono Service Award. Ms. Rose is licensed in Texas. Currently, she is chair of the Federal Bar Association's Corporate and Association Counsel Division, the co-editor of the American Health Lawyers Association's Enterprise Risk Management Handbook for Healthcare Entities (2nd Edition), and Vice-chair of the Distance Learning Committee for the Health Law Section of the American Bar Association, as well as a co-author of the book The ABCs of ACOs and What Are International Business Considerations? Ms. Rose is an Affiliated Member with the Baylor College of Medicine's Center for Medical Ethics and Health Policy, where she teaches bioethics.