PrivacySignal
Healthcare

🏃 Fitness Tracker Privacy Fails | EFFector 38.14

EFF — Deeplinks · · International · Healthcare Privacy

The Electronic Frontier Foundation reviewed how fitness tracker companies handle the sensitive health data collected by wearables like watches, bands, and rings. Their findings indicate that despite widespread adoption of these devices, manufacturers are doing far less than they could to protect users' data from outside access.

Why this matters: Your fitness tracker knows things your doctor might not. Resting heart rate, sleep patterns, menstrual cycles, stress levels — this data is deeply personal, and most people hand it over without reading a word of the privacy policy. The companies collecting it are not hospitals. They are not bound by HIPAA. That means they can share, sell, or lose your data with very little accountability. The risk is not abstract. Health data can affect insurance, employment, and personal safety. If a device is marketed as being for your health, it should actually protect it.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
DataBreaches.net · · International

HHS Releases Updated Security Risk Assessment Tool

From HHS OCR: The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) are pleased to announce the release of version 3.7 of the Security Risk Assessment (SRA) Tool. To help you make the most of these updates, ONC and OCR... Source

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices

The FDA has published a discussion paper inviting public input on how generative AI tools used in medical devices should be regulated. The agency is in early stages of developing a framework for these technologies.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · General readers · AI governance · Policy

#healthcare#regulation#ai Read original →
Healthcare
HIPAA Journal · · US Federal

HHS Updates Security Risk Assessment Tool

The U.S. Department of Health and Human Services has released version 3.7 of its Security Risk Assessment Tool, designed to help covered entities evaluate their compliance with HIPAA security requirements.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to […] The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →
Healthcare
HIPAA Journal · · US Federal

High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect

Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, […] The post High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →
Healthcare
HIPAA Journal · · US Federal

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Wellstar Health System and Cone Health (operating as Moses H. Cone Memorial Hospital) have agreed to settle class action lawsuits tied to the use of tracking pixels on their websites or patient portals. The settlements resolve claims that the hospitals shared patient data with third parties through embedded tracking technology.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →