---
title: Wearable Applications and HIPAA Compliance - TrueVault
description: A guide with everything you need to know about HIPAA compliance as it relates to your application and what steps you need to take to be sure you don't violate the law. Learn more by reading the HIPAA guide.
---

<https://safe.truevault.com/?hsLang=en>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [Personal Data](https://safe.truevault.com/learn/what-is-personal-data)
- [DSAR](https://safe.truevault.com/learn/explaining-gdpr-data-subject-requests)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-phi)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/) 
    - [Resource Center](https://safe.truevault.com/learn/)
    - [TrueVault Safe](https://safe.truevault.com/help/truevault-safe)
- [About](https://safe.truevault.com/about-us)
- [Contact](https://safe.truevault.com/contact-us)
- [Careers](https://careers.truevault.com/)

- Solutions 
    - [GDPR Compliance](https://safe.truevault.com/solutions/gdpr-compliance)
    - [HIPAA Compliance](https://safe.truevault.com/hipaa-compliance)
    - [For Applications](https://safe.truevault.com/solutions/application-compliance)
    - [For Data Exchanges](https://safe.truevault.com/solutions/data-exchange-compliance)
- [Developers](https://safe.truevault.com/resources/index)
- [Pricing](https://safe.truevault.com/safe-pricing)
- [Blog](https://safe.truevault.com/blog)
- [Login](https://console.truevault.com/login)
- [Get Started](https://safe.truevault.com/get-started)

# Wearable Applications and HIPAA Compliance

![adult-apple-watch-arms-893891](https://safe.truevault.com/hs-fs/hubfs/adult-apple-watch-arms-893891.jpg?width=600&name=adult-apple-watch-arms-893891.jpg)

Photo by Rawpixel on Pexels.com

Wearables are popping up left and right. From bands, to watches, to shirts, earbuds and more. All of these devices have the opportunity to collect PHI and require [HIPAA compliance](https://safe.truevault.com/learn/hipaa?hsLang=en). While many will choose to initially collect anonymous data that doesn't require HIPAA protection, the need to add true utility to the devices will likely push many of them down the road to compliance.

As an application developer for wearables it's important to consider whether the data you're collecting now will remain anonymous (such as a simple pedometer report) or if you're building something more ambitious that requires a larger set of personalized data that will be transmitted to HIPAA covered entities (PHI).

If it is the latter, you're likely better off building the software for the wearable in a HIPAA compliant environment to begin with, to protect against unforeseen use cases, unexpected PHI, etc.

## Considerations for wearables

Today's wearables are typically "always on" with data presentation layers that are outside of a protected lock screen or similarly private state. Therefore careful consideration needs to be taken related to how and when health data is presented on the device.

### Alerts and notifications

Much like the push notifications on mobile devices, and alerts generated by your application should be anonymous in nature and devoid of any PHI.

Proactively pushing PHI as part of an alert opens up all sorts of privacy concerns. What happens if the device is on a desk at the office, for instance?

### Default displays

Similarly default displays should be carefully considered. A default display contain PHI is a big privacy issue. Even more mundane and typically anonymous data can be troublesome due to the fact that the device is on the person.

For example, heart rate isn't really an anonymous data point when it's being tracked in real time on the watch face of the person wearing it, now is it?

### APIs and data sharing

One of the most exciting aspects of wearables may be in patient health management and compliance (e.g. does the patient get their exercise in per the doctor's orders?) In order for these apps to be used efficiently in this use case they need to talk seamlessly with the applications and software being run by covered entities.

Covered entities and their business associates are required by law to be HIPAA compliant, so any application hoping to connect to one of these entities as part of patient care must be HIPAA compliant.

### Medical devices

It is possible, based on the features and functionality that you include in your application or wearable device that it may actually be classified as a medical device. It’s important to look up FDA regulations and check whether your app will be considered to be a medical device or not.

If it does fall under those definitions it may require FDA approval which brings with it a whole host of further regulations.

Don’t launch your app until you’ve determined whether or not you are safely outside the FDA’s medical device classification.

### Data encryption

Because most wearables lack a user interface to add or manage security features on the device in the event it is lost or stolen, it's important for wearable software developers to take the appropriate precautions to encrypt the data on the device as the default.

### Data synching

HIPAA requires that data recovery be possible in the event of a disaster or emergency. Therefore, depending on the device you are developing for, you may want to take advantage of proactive synching features instead of waiting for the user to synch the device themselves.

If the device enables background synching over bluetooth or while connected to the main device it's recommended that you take advantage of that opportunity to synch your user's data automatically. Learn more about HIPAA by visiting our [HIPAA resources section](https://safe.truevault.com/learn/hipaa?hsLang=en). 

## [![Get The HIPAA Compliant Checklist](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926)

## Navigation

[Chapter 9: Mobile Applications](http://www-truevault-com.sandbox.hs-sites.com/learn/mobile-applications-and-hipaa-compliance) | [Chapter 11: Apple HealthKit](https://safe.truevault.com/learn/apple-healthkit-and-ios8?hsLang=en)

### **Disclaimer**

### *This article is provided for general informational purposes only and is not intended to be legal advice.  By using the article, you agree that the information on this article does not constitute legal or other professional advice. The article is not a substitute for obtaining legal advice from a qualified attorney licensed in your state. The information on the article may be changed without notice and is not guaranteed to be complete, correct or up-to-date, and may not reflect the most current legal developments.*

### Table of Contents

- Chapter 1: [Introduction to HIPAA Compliance](https://safe.truevault.com/learn/introduction-to-hipaa-compliance?hsLang=en)
- Chapter 2: [What is HIPAA?](https://safe.truevault.com/learn/what-is-hipaa?hsLang=en)
- Chapter 3: [Do I need to be HIPAA Compliant?](https://safe.truevault.com/learn/do-i-need-to-be-hipaa-compliant?hsLang=en)
- Chapter 4: [HIPAA Security Rule](https://safe.truevault.com/learn/the-hipaa-security-rule?hsLang=en)
- Chapter 5: [Becoming HIPAA Compliant](https://safe.truevault.com/learn/becoming-hipaa-compliant?hsLang=en)
- Chapter 6: [Who Certifies HIPAA Compliance?](https://safe.truevault.com/learn/who-certifies-hipaa-compliance?hsLang=en)
- Chapter 7: [HIPAA Fines](https://safe.truevault.com/learn/hipaa-fines?hsLang=en)
- Chapter 8: [Developer Considerations](https://safe.truevault.com/learn/developer-considerations?hsLang=en)
- Chapter 9: [Mobile Applications and HIPAA Compliance](https://safe.truevault.com/learn/mobile-applications-and-hipaa-compliance?hsLang=en)
- Chapter 10: [Wearable Applications and HIPAA Compliance](https://safe.truevault.com/learn/wearable-applications-and-hipaa-compliance?hsLang=en)
- Chapter 11:[ Apple Healthkit](https://safe.truevault.com/learn/apple-healthkit?hsLang=en)

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control?hsLang=en)

 Phillip Walters  / November 7, 2022

### Blog Subscription

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2021 © All Rights Reserved. [Privacy Policy](https://privacy.truevault.com/privacy-policy) | [Terms of Service](https://safe.truevault.com/terms-of-service?hsLang=en)

- <https://www.facebook.com/truevault?fref=ts>
- <https://www.linkedin.com/company/truevault>
- <https://twitter.com/truevault>