“Whispers from the Wrist”: Wearable Health Monitoring Devices and Privacy Regulations in the U.S.: The Loopholes, the Challenges, and the Opportunities
Abstract
:1. Introduction
2. Wearables and Health Data
3. The Issues with Wearables and Health Data
3.1. Lack of Regulation over WHMD and Health Apps Marketed for Consumers
3.2. Privacy Regulations Governing Health Information in the U.S.
3.2.1. HIPAA
3.2.2. HITECH
3.3. Consumer Literacy and Efficacy of Digital Contracts
3.4. Data Brokers and Personal Information
3.5. Summary
4. A Framework for WHMDs and Consumer Health Apps
4.1. The Problem
4.2. Data
4.3. Data Transfer
4.4. Solutions
4.4.1. Federal Framework for Health Data Generated by WHMD for Consumer Use
4.4.2. Data Brokers Regulation
4.4.3. Mandate FDA Approval and/or Regulatory Oversight
4.4.4. Increase Consumer Digital and Health Literacy
4.4.5. Improve Consent and Design Transparency
4.4.6. Improve Security
5. Challenges and Opportunities
6. Discussion
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Kang, H.S.; Exworthy, M. Wearing the Future-Wearables to Empower Users to Take Greater Responsibility for Their Health and Care: Scoping Review. JMIR MHealth UHealth 2022, 10, e35684. [Google Scholar] [CrossRef]
- Angela, C. Engaging Patients in Healthcare; McGraw-Hill Education: Berkshire, UK, 2011. [Google Scholar] [CrossRef]
- Atlantic Council. The Healthcare Internet of Things: Rewards and Risks. Available online: https://www.atlanticcouncil.org/in-depth-research-reports/report/the-healthcare-internet-of-things-rewards-and-risks/ (accessed on 22 April 2024).
- Banerjee, S.; Hemphill, T.; Longstreet, P. Wearable devices and healthcare: Data sharing and privacy. Inf. Soc. 2018, 34, 49–57. [Google Scholar] [CrossRef]
- Cate, F.H.; Mayer-Schönberger, V. Notice and consent in a world of Big Data. Int. Data Priv. Law 2013, 3, 67–73. [Google Scholar] [CrossRef]
- Tariq, M.U. Advanced Wearable Medical Devices and Their Role in Transformative Remote Health Monitoring. In Transformative Approaches to Patient Literacy and Healthcare Innovation; IGI Global: Hershey, PA, USA, 2024; pp. 308–326. [Google Scholar] [CrossRef]
- 10172 and 253. Closing the Data Broker Loophole|Brennan Center for Justice. Available online: https://www.brennancenter.org/our-work/research-reports/closing-data-broker-loophole (accessed on 4 June 2024).
- Ferguson, T.; Olds, T.; Curtis, R.; Blake, H.; Crozier, A.J.; Dankiw, K.; Dumuid, D.; Kasai, D.; O’Connor, E.; Virgara, R.; et al. Effectiveness of wearable activity trackers to increase physical activity and improve health: A systematic review of systematic reviews and meta-analyses. Lancet Digit. Health 2022, 4, e615–e626. [Google Scholar] [CrossRef]
- Kim, K.J.; Shin, D. An acceptance model for smart watches: Implications for the adoption of future wearable technology. Internet Res. Electron. Netw. Appl. Policy 2015, 25, 527–541. [Google Scholar] [CrossRef]
- Hsiao, K.-L.; Chen, C.-C. What drives smartwatch purchase intention? Perspectives from hardware, software, design, and value. Telemat. Inform. 2018, 35, 103–113. [Google Scholar] [CrossRef]
- Piwek, L.; Ellis, D.A.; Andrews, S.; Joinson, A. The Rise of Consumer Health Wearables: Promises and Barriers. PLoS Med. 2016, 13, e1001953. [Google Scholar] [CrossRef]
- IDC—Wearable Devices Market Insights. IDC: The Premier Global Market Intelligence Company. Available online: https://www.idc.com/promo/wearablevendor (accessed on 22 April 2024).
- Masoumian Hosseini, M.; Masoumian Hosseini, S.T.; Qayumi, K.; Hosseinzadeh, S.; Sajadi Tabar, S.S. Smartwatches in healthcare medicine: Assistance and monitoring; a scoping review. BMC Med. Inform. Decis. Mak. 2023, 23, 248. [Google Scholar] [CrossRef]
- Wearables, Virtual Health Are Changing Our Perception of Care. Deloitte United States. Available online: https://www2.deloitte.com/us/en/blog/health-care-blog/2022/wearables-virtual-health-are-changing-our-perception-of-care.html (accessed on 22 April 2024).
- Health App Revenue and Usage Statistics (2024). Business of Apps. Available online: https://www.businessofapps.com/data/health-app-market/ (accessed on 22 April 2024).
- Study Reveals Wearable Device Trends among U.S. Adults|NHLBI, NIH. Available online: https://www.nhlbi.nih.gov/news/2023/study-reveals-wearable-device-trends-among-us-adults (accessed on 22 April 2024).
- Khan, S.; Parkinson, S.; Grant, L.; Liu, N.; Mcguire, S. Biometric Systems Utilising Health Data from Wearable Devices: Applications and Future Challenges in Computer Security. ACM Comput. Surv. 2020, 53, 85:1–85:29. [Google Scholar] [CrossRef]
- Boerman, S.C.; Kruikemeier, S.; Zuiderveen Borgesius, F.J. Online Behavioral Advertising: A Literature Review and Research Agenda. J. Advert. 2017, 46, 363–376. [Google Scholar] [CrossRef]
- Busch, O. Programmatic Advertising: The Successful Transformation to Automated, Data-Driven Marketing in Real-Time; Springer: Berlin/Heidelberg, Germany, 2016. [Google Scholar] [CrossRef]
- The Limits of Transparency: Data Brokers and Commodification—Matthew Crain, 2018. Available online: https://journals.sagepub.com/doi/abs/10.1177/1461444816657096 (accessed on 31 July 2023).
- Researchers FAQs. Fitbit Enterprise. Available online: https://enterprise.fitbit.com/researchers/faqs/ (accessed on 22 April 2024).
- Evenson, K.R.; Goto, M.M.; Furberg, R.D. Systematic review of the validity and reliability of consumer-wearable activity trackers. Int. J. Behav. Nutr. Phys. Act. 2015, 12, 159. [Google Scholar] [CrossRef]
- U.S. Food and Drug Administration. Do Not Use Smartwatches or Smart Rings to Measure Blood Glucose Levels: FDA Safety Communication. FDA April 2024. Available online: https://www.fda.gov/medical-devices/safety-communications/do-not-use-smartwatches-or-smart-rings-measure-blood-glucose-levels-fda-safety-communication (accessed on 22 April 2024).
- Wearables, the FDA and Patient Advice: What Physicians Should Know. American Medical Association. Available online: https://www.ama-assn.org/practice-management/digital/wearables-fda-and-patient-advice-what-physicians-should-know (accessed on 22 April 2024).
- Arslan, B.; Sener, K.; Guven, R.; Kapci, M.; Korkut, S.; Sutasir, M.N.; Tekindal, M.A. Accuracy of the Apple Watch in measuring oxygen saturation: Comparison with pulse oximetry and ABG. Ir. J. Med. Sci. 2024, 193, 477–483. [Google Scholar] [CrossRef]
- Rajakariar, K.; Buntine, P.; Ghaly, A.; Zhu, Z.C.; Abeygunawardana, V.; Visakhamoorthy, S.; Owen, P.J.; Tham, S.; Hackett, L.; Roberts, L.; et al. Accuracy of Smartwatch Pulse Oximetry Measurements in Hospitalized Patients with Coronavirus Disease 2019. Mayo Clin. Proc. Digit. Health 2024, 2, 152–158. [Google Scholar] [CrossRef]
- Understanding HIPAA for Law Firms. Available online: https://legal.thomsonreuters.com/en/insights/articles/understanding-hipaa-for-law-firms (accessed on 4 June 2024).
- Cohen, I.G. Informed Consent and Medical Artificial Intelligence: What to Tell the Patient? Symposium: Law and the Nation’s Health. Georgetown Law J. 2020, 108, 1425–1470. [Google Scholar]
- Hooley, S.; Sweeney, L. Survey of Publicly Available State Health Databases. arXiv 2013. [Google Scholar] [CrossRef]
- IMS. Patient Apps for Improved Healthcare from Novelty to Mainstream; IMS Institute for Healthcare Informatics: Parsippany, NJ, USA, 2013. [Google Scholar]
- Cohen, I.G.; Mello, M.M. HIPAA and Protecting Health Information in the 21st Century. JAMA 2018, 320, 231–232. [Google Scholar] [CrossRef]
- Office for Civil Rights (OCR). Health Information Privacy. Available online: https://www.hhs.gov/hipaa/index.html (accessed on 22 April 2024).
- Office for Civil Rights (OCR). HITECH Act Enforcement Interim Final Rule. Available online: https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html (accessed on 4 June 2024).
- Solove, D.J. Introduction: Privacy self-management and the consent dilemma. Harv. Rev. 2012, 126, 1880. [Google Scholar]
- McDonald, A.M.; Cranor, L.F. The Cost of Reading Privacy Policies. J. Law Policy Inf. Soc. 2008, 4, 543. [Google Scholar]
- Richards, N. Why Privacy Matters; Oxford University Press: Oxford, UK, 2021. [Google Scholar]
- Solove, D.J.; Schwartz, P.M. Privacy Law Fundamentals. Rochester, NY, 20 March 2011. Available online: https://papers.ssrn.com/abstract=1790262 (accessed on 28 February 2024).
- Nissenbaum, H. Privacy as Contextual Integrity Symposium: Technology, Values, and the Justice System. Wash. Law Rev. 2004, 79, 119–158. [Google Scholar]
- Turow, J. Audience Construction and Culture Production: Marketing Surveillance in the Digital Age. Ann. Am. Acad. Pol. Soc. Sci. 2005, 597, 103–121. [Google Scholar] [CrossRef]
- Turow, J.; Lelkes, Y.; Draper, N.; Waldman, A.E. Americans Can’t Consent to Companies’ Use of Their Data: They Admit They Don’t Understand It, Say They’re Helpless to Control It, and Believe They’re Harmed When Firms Use Their Data—Making What Companies Do Illegitimate. Int. J. Commun. 2023, 17, 4796–4817. [Google Scholar] [CrossRef]
- Brinson, N.H.; Eastin, M.S. Juxtaposing the persuasion knowledge model and privacy paradox: An experimental look at advertising personalization, public policy and public understanding. Cyberpsychology J. Psychosoc. Res. Cyberspace 2016, 10, 7. [Google Scholar] [CrossRef]
- Solove, D.J. Murky Consent: An Approach to the Fictions of Consent in Privacy Law; SSRN: Rochester, NY, USA, 2023. [Google Scholar] [CrossRef]
- Susser, D. Notice After Notice-and-Consent: Why Privacy Disclosures Are Valuable Even If Consent Frameworks Aren’t. J. Inf. Policy 2019, 9, 148–173. [Google Scholar] [CrossRef]
- Barnes, S.B. A privacy paradox: Social networking in the United States. First Monday 2006, 11. [Google Scholar] [CrossRef]
- Data Brokers Come Under Greater Scrutiny—WSJ. Available online: https://www.wsj.com/articles/SB10001424052702303874504579377164099831516 (accessed on 22 April 2024).
- Health Insurers Are Vacuuming up Details about You—And It Could Raise Your Rates. NPR. Available online: https://www.npr.org/sections/health-shots/2018/07/17/629441555/health-insurers-are-vacuuming-up-details-about-you-and-it-could-raise-your-rates (accessed on 22 April 2024).
- Scoring Solutions|FICO. Available online: https://www.fico.com/en/customer-lifecycle/scoring-solutions (accessed on 22 April 2024).
- Acxiom Corporation. Annual Report 28 May 2014. Acxiom Corporation: Little Rock, AK, USA, 2014. [Google Scholar]
- Rieke, A.; Yu, H.; Robinson, D.; van Hoboken, J. Data Brokers in an Open Society; Open Society Foundation: London, UK, 2016. [Google Scholar]
- FTC Staff. Protecting Consumer Privacy in an Era of Rapid Change. J. Priv. Confidentiality 2012, 3. [Google Scholar] [CrossRef]
- The Pros and Cons of the House’s Data Broker Bill. Default. Available online: https://www.lawfaremedia.org/article/the-pros-and-cons-of-the-house-s-data-broker-bill (accessed on 3 June 2024).
- Rodgers, S. Themed Issue Introduction: Promises and Perils of Artificial Intelligence and Advertising. J. Advert. 2021, 50, 1–10. [Google Scholar] [CrossRef]
- Data Brokers. EPIC—Electronic Privacy Information Center. Available online: https://epic.org/issues/consumer-privacy/data-brokers/ (accessed on 22 April 2024).
- Cox, D. How overturning Roe v Wade has eroded privacy of personal data. BMJ 2022, 378, o2075. [Google Scholar] [CrossRef]
- Campanella, S. Menstrual and Fertility Tracking Apps and the Post Roe v. Wade Era. Undergraduate Study Research Internships Conf. August 2022. Available online: https://ir.lib.uwo.ca/usri/usri2022/ReOS/238 (accessed on 28 August 2022).
- Shipp, L.; Blasco, J. How private is your period?: A systematic analysis of menstrual app privacy policies. Proc. Priv. Enhancing Technol. 2020, 2020, 491–510. [Google Scholar] [CrossRef]
- Flo—Ovulation Calendar, Period Tracker, and Pregnancy App. Flo.Health—#1 Mobile Product for Women’s Health. Available online: https://flo.health/ (accessed on 22 April 2024).
- Flo Health, Inc. Federal Trade Commission. Available online: https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3133-flo-health-inc (accessed on 4 June 2024).
- FTC Finalizes Changes to the Health Breach Notification Rule. Federal Trade Commission. Available online: https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-finalizes-changes-health-breach-notification-rule (accessed on 4 June 2024).
- Lubarsky, B. Re-Identification of ‘Anonymized Data’. Georgetown Law J. 2017. [Google Scholar]
- These Academics De-Anonymized 99.98% of Americans Using Just 15 Attributes. Available online: https://techmonitor.ai/technology/data/de-anonymized-researchers (accessed on 22 April 2024).
- Chapter 19.373 RCW: Washington My Health My Data Act. Available online: https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true (accessed on 4 June 2024).
- Researchers Find Sensitive Personal Data of US Military Personnel Is for Sale Online|CNN Politics. Available online: https://www.cnn.com/2023/11/06/politics/data-of-military-personnel-for-sale-online/index.html (accessed on 22 April 2024).
- World Privacy Forum Statement on Federal Privacy Regulation & Data Brokers|World Privacy Forum. Available online: https://www.worldprivacyforum.org/2018/10/world-privacy-forum-statement-on-federal-privacy-regulation-data-brokers/ (accessed on 22 April 2024).
- Ng, A. A Company Tracked Visits to 600 Planned Parenthood Locations for Anti-Abortion Ads, Senator Says. POLITICO. Available online: https://www.politico.com/news/2024/02/13/planned-parenthood-location-track-abortion-ads-00141172 (accessed on 4 June 2024).
- Lyons, J. Senator: Data Broker Tracked Visits to Planned Parenthood. Available online: https://www.theregister.com/2024/02/15/data_broker_location_abortion/ (accessed on 4 June 2024).
- Wyden Reveals Phone Data Used to Target Abortion Misinformation at Visitors to Hundreds of Reproductive Health Clinics|U.S. Senator Ron Wyden of Oregon. Available online: https://www.wyden.senate.gov/news/press-releases/wyden-reveals-phone-data-used-to-target-abortion-misinformation-at-visitors-to-hundreds-of-reproductive-health-clinics (accessed on 4 June 2024).
- Institute of Medicine (US) Committee on Health Literacy; Nielsen-Bohlman, L.; Panzer, A.M.; Kindig, D.A. The Extent and Associations of Limited Health Literacy. In Health Literacy: A Prescription to End Confusion. National Academies Press (US): Washington, DC, USA, 2004. Available online: https://www.ncbi.nlm.nih.gov/books/NBK216036/ (accessed on 22 April 2024).
- Miller, T.A. Health literacy and adherence to medical treatment in chronic and acute illness: A meta-analysis. Patient Educ. Couns. 2016, 99, 1079–1086. [Google Scholar] [CrossRef]
- McDonald, A.; Cranor, L.F. Beliefs and behaviors: Internet users understanding of behavioral advertising. Tprc 2010. [Google Scholar]
- Marwick, A.E.; Boyd, D. I tweet honestly, I tweet passionately: Twitter users, context collapse, and the imagined audience. New Media Soc. 2011, 13, 114–133. [Google Scholar] [CrossRef]
- Norberg, P.A.; Horne, D.R.; Horne, D.A. The Privacy Paradox: Personal Information Disclosure Intentions versus Behaviors. J. Consum. Aff. 2007, 41, 100–126. [Google Scholar] [CrossRef]
- Strahilevitz, L.J.; Kugler, M.B. Is Privacy Policy Language Irrelevant to Consumers? J. Leg. Stud. 2016, 45, S69–S95. [Google Scholar] [CrossRef]
- Martin, K. Understanding privacy online: Development of a social contract approach to privacy. J. Bus. Ethics 2016, 137, 551–569. [Google Scholar] [CrossRef]
- Dunfee, T.W.; Smith, N.C.; Ross, W.T., Jr. Social contracts and marketing ethics. J. Mark. 1999, 63, 14–32. [Google Scholar] [CrossRef]
- Nissenbaum, H. Privacy in Context: Technology, Policy, and the Integrity of Social Life. In Privacy in Context; Stanford University Press: Stanford, CA, USA, 2009. [Google Scholar] [CrossRef]
- Sloan, R.H.; Warner, R. Beyond Notice and Choice: Privacy, Norms, and Consent. J. High Technol. Law 2014, 14, 370–414. [Google Scholar] [CrossRef]
- Office for Civil Rights (OCR). The Security Rule. Available online: https://www.hhs.gov/hipaa/for-professionals/security/index.html (accessed on 4 June 2024).
- Federal Trade Commission. Health Breach Notification Rule. Available online: https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule (accessed on 4 June 2024).
- Data Brokers Spend $143M on Lobbying over 3 Years as Privacy Laws in the US Tighten, Incogni Research Finds—Agility PR Solutions. Available online: https://www.agilitypr.com/pr-agency-news/data-brokers-spend-143m-on-lobbying-over-3-years-as-privacy-laws-in-the-us-tighten-incogni-research-finds/ (accessed on 4 June 2024).
- Ng, A. Privacy Bill Triggers Lobbying Surge by Data Brokers. POLITICO. Available online: https://www.politico.com/news/2022/08/28/privacy-bill-triggers-lobbying-surge-by-data-brokers-00052958 (accessed on 4 June 2024).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Sifaoui, A.; Eastin, M.S. “Whispers from the Wrist”: Wearable Health Monitoring Devices and Privacy Regulations in the U.S.: The Loopholes, the Challenges, and the Opportunities. Cryptography 2024, 8, 26. https://doi.org/10.3390/cryptography8020026
Sifaoui A, Eastin MS. “Whispers from the Wrist”: Wearable Health Monitoring Devices and Privacy Regulations in the U.S.: The Loopholes, the Challenges, and the Opportunities. Cryptography. 2024; 8(2):26. https://doi.org/10.3390/cryptography8020026
Chicago/Turabian StyleSifaoui, Asma, and Matthew S. Eastin. 2024. "“Whispers from the Wrist”: Wearable Health Monitoring Devices and Privacy Regulations in the U.S.: The Loopholes, the Challenges, and the Opportunities" Cryptography 8, no. 2: 26. https://doi.org/10.3390/cryptography8020026
APA StyleSifaoui, A., & Eastin, M. S. (2024). “Whispers from the Wrist”: Wearable Health Monitoring Devices and Privacy Regulations in the U.S.: The Loopholes, the Challenges, and the Opportunities. Cryptography, 8(2), 26. https://doi.org/10.3390/cryptography8020026