Back to all lessons
Awareness Lessons
7 months ago

IoT Health Devices Expose Sensitive Biometric Data to Legal and Commercial Exploitation

Internet of Bodies devices like smartwatches, period trackers, and mental health apps are collecting vast amounts of sensitive biometric and health data without adequate protection. Companies including Flo, Premom, and BetterHelp have been caught by the FTC selling or mishandling intimate user data including reproductive health, mental health, and sexual activity information. This uncontrolled data collection creates serious privacy risks, especially as law enforcement agencies expand their use of biometric databases and some states criminalize certain health decisions. The lack of proper data governance and privacy controls means sensitive personal information can be weaponized against vulnerable populations.

Tactical Insight

Immediate actions

  • Organizations should implement comprehensive data privacy programs that include data minimization principles, collecting only necessary information and retaining it for the shortest time possible
  • Strong consent mechanisms must be established that clearly explain data use and provide users meaningful control over their information

Long-term improvements

  • Companies should conduct regular privacy impact assessments, especially for sensitive health data, and implement technical safeguards like encryption and access controls
  • Legal teams should ensure compliance with health data protection regulations and consider the broader implications of data sharing, particularly for vulnerable populations who may face legal or social consequences from data exposure