PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Fitbit Agrees to Sign Business Associate Agreements and Take on HIPAA Compliance

Posted on September 23, 2015 by pogowasright.org
Eric Thieme of   Faegre Baker Daniels writes:

Is your Fitbit data covered by HIPAA?  It depends upon where you got it (kind of).  If you go to the store and pick up a Fitbit on your own, the data it generates is governed by the user agreement that you click through (which I’m sure everyone read carefully).  If your health plan or employer, through its self-funded health plan, provided you with the fitbit and will receive the data from the device, then it’s subject to HIPAA.

I said “kind of” earlier because you could technically buy your own device and then share the data with the health plan, which would trigger HIPAA compliance.  For a number of years, Fitbit avoided HIPAA compliance by not engaging in data sharing with health plans or healthcare providers.  In a turn of events this week, Fitbit announced it will enter into HIPAA business associate agreements with covered entity health plans and self-insured employers that will offer Fitbit’s wellness platform to employees and insured individuals.

Read more on JDSupra.

Category: BusinessHealthcareU.S.Workplace

Post navigation

← Porn Stars Panicked by California Health Record Subpoenas
Facebook accused of snooping in the EU →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy

RSS Recent Posts on DataBreaches.net

  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach
  • ‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential abuse survivors’ addresses
  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
©2025 PogoWasRight.org. All rights reserved.