Over the last few years, the trend for wearables has shown the potential benefits of transforming healthcare through digital technologies.

Alongside fitness trackers and smartwatches, there are also medical devices used to monitor a patient’s vitals and some even contain SIM cards to enable two-way communication.

Devices such as insulin pumps, heart pacemakers, and inhalers can track patient data in real-time and transmit to the user’s phone, an app, or their doctor, making the data immediately accessible, and often keeping the patient out of the hospital.

However, this presents challenges for healthcare companies. They must now accommodate providers, patients, and third parties, which have access to sensitive patient information while ensuring security and informed consent at all stages along the journey.

Consent on how personal data is used and with whom it is shared is a common concern for consumers and regulators alike. A recent survey by Deloitte showed that in the US, 40% of consumers who used wearables such as fitness trackers, had concerns about data privacy, which rose to 60% when discussing medical data.

Alongside obtaining consent, any organisation dealing with patient data must also ensure compliance with the necessary regulations. Sometimes, data collection and storage may take place in different legal jurisdictions, which can span multiple platforms across other countries with varying data protection laws. And this all requires flexibility and robustness in data management.

Where the data goes from wearable devices

Data collected from wearables is transmitted directly to a smartphone or computer before its eventual transfer to permanent data storage, which usually occurs in proprietary servers. From here, third parties can gain access to the data, provided they have the necessary permissions.

When it comes to where and how this data is stored, an added complexity for healthcare providers is that all of the individual user data won’t necessarily be stored in the same place. Building a complete picture of an individual can be challenging, with patient data coming from many different devices, systems, and touchpoints.

Another issue for data storage is cybersecurity, with the healthcare, pharma, and medical device sectors particularly susceptible to cyberattacks. With patient data being transmitted in real-time, medical device companies are now responsible for large amounts of sensitive electronic patient data.

Data protection laws

Consent within healthcare data is a complex issue. A lack of consent can lead to delayed treatment for patients and penalties for companies if not correctly recorded. From a legal standpoint, consent often has to be collected for each separate piece of data – for example, weight, BP, and heart rate.

While many of us may be happy to share our step-count with others, it’s a very different situation with medical data, which may be sensitive or affect health insurance. Conversely, many people are happy to share their information if they can see a direct benefit, such as a quicker diagnosis or treatment.

Regulations such as the EU’s GDPR, the US’s HIPAA, and California’s CCPA are in place to give people more control over what personal data a company can collect, store and share. Fines for non-compliance can be high, potentially running into millions of euros for breaches of GDPR or up to $50,000 for HIPAA in the US.

