← Back to blogGet Vitra — €19

Wearables in insurance and workplace wellness: who benefits from your data

Written by Pedro Thomaz · 8 MIN READ ·

Insurers offer premium discounts in exchange for activity data. Employers hand out rings and watches as a wellness benefit, often with a team challenge attached. Both models are growing quickly, and both change something fundamental about the numbers on your wrist: they stop being only yours. That is worth thinking through before you accept the free device.

On this page

How these programmes work

They come in two broad shapes. Insurer-linked schemes reward activity data with premium discounts, points, or vouchers, and have been running at scale for years in life and health insurance. Employer wellness programmes subsidise the device itself, wrap it in a challenge, and in some markets connect participation to health-plan contributions. The pitch in both cases is aligned incentives: you get healthier, they pay out less, everybody wins. That is a real argument and it is not obviously wrong. It is just not the whole picture.

What changes when the data has an audience

A measurement that determines a discount is no longer a neutral observation — it is a number you are being paid to produce, which is precisely the condition under which people optimise the metric instead of the underlying thing. Gaming a step count is trivial and well documented, and a programme that rewards steps rewards step-shaped behaviour rather than health. The subtler change is that your data becomes evidence about you: an incomplete, error-prone record carrying your name, held by an organisation whose interests overlap with yours but are not identical to them. A ring that misreads a night as poor sleep is a curiosity when only you see it, and something else when it feeds a score somebody else is scoring you on.

In the EU and UK, health data is a special category under GDPR and needs a strong basis to process. Consent is the usual candidate, but consent must be freely given, and data-protection regulators have repeatedly noted that consent handed to your employer is hard to call free given the power imbalance — which is why employer-run health programmes sit on shakier ground than the enrolment form suggests. In the United States, the point that surprises people most is that HIPAA generally does not cover data held by an employer’s wellness programme or by an app vendor; other rules constrain what employers may do, but the blanket protection most people assume simply is not there. This is general information, not legal advice.

The questions worth asking before you enrol

Ask who holds the raw data as opposed to the derived score, and whether the two are shared with different parties. Ask whether anything reaches an insurer, a broker, an underwriter or an analytics vendor. Ask what happens to the record if you stop participating, change plan, or leave the job — and whether the device stays yours. Ask whether participation is genuinely optional or merely priced, because a discount for joining is a penalty for declining wearing a friendlier name. And ask whether you can have the data deleted on request. If those answers are not easy to find in the programme’s own documentation, that is itself an answer.

Where a local-first app sits in this

Vitra is a desktop app that reads your Oura history and keeps it on your own machine. There is no account holding your health data and no server-side copy of it, which means there is nothing for us to hand to a third party, because there is nothing held — and the coach feature is opt-in and scoped for the same reason rather than switched on by default. Two honest caveats, though. Your ring’s data still lives in the manufacturer’s cloud, because that is where the app syncs it from; choosing a local-first reader limits how many additional parties get a copy, it does not undo the relationship with the device maker. And a licence is still a purchase, so an email address exists on our side even though your nights do not.

Frequently asked questions

Can my employer see my sleep data?
It depends entirely on the programme, which is why the question is worth asking in writing before enrolling. Many schemes are designed so the employer sees only aggregate or threshold data — whether you hit a target — rather than the underlying records. Others are far less restrained, and the distinction is rarely prominent in the marketing.
Does GDPR protect wearable data in a workplace programme?
Health data is a special category under GDPR and requires a strong lawful basis. Consent is the usual one, but regulators have repeatedly questioned whether consent given to an employer can be freely given, given the imbalance of power. That makes employer-run schemes legally more delicate than the sign-up flow implies, though the protection is real and stronger than in the US.
Can an insurer raise my premium based on my ring?
Programmes are generally structured as rewards for participation rather than penalties for data, which amounts to a similar thing from the other direction. What matters is what the contract permits at renewal and whether the data can inform underwriting. Read that before joining rather than after, and treat a discount as a price signal about what your data is worth to them.
Share
About the author
Pedro Thomaz

Pedro Thomaz builds Vitra, a desktop app that reads Oura data against your own baseline instead of a population average. He has worn a ring daily for years and reads these same numbers every morning — which is where most of what is written here comes from. Vitra is not a medical device and nothing on this blog is medical advice.

Try Vitra with your Oura Ring

Local AI on your Mac or PC. One-time purchase, 7-day trial, no Vitra subscription.

Download Vitra →