Who we are
Wearable Technologies Inc. ("WTI" or "Wear-Tech") provides wearable devices and digital health services that collect, store, and securely transmit vital sign and health data to your designated health care providers and partner organizations. WTI acts as a:
- Business Associate (BA) under the federal Health Insurance Portability and Accountability Act (HIPAA). WTI is not a Covered Entity (CE). WTI's HIPAA obligations run to the Covered Entities with whom it holds Business Associate Agreements, specifically your physician, clinic, hospital, or health plan. Requests for access to your health information must be directed to your Covered Entity provider, who will coordinate with WTI as required.
- CMIA Handler: A handler of medical information under the California Confidentiality of Medical Information Act (CMIA), Cal. Civil Code §§ 56–56.37.
Note: WTI does not provide medical treatment, diagnosis, or clinical care. Your physician, clinic, or hospital remains solely responsible for your medical care and clinical decisions.
Information we collect
We collect only the information necessary to provide the services you or your health care provider have requested. The categories of personal information we collect include:
Health and medical data
- Vital sign data (e.g., heart rate, oxygen saturation, blood pressure, respiratory rate)
- Mobility and activity data (e.g., movement patterns, fall events, physical activity levels)
- Device-generated health metrics produced through the use of wearable devices and software applications
Health data collected through our services is used exclusively for the intended purposes of the software: to collect, transmit, and support clinical review of your health status. It is not used for identification, profiling, or any commercial purpose beyond the services agreed upon with your health care provider.
Identifiers and account information
- Full name and date of birth
- Device identifier (unique hardware ID assigned to your Wear-Tech device)
- Contact information (address, telephone number, email address)
- Government-issued identification numbers where required for service enrollment
- Medicare beneficiary number or health insurance member identification number, where applicable for billing and care coordination
Location data
- Geolocation data collected as part of location-based services within our software applications (e.g., GPS coordinates for emergency response functions)
Location data is collected only when the location services function of the applicable software is active. When collected, location data is treated as electronically Protected Health Information (ePHI) under HIPAA and is subject to all applicable security and privacy protections. Location data is not used for advertising, marketing, or any purpose beyond the health and safety functions of the service.
Technical and device data
- Device performance and diagnostic data
- System logs and security monitoring data
- Application usage data necessary to maintain service reliability
Data WTI does not collect
WTI does not collect the following categories of personal information:
- Financial account information (credit card numbers, bank account details)
- Private communications (emails, texts, or messages not generated through WTI's platform)
- Genetic data or genomic information
- Data relating to sexual orientation or gender identity
- Citizenship or immigration status
- Inference data (WTI does not create consumer profiles or behavioral inferences from data collected)
Biometric data
Where our devices or software collect data that may constitute biometric information (such as heart rate waveform patterns or gait analysis derived from motion sensors), such data is collected solely for the intended health data reporting purposes of the software. Biometric data collected by WTI is not used for biometric identification or authentication of any individual. When collected, biometric information is treated as ePHI and subject to all HIPAA Security Rule protections.
Under CPRA, health data, biometric information, and precise geolocation data constitute Sensitive Personal Information. WTI limits its use and disclosure of such data strictly to what is necessary to provide the agreed-upon services, as required by law.
How we use your information
WTI uses your information only to provide the health data collection and transmission services you or your health care provider has engaged us to deliver. We do not use data gathered through our services for commercial purposes outside the services agreed upon. The only commercial use of your data that occurs is within the scope of agreed services delivered by WTI or authorized partner providers.
Specifically, WTI uses your information to:
- Collect and securely transmit vital sign and health data to your designated health care providers, including Physician Practices, Senior Living Communities, Home Health Agencies, Hospitals
- Support Remote Patient Monitoring (RPM), Chronic Care Management (CCM) and Remote Therapeutic Monitoring (RTM) service delivery
- Maintain and support system performance, device reliability, and application security
- Improve service functionality in the context of the services provided to you
- Comply with legal and regulatory requirements
- Support billing and care coordination with your health care provider and, where applicable, Medicare or your health insurer
What we do not do
- We do not sell your personal or health information
- We do not share your information for cross-context behavioral advertising
- We do not use your information for marketing to you or to third parties
- We do not use your information for employment or insurance underwriting decisions
- We do not use your information for any purpose outside the scope of services agreed upon with you or your health care provider
Legal bases for use and disclosure
Our use and disclosure of your information is permitted under the following legal authorities:
Under HIPAA (as Business Associate)
As a Business Associate, WTI may use and disclose Protected Health Information (PHI) as permitted or required by our Business Associate Agreements with Covered Entities, and as permitted by the HIPAA Privacy Rule (45 CFR Part 164), including:
- Treatment: to support the delivery of health care services to you by your physician or health care provider
- Payment: to support billing, claims submission, and health plan administration on behalf of your Covered Entity provider
- Health Care Operations: for quality assessment, care coordination, and operational activities of the Covered Entity we serve
- As required by law: where federal or state law requires disclosure
Example of treatment use: WTI transmits your heart rate and oxygen saturation data in real time to your physician's clinical dashboard so your care team can monitor your status between office visits.
Example of payment use: WTI provides service delivery records to support your physician's billing of Remote Patient Monitoring services to Medicare or your health insurer.
Example of health care operations use: WTI reviews de-identified device performance data in aggregate to identify device reliability issues and improve service quality across the patient population it serves.
Under CMIA (California)
- With patient written authorization meeting the requirements of Cal. Civil Code § 56.11
- For treatment and care coordination by the patient's health care providers
- As required by limited statutory exceptions under California law
Disclosures requiring your authorization
Except as described in the Permitted Disclosures section below, WTI will not use or disclose your health information without a valid written authorization from you. Under CMIA, a valid written authorization must include:
- Your name
- The name of WTI or the Covered Entity authorized to make the disclosure
- The name or description of the person or entity to whom disclosure is authorized
- A description of the specific information to be disclosed
- The purpose of the disclosure
- An expiration date or expiration event
- Your signature and the date signed
You have the right to revoke an authorization at any time by submitting a written revocation to your Covered Entity provider's Privacy Officer. Revocation does not apply to disclosures already made in reliance on the authorization.
Permitted disclosures without authorization
As a Business Associate, WTI may disclose PHI without patient authorization in the following circumstances, as permitted or required by applicable law. These disclosures are made through or in coordination with the Covered Entity we serve:
- Public health activities: to public health authorities authorized to collect or receive information for the purpose of preventing or controlling disease, injury, or disability
- Abuse, neglect, or domestic violence: to government authorities authorized to receive reports of abuse, neglect, or domestic violence where required or permitted by law
- Health oversight activities: to health oversight agencies for activities authorized by law, including audits and investigations
- Judicial and administrative proceedings: in response to a court order, subpoena, or other lawful process
- Law enforcement: to law enforcement officials for limited purposes as permitted by the HIPAA Privacy Rule
- Decedents: to coroners, medical examiners, and funeral directors as authorized by law
- Serious threats to health or safety: to prevent or lessen a serious and imminent threat to the health or safety of a person or the public
- National security and intelligence: to authorized federal officials for intelligence, counterintelligence, or other national security activities
- Required by law: any other disclosure required by applicable federal or state law
WTI will notify the Covered Entity of any such disclosure as required by our Business Associate Agreement.
Your rights under HIPAA
Because WTI serves as a Business Associate and not a Covered Entity, your HIPAA rights with respect to your Protected Health Information are exercised through the Covered Entity (your physician, clinic, hospital, or health plan) that is responsible for your care. Please contact your health care provider's Privacy Officer to exercise the following rights. WTI will cooperate with and support the Covered Entity in fulfilling your requests.
Right to access and receive copies
You have the right to access and receive copies of your health information maintained by your Covered Entity provider. You may also request an electronic copy of information maintained in an electronic health record. Your provider will coordinate with WTI to fulfill your request.
Right to request amendment
You have the right to request that your Covered Entity provider amend health information that you believe is incorrect or incomplete. Your provider may deny the request under limited circumstances as permitted by law.
Right to an accounting of disclosures
You have the right to request a list of certain disclosures of your health information made by the Covered Entity or its Business Associates during the prior six years. Not all disclosures must be included in an accounting.
Right to request restrictions
You have the right to request restrictions on how your health information is used or disclosed. Your Covered Entity is not required to agree to most restriction requests, except in one circumstance: if you pay for a service entirely out of pocket and request that your provider not disclose information about that service to your health plan, your provider must comply with that request.
Right to request confidential communications
You have the right to request that your health care provider communicate with you about your health information in a specific way or at a specific location (for example, only by mail to a particular address). Your provider must accommodate reasonable requests.
Right to receive breach notification
You have the right to receive notification if there is a breach of your unsecured Protected Health Information. See the Breach Notification section of this notice.
To exercise any of the rights described above, please contact your health care provider's Privacy Officer directly. You may also contact WTI's Privacy Officer using the information at the end of this notice, and we will direct you to the appropriate Covered Entity contact.
Your rights under CMIA (California medical privacy law)
California's Confidentiality of Medical Information Act (Cal. Civil Code §§ 56–56.37) provides additional protections for your medical information beyond those required by federal HIPAA law. Under CMIA you have the right to:
- Prevent unauthorized disclosure of your medical information
- Receive written authorization before your medical information is disclosed (except as required by law or for treatment and care coordination)
- Revoke authorization for disclosure of your medical information at any time in writing
- Receive notification if your medical information has been subject to unauthorized access or disclosure
- Control disclosure of sensitive categories of medical information
- Bring a civil action for damages if your medical information is negligently or willfully disclosed in violation of CMIA
CMIA provides a private right of action. If your medical information is improperly disclosed, you may bring a civil action for actual damages, nominal damages of no less than $1,000 per violation, punitive damages up to $3,000 for willful violations, plus attorney's fees and costs. These remedies are in addition to any remedies available under HIPAA.
To exercise your rights under CMIA, contact your health care provider's Privacy Officer. You may also contact WTI's Privacy Officer at the address below.
Automated technology and artificial intelligence
WTI uses artificial intelligence (AI) and automated software technology in certain of its products. The following describes how AI is used, its scope, and its limitations:
- Purpose: WTI's AI technology is used to enhance event detection functions within our software applications, for example, to assist in identifying potential fall events or anomalous vital sign patterns that may require clinical attention.
- Human oversight: All responses and outputs generated by WTI's AI are governed by human oversight. WTI's AI is not autonomous. No AI-generated alert or determination results in any automated action that affects your care without human review.
- Updates and training: WTI's AI and software models are updated exclusively through human input and a supervised development process. The AI does not self-modify, self-train, or update its own parameters without human direction.
- Not a clinical decision-maker: WTI's AI assists with event detection and data flagging only. It does not diagnose, prescribe, or make clinical decisions. All clinical decisions remain the responsibility of your licensed health care provider.
Data used in AI event detection functions is used exclusively for those functions within the scope of the agreed services. AI-generated outputs are treated as health data and are subject to all applicable HIPAA and CMIA protections.
Biometric and sensitive data
WTI recognizes that certain data it collects requires heightened protection. The following describes how WTI handles biometric and other sensitive categories of information:
Biometric data
Where WTI's devices or software collect data that may constitute biometric information (including but not limited to physiological signal patterns, waveform data, or motion-based data), such data is collected solely for the health data reporting purposes of the applicable software. Biometric data is not collected for biometric identification, and WTI does not use biometric information to identify individuals. All biometric data collected in connection with WTI services is treated as ePHI under HIPAA and is stored, transmitted, and disposed of in accordance with the HIPAA Security Rule.
Sensitive personal information
Under California law, WTI treats the following as Sensitive Personal Information (SPI), subject to heightened use restrictions:
- Health and medical data
- Biometric information (as described above)
- Precise geolocation data (when collected through location services)
- Government identification numbers and health insurance identifiers
WTI does not use Sensitive Personal Information for any purpose other than providing the services you have requested or as required by law. WTI does not sell, share for advertising, or otherwise use SPI beyond the scope of the agreed services.
Data retention
WTI retains your personal and health information for a standard period of ten (10) years from the date of collection or last service activity, whichever is later. This retention period applies to all categories of personal information collected by WTI, including Protected Health Information, and is designed to satisfy:
- HIPAA requirements for Business Associate documentation and records (45 CFR § 164.530(j), requiring a six-year minimum)
- California health record retention requirements (seven years from date of service for adult patients)
- Legal, audit, tax, and regulatory compliance requirements
- Investigative and security obligations
Following the applicable retention period, WTI will securely destroy or de-identify your information in accordance with HIPAA Safe Harbor or Expert Determination de-identification standards. Records will not be retained beyond the ten-year period except where required by a legal hold, ongoing litigation, regulatory investigation, or applicable law requiring a longer retention period.
Note: Health information incorporated into records maintained by your Covered Entity provider may be subject to the retention policies of that provider, which may differ from WTI's ten-year standard.
Our responsibilities
WTI is required by law to:
- Maintain the privacy and security of your Protected Health Information
- Provide you with this Notice of Privacy Practices
- Abide by the terms of this notice currently in effect
- Implement administrative, physical, and technical safeguards to protect your information
- Maintain written Business Associate Agreements with all Covered Entities we serve
- Apply the HIPAA "minimum necessary" standard, which requires using and disclosing only the minimum amount of information necessary to accomplish the purpose of the use or disclosure
- Provide breach notification as required by HIPAA, CMIA, and California breach notification law
- Not retaliate against you for exercising your privacy rights
- Not condition treatment or services on your agreement to uses or disclosures not otherwise permitted by law
Security safeguards
WTI's security program includes:
- Encryption of health data in transit and at rest
- Role-based access controls limiting access to authorized personnel only
- Multi-factor authentication for all systems holding ePHI
- Routine security monitoring and audit logging
- Vendor and sub-contractor oversight with written contractual protections (sub-Business Associate Agreements where required)
- Annual security risk analysis and risk management program
Breach notification
If WTI discovers a breach of unsecured Protected Health Information, WTI will act as follows:
- Covered Entity notification: Notify your Covered Entity (your health care provider or health plan) without unreasonable delay and no later than sixty (60) days after discovery of the breach, as required by 45 CFR § 164.410.
- Individual notification: Your Covered Entity will notify you of the breach as required by HIPAA (45 CFR § 164.404) and California law (Cal. Civil Code § 1798.82 and CMIA § 56.06). Individual notification must be provided without unreasonable delay and, for HIPAA purposes, no later than 60 days following discovery. California law may require notification in a more expedient timeframe.
- HHS notification: For breaches affecting 500 or more residents of a state or jurisdiction, the Covered Entity will notify the Secretary of the U.S. Department of Health and Human Services simultaneously with individual notification. For smaller breaches, WTI and the Covered Entity will maintain a log for annual reporting.
- Regulatory reporting: WTI will report to California regulatory authorities and other applicable regulators as required by state and federal law.
Breach notifications will include: a description of what occurred; the types of information involved; steps you should take to protect yourself; steps WTI and the Covered Entity are taking to investigate, mitigate harm, and prevent future breaches; and contact information for questions.
Changes to this notice
WTI reserves the right to update this Notice of Privacy Practices. Any revised notice will apply to all health information we maintain, including information created or received before the revision. Changes will be:
- Posted on our website at www.wear-tech.com
- Made available in paper form upon request at any WTI location
- Provided to you or your health care provider upon request
WTI conducts an annual review of this Notice and updates it as needed to reflect changes in law, regulation, or WTI's practices. The effective date at the top of this Notice reflects the date of the most recent revision.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with:
- WTI's Privacy Officer using the contact information below
- The U.S. Department of Health and Human Services, Office for Civil Rights (OCR): www.hhs.gov/ocr/privacy/hipaa/complaints or 1-800-368-1019
- The California Attorney General (for CMIA violations): oag.ca.gov
You will not be retaliated against for filing a complaint with WTI or with any government authority. Filing a complaint will not affect the services you receive.
Submit a Privacy Rights Request
Exercise your rights under HIPAA, CCPA/CPRA, CMIA, and FTC Health Breach Notification Rule. Requests are acknowledged within 10 business days and fulfilled within 45 calendar days.
Contact information
Privacy Officer, Wearable Technologies Inc.
Email: privacy@wear-tech.com
Mailing Address: 1806 State Road 83, Hartland Wisconsin 53029
Telephone: 414-567-8500