I think a whole generation of fitbit users are going to be horrified when their insurance premiums go up based on data that was purchased by insurers. If Apple watch starts making a health play, I don't see why it would be any different.
I think a whole generation of fitbit users are going to be horrified when their insurance premiums go up based on data that was purchased by insurers. If Apple watch starts making a health play, I don't see why it would be any different.
The good news is you're protected by the law. Under the Affordable Care Act, insurers can only vary your rate based on your age, location, and whether you smoke. They can't take into account prior health conditions or biomarkers, including novel biomarkers measured on wearables.
Every major Republican "repeal & replace" bill has preserved this part of the law, called "rating factor limitations", although sometimes they vary the constants. For example, the Paul Ryan plan let insurers charge the elderly 5x more than the young, compared to the current law of 3x, but otherwise preserved the rule that insurers can only vary rate based on age, location, and whether you smoke.
What insurers can do is offer you a 30% (maximum) premium rebate for taking healthy actions, like going for a run, enrolling in a diabetes prevention program, or getting your blood pressure checked. But they can't tie the rebate to the outcome of the test (health status), only your participation.
This is a good point, though, and shows a case where regulation helps technology have a positive impact. If people fear their insurance premiums will go up, they'll avoid all forms of diagnosis, not just Apple Watch.
Yet.
It might not always be the case but they can future-proof that claim by keeping that data on your device or protect it using differential privacy.
What might happen if health plans become habitually based on tracking (which I expect will be the case) is that having an Apple watch (or nothing) will be considered suspicious and charged a premium.
1. The extremely lucrative market of personal data
2. Their continued collection of such personal data
Some company do sell the data they have behind the scene (Experian is one of them) but there are few buyers, those buyers can tell their data is of bad quality and they have competitors with similar data, so it is hardly lucrative.
As far as I can tell, Apple’s efforts to make articles readable by removing JS-embeds a while ago, encrypt iMessage, fight the FBI about weakening their security or to fight against cross-site cookies more recently, all that seems both real and representative of how they value their product. I have not seen crowds ask for differential privacy and yet they spend precious time in their recent keynotes about it.
Apple is aggressively privacy focused. Apple is the most valuable company in the world, and none of that money has come from selling users' data despite the fact that they're sitting on probably the second most valuable corporate dataset in the world (behind Google).
And while Fitbit might also be very clear about their users' privacy, they don't share one quality Apple has: a virtual guarantee that they won't go under new ownership in the near future.
They have borrowed an identical copy of the auto insurance industry playbook [1]. Start out by offering "discounts" in exchange for tracking, and then slowly the cost of the insurance ramps up, unless you have the discount.
[0] https://www.macrumors.com/2017/10/24/vitality-uk-free-apple-...
Short term regressions to that seem likely enough. Long term I think you have to consider whether we even stick to anything resembling the model we have now (with mandatory private insurance being something like the baseline expectation).
However, this page does speak for Fitbit: https://www.fitbit.com/legal/privacy
For insurers to purchase data on Fitbit users, they'll have to purchase it from the users themselves.
I do know something about the financial incentives, though. Fitbit's users are its customers. Insurers and employers are a small part of revenue. The people Fitbit needs to keep happy are users.
There is stuff like If we are involved in a merger, acquisition, or sale of assets, we will continue to take measures to protect the confidentiality of personal information and give affected users notice before transferring any personal information to a new entity.
But "measures" and "notice" are pretty weak sauce if they can result in the new entity still doing whatever it wants with the data. How about an explicit opt in policy that would actually impact the sale value of the data?
Either Fitbit's acquirer is contractually bound by the privacy policy or it isn't. If it isn't, then the specifics about acquisition don't add anything. If it is, then "We pledge...to never sell your personal data" is enough.
FWIW, Fitbit's publicly traded stock is non-voting, so hostile takeover is not possible.
It's kinda maybe in there already, but not directly (there is an offer to delete data and the language about continuing to use the service given a change).
I consider the pledge to be nearly meaningless. It's certainly a statement of good faith from the people working at and controlling the company today, but without any sort of legal teeth, it's also little more than a wet napkin.
http://lawprofessors.typepad.com/contractsprof_blog/2010/08/...
Fitbit seems like a cool company and I don’t personally distrust them, but I don’t think that particular argument holds water.
I don't really see what the analogous situation would be with insurers and Fitbit. Fitbit won't lose customers to a competitor that violates their privacy.